Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.
39,406 vulnerabilities found (page 72 of 1577)
| CVE ID | Plugin / Theme | Severity | CVSS | Description | Fixed In | Source |
|---|---|---|---|---|---|---|
| 4d79df74-bb28-412b-bba1-9f8a40ae981d | < 1.2.25 |
CRITICAL | 9.8 | The Appointment Booking Calendar plugin for WordPress is vulnerable to generic SQL Injection via any of the 'specialDat… | — | wordfence |
| 4d739821-569d-42d7-a4c5-70e32d5d41a1 | < 5.2.9 |
CRITICAL | 9.8 | The The Plus Addons for Elementor Page Builder plugin for WordPress is vulnerable to Local File Inclusion in all version… | — | wordfence |
| 4d476336-e997-4379-a8f6-963ae22b2417 | CRITICAL | 9.8 | The Relais 2FA plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 1.0. This i… | — | wordfence | |
| 4d3fd9b8-b9b7-4884-9188-6bf255058323 | < 1.3.59 |
CRITICAL | 9.8 | The Users Ultra Membership, Users Community and Member Profiles With PayPal Integration Plugin plugin for WordPress is v… | — | wordfence |
| 4d38167c-47f8-473c-94de-91d9b439ddde | < 7.6 |
CRITICAL | 9.8 | The Indeed Membership Pro plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validati… | — | wordfence |
| 4d0a3cad-baa6-4de3-9420-c2d575dfd868 | CRITICAL | 9.8 | Multiple plugins by itayamar for WordPress have been compromised via a supply chain attack. This is due to an abandoned … | — | wordfence | |
| 4d052f3e-8554-43f0-a5ae-1de09c198d7b | < 3.7.8 |
CRITICAL | 9.8 | The Stripe Payment Plugin for WooCommerce plugin for WordPress is vulnerable to authentication bypass in versions up to,… | — | wordfence |
| 4ce039cd-2662-4cc3-9d38-932be7b7726d | < 3.8.8 |
CRITICAL | 9.8 | The PayU CommercePro Plugin plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and inclu… | — | wordfence |
| 4cb77a63-360b-4917-8a3c-263f5282742c | < 2.0.3 |
CRITICAL | 9.8 | The Pricing Deals for WooCommerce plugin for WordPress is vulnerable to SQL Injection via the 'term' parameter in versio… | — | wordfence |
| 4cada002-1fae-43fa-b1e0-e71afb223c53 | < 1.3.1 |
CRITICAL | 9.8 | The clanora theme for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in all versi… | — | wordfence |
| 4c8f2872-06ff-41a2-b601-77a47470de0c | < 4.0.4 |
CRITICAL | 9.8 | The Cost Calculator Builder PRO plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and i… | — | wordfence |
| 4c747e6f-31fc-41b0-ba62-f009b5483696 | < 4.4.1 |
CRITICAL | 9.8 | The package simple-git is vulnerable to Remote Code Execution in versions before 3.15.0 when the ext transport protocol … | — | wordfence |
| 4c64089a-929c-4a36-8aa8-61a5c9e8562b | < 5.4.15 |
CRITICAL | 9.8 | The Woffice CRM theme for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, an… | — | wordfence |
| 4c5c757f-8546-4a95-a9f4-92d59106aa83 | < 1.3.0 |
CRITICAL | 9.8 | The PowerPack for LearnDash plugin for WordPress is vulnerable to unauthorized modification of data that can lead to pri… | — | wordfence |
| 4c367565-75f7-4dd7-a2f1-111df581bd7a | < 1.1.8 |
CRITICAL | 9.8 | The Appointment Booking Calendar Plugin and Online Scheduling Plugin – BookingPress plugin for WordPress is vulnerable… | — | wordfence |
| 4bbb0146-436f-42fa-802b-cdcf39ae97db | < 4.0.27 |
CRITICAL | 9.8 | The Event Manager, Events Calendar, Tickets, Registrations – Eventin plugin for WordPress is vulnerable to unauthorize… | — | wordfence |
| 4b8d057b-1909-46d4-8e0a-d5c7c9f7001c | < 3.3.1 |
CRITICAL | 9.8 | The Relevanssi plugin for WordPress is vulnerable to SQL Injection via the ‘category_name’ parameter in versions up … | — | wordfence |
| 4b704c42-181b-47cb-9df8-3b82f7b830e1 | < 1.1.24 |
CRITICAL | 9.8 | The appointment-booking-calendar plugin before 1.1.24 for WordPress has SQL injection, a different vulnerability than CV… | — | wordfence |
| 4b585243-943d-48d4-bee3-407ff3ae8078 | < 1.9.9.5 |
CRITICAL | 9.8 | The VibeBP plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.9.9.4.1. T… | — | wordfence |
| 4b40e33b-4aa8-4378-b044-a8a636d34f73 | CRITICAL | 9.8 | The Referrer Detector plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 4.2.1… | — | wordfence | |
| 4b39c8e1-f2b7-436d-97d1-2d503d7ac835 | < 3.2.5 |
CRITICAL | 9.8 | The wp-all-import plugin before 3.2.5 for WordPress has blind SQL injection. | — | wordfence |
| 4b2d685f-0426-4837-bf96-07ebda499bed | CRITICAL | 9.8 | The Blog Designer PRO for WordPress plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and in… | — | wordfence | |
| 4b0e763e-f03e-41fb-8c6c-4de5d3acae00 | < 2.6.7 |
CRITICAL | 9.8 | The Ultimate Member plugin for WordPress is vulnerable to privilege escalation in versions up to, and including, 2.6.6. … | — | wordfence |
| 4ad379ad-8733-4015-a892-375604339695 | < 15.8 |
CRITICAL | 9.8 | SQL injection vulnerability in the WP Symposium plugin before 15.8 for WordPress allows remote attackers to execute arbi… | — | wordfence |
| 4aa89fab-b6fe-423a-a7f5-dbe6c92d1b56 | < 3.8.7.6 |
CRITICAL | 9.8 | SQL injection vulnerability in the WP e-Commerce plugin before 3.8.7.6 for WordPress allows remote attackers to execute … | — | wordfence |
EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.
Scan My Website →