Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.
39,409 vulnerabilities found (page 81 of 1577)
| CVE ID | Plugin / Theme | Severity | CVSS | Description | Fixed In | Source |
|---|---|---|---|---|---|---|
| 31bcc1e1-08b6-4bbc-a28c-9c2d8feea819 | < 1.3.4 |
CRITICAL | 9.8 | The Personal Dictionary WordPress plugin before 1.3.4 fails to properly sanitize user supplied POST data before it is be… | — | wordfence |
| 3184c304-52d3-4baa-b3c2-90957e1d8e79 | < 13.1.0.6 |
CRITICAL | 9.8 | The Contest Gallery WordPress plugin before 13.1.0.6 does not have capability checks and does not sanitise or escape the… | — | wordfence |
| 31513f9e-6185-425b-9e7e-36f21f72d0a2 | < 2.8.7 |
CRITICAL | 9.8 | The JS Help Desk – The Ultimate Help Desk & Support Plugin plugin for WordPress is vulnerable to PHP Code Injection le… | — | wordfence |
| 3131eeeb-593d-443e-8641-7470bd1e556b | CRITICAL | 9.8 | Mufeng's Hermit éŸ³ä¹æ’放器 plugin <= 3.1.6 is vulnerable to SQL injection. This allows unauthenticated attackers to… | — | wordfence | |
| 311636d5-e990-4cdd-af1c-8b9610afa73e | CRITICAL | 9.8 | The Team Rosters plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 4.8.2 via … | — | wordfence | |
| 31052fe6-a0ae-4502-b2d2-dbc3b3bf672f | < 4.25.0 |
CRITICAL | 9.8 | The WordPress File Upload plugin for WordPress is vulnerable to Remote Code Execution, Arbitrary File Read, and Arbitrar… | — | wordfence |
| 30f8419c-c7b9-4c68-a845-26c0308d76f3 | < 1.5.0 |
CRITICAL | 9.8 | The Burst Statistics – Privacy-Friendly Analytics for WordPress plugin for WordPress is vulnerable to SQL Injection vi… | — | wordfence |
| 30ea46c1-bb29-49b8-b161-e61f13167ff4 | CRITICAL | 9.8 | The Gallery From Files plugin for WordPress is vulnerable to arbitrary file uploads in versions up to, and including, 1.… | — | wordfence | |
| 30d592d0-323b-40d8-9f13-22041dbded31 | < 2.0.14 |
CRITICAL | 9.8 | The plugmatter-optin-feature-box-lite plugin before 2.0.14 for WordPress has SQL injection via the wp-admin/admin-ajax.p… | — | wordfence |
| 30aab1af-a78f-4bac-b3c5-30ea854ccef7 | < 4.0.2 |
CRITICAL | 9.8 | The MStore API plugin for WordPress is vulnerable to Unauthenticated Blind SQL Injection via the 'id' parameter in versi… | — | wordfence |
| 308cd28a-a477-4bc6-a392-ad5a9eca1cb5 | < 1.3.2 |
CRITICAL | 9.8 | The Quick Playground plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 1… | — | wordfence |
| 30532dc1-5d40-4585-abd2-c08ed0682d72 | < 4.0.0 |
CRITICAL | 9.8 | An issue was discovered in the Login by Auth0 plugin before 4.0.0 for WordPress. It has numerous fields that can contain… | — | wordfence |
| 3045c9e5-4095-48e5-8d9d-16a091e69d54 | CRITICAL | 9.8 | The Copypress Rest API plugin for WordPress is vulnerable to Remote Code Execution via copyreap_handle_image() Function … | — | wordfence | |
| 2fb44c6e-520e-4a9f-9987-8b770feb710d | < 2.5.2 |
CRITICAL | 9.8 | The Kubio AI Page Builder plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and includin… | — | wordfence |
| 2fa6d06d-7323-42d1-94ef-9dfda9c166c4 | < 7.8.0 |
CRITICAL | 9.8 | The miniOrange Social Login and Register (Discord, Google, Twitter, LinkedIn) Pro Addon plugin for WordPress is vulnerab… | — | wordfence |
| 2fa59f00-49f5-43ff-b3fe-0a62f52b0257 | < 5.5.4 |
CRITICAL | 9.8 | The iControlWP plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 5.5.3. T… | — | wordfence |
| 2f8f6ade-84a2-4a42-9208-a74f5ebe19b3 | < 1.8.3 |
CRITICAL | 9.8 | The Collne Welcart e-Commerce plugin before 1.8.3 for WordPress mishandles sessions, which allows remote attackers to ob… | — | wordfence |
| 2f7e7b03-e709-44b6-8ff9-f2f0b3836629 | < 1.3.8 |
CRITICAL | 9.8 | The AI Hub plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in all versi… | — | wordfence |
| 2f6822a9-94b2-47a8-9faa-5e1498e0dbde | CRITICAL | 9.8 | The Background Image Cropper plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and incl… | — | wordfence | |
| 2f52298b-344b-4561-b1bf-93bea95a3e53 | < 1.0.29 |
CRITICAL | 9.8 | The Piotnet Forms plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in th… | — | wordfence |
| 2f47a01d-b259-465e-bec1-9079987dc5a5 | < 2.0.11 |
CRITICAL | 9.8 | The Kiwi Social Share plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on th… | — | wordfence |
| 2f0a7d6f-9b95-4052-bab3-85aca01f6ab7 | < 1.1.11 |
CRITICAL | 9.8 | The Form Notify plugin for WordPress is vulnerable to Authentication Bypass in versions up to and including 1.1.10. This… | — | wordfence |
| 2ef5e73e-a627-4e9c-9784-493ace5c8614 | < 4.91.9 |
CRITICAL | 9.8 | The VideoWhisper videowhisper-video-conference-integration plugin 4.91.8 for WordPress allows remote attackers to execut… | — | wordfence |
| 2ef21a44-6d03-4197-b49c-d881f9831f46 | < 8.9.1 |
CRITICAL | 9.8 | The Admin and Site Enhancements (ASE) Pro plugin for WordPress is vulnerable to Remote Code Execution in all versions up… | — | wordfence |
| 2eeeb4b5-972b-471b-8f0f-a198640fc894 | < 3.0 |
CRITICAL | 9.8 | The Memphis Documents Library plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and includin… | — | wordfence |
EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.
Scan My Website →