Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.
39,409 vulnerabilities found (page 73 of 1577)
| CVE ID | Plugin / Theme | Severity | CVSS | Description | Fixed In | Source |
|---|---|---|---|---|---|---|
| 4a263b74-e9ae-4fd2-be9b-9b8e9eee5982 | < 1.5.6 |
CRITICAL | 9.8 | The Adning Advertising plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation … | — | wordfence |
| 4a154c3f-e2c4-454d-94f9-539d8b289e4e | < 3.1.4 |
CRITICAL | 9.8 | The Ajar in5 Embed plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in a… | — | wordfence |
| 49ea8af1-7171-4498-bfb0-bb3cbd72e6f3 | < 5.1 |
CRITICAL | 9.8 | The Limit Login Attempts (Spam Protection) WordPress plugin before 5.1 does not sanitise and escape some parameters befo… | — | wordfence |
| 49e133c9-5d3b-4a2a-8385-e2db44baa217 | < 1.5.4 |
CRITICAL | 9.8 | The Doccure Core plugin for WordPress is vulnerable to privilege escalation in versions up to, and excluding, 1.5.4. Thi… | — | wordfence |
| 49cac6e5-c224-49f3-9f3d-07b07fc5e4cc | < 3.15.2 |
CRITICAL | 9.8 | The User Profile Builder โ Beautiful User Registration Forms, User Profiles & User Role Editor plugin for WordPress is… | — | wordfence |
| 49ca1e15-b015-4e9e-bb79-be3968689609 | CRITICAL | 9.8 | The Userpro plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 5.1.9. This mak… | — | wordfence | |
| 49ae7971-7bdf-4369-b04b-fb48ea5b9518 | < 2.6.1 |
CRITICAL | 9.8 | The ็ฎๆฐ้้ๅจ (Keydatas) plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type val… | — | wordfence |
| 496b1c3a-7fbb-4088-9936-6b023718946d | < 3.4.22 |
CRITICAL | 9.8 | The My Calendar plugin for WordPress is vulnerable to [blind|generic|time-based] SQL Injection via the 'from' and 'to' p… | — | wordfence |
| 494ef738-c900-4d00-8739-3b261586d4ff | CRITICAL | 9.8 | The Wux Blog Editor plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 3.0.0.… | — | wordfence | |
| 494c780d-5441-407d-8947-e56d7cac32d6 | < 3.9.8 |
CRITICAL | 9.8 | The MStore API plugin for WordPress is vulnerable to Unauthenticated Blind SQL Injection via the 'store_id' parameter in… | — | wordfence |
| 491f44fc-712c-4f67-b5c2-a7396941afc1 | < 3.6.1 |
CRITICAL | 9.8 | The Post SMTP โ Complete SMTP Solution with Logs, Alerts, Backup SMTP & Mobile App plugin for WordPress is vulnerable … | — | wordfence |
| 48f7ad3b-608b-4802-b7ab-fad4c449cc62 | < 2.6.1.4 |
CRITICAL | 9.8 | The SP Projects & Document Manager plugin for WordPress is vulnerable to arbitrary file uploads in versions up to, and i… | — | wordfence |
| 48e7acf2-61d4-4762-8657-0701910ce69b | < 0.0.9.19 |
CRITICAL | 9.8 | The InstaWP Connect plugin for WordPress is vulnerable to unauthorized access of data, modification of data and loss of … | — | wordfence |
| 48add930-a350-4828-84a0-e1207a9b239b | < 3.26 |
CRITICAL | 9.8 | The Kalium 3 | Creative WordPress & WooCommerce Theme theme for WordPress is vulnerable to Remote Code Execution in all … | — | wordfence |
| 48950965-f7da-42af-9f9a-4bf7fd33be45 | < 7.0 |
CRITICAL | 9.8 | The AR for WooCommerce plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation … | — | wordfence |
| 48949329-8918-4d37-9f3a-1005e99d7e4d | < 1.7.0 |
CRITICAL | 9.8 | The Advanced Booking Calendar WordPress plugin before 1.7.0 does not validate and escape the calendar parameter before u… | — | wordfence |
| 4893d7a7-6e37-4b58-b7ae-53feb0c85ff5 | CRITICAL | 9.8 | The Uploadify plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'p… | — | wordfence | |
| 4848292a-0378-4e0c-a95f-3232c5ce9b9f | CRITICAL | 9.8 | The The Business theme for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 1.6.1 via d… | — | wordfence | |
| 4830fb09-c138-4316-bdde-c233d58b0d91 | < 5.1.9 |
CRITICAL | 9.8 | The UserPro - Community and User Profile WordPress Plugin plugin for WordPress is vulnerable to unauthenticated account … | — | wordfence |
| 481c738e-d544-4587-8632-e85a7ddd8b14 | < 3.6.17 |
CRITICAL | 9.8 | The WatchTowerHQ plugin for WordPress is vulnerable to a type juggling issue in versions up to, and including, 3.6.16. T… | — | wordfence |
| 4770441f-5d8b-4edb-93e3-d2d73f145d26 | < 2.0.9 |
CRITICAL | 9.8 | SQL injection vulnerability in wp-download_monitor/download.php in the Download Monitor 2.0.6 plugin for WordPress allow… | — | wordfence |
| 476df648-5024-42af-9bbd-a5a98e79453f | < 1.8.5 |
CRITICAL | 9.8 | The Ovatheme Events Manager plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type valida… | — | wordfence |
| 4750b57e-7d8d-49d7-bbbf-46483eb97bd9 | CRITICAL | 9.8 | The Tiger theme for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 101.2.1. This … | — | wordfence | |
| 474ad5a5-6384-41cb-a60b-e25477d48ad7 | CRITICAL | 9.8 | upload.php in the Powerplay Gallery plugin 3.3 for WordPress allows remote attackers to create arbitrary directories via… | — | wordfence | |
| 4712b12f-097b-4106-b2ba-e4c6cb7c32c2 | < 1.0.1 |
CRITICAL | 9.8 | The WP-Mobile-BankID-Integration plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and exclu… | — | wordfence |
EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.
Scan My Website →