Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.
39,409 vulnerabilities found (page 88 of 1577)
| CVE ID | Plugin / Theme | Severity | CVSS | Description | Fixed In | Source |
|---|---|---|---|---|---|---|
| 1d87d225-7de4-49f8-9cba-391d718af7fd | CRITICAL | 9.8 | The Arigato Autoresponder and Newsletter (aka bft-autoresponder) v2.5.1.7 plugin for WordPress allows remote attackers t… | — | wordfence | |
| 1d7f1283-a274-49a2-8bec-da178771b13a | < 4.11.2 |
CRITICAL | 9.8 | The Hotel Booking Lite plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, … | — | wordfence |
| 1d779ad1-fdbe-444c-85c5-99146a1a03d8 | < 1.0.5 |
CRITICAL | 9.8 | The WPBookit plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the ima… | — | wordfence |
| 1d640d8e-7730-47e1-9f01-b9656f1ebb1c | < 1.6.1 |
CRITICAL | 9.8 | The GrandPrix theme for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.6. This make… | — | wordfence |
| 1d54bd25-148f-4e9a-bd31-77b52efd5499 | CRITICAL | 9.8 | The Wp NssUser Register plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including,… | — | wordfence | |
| 1d2b78e0-1b82-4074-8051-e44dcfe3ac51 | CRITICAL | 9.8 | The Compute Links plugin for WordPress is vulnerable to Remote File Inclusion in all versions up to, and including, 1.2.… | — | wordfence | |
| 1cefe584-c1b0-418c-bade-ca4092807b1b | < 2.6 |
CRITICAL | 9.8 | The duplicate-post plugin before 2.6 for WordPress has SQL injection. | — | wordfence |
| 1cc1727e-92a6-484d-bdd1-d79aec534df5 | CRITICAL | 9.8 | The Product Lister for eBay plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including,… | — | wordfence | |
| 1cbd298c-cba3-4986-b44c-a75b005b4340 | < 0.9.7b |
CRITICAL | 9.8 | The The Hacker's Diet plugin for WordPress is vulnerable to SQL Injection via the 'user' parameter in all versions up to… | — | wordfence |
| 1cab1bef-c8c5-45ee-921e-0d01736e74c6 | CRITICAL | 9.8 | The postMash – custom post order plugin for WordPress is vulnerable to SQL Injection in versions up to, and including,… | — | wordfence | |
| 1c7c0c35-5f44-488f-9fe1-269ea4a73854 | < 4.10.8 |
CRITICAL | 9.8 | The MStore API plugin for WordPress is vulnerable to Unauthorized Account Access and Privilege Escalation in versions up… | — | wordfence |
| 1c6bf45b-b02d-43bb-b682-7f1ae994e1d3 | < 1.7 |
CRITICAL | 9.8 | The Unauthenticated Account Creation plugin for WordPress is vulnerable to Unauthenticated Account Creation in versions … | — | wordfence |
| 1c648de5-14b3-4c7f-a1c2-46d91b56b0ff | < 1.11 |
CRITICAL | 9.8 | PHP remote file inclusion vulnerability in myflash-button.php in the myflash 1.00 and earlier plugin for WordPress allow… | — | wordfence |
| 1c0c6a45-2c4a-4a23-84e6-7a9759796824 | < 4.9.56 |
CRITICAL | 9.8 | The Product Options and Price Calculation Formulas for WooCommerce – Uni CPO (Premium) plugin for WordPress is vulnera… | — | wordfence |
| 1bd44471-1a9c-4465-a52a-be64d51e7ea1 | CRITICAL | 9.8 | The Wechat Social login plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 1.… | — | wordfence | |
| 1bbe01b8-24ed-4e1e-bafc-0f4dea96c1f3 | < 2.3.4 |
CRITICAL | 9.8 | The Post Grid and Gutenberg Blocks plugin for WordPress is vulnerable to privilege escalation in versions 2.2.85 to 2.3.… | — | wordfence |
| 1bb4674e-71e4-43db-ad9e-36ab15432149 | < 4.6.9 |
CRITICAL | 9.8 | The Fancy Product Designer WordPress plugin before 4.6.9 allows unauthenticated attackers to upload arbitrary files, res… | — | wordfence |
| 1ba55302-b38f-4932-bbba-cdd517380ad7 | < 6.9.5 |
CRITICAL | 9.8 | WordPress Core is vulnerable to Remote Code Execution in all versions 6.9 to 7.0.1 via the REST API batch request endpoi… | — | wordfence |
| 1b94583f-405e-4fd3-849e-33563b72f698 | < 7.2.3 |
CRITICAL | 9.8 | The Image Optimizer, Resizer and CDN – Sirv plugin for WordPress is vulnerable to unauthorized modification of data du… | — | wordfence |
| 1b5a0c87-59b0-4da4-8949-0957f8e1b479 | CRITICAL | 9.8 | The EventON - WordPress Virtual Event Calendar Plugin plugin for WordPress (full) is vulnerable to SQL Injection via the… | — | wordfence | |
| 1b4acf11-114a-4e97-89cd-1d387f14a730 | CRITICAL | 9.8 | The URL Shortener Plugin For WordPress plugin for WordPress is vulnerable to SQL Injection via the ‘analytic_id’ par… | — | wordfence | |
| 1b4630f7-74db-46c4-bf86-f1ff64be3463 | < 1.11.10.8 |
CRITICAL | 9.8 | The BERTHA AI. Your AI co-pilot for WordPress and Chrome plugin for WordPress is vulnerable to arbitrary file uploads du… | — | wordfence |
| 1b097ab2-7675-4409-b22a-ad70cee35ab1 | < 2.5.7.1 |
CRITICAL | 9.8 | The GamiPress plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 2.5.7 due to insuffi… | — | wordfence |
| 1ad38d18-689c-41ab-9e33-fccbf6791cdb | CRITICAL | 9.8 | Remote file upload vulnerability in Wordpress Plugin Mobile App Native 3.0 in /zen-mobile-app-native/server/images.php f… | — | wordfence | |
| 1ac218f6-0bfa-480c-9159-d75a027022ba | < 17.8 |
CRITICAL | 9.8 | The WooCommerce Support Ticket System plugin for WordPress is vulnerable to arbitrary file uploads due to missing file t… | — | wordfence |
EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.
Scan My Website →