Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.
41,761 vulnerabilities found (page 80 of 1671)
| CVE ID | Plugin / Theme | Severity | CVSS | Description | Fixed In | Source |
|---|---|---|---|---|---|---|
| 420580e1-b6cf-4fd7-87fd-e415b097f4c9 | CRITICAL | 9.8 | The Davenport - Versatile Blog and Magazine WordPress Theme plugin for WordPress is vulnerable to Local File Inclusion i… | — | wordfence | |
| 41cfe1d7-2fab-413c-80e5-40d77133d229 | < 11.31.0 |
CRITICAL | 9.8 | The Knowledge Base for Documentation, FAQs with AI Assistance plugin for WordPress is vulnerable to PHP Object Injection… | — | wordfence |
| 41cf57ff-421d-4db2-894f-17f2c4d4b9ed | < 5.6.2 |
CRITICAL | 9.8 | The WooCommerce Payments plugin is vulnerable to authentication bypass via the determine_current_user_for_platform_check… | — | wordfence |
| 41af6441-bc1d-4210-92f3-4c765fda6df9 | < 1.9.13 |
CRITICAL | 9.8 | NextGEN Gallery plugin before 1.9.13 for WordPress: ngggallery.php file upload | — | wordfence |
| 41a61c0f-fffb-4810-b44a-74cbc1192ecd | CRITICAL | 9.8 | The HTML5 AV Manager plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation vi… | — | wordfence | |
| 419a42eb-19ed-46a3-9da0-3fcd2c8e2527 | CRITICAL | 9.8 | The Share Buttons – Social Media plugin for WordPress is vulnerable to SQL Injection in versions up to, and including,… | — | wordfence | |
| 41800ea9-1ace-42fc-9e7f-d760a126342b | < 1.7 |
CRITICAL | 9.8 | The uListing plugin for WordPress is vulnerable to Unauthenticated Arbitrary Account Changes in versions up to, and incl… | — | wordfence |
| 415c9658-bfb2-453b-a697-c63c08b0ca61 | < 1.8.0 |
CRITICAL | 9.8 | The Contact Form by Supsystic plugin for WordPress is vulnerable to Server-Side Template Injection (SSTI) leading to Rem… | — | wordfence |
| 414636bc-3fab-41f9-9d4b-17ca1ac8a3df | < 1.4.72 |
CRITICAL | 9.8 | The Motors plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.4.71. This mak… | — | wordfence |
| 4124003c-4864-48f1-acba-9a613d9c99ae | < 5.4 |
CRITICAL | 9.8 | The tagDiv Composer plugin for WordPress is vulnerable to PHP Object Instantiation in all versions up to, and including,… | — | wordfence |
| 4122a963-b8e2-448a-b268-3192613fa3df | < 4.1.4 |
CRITICAL | 9.8 | The LearnPress WordPress plugin before 4.1.4 does not sanitise, validate and escape the id parameter before using it in … | — | wordfence |
| 41108c2c-99b2-4aff-8c06-bee0b6547a9a | < 3.9.7 |
CRITICAL | 9.8 | The Smart Manager For WooCommerce plugin for WordPress is vulnerable to blind SQL Injection via the ‘edited’ paramet… | — | wordfence |
| 41048058-1662-4ec1-81ac-6e8e42351e7e | < 12.3.1 |
CRITICAL | 9.8 | The Order Delivery Date for WooCommerce plugin for WordPress is vulnerable to unauthorized modification of data that can… | — | wordfence |
| 40a6d10e-5e68-4280-a3e2-0b93095bb4dd | < 3.4.8 |
CRITICAL | 9.8 | The Pearl - Corporate Business theme for WordPress is vulnerable to Local File Inclusion in versions up to 3.4.8. This m… | — | wordfence |
| 40a6a810-1151-49e6-bed4-2b7a572ac015 | < 2.4 |
CRITICAL | 9.8 | pixabay-images.php in the Pixabay Images plugin before 2.4 for WordPress does not properly restrict access to the upload… | — | wordfence |
| 40937e18-3828-4e36-8bc1-5b8eb4838c3b | < 1.2.1 |
CRITICAL | 9.8 | SQL injection vulnerability in the Responsive Image Gallery plugin before 1.2.1 for WordPress allows remote attackers to… | — | wordfence |
| 407b8568-0b47-48d1-a006-2c42e7cfdec3 | CRITICAL | 9.8 | The Right Now theme for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'up… | — | wordfence | |
| 407a0bc3-2775-4a34-9817-924bf94a4f94 | CRITICAL | 9.8 | The WooCommerce Designer Pro plugin for WordPress, used by the Pricom - Printing Company & Design Services WordPress the… | — | wordfence | |
| 40765cfe-a60a-44dc-8cdb-f9c8e42654c3 | < 9.1.1 |
CRITICAL | 9.8 | The BuddyPress plugin for WordPress is vulnerable to generic SQL Injection via the ‘BP_Notifications_Notification::get… | — | wordfence |
| 40716c58-1075-492b-9323-13e7b831e206 | < 3.5.19 |
CRITICAL | 9.8 | The WPFunnels plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 3.5.18 via de… | — | wordfence |
| 406c02e0-cebb-400a-b276-dc0b0bd9f1ad | CRITICAL | 9.8 | The Workreap Core plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 3.4.… | — | wordfence | |
| 40519181-540e-44d4-a9b7-6c8c321b1592 | < 2.2.14.1 |
CRITICAL | 9.8 | The Kids Planet theme for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 2.2.14 via d… | — | wordfence |
| 403c881c-b687-4e7e-8e77-a55203cfde96 | < 3.9 |
CRITICAL | 9.8 | The Chameleon theme for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'qq… | — | wordfence |
| 40010bbd-049f-44b0-9492-4126c4894656 | < 1.8.0 |
CRITICAL | 9.8 | The Cooked Pro plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in all v… | — | wordfence |
| 40000879-a5ef-48f2-97e4-77d527259af0 | < 1.2.6 |
CRITICAL | 9.8 | The Flex QR Code Generator plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validat… | — | wordfence |
EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.
Scan My Website →