Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.
39,403 vulnerabilities found (page 9 of 1577)
| CVE ID | Plugin / Theme | Severity | CVSS | Description | Fixed In | Source |
|---|---|---|---|---|---|---|
| fca20535-d033-45d5-acc3-72ad53d34b4f | < 3.3 |
CRITICAL | 9.8 | The Login as User or Customer plugin for WordPress is vulnerable to authorization bypass due to improper authorization c… | — | wordfence |
| fca11e5b-2b6c-42f0-baf3-4ee023535f83 | CRITICAL | 9.8 | The lim4wp plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the uploa… | — | wordfence | |
| fc747d1a-9d95-4127-8bb9-13dc2beb1874 | CRITICAL | 9.8 | The Stacks Mobile App Builder β The most powerful Mobile Applications Drag and Drop builder plugin for WordPress is vu… | — | wordfence | |
| fc6dcf93-7f1f-4e87-8ba5-852d23b1f0fd | < 4.2 |
CRITICAL | 9.8 | The Jetpack plugin for WordPress is vulnerable to timing attacks in versions up to, and including, 4.1.x. This is due to… | — | wordfence |
| fbf2aeed-0f18-4ef6-aff8-9e8c4531d789 | < 3.1.8 |
CRITICAL | 9.8 | The Adifier System plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to… | — | wordfence |
| fbdd01b3-153b-4783-b686-558874d2856e | CRITICAL | 9.8 | Directory traversal vulnerability in download_audio.php in the SE HTML5 Album Audio Player (se-html5-album-audio-player)… | — | wordfence | |
| fbdc0074-f357-455e-8f17-0821494ea550 | < 6.3.6 |
CRITICAL | 9.8 | The WP Travel Engine plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 6.3.5.… | — | wordfence |
| fbd978fd-f759-4983-90b0-af7338e21d30 | < 5.0.1.8 |
CRITICAL | 9.8 | The RegistrationMagic WordPress plugin made it possible for unauthenticated users to log in as any site user, including … | — | wordfence |
| fbc8c188-dd68-481c-9584-f9d856db8b7d | < 2.1.1 |
CRITICAL | 9.8 | The g-FFL Checkout plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in a… | — | wordfence |
| fbba5284-917a-4056-a798-b4d155c58313 | < 3.2.0 |
CRITICAL | 9.8 | The WP Event Manager plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 3.1.51… | — | wordfence |
| fb7112bb-c76a-4665-b891-8c388ce05d51 | < 4.2.2 |
CRITICAL | 9.8 | The Visual Website Collaboration, Feedback & Project Management β Atarim plugin for WordPress is vulnerable to Privile… | — | wordfence |
| fb66378c-4e64-4f05-a466-72a3c2d0b330 | < 5.6 |
CRITICAL | 9.8 | The Events Manager plugin for WordPress is vulnerable to Code Injection in versions up to, and including, 5.5.7.1. This … | — | wordfence |
| fb5a65a2-e748-4c23-8cae-cb0a7de74911 | < 4.13.0 |
CRITICAL | 9.8 | An issue was discovered in the File Upload plugin before 4.13.0 for WordPress. A directory traversal can lead to remote … | — | wordfence |
| fb11ad61-4ee7-45d2-a8e4-388f86bf4a0e | < 2.3.1 |
CRITICAL | 9.8 | The Joy Of Text Lite plugin for WordPress is vulnerable to SQL Injection via several parameters in versions up to, and i… | — | wordfence |
| fae8a397-bbe9-4acf-a35e-9bad67df69f1 | CRITICAL | 9.8 | The GRΓN spendino Spendenformular β Mehr Spenden! Weniger Arbeit! plugin for WordPress is vulnerable to unauthorized … | — | wordfence | |
| facba004-fc2a-4ba0-aabf-551b5f11e567 | < 1.5.4 |
CRITICAL | 9.8 | The Fediverse Embeds plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in… | — | wordfence |
| fac29bb3-e534-4bee-9974-5ccac7d445db | < 1.6.3 |
CRITICAL | 9.8 | The Daily Edition theme for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the… | — | wordfence |
| fabc7ad3-1d20-493f-aacb-1832d33d8e14 | < 2.12.1 |
CRITICAL | 9.8 | The Porto Theme - Functionality plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 2.… | — | wordfence |
| faa3f6ab-43d6-4874-b16e-93abbb4ba72e | < 1.9 |
CRITICAL | 9.8 | The Bit Form plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the sav… | — | wordfence |
| fa86b98c-9690-4ef6-ac50-895035ed2b55 | CRITICAL | 9.8 | The Smart Slideshow plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation via… | — | wordfence | |
| fa8124db-ee6a-481d-88c6-4cc84fefcf1c | < 2.2.1 |
CRITICAL | 9.8 | The Flynax Bridge plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to,… | — | wordfence |
| fa7e74ee-fd66-41e2-babd-06bdfb32d013 | < 4.1.7.2 |
CRITICAL | 9.8 | The LearnPress plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 4.1.7.1 via … | — | wordfence |
| fa45d830-fa28-4d94-a6d5-2dc2b8456cf2 | < 2.0.4 |
CRITICAL | 9.8 | The "WordPress Automatic Plugin" plugin for WordPress is vulnerable to generic SQL Injection via the βqβ parameter i… | — | wordfence |
| fa412364-2e22-439f-8f94-2c525cfbf1a7 | CRITICAL | 9.8 | The Saoshyant Slider plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 3.0 vi… | — | wordfence | |
| fa2bc3ae-1162-496b-8bc3-5bee1c0ff702 | < 1.2.7 |
CRITICAL | 9.8 | The Cherry Plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation and lack of … | — | wordfence |
EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.
Scan My Website →