Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.
39,409 vulnerabilities found (page 89 of 1577)
| CVE ID | Plugin / Theme | Severity | CVSS | Description | Fixed In | Source |
|---|---|---|---|---|---|---|
| 1aac7677-53f4-4944-9bdc-7e07b09c6c13 | < 1.5 |
CRITICAL | 9.8 | The ND Restaurant Reservations plugin before 1.5 for WordPress is vulnerable to unauthenticated option changes via the n… | — | wordfence |
| 1a74252c-1385-4ee7-aeaa-f0476336b1e6 | CRITICAL | 9.8 | The Umberto theme for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 1.2.8 via deseri… | — | wordfence | |
| 1a4cc739-0563-4ca2-931d-818a0c285257 | < 1.5.5 |
CRITICAL | 9.8 | SQL injection vulnerability in wp-load.php in the BuddyPress plugin 1.5.x before 1.5.5 of WordPress allows remote attack… | — | wordfence |
| 1a385af7-4094-4a1e-9f1f-6291698f71af | < 11.1.0 |
CRITICAL | 9.8 | The SUMO Affiliates Pro plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation… | — | wordfence |
| 1a14b674-620e-4247-a200-92d9f23acbca | < 1.6.49.10 |
CRITICAL | 9.8 | The ThemeREX Addons plugin for WordPress is vulnerable to Improper Access Control in various versions. This is due to th… | — | wordfence |
| 19f737a8-21e6-49d3-95b9-24fb6e5d7af7 | < 2.1.2.1 |
CRITICAL | 9.8 | The InPost Gallery Plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 2.1.2 vi… | — | wordfence |
| 19d1c0ee-9f9b-42a1-8d25-f8ba07e15b0c | CRITICAL | 9.8 | The Motors - Events plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.4.7. … | — | wordfence | |
| 19c824ce-40e2-44fb-a356-6a02bd13cc67 | < 2.5.5 |
CRITICAL | 9.8 | The Residential Address Detection plugin for WordPress is vulnerable to unauthorized modification of data that can lead … | — | wordfence |
| 19c370f1-322b-4c35-b100-244547373e1a | CRITICAL | 9.8 | The User Post Gallery - UPG plugin for WordPress is vulnerable to authorization bypass which leads to remote command exe… | — | wordfence | |
| 19bf7a68-e76d-4740-9f35-b6084094f59b | < 1.6.10 |
CRITICAL | 9.8 | The WPBookit plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient file type validation in th… | — | wordfence |
| 19868c11-67a7-420f-911d-520e00f2f4f5 | CRITICAL | 9.8 | The Houzez Login Register plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and includin… | — | wordfence | |
| 194f71d8-43d7-4a1f-8390-2c1efd0b0a23 | < 0.2.28 |
CRITICAL | 9.8 | The ActiveDEMAND plugin for WordPress is vulnerable to unauthenticated post updates and deletion due to missing authoriz… | — | wordfence |
| 1932c9b4-2fea-40f8-9748-09ded8143c11 | < 4.963 |
CRITICAL | 9.8 | The WPLMS Learning Management System for WordPress, WordPress LMS theme for WordPress is vulnerable to arbitrary file re… | — | wordfence |
| 18fd631d-9e9b-46ee-953f-61ad3458e1dd | < 2.7.6 |
CRITICAL | 9.8 | The MasterStudy LMS WordPress plugin before 2.7.6 does to validate some parameters given when registering a new account,… | — | wordfence |
| 18e562fb-9035-4f2d-a2d3-9a74ff1e4e32 | CRITICAL | 9.8 | The Ketchup Restaurant Reservations plugin for WordPress is vulnerable to blind SQL Injection in versions up to, and inc… | — | wordfence | |
| 189d22e0-c16a-48ab-a278-a132cd1057b6 | < 1.9.0 |
CRITICAL | 9.8 | An issue was discovered in the Huge-IT gallery-images plugin before 1.9.0 for WordPress. The headers Client-Ip and X-For… | — | wordfence |
| 1898fbe5-de5d-45e3-95be-db500f093908 | < 1.1.1 |
CRITICAL | 9.8 | The Lasa theme for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.1. This makes it … | — | wordfence |
| 187df8e0-80f0-4805-823b-80627b76db2a | CRITICAL | 9.8 | The Facebook Survey Pro plugin for WordPress is vulnerable to generic SQL Injection via the βidβ parameter in versio… | — | wordfence | |
| 18739406-fa04-4045-9539-4e943dfe6084 | CRITICAL | 9.8 | The Winnex theme for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.3.2. This makes… | — | wordfence | |
| 186517cd-e444-457a-9e10-583f41595511 | < 1.0.4 |
CRITICAL | 9.8 | The Easy Digital Downloads β Upload File for WordPress is vulnerable to Arbitrary File Upload/Delete and Remote Code E… | — | wordfence |
| 185d692c-bc67-44de-82c7-bcbe454dc178 | CRITICAL | 9.8 | The Contact Form 7 Campaign Monitor Extension plugin for WordPress is vulnerable to arbitrary file deletion due to insuf… | — | wordfence | |
| 18557f4a-05b2-4cb4-afef-19c5c63c37a4 | CRITICAL | 9.8 | The "LB Mixed Slideshow for WordPress" plugin for WordPress is vulnerable to arbitrary file uploads due to missing file … | — | wordfence | |
| 18368ad4-4c35-4b08-8297-2ebdf1bb6e46 | < 2.8.9 |
CRITICAL | 9.8 | The Ezoic plugin for WordPress is vulnerable to authorization bypass to stored cross-site scripting via several REST-API… | — | wordfence |
| 1833720c-e714-4ec5-9ebb-24a4612195d6 | < 2.3.2 |
CRITICAL | 9.8 | The Work The Flow plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in th… | — | wordfence |
| 182370f5-0f56-4757-8276-1399606c1a2d | < 1.44 |
CRITICAL | 9.8 | Directory traversal vulnerability in js/wptable-button.php in the wp-Table 1.43 and earlier plugin for WordPress, when r… | — | wordfence |
EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.
Scan My Website →