Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.
41,761 vulnerabilities found (page 74 of 1671)
| CVE ID | Plugin / Theme | Severity | CVSS | Description | Fixed In | Source |
|---|---|---|---|---|---|---|
| 525b466d-137a-467b-8b49-e51393a73866 | CRITICAL | 9.8 | The Kento Post View Counter plugin for WordPress is vulnerable to SQL Injection via the 'kento_pvc_geo' parameter in ver… | — | wordfence | |
| 523b5dd3-eb73-4156-ad2b-4d532e8d40f3 | < 2.6.60 |
CRITICAL | 9.8 | The Datalogics Ecommerce Delivery β Datalogics plugin for WordPress is vulnerable to privilege escalation in all versi… | — | wordfence |
| 522ecc1c-5834-4325-9234-79cf712213f3 | < 1.7.0.13 |
CRITICAL | 9.8 | The Donation Forms by Charitable plugin for WordPress is vulnerable to privilege escalation in versions up to, and inclu… | — | wordfence |
| 5228221f-b0b4-4faf-bde6-07666a96a278 | < 3.6.3 |
CRITICAL | 9.8 | The Order Notification for WooCommerce β Get Audio Alert on new Orders plugin for WordPress is vulnerable to Remote Co… | — | wordfence |
| 521b1786-3527-4b4e-b1c4-ff4fbfed8107 | CRITICAL | 9.8 | The My Reading Library plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 1.0 … | — | wordfence | |
| 52198053-206c-4002-8e26-dd5b4850e151 | < 1.6.30 |
CRITICAL | 9.8 | The SalesKing plugin for WordPress is vulnerable to privilege escalation in versions up to, and including, 1.6.15. This … | — | wordfence |
| 520c1e8b-d0c1-4201-90bf-0cefab9af7e0 | CRITICAL | 9.8 | The Service Finder SMS System plugin for WordPress is vulnerable to privilege escalation via account takeover in all ver… | — | wordfence | |
| 5205fcde-2e6c-49de-b132-1ebefcd1ba59 | < 1.4.4 |
CRITICAL | 9.8 | Multiple SQL injection vulnerabilities in main.php in the WassUp plugin 1.4 through 1.4.3 for WordPress allow remote att… | — | wordfence |
| 51fc7d47-2a0f-4713-9859-120321aa32dc | < 3.3.7 |
CRITICAL | 9.8 | The DWT - Directory & Listing WordPress Theme theme for WordPress is vulnerable to privilege escalation via account take… | — | wordfence |
| 51f73041-927d-42da-92cc-14242a397356 | CRITICAL | 9.8 | The Email posts to subscribers plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 6.2… | — | wordfence | |
| 51d3c250-301c-4f91-9fe5-56879a65fde7 | CRITICAL | 9.8 | Unrestricted file upload vulnerability in includes/upload.php in the Aviary Image Editor Add-on For Gravity Forms plugin… | — | wordfence | |
| 51957ee1-a423-485b-8cfd-8eafaf6744e4 | < 4.9.17.1 |
CRITICAL | 9.8 | The UserPro plugin before 4.9.17.1 for WordPress, when used on a site with the "admin" username, allows remote attackers… | — | wordfence |
| 5183d676-eb91-4c03-8d12-c15c68839f02 | < 4.02 |
CRITICAL | 9.8 | The SEMA API WordPress plugin through 3.64 does not properly sanitise and escape some parameters before using them in SQ… | — | wordfence |
| 515d6e6c-e20d-4fc4-9c56-80020196f2f0 | < 1.7.2 |
CRITICAL | 9.8 | PHP remote file inclusion vulnerability in wp_xml_export.php in the BackWPup plugin before 1.7.2 for WordPress allows re… | — | wordfence |
| 51424768-27c7-40b2-8d1c-838c419add8a | < 3.12 |
CRITICAL | 9.8 | SQL injection vulnerability in the Store Locator plugin 2.3 through 3.11 for WordPress allows remote attackers to execut… | — | wordfence |
| 50bdca4a-23c0-46aa-8c08-5987a2e28604 | < 9.10.0 |
CRITICAL | 9.8 | The Private Content plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 9.9… | — | wordfence |
| 50bcea94-b12a-4b31-b0c1-bba834ea9bd0 | < 2.9.8.6 |
CRITICAL | 9.8 | The Feed Them Social β for Twitter feed, Youtube and more plugin for WordPress is vulnerable to deserialization of unt… | — | wordfence |
| 509c881d-22bc-473f-b57b-4ec3ddf6abaf | CRITICAL | 9.8 | The fMoblog plugin for WordPress is vulnerable to SQL Injection via the 'id' parameter in versions up to, and including,… | — | wordfence | |
| 5093d787-0357-4c28-9d27-8335b10fc499 | < 1.2.54 |
CRITICAL | 9.8 | The 5 Stars Rating Funnel WordPress Plugin | RRatingg WordPress plugin before 1.2.54 does not properly sanitise, validat… | — | wordfence |
| 508ff025-d1ab-4c8d-ac39-078023c4b5ce | < 1.6.8 |
CRITICAL | 9.8 | The All Post Contact Form plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validati… | — | wordfence |
| 508b6466-2786-4d6b-9ab2-772050af4803 | < 3.1.0.4 |
CRITICAL | 9.8 | The Easy Digital Downloads plugin for WordPress is vulnerable to SQL Injection in versions before 3.1.0.4 via the 's' pa… | — | wordfence |
| 505b797f-f812-4da3-91c3-44f27a240ec2 | CRITICAL | 9.8 | The The E-Commerce ERP: Purchasing, Inventory, Fulfillment, Manufacturing, BOM, Accounting, Sales Analysis plugin for Wo… | — | wordfence | |
| 505b1f87-52c6-439c-a108-e2003971dc07 | < 1.5.2 |
CRITICAL | 9.8 | An Improper Access Control vulnerability was discovered in the Controlled Admin Access WordPress plugin before 1.5.2. Un… | — | wordfence |
| 50537e01-834e-4247-a80f-daa114eedcf1 | < 2.5.2 |
CRITICAL | 9.8 | The Resume Submissions & Job Postings plugin for WordPress is vulnerable to arbitrary file uploads due to missing file t… | — | wordfence |
| 504476f8-3583-448b-80fd-ed03b672a4e8 | < 2.3.0 |
CRITICAL | 9.8 | The Easy Real Estate plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 2.… | — | wordfence |
EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.
Scan My Website →