Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.
39,409 vulnerabilities found (page 76 of 1577)
| CVE ID | Plugin / Theme | Severity | CVSS | Description | Fixed In | Source |
|---|---|---|---|---|---|---|
| 41af6441-bc1d-4210-92f3-4c765fda6df9 | < 1.9.13 |
CRITICAL | 9.8 | NextGEN Gallery plugin before 1.9.13 for WordPress: ngggallery.php file upload | — | wordfence |
| 41a61c0f-fffb-4810-b44a-74cbc1192ecd | CRITICAL | 9.8 | The HTML5 AV Manager plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation vi… | — | wordfence | |
| 419a42eb-19ed-46a3-9da0-3fcd2c8e2527 | CRITICAL | 9.8 | The Share Buttons – Social Media plugin for WordPress is vulnerable to SQL Injection in versions up to, and including,… | — | wordfence | |
| 41800ea9-1ace-42fc-9e7f-d760a126342b | < 1.7 |
CRITICAL | 9.8 | The uListing plugin for WordPress is vulnerable to Unauthenticated Arbitrary Account Changes in versions up to, and incl… | — | wordfence |
| 415c9658-bfb2-453b-a697-c63c08b0ca61 | < 1.8.0 |
CRITICAL | 9.8 | The Contact Form by Supsystic plugin for WordPress is vulnerable to Server-Side Template Injection (SSTI) leading to Rem… | — | wordfence |
| 414636bc-3fab-41f9-9d4b-17ca1ac8a3df | < 1.4.72 |
CRITICAL | 9.8 | The Motors plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.4.71. This mak… | — | wordfence |
| 4124003c-4864-48f1-acba-9a613d9c99ae | < 5.4 |
CRITICAL | 9.8 | The tagDiv Composer plugin for WordPress is vulnerable to PHP Object Instantiation in all versions up to, and including,… | — | wordfence |
| 4122a963-b8e2-448a-b268-3192613fa3df | < 4.1.4 |
CRITICAL | 9.8 | The LearnPress WordPress plugin before 4.1.4 does not sanitise, validate and escape the id parameter before using it in … | — | wordfence |
| 41108c2c-99b2-4aff-8c06-bee0b6547a9a | < 3.9.7 |
CRITICAL | 9.8 | The Smart Manager For WooCommerce plugin for WordPress is vulnerable to blind SQL Injection via the ‘edited’ paramet… | — | wordfence |
| 41048058-1662-4ec1-81ac-6e8e42351e7e | < 12.3.1 |
CRITICAL | 9.8 | The Order Delivery Date for WooCommerce plugin for WordPress is vulnerable to unauthorized modification of data that can… | — | wordfence |
| 40a6d10e-5e68-4280-a3e2-0b93095bb4dd | < 3.4.8 |
CRITICAL | 9.8 | The Pearl - Corporate Business theme for WordPress is vulnerable to Local File Inclusion in versions up to 3.4.8. This m… | — | wordfence |
| 40a6a810-1151-49e6-bed4-2b7a572ac015 | < 2.4 |
CRITICAL | 9.8 | pixabay-images.php in the Pixabay Images plugin before 2.4 for WordPress does not properly restrict access to the upload… | — | wordfence |
| 40937e18-3828-4e36-8bc1-5b8eb4838c3b | < 1.2.1 |
CRITICAL | 9.8 | SQL injection vulnerability in the Responsive Image Gallery plugin before 1.2.1 for WordPress allows remote attackers to… | — | wordfence |
| 407b8568-0b47-48d1-a006-2c42e7cfdec3 | CRITICAL | 9.8 | The Right Now theme for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'up… | — | wordfence | |
| 407a0bc3-2775-4a34-9817-924bf94a4f94 | CRITICAL | 9.8 | The WooCommerce Designer Pro plugin for WordPress, used by the Pricom - Printing Company & Design Services WordPress the… | — | wordfence | |
| 40765cfe-a60a-44dc-8cdb-f9c8e42654c3 | < 9.1.1 |
CRITICAL | 9.8 | The BuddyPress plugin for WordPress is vulnerable to generic SQL Injection via the ‘BP_Notifications_Notification::get… | — | wordfence |
| 40716c58-1075-492b-9323-13e7b831e206 | < 3.5.19 |
CRITICAL | 9.8 | The WPFunnels plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 3.5.18 via de… | — | wordfence |
| 406c02e0-cebb-400a-b276-dc0b0bd9f1ad | CRITICAL | 9.8 | The Workreap Core plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 3.4.… | — | wordfence | |
| 40519181-540e-44d4-a9b7-6c8c321b1592 | < 2.2.14.1 |
CRITICAL | 9.8 | The Kids Planet theme for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 2.2.14 via d… | — | wordfence |
| 403c881c-b687-4e7e-8e77-a55203cfde96 | < 3.9 |
CRITICAL | 9.8 | The Chameleon theme for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'qq… | — | wordfence |
| 40010bbd-049f-44b0-9492-4126c4894656 | < 1.8.0 |
CRITICAL | 9.8 | The Cooked Pro plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in all v… | — | wordfence |
| 40000879-a5ef-48f2-97e4-77d527259af0 | < 1.2.6 |
CRITICAL | 9.8 | The Flex QR Code Generator plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validat… | — | wordfence |
| 3fddf96e-029c-4753-ba82-043ca64b78d3 | < 7.10.1 |
CRITICAL | 9.8 | The LayerSlider plugin for WordPress is vulnerable to SQL Injection via the ls_get_popup_markup action in versions 7.9.1… | — | wordfence |
| 3f95f73c-2377-46b7-a96f-6014a5b012c3 | < 2.4.4 |
CRITICAL | 9.8 | Multiple SQL injection vulnerabilities in classes/ajax.php in the Smarty Pants Plugins SP Project & Document Manager plu… | — | wordfence |
| 3f915fa1-38ca-4090-8f3f-3d8a1b0a2c4c | CRITICAL | 9.8 | The MH Board plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1.3.2.1. T… | — | wordfence |
EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.
Scan My Website →