Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.
41,761 vulnerabilities found (page 76 of 1671)
| CVE ID | Plugin / Theme | Severity | CVSS | Description | Fixed In | Source |
|---|---|---|---|---|---|---|
| 4ce039cd-2662-4cc3-9d38-932be7b7726d | < 3.8.8 |
CRITICAL | 9.8 | The PayU CommercePro Plugin plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and inclu… | — | wordfence |
| 4cb77a63-360b-4917-8a3c-263f5282742c | < 2.0.3 |
CRITICAL | 9.8 | The Pricing Deals for WooCommerce plugin for WordPress is vulnerable to SQL Injection via the 'term' parameter in versio… | — | wordfence |
| 4cada002-1fae-43fa-b1e0-e71afb223c53 | < 1.3.1 |
CRITICAL | 9.8 | The clanora theme for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in all versi… | — | wordfence |
| 4c8f2872-06ff-41a2-b601-77a47470de0c | < 4.0.4 |
CRITICAL | 9.8 | The Cost Calculator Builder PRO plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and i… | — | wordfence |
| 4c747e6f-31fc-41b0-ba62-f009b5483696 | < 4.4.1 |
CRITICAL | 9.8 | The package simple-git is vulnerable to Remote Code Execution in versions before 3.15.0 when the ext transport protocol … | — | wordfence |
| 4c64089a-929c-4a36-8aa8-61a5c9e8562b | < 5.4.15 |
CRITICAL | 9.8 | The Woffice CRM theme for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, an… | — | wordfence |
| 4c5c757f-8546-4a95-a9f4-92d59106aa83 | < 1.3.0 |
CRITICAL | 9.8 | The PowerPack for LearnDash plugin for WordPress is vulnerable to unauthorized modification of data that can lead to pri… | — | wordfence |
| 4c367565-75f7-4dd7-a2f1-111df581bd7a | < 1.1.8 |
CRITICAL | 9.8 | The Appointment Booking Calendar Plugin and Online Scheduling Plugin – BookingPress plugin for WordPress is vulnerable… | — | wordfence |
| 4c221909-bc1b-47e3-bfec-71b419f48ae3 | < 2.0.2 |
CRITICAL | 9.8 | The Product Input Fields for WooCommerce plugin for WordPress is vulnerable to Arbitrary File Upload in versions up to, … | — | wordfence |
| 4bbb0146-436f-42fa-802b-cdcf39ae97db | < 4.0.27 |
CRITICAL | 9.8 | The Event Manager, Events Calendar, Tickets, Registrations – Eventin plugin for WordPress is vulnerable to unauthorize… | — | wordfence |
| 4b8d057b-1909-46d4-8e0a-d5c7c9f7001c | < 3.3.1 |
CRITICAL | 9.8 | The Relevanssi plugin for WordPress is vulnerable to SQL Injection via the ‘category_name’ parameter in versions up … | — | wordfence |
| 4b704c42-181b-47cb-9df8-3b82f7b830e1 | < 1.1.24 |
CRITICAL | 9.8 | The appointment-booking-calendar plugin before 1.1.24 for WordPress has SQL injection, a different vulnerability than CV… | — | wordfence |
| 4b585243-943d-48d4-bee3-407ff3ae8078 | < 1.9.9.5 |
CRITICAL | 9.8 | The VibeBP plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.9.9.4.1. T… | — | wordfence |
| 4b40e33b-4aa8-4378-b044-a8a636d34f73 | CRITICAL | 9.8 | The Referrer Detector plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 4.2.1… | — | wordfence | |
| 4b39c8e1-f2b7-436d-97d1-2d503d7ac835 | < 3.2.5 |
CRITICAL | 9.8 | The wp-all-import plugin before 3.2.5 for WordPress has blind SQL injection. | — | wordfence |
| 4b2d685f-0426-4837-bf96-07ebda499bed | CRITICAL | 9.8 | The Blog Designer PRO for WordPress plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and in… | — | wordfence | |
| 4b0e763e-f03e-41fb-8c6c-4de5d3acae00 | < 2.6.7 |
CRITICAL | 9.8 | The Ultimate Member plugin for WordPress is vulnerable to privilege escalation in versions up to, and including, 2.6.6. … | — | wordfence |
| 4b0445ce-614b-4948-a48c-c1b95cc7f043 | < 1.7.0 |
CRITICAL | 9.8 | Multiple Supsystic Pro plugins for WordPress contain backdoors in various versions. This is due to the vendors update se… | — | wordfence |
| 4ad379ad-8733-4015-a892-375604339695 | < 15.8 |
CRITICAL | 9.8 | SQL injection vulnerability in the WP Symposium plugin before 15.8 for WordPress allows remote attackers to execute arbi… | — | wordfence |
| 4aa89fab-b6fe-423a-a7f5-dbe6c92d1b56 | < 3.8.7.6 |
CRITICAL | 9.8 | SQL injection vulnerability in the WP e-Commerce plugin before 3.8.7.6 for WordPress allows remote attackers to execute … | — | wordfence |
| 4a47660e-67a6-42d4-a7ec-911dcf3e6e47 | < 4.4.2 |
CRITICAL | 9.8 | The WPLP Cookie Consent – Cookie Banner & Consent Management for GDPR, CCPA & Google Consent Mode plugin for WordPress… | — | wordfence |
| 4a263b74-e9ae-4fd2-be9b-9b8e9eee5982 | < 1.5.6 |
CRITICAL | 9.8 | The Adning Advertising plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation … | — | wordfence |
| 4a154c3f-e2c4-454d-94f9-539d8b289e4e | < 3.1.4 |
CRITICAL | 9.8 | The Ajar in5 Embed plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in a… | — | wordfence |
| 4a1127af-74f6-4748-9aee-5a8c6c2766a4 | < 4.21.1 |
CRITICAL | 9.8 | The Mstore Api plugin for WordPress is vulnerable to Authentication Bypass via JWT Forgery in versions up to, and includ… | — | wordfence |
| 49ea8af1-7171-4498-bfb0-bb3cbd72e6f3 | < 5.1 |
CRITICAL | 9.8 | The Limit Login Attempts (Spam Protection) WordPress plugin before 5.1 does not sanitise and escape some parameters befo… | — | wordfence |
EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.
Scan My Website →