Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.
39,409 vulnerabilities found (page 75 of 1577)
| CVE ID | Plugin / Theme | Severity | CVSS | Description | Fixed In | Source |
|---|---|---|---|---|---|---|
| 444fae52-ffcb-4502-a052-239693bfa326 | < 4.2.2 |
CRITICAL | 9.8 | The Visual Website Collaboration, Feedback & Project Management – Atarim plugin for WordPress is vulnerable to arbitra… | — | wordfence |
| 440e34a2-0185-4294-b82d-a0249769731e | < 3.14.28 |
CRITICAL | 9.8 | The Flexmls® IDX plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 3.14.27 v… | — | wordfence |
| 43d1f708-58bd-4d42-b8dd-0c1247546577 | < 1.4.3 |
CRITICAL | 9.8 | The Floating Social Media Links plugin for WordPress is vulnerable to Remote File Inclusion in versions before 1.4.3 via… | — | wordfence |
| 43cb0399-4add-43d5-863c-30e11803bd90 | < 4.4.7 |
CRITICAL | 9.8 | The AppPresser – Mobile App Framework plugin for WordPress is vulnerable to privilege escalation via account takeover … | — | wordfence |
| 43b7e458-73d7-4a02-8184-081654a9f58e | < 1.1.5 |
CRITICAL | 9.8 | The Multi Uploader for Gravity Forms plugin for WordPress is vulnerable to arbitrary file uploads due to missing file ty… | — | wordfence |
| 43a64074-ca64-4c34-b467-06d1ad8c5aa0 | < 5.10.0 |
CRITICAL | 9.8 | The Social Login plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 5.9.0… | — | wordfence |
| 438d73bb-80f1-460f-8c62-2a40856e4c29 | < 5.0 |
CRITICAL | 9.8 | The Auto Affiliate Links plugin for WordPress is vulnerable to multiple SQL Injections via the 'aal_massstring' and 'aal… | — | wordfence |
| 437c88f8-9457-48e5-b10f-aa453720bc5a | CRITICAL | 9.8 | The Zita Site Builder plugin for WordPress is vulnerable to unauthorized access of functionality due to a missing capabi… | — | wordfence | |
| 436fc1c8-3141-445d-902e-f759feefe1cc | CRITICAL | 9.8 | The Husker Portfolio plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation vi… | — | wordfence | |
| 431b0f09-6b0a-4f67-bd39-38ee7d90eb07 | < 1.0.15 |
CRITICAL | 9.8 | The Mail Picker plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 1.0.14 via … | — | wordfence |
| 42ff1e17-ccc2-478b-a3b5-88e3bea28a5e | < 1.44 |
CRITICAL | 9.8 | PHP remote file inclusion vulnerability in wordtube-button.php in the wordTube 1.43 and earlier plugin for WordPress, wh… | — | wordfence |
| 42f5d834-d63c-4690-a03b-e573ce91465c | CRITICAL | 9.8 | The WooCommerce Pickupp plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 2.4… | — | wordfence | |
| 4299e97c-3b91-4870-bafd-557b72b93b44 | < 1.5.52 |
CRITICAL | 9.8 | SQL injection in the Spider Event Calendar (aka spider-event-calendar) plugin before 1.5.52 for WordPress is exploitable… | — | wordfence |
| 4280654a-9eab-4541-8b82-74086d37d928 | < 3.2.1 |
CRITICAL | 9.8 | The CM Registration Pro plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 3.2… | — | wordfence |
| 427a788b-e9d9-422a-ab63-179f12860e4e | < 3.2.1 |
CRITICAL | 9.8 | The Traveler theme for WordPress is vulnerable to PHP Object Injection in versions up to 3.2.1 via deserialization of un… | — | wordfence |
| 4252c092-1276-4f69-88f9-cf78799c725c | < 4.0.27 |
CRITICAL | 9.8 | The ARMember – Membership Plugin, Content Restriction, Member Levels, User Profile & User signup plugin for WordPress … | — | wordfence |
| 42525101-6196-40b9-90e7-c7f1886ef247 | < 2.9.21 |
CRITICAL | 9.8 | The Gravity Forms plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in th… | — | wordfence |
| 424ebeb4-eb53-4c87-9a86-aff1c784aa3c | CRITICAL | 9.8 | The WordPress Spreadsheet plugin for WordPress is vulnerable to SQL Injection via the 'ss_id' parameter in versions up t… | — | wordfence | |
| 4240c04b-cad3-496f-b12f-7718bb498fe0 | CRITICAL | 9.8 | Vulnerability in wordpress plugin flickr-picture-backup v0.7, The code in flickr-picture-download.php doesn't check to s… | — | wordfence | |
| 42378b83-2a39-4e5f-8671-ee4a44ee92a5 | < 1.302 |
CRITICAL | 9.8 | The MemberSonic Lite plugin before 1.302 for WordPress has incorrect login access control because only knowledge of an e… | — | wordfence |
| 42222c64-6492-4774-b5bc-8e62a1a328cf | < 2.11.0 |
CRITICAL | 9.8 | The WCFM Membership – WooCommerce Memberships for Multivendor Marketplace plugin for WordPress is vulnerable to Insecu… | — | wordfence |
| 4221b33c-5cfa-48db-92bf-bf25ff3c5a5f | < 1.7.14 |
CRITICAL | 9.8 | The Startklar Elementor Addons plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient file typ… | — | wordfence |
| 420580e1-b6cf-4fd7-87fd-e415b097f4c9 | CRITICAL | 9.8 | The Davenport - Versatile Blog and Magazine WordPress Theme plugin for WordPress is vulnerable to Local File Inclusion i… | — | wordfence | |
| 41cfe1d7-2fab-413c-80e5-40d77133d229 | < 11.31.0 |
CRITICAL | 9.8 | The Knowledge Base for Documentation, FAQs with AI Assistance plugin for WordPress is vulnerable to PHP Object Injection… | — | wordfence |
| 41cf57ff-421d-4db2-894f-17f2c4d4b9ed | < 5.6.2 |
CRITICAL | 9.8 | The WooCommerce Payments plugin is vulnerable to authentication bypass via the determine_current_user_for_platform_check… | — | wordfence |
EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.
Scan My Website →