Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.
41,761 vulnerabilities found (page 90 of 1671)
| CVE ID | Plugin / Theme | Severity | CVSS | Description | Fixed In | Source |
|---|---|---|---|---|---|---|
| 2565852f-43df-41b1-949e-6c02a8946407 | < 3.0.0 |
CRITICAL | 9.8 | The Sitepact's Contact Form 7 Extension For Klaviyo plugin for WordPress is vulnerable to SQL Injection parameter in ver… | — | wordfence |
| 25627b5c-958c-45ad-8450-8dfccdfdac31 | CRITICAL | 9.8 | The Radykal Fancy Gallery plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validati… | — | wordfence | |
| 2513a199-30a8-45a9-80b3-1f6e51534c88 | CRITICAL | 9.8 | The Nightlife Theme for WordPress is vulnerable to arbitrary file uploads due to missing file type validation via the up… | — | wordfence | |
| 24f31bbf-883f-4903-847a-7bfc3e45654c | CRITICAL | 9.8 | The Icons Factory plugin for WordPress is vulnerable to Arbitrary File Deletion due to insufficient authorization and im… | — | wordfence | |
| 24e8d1a4-9853-4f60-a371-7fdbe86d554b | < 12.4 |
CRITICAL | 9.8 | The tagDiv Cloud Library plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capabi… | — | wordfence |
| 24d081e3-4291-427c-bf2c-726d93aa00ac | < 1.4 |
CRITICAL | 9.8 | The filedownload plugin for WordPress is vulnerable to blind SQL Injection in versions before 1.4 due to insufficient es… | — | wordfence |
| 24c9a333-e60e-481b-ba27-65094f4f8d39 | < 5.0.7 |
CRITICAL | 9.8 | The Drag and Drop Multiple File Upload (Pro) - WooCommerce plugin for WordPress is vulnerable to arbitrary file uploads … | — | wordfence |
| 24a88f20-ddc4-4544-ac18-ed538ecfa1c7 | CRITICAL | 9.8 | Remote file upload vulnerability in wordpress plugin csv2wpec-coupon v1.1 in csv2wpecCoupon_FileUpload.php file. | — | wordfence | |
| 2491d502-8087-4e95-b047-a3b196322d94 | < 4.7.4 |
CRITICAL | 9.8 | The Filebird Plugin 4.7.3 introduced a SQL injection vulnerability as it is making SQL queries without escaping user inp… | — | wordfence |
| 2489e649-27f7-4ca0-8655-0957016fa89a | CRITICAL | 9.8 | The UserPlus plugin for WordPress is vulnerable to privilege escalation in versions up to, and including, 2.0 due to ins… | — | wordfence | |
| 247ee5bf-1e77-4461-b9f7-28b051b78af7 | CRITICAL | 9.8 | The Real Estate Manager plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 7.3… | — | wordfence | |
| 24517dc6-4995-48ee-9b02-5c7c29d359f6 | < 3.05.1 |
CRITICAL | 9.8 | The Webinar Plugin: Create live/evergreen/automated/instant webinars, stream & Zoom Meetings | WebinarIgnition plugin fo… | — | wordfence |
| 2450277e-589d-4153-bd3f-ffed1a8b4340 | CRITICAL | 9.8 | The epic theme through 2014-09-07 for WordPress allows arbitrary file downloads via the file parameter to includes/downl… | — | wordfence | |
| 244b6773-8983-4435-8d1c-240bcc54e061 | CRITICAL | 9.8 | The Lis Video Gallery plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 0.2.1… | — | wordfence | |
| 240cc19a-9bae-4e69-a16f-46901daaa945 | < 3.0.1 |
CRITICAL | 9.8 | The Brandfolder β Digital Asset Management Simplified. plugin for WordPress is vulnerable to Local and Remote File Inc… | — | wordfence |
| 24092cd1-cf89-49c1-a607-4d5d06d0c804 | CRITICAL | 9.8 | The IP Loc8 plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 1.1 via deseria… | — | wordfence | |
| 23fbb011-cf60-4c75-ac68-b5d0dfa3c356 | < 1.6.7 |
CRITICAL | 9.8 | Server-Side Request Forgery (SSRF) exists in the Print My Blog plugin before 1.6.7 for WordPress via the site parameter. | — | wordfence |
| 23da892a-62c1-4c4b-8b86-4b55018c309b | CRITICAL | 9.8 | The WPSPX plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1.0.2. This m… | — | wordfence | |
| 23c99d3c-5ee5-4793-92a4-f49bf345c634 | CRITICAL | 9.8 | The Spreadsheet Price Changer for WooCommerce and WP E-commerce β Light plugin for WordPress is vulnerable to Remote C… | — | wordfence | |
| 23aa8a2f-9238-4d93-b2d2-de7838ccb156 | < 1.5.5 |
CRITICAL | 9.8 | SQL injection vulnerability in WordPress Tune Library plugin before 1.5.5. | — | wordfence |
| 236bb9a8-49f7-4b75-a0b1-fa4ff65394f8 | CRITICAL | 9.8 | The HotStar β Multi-Purpose Business Theme theme for WordPress is vulnerable to PHP Object Injection in versions up to… | — | wordfence | |
| 235c9967-808f-45f2-85cf-7ee7a523593d | < 1.5.16 |
CRITICAL | 9.8 | Multiple SQL injection vulnerabilities in the ratings module in the Users Ultra plugin before 1.5.16 for WordPress allow… | — | wordfence |
| 233a75c7-9e45-4509-8f7c-584e2f5b38c7 | < 14.4.5 |
CRITICAL | 9.8 | The StoreKeeper for WooCommerce plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type va… | — | wordfence |
| 23399606-20b6-4d0b-b613-06dc838dc1e7 | < 2.9.5 |
CRITICAL | 9.8 | The Welcart e-Commerce plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, … | — | wordfence |
| 232dd4fa-748e-4b65-8b78-7b2d8e9831aa | < 7.3.19.727 |
CRITICAL | 9.8 | A SQL injection vulnerability exists in the FolioVision FV Flowplayer Video Player plugin before 7.3.19.727 for WordPres… | — | wordfence |
EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.
Scan My Website →