Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.
39,409 vulnerabilities found (page 90 of 1577)
| CVE ID | Plugin / Theme | Severity | CVSS | Description | Fixed In | Source |
|---|---|---|---|---|---|---|
| 181eb0e4-3529-4069-91b4-6f6c6ee2c786 | CRITICAL | 9.8 | The UsersControl β Users Profile, Free or Paid Subscriptions, User Access Restriction & Members Directory plugin for … | — | wordfence | |
| 181e41d6-1599-4229-ace8-0bdb5735858f | CRITICAL | 9.8 | … | — | wordfence | |
| 1814ad55-0807-4def-b584-6dbbc5d6eb72 | < 3.10 |
CRITICAL | 9.8 | The rtMedia for WordPress, BuddyPress and bbPress plugin for WordPress is vulnerable to Local File Inclusion in versions… | — | wordfence |
| 1814537d-8307-4d1f-86c8-801519172be5 | < 1.7 |
CRITICAL | 9.8 | The uListing plugin for WordPress is vulnerable to authorization bypass via Ajax due to missing capability checks, missi… | — | wordfence |
| 17dcacaf-0e2a-4bef-b944-fb7e43d25777 | < 2.7.3 |
CRITICAL | 9.8 | The Country State City Dropdown CF7 plugin for WordPress is vulnerable to SQL Injection via the βcntβ and 'sid' para… | — | wordfence |
| 17d8e2e9-5e3f-433b-be1a-6ea765eba547 | < 4.15.0 |
CRITICAL | 9.8 | The MStore API β Create Native Android & iOS Apps On The Cloud plugin for WordPress is vulnerable to authentication by… | — | wordfence |
| 17ccf3f5-ac71-4827-bf11-9a5199f8752e | CRITICAL | 9.8 | The AJAX Random Posts plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 0.3.3… | — | wordfence | |
| 17cc137e-da04-42ea-9336-24c4e0b9264a | CRITICAL | 9.8 | The Devexhub Gallery plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in… | — | wordfence | |
| 1789b78a-4733-40b9-b28f-f63aeb4c0f0b | < 2.10.0 |
CRITICAL | 9.8 | The TI WooCommerce Wishlist plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type valida… | — | wordfence |
| 178911d9-0552-4f44-aae5-06fc9734cfac | < 5.9.6 |
CRITICAL | 9.8 | The Event post plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 5.9.5 vi… | — | wordfence |
| 17641096-1c7f-43f7-90d6-14c368c95d72 | CRITICAL | 9.8 | The Advanced Personalization plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including… | — | wordfence | |
| 16e3ca1b-817d-4f03-92ae-346a56271c47 | < 3.2.0 |
CRITICAL | 9.8 | A business logic issue in the MStore API WordPress plugin, versions before 3.2.0, had an authentication bypass with Sign… | — | wordfence |
| 16c0a3b7-25b0-457e-b883-a780bc6a29a7 | CRITICAL | 9.8 | The Member Hero WordPress plugin through 1.0.9 lacks authorization checks, and does not validate the a request parameter… | — | wordfence | |
| 16bce38a-07fa-43b7-aacb-6c932c3d0987 | < 7.7.2 |
CRITICAL | 9.8 | The Simple Link Directory WordPress plugin before 7.7.2 does not validate and escape the post_id parameter before using … | — | wordfence |
| 16af4d96-e7e0-4b13-90a5-ddf62909271a | CRITICAL | 9.8 | The Contus Video Comments plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validati… | — | wordfence | |
| 169d06e1-055b-422a-a466-155ec43e0dbb | < 6.8 |
CRITICAL | 9.8 | The Simple User Registration plugin for WordPress is vulnerable to privilege escalation due to a missing capability chec… | — | wordfence |
| 167436b7-3d2b-46fc-a1bc-2bcfd899182e | < 4.7.6 |
CRITICAL | 9.8 | The Noo JobMonster theme for WordPress is vulnerable to privilege escalation in all versions up to, and including, 4.7.5… | — | wordfence |
| 1672e8fb-900b-4c2a-b9fd-e64dbb1046af | CRITICAL | 9.8 | The user files plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in all v… | — | wordfence | |
| 162a9203-d169-4d96-9839-110f6a9e4ad3 | < 1.5.3 |
CRITICAL | 9.8 | The Poll, Survey, Questionnaire and Voting system WordPress plugin before 1.5.3 did not sanitise, escape or validate the… | — | wordfence |
| 15fecefa-f1f1-47f3-8ad7-ec7772ecafc4 | CRITICAL | 9.8 | Unrestricted file upload vulnerability in admin/upload-file.php in the Holding Pattern theme (aka holding_pattern) 0.6 a… | — | wordfence | |
| 15deb0db-5a13-4018-88e5-5f5cb61bd495 | < 1.2 |
CRITICAL | 9.8 | The wp-ultimate-exporter plugin through 1.1 for WordPress has SQL injection via the export_type_name parameter. | — | wordfence |
| 1560b740-4018-4b08-9399-2fc87e16ea7b | < 1.1.1 |
CRITICAL | 9.8 | The limit-attempts plugin before 1.1.1 for WordPress has SQL injection during IP address handling. | — | wordfence |
| 155e3de1-e115-4683-bb4d-a0c5667dc3d3 | < 3.3.0 |
CRITICAL | 9.8 | The WP Post Author plugin for WordPress is vulnerable to privilege escalation in versions up to, and including, 3.2.3. T… | — | wordfence |
| 1540bf3e-2928-476c-8e5b-241b80dd699f | < 4.3.7 |
CRITICAL | 9.8 | The RealHomes theme for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 4.3.6. Thi… | — | wordfence |
| 153e435b-9986-4242-a89b-12e8f1552803 | < 1.0.1 |
CRITICAL | 9.8 | The Zendrop β Global Dropshipping plugin for WordPress is vulnerable to generic SQL Injection via the setMetaData func… | — | wordfence |
EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.
Scan My Website →