Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.
39,403 vulnerabilities found (page 8 of 1577)
| CVE ID | Plugin / Theme | Severity | CVSS | Description | Fixed In | Source |
|---|---|---|---|---|---|---|
| ffd9cbd1-f8a9-401e-8cdd-1ff16f438b4a | < 4.1.2 |
CRITICAL | 9.8 | The User Registration & Membership plugin for WordPress is vulnerable to privilege escalation in versions up to, and inc… | — | wordfence |
| ffd592e6-2ac4-4af4-bfc0-d4f834157d71 | < 2.6.3 |
CRITICAL | 9.8 | The WooCommerce - Social Login plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and inc… | — | wordfence |
| ffa0d1ff-a1df-4a90-bfe5-3f4c8a7942c6 | < 1.0.11 |
CRITICAL | 9.8 | The BookingPress WordPress plugin before 1.0.11 fails to properly sanitize user supplied POST data before it is used in … | — | wordfence |
| ff87e9e0-d8b1-47d3-92d6-48e6b00ac1a0 | CRITICAL | 9.8 | The Real Time Validation for Gravity Forms plugin for WordPress is vulnerable to Local File Inclusion in versions up to,… | — | wordfence | |
| ff6fc652-dcf8-4ff6-b8d8-cb9fad5b34bd | < 2.2 |
CRITICAL | 9.8 | The 3D Flick Slideshow plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation … | — | wordfence |
| ff5755dc-2262-47f6-ac3a-6bca9529d088 | < 1.7 |
CRITICAL | 9.8 | The uListing plugin for WordPress is vulnerable to authorization bypass via wp_route due to missing capability checks, a… | — | wordfence |
| ff4b47d8-28c1-4706-91d9-0285f419147e | < 3.7.40 |
CRITICAL | 9.8 | WordPress Core is vulnerable to SQL Injection in versions up to 6.0.3. This is due to insufficient escaping on where β… | — | wordfence |
| ff4243e9-cf72-40d5-bc7d-204426024a1d | CRITICAL | 9.8 | The Optional Email plugin for WordPress is vulnerable to Privilege Escalation via Account Takeover in all versions up to… | — | wordfence | |
| ff1f303f-17fc-4006-b21b-5846216995da | < 92.0.0 |
CRITICAL | 9.8 | The School Management System for Wordpress plugin for WordPress is vulnerable to arbitrary file uploads due to missing f… | — | wordfence |
| fea82b46-cb23-4603-8e50-565cc65db857 | < 1.5.8 |
CRITICAL | 9.8 | The AI Copilot β Content Generator plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, a… | — | wordfence |
| fea6ddd5-f168-471c-99eb-efc46d1bfeb9 | < 1.4.13 |
CRITICAL | 9.8 | The wpForo Forum plugin for WordPress is vulnerable to Blind SQL Injection via the βwpfoβ parameter in versions up t… | — | wordfence |
| fe887475-f7e8-4fda-a793-bc6f37b70f3e | < 1.9.15 |
CRITICAL | 9.8 | The MoreConvert Pro plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 1.… | — | wordfence |
| fe8723a7-bbb1-41a0-b222-3cf4eb44cd64 | < 1.0.3 |
CRITICAL | 9.8 | The GB Forms DB plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 1.0.2 … | — | wordfence |
| fe17abd8-9ee2-4b9c-a30b-68d95e341722 | < 3.1.4 |
CRITICAL | 9.8 | The ReFlex Gallery Β» WordPress Photo Gallery for WordPress is vulnerable to arbitrary file uploads due to missing file … | — | wordfence |
| fdc2de78-5601-461f-b2f0-c80b592ccb1b | < 1.22.22 |
CRITICAL | 9.8 | The Backup and Staging by WP Time Capsule plugin for WordPress is vulnerable to arbitrary file uploads due to missing fi… | — | wordfence |
| fdc2a31f-19c2-4474-a3b0-16ded1912ddd | < 5.6.4 |
CRITICAL | 9.8 | The rsvpmaker plugin before 5.6.4 for WordPress has SQL injection. | — | wordfence |
| fdba935b-4c78-48e2-ae32-f68748f6df97 | CRITICAL | 9.8 | The TheCartPress eCommerce Shopping Cart plugin for WordPress is vulnerable to Privilege Escalation in all versions up t… | — | wordfence | |
| fd978ac0-42f2-4746-9430-37458375b588 | < 2.0.9.9 |
CRITICAL | 9.8 | The JetBackup β WP Backup, Migrate & Restore plugin for WordPress is vulnerable to Sensitive Information Exposure in a… | — | wordfence |
| fd8e6b8a-0161-4bf7-b480-77258337e9b9 | < 3.4.1 |
CRITICAL | 9.8 | The wp-file-upload plugin before 3.4.1 for WordPress has insufficient restrictions on upload of .php.js files. | — | wordfence |
| fd50ac2c-3049-4a44-b7f8-a5f87c42555c | < 1.3.1 |
CRITICAL | 9.8 | The Taxi Booking Manager for Woocommerce | E-cab plugin for WordPress is vulnerable to privilege escalation via account … | — | wordfence |
| fd3b4c44-d47a-45de-bcb2-0820e475b331 | < 24.0.4 |
CRITICAL | 9.8 | The Photos, Files, YouTube, Twitter, Instagram, TikTok, Ecommerce Contest Gallery β Upload, Vote, Sell via PayPal, Soc… | — | wordfence |
| fcf4bf2c-2f65-415b-bbf3-d7c01d88c8f8 | < 6.2.3 |
CRITICAL | 9.8 | The LoginPress Pro plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 6.2.… | — | wordfence |
| fced0686-f56d-4163-80fd-362ee652d148 | < 3.6.8 |
CRITICAL | 9.8 | The WP Timeline β Vertical and Horizontal timeline plugin plugin for WordPress is vulnerable to Local File Inclusion i… | — | wordfence |
| fccfe581-16aa-4a6e-a6aa-60c05e4d26cb | < 3.2.0 |
CRITICAL | 9.8 | The woo-confirmation-email plugin before 3.2.0 for WordPress has no blocking of direct access to supportive xl folders i… | — | wordfence |
| fcc78fa6-a5f0-4f29-ae19-8e783698b19e | < 1.9.5 |
CRITICAL | 9.8 | The Create by Mediavine plugin for WordPress is vulnerable to SQL Injection via the 'id' parameter in all versions up to… | — | wordfence |
EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.
Scan My Website →