Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.
39,409 vulnerabilities found (page 80 of 1577)
| CVE ID | Plugin / Theme | Severity | CVSS | Description | Fixed In | Source |
|---|---|---|---|---|---|---|
| 35a7b5a1-b052-4390-8e08-f97aa9c16b29 | < 3.2.7 |
CRITICAL | 9.8 | The WooCommerce Refund And Exchange with RMA - Warranty Management, Refund Policy, Manage User Wallet theme for WordPres… | — | wordfence |
| 359833dd-de3c-48ea-8eef-06588a590da2 | < 3.2.2 |
CRITICAL | 9.8 | The RestroPress β Online Food Ordering System plugin for WordPress is vulnerable to Authentication Bypass in versions … | — | wordfence |
| 35806af6-bb63-41c8-a20b-f5e36d2aa515 | CRITICAL | 9.8 | The WP Ultimate Email Marketer plugin 1.2.0 and possibly earlier for Wordpress does not properly restrict access to (1) … | — | wordfence | |
| 3511ba64-56a3-43d7-8ab8-c6e40e3b686e | < 1.3.8 |
CRITICAL | 9.8 | The Backup Migration plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 1… | — | wordfence |
| 34fd42cb-3868-4b1c-bc56-575faf01e8f3 | < 6.0.13 |
CRITICAL | 9.8 | The AdForest theme for WordPress is vulnerable to authentication bypass in all versions up to, and including, 6.0.12. Th… | — | wordfence |
| 34b52ca2-c05f-49b7-846f-a67136d7d379 | CRITICAL | 9.8 | The Slider Future plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in th… | — | wordfence | |
| 346af237-0411-4cc4-9544-eab697385a2f | < 1.1.8 |
CRITICAL | 9.8 | The Multi Uploader for Gravity Forms plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient f… | — | wordfence |
| 34612902-1a26-4759-bca6-b5aaffa25af4 | CRITICAL | 9.8 | The Integration Opvius AI for WooCommerce plugin for WordPress is vulnerable to Path Traversal in all versions up to, an… | — | wordfence | |
| 345834f2-e95e-4ea1-b171-1c3f4aa17e0e | CRITICAL | 9.8 | The WordPress Checkout plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation … | — | wordfence | |
| 34439db4-1b66-4ccb-bf84-fddef6bc1f88 | < 1.5.2 |
CRITICAL | 9.8 | The Simple Inventory Management β just scan barcode to manage products and orders. For WooCommerce plugin for WordPres… | — | wordfence |
| 33df72a5-d2bc-4af5-b5bc-f26d7249d238 | CRITICAL | 9.8 | The Think Responsive theme for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in … | — | wordfence | |
| 339ab2b6-ca5e-41a8-ad32-9d2a271fb320 | CRITICAL | 9.8 | The amerisale-re plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation via th… | — | wordfence | |
| 33989611-8640-4c33-a34e-14f10cd7286d | < 3.8.1 |
CRITICAL | 9.8 | The Support Board plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation… | — | wordfence |
| 33680429-8a52-412b-ab61-d261801319a0 | < 1.1.2 |
CRITICAL | 9.8 | The simple-login-log plugin before 1.1.2 for WordPress has SQL injection via the 'orderby' parameter in the get_results … | — | wordfence |
| 3320c182-b1f9-4e06-92ea-0fa670557dd0 | CRITICAL | 9.8 | The Network Summary plugin for WordPress is vulnerable to SQL Injection via the 'category' parameter in all versions up … | — | wordfence | |
| 32fe415d-f96d-4023-9faf-b83e7ff6acb1 | CRITICAL | 9.8 | The Quick Count plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 3.00 via de… | — | wordfence | |
| 32e8224d-a653-48d7-a3f4-338fc0c1dc77 | < 1.3.9.6 |
CRITICAL | 9.8 | The WPshop 2 β E-Commerce plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type valida… | — | wordfence |
| 32d81267-f17c-4d53-bbc9-7b52683351e3 | CRITICAL | 9.8 | The sitebuilder-dynamic-components plugin through 1.0 for WordPress has PHP object injection via an AJAX request. | — | wordfence | |
| 32b6ccfe-a659-41e4-9cec-146f4f910071 | < 1.4.5 |
CRITICAL | 9.8 | The Easy Elements for Elementor β Addons & Website Templates plugin for WordPress is vulnerable to privilege escalatio… | — | wordfence |
| 324fcf1b-a811-4750-bf48-87cb6570d51a | CRITICAL | 9.8 | The Wechat Broadcast plugin 1.2.0 and earlier for WordPress allows Directory Traversal via the Image.php url parameter. | — | wordfence | |
| 31f32e84-773e-492d-8f1a-5250e602f952 | CRITICAL | 9.8 | The the-wound plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 0.0.1. Th… | — | wordfence | |
| 31e518a9-316b-40a4-ada7-317fb2c16766 | < 2.2.7 |
CRITICAL | 9.8 | The Frontend Dashboard plugin for WordPress is vulnerable to Privilege Escalation due to a missing capability check on t… | — | wordfence |
| 31d7c673-b625-4862-bc03-378ad663467c | CRITICAL | 9.8 | Vulnerability in wordpress plugin mobile-app-builder-by-wappress v1.05, The plugin includes unlicensed vulnerable CMS so… | — | wordfence | |
| 31cafa29-6040-4fb3-a929-a13b4c087ae0 | < 1.1.16 |
CRITICAL | 9.8 | The Maia theme for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.1.15. This makes … | — | wordfence |
| 31ca2de5-d63c-4ff8-9963-b96213d17cd0 | < 3.4 |
CRITICAL | 9.8 | The BearDev JoomSport plugin 3.3 for WordPress allows SQL injection to steal, modify, or delete database information via… | — | wordfence |
EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.
Scan My Website →