Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.
39,409 vulnerabilities found (page 84 of 1577)
| CVE ID | Plugin / Theme | Severity | CVSS | Description | Fixed In | Source |
|---|---|---|---|---|---|---|
| 2945ab15-e211-4a11-954a-002d0fd2a04d | < 1.61.1 |
CRITICAL | 9.8 | The Ogami theme for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.53. This makes i… | — | wordfence |
| 2927aa13-b012-41eb-93bd-38a4e5fc5455 | < 3.19 |
CRITICAL | 9.8 | The TicketBAI Facturas para WooCommerce plugin for WordPress is vulnerable to arbitrary file deletion due to insufficien… | — | wordfence |
| 290e7b9d-23b6-47bb-9169-d2f9922b6492 | CRITICAL | 9.8 | The Fami Sales Popup plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 2.0.0.… | — | wordfence | |
| 28cb96a9-12bd-4d9c-ac53-72e81d11b0b6 | < 3.0.96 |
CRITICAL | 9.8 | The ThemePunch Slider Revolution (revslider) plugin before 3.0.96 for WordPress and Showbiz Pro plugin 1.7.1 and earlier… | — | wordfence |
| 2882d9dd-0c73-4c9a-99cb-d10900503103 | CRITICAL | 9.8 | The Social Connect plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 1.2. Th… | — | wordfence | |
| 28713983-86ef-45d1-9258-d1a4feedcadd | < 4.08.253 |
CRITICAL | 9.8 | The WebinarIgnition β Live, Automated & Evergreen Webinar System also for WooCommerce plugin for WordPress is vulnerab… | — | wordfence |
| 284eafb9-94bc-4478-abff-f7dafd510a1d | < 4.1.3 |
CRITICAL | 9.8 | The Simple Membership plugin for WordPress is vulnerable to membership related privilege escalation in versions up to, a… | — | wordfence |
| 283b10e6-61ae-4e1d-be7b-a63aece6ffda | < 4.2.23 |
CRITICAL | 9.8 | The Etoile Ultimate Product Catalog plugin 4.2.22 for WordPress has SQL injection with these wp-admin/admin-ajax.php POS… | — | wordfence |
| 282a26e8-4848-4e40-bfe5-fe2ba40f198e | < 1.0.34 |
CRITICAL | 9.8 | Multiple SQL injection vulnerabilities in wpf.class.php in the Mingle Forum plugin before 1.0.34 for WordPress allow rem… | — | wordfence |
| 27f90d97-c62f-4591-ba26-8d204d567687 | < 2.5.0 |
CRITICAL | 9.8 | The Avantage theme for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 2.4.9 via deser… | — | wordfence |
| 27bb60c1-43fa-4a18-b9ca-059535b0d5b6 | < 1.1.20 |
CRITICAL | 9.8 | The Users manager β PN plugin for WordPress is vulnerable to Privilege Escalation via Arbitrary User Meta Update in al… | — | wordfence |
| 2742cc47-8e3d-4fe4-b653-7310a4156a84 | < 1.3.1 |
CRITICAL | 9.8 | The aDirectory β Directory Listing WordPress Plugin plugin for WordPress is vulnerable to arbitrary file uploads due t… | — | wordfence |
| 271b151c-5646-4206-a7db-739ac36a9fdd | CRITICAL | 9.8 | The 1-Click Login: Passwordless Authentication plugin for WordPress is vulnerable to authentication bypass in version 1.… | — | wordfence | |
| 271a35fb-56b7-4d6b-bccc-fea1227d0913 | CRITICAL | 9.8 | The Riaxe Product Customizer plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and inclu… | — | wordfence | |
| 2710b445-4281-4055-be37-56902ae1d1b6 | < 2.0.66.1 |
CRITICAL | 9.8 | The Yozi theme for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 2.0.63. This makes … | — | wordfence |
| 26f4e785-724b-41d3-b479-cb0150e70f9e | CRITICAL | 9.8 | The Advanced Booking Calendar for WordPress is vulnerable to SQL Injection in versions up to, and including, 1.7.1 due t… | — | wordfence | |
| 26d83a9d-3e51-450e-b3cb-7c53a4bcba60 | CRITICAL | 9.8 | The PICA Photo Gallery plugin for WordPress is vulnerable to SQL Injection via the βaidβ parameter in versions up to… | — | wordfence | |
| 2693ae37-790d-4b18-a9ec-054c8c27b8bc | < 3.4.4 |
CRITICAL | 9.8 | The Everest Forms plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 3.4.3… | — | wordfence |
| 268b77b9-af1d-41c8-9f24-99b60eb04cc4 | < 3.4.3 |
CRITICAL | 9.8 | The ConvertPlug plugin for WordPress is vulnerable to Unauthenticated Administrator Creation in versions up to, and incl… | — | wordfence |
| 2685a2b4-aba3-425b-af0d-06f7693ab3d7 | < 1.1.5 |
CRITICAL | 9.8 | The Drag and Drop Multiple File Upload for WooCommerce plugin for WordPress is vulnerable to arbitrary file moving due t… | — | wordfence |
| 2655ec9f-471f-48e7-8e1c-a428ef3b46ee | CRITICAL | 9.8 | Unrestricted file upload vulnerability in upload.php in the Powerplay Gallery plugin 3.3 for WordPress allows remote att… | — | wordfence | |
| 2652a7fc-b610-40f1-8b76-2129f59390ec | < 3.8.0 |
CRITICAL | 9.8 | The Stripe Payment Plugin for WooCommerce plugin for WordPress is vulnerable to SQL Injection via the 'id' parameter in … | — | wordfence |
| 2637e273-a308-4033-be5a-2f778f8df282 | < 1.2.2 |
CRITICAL | 9.8 | The Create Block Theme plugin for WordPress is vulnerable to arbitrary file uploads due to missing authorization via the… | — | wordfence |
| 262e3bb3-bc83-4d0b-8056-9f94ec141b8f | < 6.05 |
CRITICAL | 9.8 | The ZoomSounds plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the '… | — | wordfence |
| 26153183-45f1-4694-94ec-f547f1b99089 | CRITICAL | 9.8 | The Recently plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 1.1 via deseri… | — | wordfence |
EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.
Scan My Website →