Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.
39,409 vulnerabilities found (page 85 of 1577)
| CVE ID | Plugin / Theme | Severity | CVSS | Description | Fixed In | Source |
|---|---|---|---|---|---|---|
| 26140315-04c7-4056-a570-865cd4ffe85e | < 7.0.2 |
CRITICAL | 9.8 | The Quiz and Survey Master plugin for WordPress is vulnerable to arbitrary file uploads due to missing filename sanitiza… | — | wordfence |
| 2597724a-9a39-4e46-b153-f42366f833ba | < 1.5.6.1 |
CRITICAL | 9.8 | All plugins by Essentialplugin for WordPress are vulnerable to an injected backdoor in various versions. This is due to … | — | wordfence |
| 25971f3f-4816-416c-9de9-feb6326fe948 | < 6.5 |
CRITICAL | 9.8 | The Super Store Finder plugin in versions up to, and including 6.4 and the Super Interactive Maps plugin in versions up … | — | wordfence |
| 259158f0-390a-458f-9d8e-262006c4c18d | < 1.0.7 |
CRITICAL | 9.8 | The Really Simple Guest Post plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including… | — | wordfence |
| 256c4984-eee8-4ed0-ba34-e022822d6387 | CRITICAL | 9.8 | The Private Content plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 8.1… | — | wordfence | |
| 2565852f-43df-41b1-949e-6c02a8946407 | < 3.0.0 |
CRITICAL | 9.8 | The Sitepact's Contact Form 7 Extension For Klaviyo plugin for WordPress is vulnerable to SQL Injection parameter in ver… | — | wordfence |
| 25627b5c-958c-45ad-8450-8dfccdfdac31 | CRITICAL | 9.8 | The Radykal Fancy Gallery plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validati… | — | wordfence | |
| 2513a199-30a8-45a9-80b3-1f6e51534c88 | CRITICAL | 9.8 | The Nightlife Theme for WordPress is vulnerable to arbitrary file uploads due to missing file type validation via the up… | — | wordfence | |
| 24f31bbf-883f-4903-847a-7bfc3e45654c | CRITICAL | 9.8 | The Icons Factory plugin for WordPress is vulnerable to Arbitrary File Deletion due to insufficient authorization and im… | — | wordfence | |
| 24e8d1a4-9853-4f60-a371-7fdbe86d554b | < 12.4 |
CRITICAL | 9.8 | The tagDiv Cloud Library plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capabi… | — | wordfence |
| 24d081e3-4291-427c-bf2c-726d93aa00ac | < 1.4 |
CRITICAL | 9.8 | The filedownload plugin for WordPress is vulnerable to blind SQL Injection in versions before 1.4 due to insufficient es… | — | wordfence |
| 24c9a333-e60e-481b-ba27-65094f4f8d39 | < 5.0.7 |
CRITICAL | 9.8 | The Drag and Drop Multiple File Upload (Pro) - WooCommerce plugin for WordPress is vulnerable to arbitrary file uploads … | — | wordfence |
| 24a88f20-ddc4-4544-ac18-ed538ecfa1c7 | CRITICAL | 9.8 | Remote file upload vulnerability in wordpress plugin csv2wpec-coupon v1.1 in csv2wpecCoupon_FileUpload.php file. | — | wordfence | |
| 2491d502-8087-4e95-b047-a3b196322d94 | < 4.7.4 |
CRITICAL | 9.8 | The Filebird Plugin 4.7.3 introduced a SQL injection vulnerability as it is making SQL queries without escaping user inp… | — | wordfence |
| 2489e649-27f7-4ca0-8655-0957016fa89a | CRITICAL | 9.8 | The UserPlus plugin for WordPress is vulnerable to privilege escalation in versions up to, and including, 2.0 due to ins… | — | wordfence | |
| 247ee5bf-1e77-4461-b9f7-28b051b78af7 | CRITICAL | 9.8 | The Real Estate Manager plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 7.3… | — | wordfence | |
| 24517dc6-4995-48ee-9b02-5c7c29d359f6 | < 3.05.1 |
CRITICAL | 9.8 | The Webinar Plugin: Create live/evergreen/automated/instant webinars, stream & Zoom Meetings | WebinarIgnition plugin fo… | — | wordfence |
| 2450277e-589d-4153-bd3f-ffed1a8b4340 | CRITICAL | 9.8 | The epic theme through 2014-09-07 for WordPress allows arbitrary file downloads via the file parameter to includes/downl… | — | wordfence | |
| 244b6773-8983-4435-8d1c-240bcc54e061 | CRITICAL | 9.8 | The Lis Video Gallery plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 0.2.1… | — | wordfence | |
| 240cc19a-9bae-4e69-a16f-46901daaa945 | < 3.0.1 |
CRITICAL | 9.8 | The Brandfolder β Digital Asset Management Simplified. plugin for WordPress is vulnerable to Local and Remote File Inc… | — | wordfence |
| 24092cd1-cf89-49c1-a607-4d5d06d0c804 | CRITICAL | 9.8 | The IP Loc8 plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 1.1 via deseria… | — | wordfence | |
| 23fbb011-cf60-4c75-ac68-b5d0dfa3c356 | < 1.6.7 |
CRITICAL | 9.8 | Server-Side Request Forgery (SSRF) exists in the Print My Blog plugin before 1.6.7 for WordPress via the site parameter. | — | wordfence |
| 23da892a-62c1-4c4b-8b86-4b55018c309b | CRITICAL | 9.8 | The WPSPX plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1.0.2. This m… | — | wordfence | |
| 23c99d3c-5ee5-4793-92a4-f49bf345c634 | CRITICAL | 9.8 | The Spreadsheet Price Changer for WooCommerce and WP E-commerce β Light plugin for WordPress is vulnerable to Remote C… | — | wordfence | |
| 23aa8a2f-9238-4d93-b2d2-de7838ccb156 | < 1.5.5 |
CRITICAL | 9.8 | SQL injection vulnerability in WordPress Tune Library plugin before 1.5.5. | — | wordfence |
EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.
Scan My Website →