Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.
39,409 vulnerabilities found (page 86 of 1577)
| CVE ID | Plugin / Theme | Severity | CVSS | Description | Fixed In | Source |
|---|---|---|---|---|---|---|
| 236bb9a8-49f7-4b75-a0b1-fa4ff65394f8 | CRITICAL | 9.8 | The HotStar – Multi-Purpose Business Theme theme for WordPress is vulnerable to PHP Object Injection in versions up to… | — | wordfence | |
| 235c9967-808f-45f2-85cf-7ee7a523593d | < 1.5.16 |
CRITICAL | 9.8 | Multiple SQL injection vulnerabilities in the ratings module in the Users Ultra plugin before 1.5.16 for WordPress allow… | — | wordfence |
| 233a75c7-9e45-4509-8f7c-584e2f5b38c7 | < 14.4.5 |
CRITICAL | 9.8 | The StoreKeeper for WooCommerce plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type va… | — | wordfence |
| 23399606-20b6-4d0b-b613-06dc838dc1e7 | < 2.9.5 |
CRITICAL | 9.8 | The Welcart e-Commerce plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, … | — | wordfence |
| 232dd4fa-748e-4b65-8b78-7b2d8e9831aa | < 7.3.19.727 |
CRITICAL | 9.8 | A SQL injection vulnerability exists in the FolioVision FV Flowplayer Video Player plugin before 7.3.19.727 for WordPres… | — | wordfence |
| 23239fc1-8683-446e-bc61-03d819edf99d | CRITICAL | 9.8 | The DiveBook plugin 1.1.4 for WordPress was prone to a SQL injection within divelog.php, allowing unauthenticated users … | — | wordfence | |
| 23068a98-623d-4eb3-a7c5-6af410de4320 | CRITICAL | 9.8 | The Realtyna Organic IDX plugin + WPL Real Estate plugin for WordPress is vulnerable to Arbitrary File Upload in all ver… | — | wordfence | |
| 23003405-29c5-41e2-9081-35f05a08a0c3 | CRITICAL | 9.8 | The Arrival theme for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.4.5. This make… | — | wordfence | |
| 22dd9fbb-77d2-48cd-91a5-eba39ef9d2c1 | < 2.5.2 |
CRITICAL | 9.8 | The Modular DS: Monitor, update, and backup multiple websites plugin for WordPress is vulnerable to Privilege Escalation… | — | wordfence |
| 22dced08-20b1-4f21-8c43-148d40a29701 | CRITICAL | 9.8 | The ReFormer – Multichannel Contact Form for Elementor plugin for WordPress is vulnerable to arbitrary file uploads du… | — | wordfence | |
| 22cfa0da-9370-4d95-8b23-024447fd84cd | CRITICAL | 9.8 | The Xews Lite theme for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.0.9. This ma… | — | wordfence | |
| 22a42dc3-0b9b-47c8-9236-5dc3b58149c5 | CRITICAL | 9.8 | SQL injection vulnerability in wp-people-popup.php in Dean Logan WP-People plugin 3.4.1 and below for WordPress allows r… | — | wordfence | |
| 227fb6d1-3515-4172-9d7c-57a66d17858f | < 8.0.27 |
CRITICAL | 9.8 | The WP Live Chat Support Pro plugin through 8.0.26 for WordPress contains an arbitrary file upload vulnerability. This r… | — | wordfence |
| 2259ae51-447c-431d-97af-7fddefb0f349 | CRITICAL | 9.8 | The Grand Restaurant WordPress theme for WordPress is vulnerable to PHP Object Injection in all versions up to, and incl… | — | wordfence | |
| 2250fa2d-82f5-4553-a52e-0c43d215aaba | < 0.4.3 |
CRITICAL | 9.8 | Multiple PHP remote file inclusion vulnerabilities in the BackUpWordPress 0.4.2b and earlier plugin for WordPress allow … | — | wordfence |
| 22356f42-af5e-4479-919c-9ceac42e686f | < 14.8 |
CRITICAL | 9.8 | Unrestricted file upload vulnerability in lib_nonajax.php in the CformsII plugin 14.7 and earlier for WordPress allows r… | — | wordfence |
| 22351b90-fc34-44ce-9241-4a0f01eb7b1c | < 2.0.1 |
CRITICAL | 9.8 | The FS Registration Password plugin for WordPress is vulnerable to privilege escalation via account takeover in all vers… | — | wordfence |
| 2205a0c8-0834-440b-9fee-3223de05a3ac | < 5.4.0 |
CRITICAL | 9.8 | The K Elements plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 5.3.9. … | — | wordfence |
| 21e4b1fe-993b-4898-a523-e0a858c30a38 | < 1.33 |
CRITICAL | 9.8 | The TagGator plugin for WordPress is vulnerable to generic SQL Injection via the ‘tagid’ parameter in versions up to… | — | wordfence |
| 21d244f4-f0cd-4d4d-8c6a-edea6b7b8145 | < 34.06 |
CRITICAL | 9.8 | Multiple security bypass vulnerabilities in the editAnswer, deleteAnswer, addAnswer, and deletePoll functions in WordPre… | — | wordfence |
| 21a1b117-945f-49bc-9ea1-313afa93bf32 | < 4.0.10 |
CRITICAL | 9.8 | The EmbedPress – Embed PDF, 3D Flipbook, Social Feeds, Google Docs, Vimeo, Wistia, YouTube Videos, Audios, Google Maps… | — | wordfence |
| 21930a4f-2f78-42c5-8ffa-2993333db2fe | < 3.1.3 |
CRITICAL | 9.8 | The Ultimate Product Catalogue for WordPress is vulnerable to SQL Injection via the ‘Item_ID’ and 'SingleProduct' pa… | — | wordfence |
| 215f5ab4-44be-4db0-86d5-e7ff0630e15d | < 1.4.6 |
CRITICAL | 9.8 | The Material Dashboard plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.4.… | — | wordfence |
| 215aaad5-bf34-4817-a220-7077e9aa808b | < 1.5.4 |
CRITICAL | 9.8 | The AI Copilot – Content Generator plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, a… | — | wordfence |
| 21456889-058c-46a5-80c3-a0c8f90cd3bf | < 2.82 |
CRITICAL | 9.8 | In the Media Library Assistant plugin before 2.82 for WordPress, Remote Code Execution can occur via the tax_query, meta… | — | wordfence |
EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.
Scan My Website →