Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.
39,409 vulnerabilities found (page 74 of 1577)
| CVE ID | Plugin / Theme | Severity | CVSS | Description | Fixed In | Source |
|---|---|---|---|---|---|---|
| 470fbac6-45bf-400e-b415-32e7989abbad | < 3.0 |
CRITICAL | 9.8 | The Popup Builder plugin 2.2.8 through 2.6.7.6 for WordPress is vulnerable to SQL injection (in the sgImportPopups funct… | — | wordfence |
| 470285d6-b309-409c-b2c3-8766a0cf9e98 | < 3.1.5 |
CRITICAL | 9.8 | The ProductX – WooCommerce Builder & Gutenberg WooCommerce Blocks plugin for WordPress is vulnerable to PHP Object Inj… | — | wordfence |
| 46f3cc62-c2d8-45af-bb92-c2040789cbc0 | < 2.2.1 |
CRITICAL | 9.8 | The HT Mega plugin for WordPress is vulnerable to Missing Authorization in versions up to, and including, 2.2.0. This is… | — | wordfence |
| 46f31a60-0a0e-449d-a10a-3cafd0492a9c | CRITICAL | 9.8 | The Recently Viewed Products plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including… | — | wordfence | |
| 46d83cc9-0094-4f08-a8f2-270d5dbd66ac | < 2.4.1 |
CRITICAL | 9.8 | The EventON plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 2.4. This makes… | — | wordfence |
| 46b3f3fb-5bd5-4af4-a281-647ad0b8e992 | < 2.2.6 |
CRITICAL | 9.8 | The Google Map plugin for WordPress is vulnerable to blind SQL Injection via the ‘table’ parameter in versions up to… | — | wordfence |
| 46b3b01c-8739-4b51-be34-1dd3c50d772e | < 0.9.10 |
CRITICAL | 9.8 | WP-Syntax plugin 0.9.9 and earlier for Wordpress, with register_globals enabled, allows remote attackers to execute arbi… | — | wordfence |
| 46545227-3c04-40a4-a25c-8f43845e90d3 | < 13.1.6 |
CRITICAL | 9.8 | The WP Statistics WordPress plugin is vulnerable to SQL Injection due to insufficient escaping and parameterization of t… | — | wordfence |
| 4624d197-db90-41ee-a3d5-a83a0dbf6b7c | < 0.15.2 |
CRITICAL | 9.8 | The Global Flash Gallery Plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validatio… | — | wordfence |
| 462125cd-c91a-44b1-9004-4a62f2aed52c | CRITICAL | 9.8 | The Woocommerce Product Design plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type val… | — | wordfence | |
| 45e0664a-385d-4879-acf6-46e837aaa03f | CRITICAL | 9.8 | The kernel-theme theme for WordPress is vulnerable to arbitrary file uploads due to missing file type validation via the… | — | wordfence | |
| 45d66743-300e-480d-98b8-99dc30b6e786 | < 2.2.1 |
CRITICAL | 9.8 | The CE21 Suite plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 2.2.0. This… | — | wordfence |
| 45b6a72a-9aa9-4d77-b250-575d55538110 | < 1.1.4 |
CRITICAL | 9.8 | PHP remote file inclusion vulnerability in actions.php in the Allwebmenus plugin 1.1.3 for WordPress allows remote attac… | — | wordfence |
| 45a778cc-0063-4c07-ae57-bd473976e68c | < 1.0.8 |
CRITICAL | 9.8 | The Ruza theme for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.0.7. This makes i… | — | wordfence |
| 4592fea7-65c4-45f6-8674-ae5f706db413 | CRITICAL | 9.8 | The A/B Test for WordPress plugin for WordPress is vulnerable to Local File Inclusion via the 'action' parameter in the … | — | wordfence | |
| 45760755-472a-4b5f-abdf-373173ef64d3 | < 1.1.4 |
CRITICAL | 9.8 | The WP Smart Import plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.1.3. … | — | wordfence |
| 45531492-9238-4e2e-ad37-d0e5c457af07 | < 1.9.9.1 |
CRITICAL | 9.8 | The WPLMS Learning Management System for WordPress, WordPress LMS theme for WordPress is vulnerable to arbitrary file up… | — | wordfence |
| 45240c80-44b3-45d6-b23e-0d4c29cca502 | < 24.07.03 |
CRITICAL | 9.8 | The Docket Cache plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 24.07.02. … | — | wordfence |
| 451db756-9d62-4c8e-b735-e5e5207b81e3 | < 1.5.0 |
CRITICAL | 9.8 | The Themify – WooCommerce Product Filter plugin for WordPress is vulnerable to time-based SQL Injection via the ‘con… | — | wordfence |
| 45163d7f-59c9-4bce-95a7-5b56e1cc018b | < 12.12 |
CRITICAL | 9.8 | The WP Symposium plugin for WordPress is vulnerable to various SQL Injections in versions up to, and including, 12.09 du… | — | wordfence |
| 44edf44b-5456-4c4b-86c3-80ad785cfb6a | CRITICAL | 9.8 | The JS Job Manager plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 2.0.2. T… | — | wordfence | |
| 44e54ac5-8091-4154-a14c-5cd67647f722 | < 3.1.4 |
CRITICAL | 9.8 | Unrestricted file upload vulnerability in admin/scripts/FileUploader/php.php in the ReFlex Gallery plugin before 3.1.4 f… | — | wordfence |
| 44c96df2-530a-4ebe-b722-c606a7b135f9 | < 1.6.2 |
CRITICAL | 9.8 | The BP Social Connect plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 1.5.… | — | wordfence |
| 44ba3eee-525e-46ba-ae02-6f7a28f80c50 | < 1.5.2 |
CRITICAL | 9.8 | An issue was discovered in the update function in the wpForo Forum plugin before 1.5.2 for WordPress. A registered forum… | — | wordfence |
| 44a921e7-cce3-4347-968d-76dab243fcd6 | < 2.4.3 |
CRITICAL | 9.8 | The Clone plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.4… | — | wordfence |
EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.
Scan My Website →