Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.
41,761 vulnerabilities found (page 85 of 1671)
| CVE ID | Plugin / Theme | Severity | CVSS | Description | Fixed In | Source |
|---|---|---|---|---|---|---|
| 336675c3-b397-42c5-85b0-5a38e1d7bc92 | CRITICAL | 9.8 | The SoftMarket β Digital Marketplace plugin for WordPress is vulnerable to privilege escalation via account takeover i… | — | wordfence | |
| 3320c182-b1f9-4e06-92ea-0fa670557dd0 | CRITICAL | 9.8 | The Network Summary plugin for WordPress is vulnerable to SQL Injection via the 'category' parameter in all versions up … | — | wordfence | |
| 32fe415d-f96d-4023-9faf-b83e7ff6acb1 | CRITICAL | 9.8 | The Quick Count plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 3.00 via de… | — | wordfence | |
| 32e8224d-a653-48d7-a3f4-338fc0c1dc77 | < 1.3.9.6 |
CRITICAL | 9.8 | The WPshop 2 β E-Commerce plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type valida… | — | wordfence |
| 32d81267-f17c-4d53-bbc9-7b52683351e3 | CRITICAL | 9.8 | The sitebuilder-dynamic-components plugin through 1.0 for WordPress has PHP object injection via an AJAX request. | — | wordfence | |
| 32b6ccfe-a659-41e4-9cec-146f4f910071 | < 1.4.5 |
CRITICAL | 9.8 | The Easy Elements for Elementor β Addons & Website Templates plugin for WordPress is vulnerable to privilege escalatio… | — | wordfence |
| 324fcf1b-a811-4750-bf48-87cb6570d51a | CRITICAL | 9.8 | The Wechat Broadcast plugin 1.2.0 and earlier for WordPress allows Directory Traversal via the Image.php url parameter. | — | wordfence | |
| 31f32e84-773e-492d-8f1a-5250e602f952 | CRITICAL | 9.8 | The the-wound plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 0.0.1. Th… | — | wordfence | |
| 31e518a9-316b-40a4-ada7-317fb2c16766 | < 2.2.7 |
CRITICAL | 9.8 | The Frontend Dashboard plugin for WordPress is vulnerable to Privilege Escalation due to a missing capability check on t… | — | wordfence |
| 31d7c673-b625-4862-bc03-378ad663467c | CRITICAL | 9.8 | Vulnerability in wordpress plugin mobile-app-builder-by-wappress v1.05, The plugin includes unlicensed vulnerable CMS so… | — | wordfence | |
| 31cafa29-6040-4fb3-a929-a13b4c087ae0 | < 1.1.16 |
CRITICAL | 9.8 | The Maia theme for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.1.15. This makes … | — | wordfence |
| 31ca2de5-d63c-4ff8-9963-b96213d17cd0 | < 3.4 |
CRITICAL | 9.8 | The BearDev JoomSport plugin 3.3 for WordPress allows SQL injection to steal, modify, or delete database information via… | — | wordfence |
| 31bcc1e1-08b6-4bbc-a28c-9c2d8feea819 | < 1.3.4 |
CRITICAL | 9.8 | The Personal Dictionary WordPress plugin before 1.3.4 fails to properly sanitize user supplied POST data before it is be… | — | wordfence |
| 3184c304-52d3-4baa-b3c2-90957e1d8e79 | < 13.1.0.6 |
CRITICAL | 9.8 | The Contest Gallery WordPress plugin before 13.1.0.6 does not have capability checks and does not sanitise or escape the… | — | wordfence |
| 31513f9e-6185-425b-9e7e-36f21f72d0a2 | < 2.8.7 |
CRITICAL | 9.8 | The JS Help Desk β The Ultimate Help Desk & Support Plugin plugin for WordPress is vulnerable to PHP Code Injection le… | — | wordfence |
| 3131eeeb-593d-443e-8641-7470bd1e556b | CRITICAL | 9.8 | Mufeng's Hermit ι³δΉζζΎε¨ plugin <= 3.1.6 is vulnerable to SQL injection. This allows unauthenticated attackers to… | — | wordfence | |
| 311636d5-e990-4cdd-af1c-8b9610afa73e | CRITICAL | 9.8 | The Team Rosters plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 4.8.2 via … | — | wordfence | |
| 31052fe6-a0ae-4502-b2d2-dbc3b3bf672f | < 4.25.0 |
CRITICAL | 9.8 | The WordPress File Upload plugin for WordPress is vulnerable to Remote Code Execution, Arbitrary File Read, and Arbitrar… | — | wordfence |
| 30f8419c-c7b9-4c68-a845-26c0308d76f3 | < 1.5.0 |
CRITICAL | 9.8 | The Burst Statistics β Privacy-Friendly Analytics for WordPress plugin for WordPress is vulnerable to SQL Injection vi… | — | wordfence |
| 30ea46c1-bb29-49b8-b161-e61f13167ff4 | CRITICAL | 9.8 | The Gallery From Files plugin for WordPress is vulnerable to arbitrary file uploads in versions up to, and including, 1.… | — | wordfence | |
| 30d592d0-323b-40d8-9f13-22041dbded31 | < 2.0.14 |
CRITICAL | 9.8 | The plugmatter-optin-feature-box-lite plugin before 2.0.14 for WordPress has SQL injection via the wp-admin/admin-ajax.p… | — | wordfence |
| 30cc4552-bd12-4211-bd06-637352ceb5df | < 1.3.9.9 |
CRITICAL | 9.8 | The Drag and Drop Multiple File Upload for Contact Form 7 plugin for WordPress is vulnerable to Remote Code Execution in… | — | wordfence |
| 30aab1af-a78f-4bac-b3c5-30ea854ccef7 | < 4.0.2 |
CRITICAL | 9.8 | The MStore API plugin for WordPress is vulnerable to Unauthenticated Blind SQL Injection via the 'id' parameter in versi… | — | wordfence |
| 308cd28a-a477-4bc6-a392-ad5a9eca1cb5 | < 1.3.2 |
CRITICAL | 9.8 | The Quick Playground plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 1… | — | wordfence |
| 30532dc1-5d40-4585-abd2-c08ed0682d72 | < 4.0.0 |
CRITICAL | 9.8 | An issue was discovered in the Login by Auth0 plugin before 4.0.0 for WordPress. It has numerous fields that can contain… | — | wordfence |
EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.
Scan My Website →