Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.
39,409 vulnerabilities found (page 79 of 1577)
| CVE ID | Plugin / Theme | Severity | CVSS | Description | Fixed In | Source |
|---|---|---|---|---|---|---|
| 3925311f-d40b-4f54-9b98-a709b53ed179 | < 2.1.1 |
CRITICAL | 9.8 | The Bug Library plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the … | — | wordfence |
| 38bcb908-1e6e-44be-9cf5-72dcfa4c4a4e | CRITICAL | 9.8 | Unrestricted file upload vulnerability in the Gravity Upload Ajax plugin 1.1 and earlier for WordPress allows remote att… | — | wordfence | |
| 389c0b89-e408-4ad5-9723-a16b745771f0 | < 1.9.13 |
CRITICAL | 9.8 | The Everest Forms Pro plugin for WordPress is vulnerable to Remote Code Execution via PHP Code Injection in all versions… | — | wordfence |
| 385f5f37-6be8-4736-91ca-0dd6f1d762a9 | < 3.0.7 |
CRITICAL | 9.8 | The Clean Retina theme for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 3.0.6. This… | — | wordfence |
| 385c01fc-bed8-4c12-b420-9aecf4857434 | CRITICAL | 9.8 | The Surveys plugin for WordPress is vulnerable to blind SQL Injection via the β$_REQUEST['action']β parameter in ver… | — | wordfence | |
| 3852aef6-42e7-4b71-a1ba-dd41284fd07b | < 2.0.0 |
CRITICAL | 9.8 | The ProSolution WP Client plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validati… | — | wordfence |
| 385235e0-be33-49c6-bcde-27f3cd936ddf | CRITICAL | 9.8 | The Signup Page plugin for WordPress is vulnerable to unauthorized modification of data that can lead to privilege escal… | — | wordfence | |
| 37fd0582-5baf-4ced-a798-dc0970e90a3e | < 1.2.11 |
CRITICAL | 9.8 | The UsersWP β Front-end login form, User Registration, User Profile & Members Directory plugin for WordPress plugin fo… | — | wordfence |
| 37e1a755-7c17-4cb4-acca-9f26238230f3 | < 5.1.3 |
CRITICAL | 9.8 | The User Registration & Membership β Free & Paid Memberships, Subscriptions, Content Restriction, User Profile, Custom… | — | wordfence |
| 37c22521-68ef-4d15-9633-8fe1af493a52 | < 3.41 |
CRITICAL | 9.8 | The IP Blacklist Cloud plugin for WordPress is vulnerable to SQL Injections via several parameters in versions before 3.… | — | wordfence |
| 37a8642d-07f5-4b1b-8419-e30589089162 | < 12.0.4 |
CRITICAL | 9.8 | The Snow Monkey Forms plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path valida… | — | wordfence |
| 3755a06e-2c2e-4c88-95d7-2619bb84efab | CRITICAL | 9.8 | The WP Cookies Enabler plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.0.… | — | wordfence | |
| 373b51f0-92ad-4c9e-87b9-96b4e57cc05d | < 1.4.5 |
CRITICAL | 9.8 | The Anthology Theme for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the via… | — | wordfence |
| 3718690f-68f1-49cd-8193-b30887daabf2 | CRITICAL | 9.8 | The Revo theme for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 4.0.26. This makes … | — | wordfence | |
| 370fbe22-df48-4f64-ba7f-5ab98b908f58 | CRITICAL | 9.8 | The Yvora theme for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'upload… | — | wordfence | |
| 36fb5b8d-1ea4-45c2-8639-b229efdb57db | < 1.1.3 |
CRITICAL | 9.8 | The Appy Pie Connect for WooCommerce plugin for WordPress is vulnerable to Privilege Escalation due to missing authoriza… | — | wordfence |
| 36fa4540-68d9-474f-abfc-ad91af97a238 | < 1.7.6 |
CRITICAL | 9.8 | The GiftXtore theme for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.7.5. This ma… | — | wordfence |
| 36a7b681-6059-46a4-82a8-addfb8f452cc | CRITICAL | 9.8 | The Master Elements WordPress plugin through 8.0 does not validate and escape the meta_ids parameter of its remove_post_… | — | wordfence | |
| 36a01fa7-39a6-4d33-9c6e-1c76756f02cf | CRITICAL | 9.8 | The HB AUDIO GALLERY plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in… | — | wordfence | |
| 368a3911-1d29-4378-aa6e-8a6ed54bbe0f | < 2.0.4 |
CRITICAL | 9.8 | The Ultimate Store Kit Elementor Addons, Woocommerce Builder, EDD Builder, Elementor Store Builder, Product Grid, Produc… | — | wordfence |
| 364fe5b3-561e-4005-a589-c7c2b9e85b99 | < 4.4.7 |
CRITICAL | 9.8 | The ChatBot plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 4.4.6 via deser… | — | wordfence |
| 361f3fec-7176-4a25-943b-44a44dd77784 | < 14.6.10 |
CRITICAL | 9.8 | The cforms2 plugin before 14.6.10 for WordPress has SQL injection via several parameters. | — | wordfence |
| 35f59c05-8d1d-45b1-813f-65435e4aaed3 | CRITICAL | 9.8 | The Nabz Image Gallery plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, v1.00 due t… | — | wordfence | |
| 35b86488-8f68-4738-a9a8-76d0b7976165 | < 2.0.47 |
CRITICAL | 9.8 | The User Verification by PickPlugins plugin for WordPress is vulnerable to authentication bypass in all versions up to, … | — | wordfence |
| 35b74f5b-f088-4307-81ba-2c379754c4a2 | CRITICAL | 9.8 | Vulnerability in wordpress plugin wordpress-gallery-transformation v1.0, SQL injection is in ./wordpress-gallery-transfo… | — | wordfence |
EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.
Scan My Website →