Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.
39,409 vulnerabilities found (page 87 of 1577)
| CVE ID | Plugin / Theme | Severity | CVSS | Description | Fixed In | Source |
|---|---|---|---|---|---|---|
| 20df30e2-7e59-479c-946d-e0128b7d8401 | < 3.7.3 |
CRITICAL | 9.8 | The i-recommend-this plugin before 3.7.3 for WordPress has SQL injection. | — | wordfence |
| 20746c92-6e63-47dd-b0f7-9d20bdbdd9cb | CRITICAL | 9.8 | The DesignFolio Plus Theme for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in … | — | wordfence | |
| 206c3f15-72d2-4aac-9500-0f794485639e | < 3.0.0 |
CRITICAL | 9.8 | Incorrect access control in migla_ajax_functions.php in the Calmar Webmedia Total Donations plugin through 2.0.5 for Wor… | — | wordfence |
| 205e0b90-0d84-4b16-b968-8ec7770f0695 | CRITICAL | 9.8 | The ACF-Frontend-Display plugin through 2.0.6 for WordPress has arbitrary file upload via an action=upload request to js… | — | wordfence | |
| 205a3e43-8ac6-4a0d-86d3-bb433a992e3d | < 1.9 |
CRITICAL | 9.8 | The RokIntroScroller plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in… | — | wordfence |
| 20188fd3-c330-4c76-912b-72731e14c450 | < 1.6.0 |
CRITICAL | 9.8 | The Pix for WooCommerce plugin for WordPress is vulnerable to arbitrary file uploads due to missing capability check and… | — | wordfence |
| 200f724e-7911-46d0-82c0-ffa207d8ee17 | < 2.4.0 |
CRITICAL | 9.8 | The Printcart Web to Print Product Designer for WooCommerce plugin for WordPress is vulnerable to arbitrary file uploads… | — | wordfence |
| 20077e55-fe75-49c7-ba3f-ccd683a3f722 | CRITICAL | 9.8 | The Vithy theme for WordPress is vulnerable to arbitrary file uploads due to missing file type validation via the upload… | — | wordfence | |
| 1fa39169-1cba-43ce-aa29-adf7ce09ce75 | < 1.6.0 |
CRITICAL | 9.8 | The Bello - Directory & Listing WordPress theme before 1.6.0 did not sanitise the bt_bb_listing_field_price_range_to, bt… | — | wordfence |
| 1f93ecf7-ba49-47f6-abe3-33e3bc6e7054 | < 1.1.7 |
CRITICAL | 9.8 | Multiple SQL injection vulnerabilities in dex_reservations.php in the CP Reservation Calendar plugin before 1.1.7 for Wo… | — | wordfence |
| 1f891b68-72c4-4f94-bd49-52576ad710f9 | CRITICAL | 9.8 | The Spreadsheet Price Changer for WooCommerce and WP E-commerce – Light plugin for WordPress is vulnerable to Missing … | — | wordfence | |
| 1f714f97-5e1a-498a-9722-1e4bb883c5c7 | < 1.2.1 |
CRITICAL | 9.8 | Minimist <=1.2.5 is vulnerable to Prototype Pollution via file index.js, function setKey() (lines 69-95). Fixed in 1.2.6… | — | wordfence |
| 1f5b4f9a-4067-4514-9027-b645921d807f | < 1.3.0 |
CRITICAL | 9.8 | Multiple directory traversal vulnerabilities in (1) includes/MapImportCSV2.php and (2) includes/MapImportCSV.php in the … | — | wordfence |
| 1f4f66fd-189a-4036-8e44-c401647bc655 | < 2.1.1 |
CRITICAL | 9.8 | The Medicare theme for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 2.1.0 via deser… | — | wordfence |
| 1ef13f92-ae45-411a-b7b4-cdaf299afc8a | CRITICAL | 9.8 | The CoSchool LMS – A complete Learning Management System to Create and Sell Your Courses Online plugin for WordPress i… | — | wordfence | |
| 1ec14b1e-6d1a-4451-9fce-ac064623d92f | < 1.4.0 |
CRITICAL | 9.8 | The Themes Coder – Create Android & iOS Apps For Your Woocommerce Site plugin for WordPress is vulnerable to privilege… | — | wordfence |
| 1ead6a38-b495-47d2-8d40-1f17e64fd1ff | < 1.8.10.2 |
CRITICAL | 9.8 | SQL injection vulnerability in the Contextual Related Posts plugin before 1.8.10.2 for WordPress allows remote attackers… | — | wordfence |
| 1e8f71cc-3197-4cdb-9e3b-a544f689df2d | CRITICAL | 9.8 | The Pathomation plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in all … | — | wordfence | |
| 1e65922a-3498-4946-8415-3d922e85e46a | < 4.5.0.2 |
CRITICAL | 9.8 | The GEO my WP plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 4.5.0.1 v… | — | wordfence |
| 1e61cc33-d58e-425e-9835-4d45461edbac | CRITICAL | 9.8 | The Nasa Core plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 6.3.2. This m… | — | wordfence | |
| 1e37e54b-9c00-4d04-9c81-791242d45d6c | CRITICAL | 9.8 | The iDump iPhone to WordPress Photo Uploader for WordPress is vulnerable to arbitrary file uploads due to missing file t… | — | wordfence | |
| 1decdfd8-a2e8-49af-ade8-01d19814b6fb | CRITICAL | 9.8 | The Flagallery-skins plugin for WordPress is vulnerable to generic SQL Injection via the ‘playlist’ parameter in all… | — | wordfence | |
| 1de9183c-95b9-4500-85e2-08dcee956360 | < 1.0.5 |
CRITICAL | 9.8 | The Wordpress Plugin Smart Product Review plugin for WordPress is vulnerable to arbitrary file uploads due to missing fi… | — | wordfence |
| 1d9ffbf3-520a-4563-85e1-27c1cc544856 | CRITICAL | 9.8 | The Users Ultra WordPress plugin through 3.1.0 fails to properly sanitize and escape the data_target parameter before it… | — | wordfence | |
| 1d8d393e-764c-491d-8afb-7d4f8d0c387a | < 2.1.0 |
CRITICAL | 9.8 | The Single Sign On For TNG plugin for WordPress is vulnerable to Authentication Bypass via unauthenticated password rese… | — | wordfence |
EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.
Scan My Website →