Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.
39,409 vulnerabilities found (page 91 of 1577)
| CVE ID | Plugin / Theme | Severity | CVSS | Description | Fixed In | Source |
|---|---|---|---|---|---|---|
| 14f86410-a21c-43ee-8d78-6fcce3a5b99b | CRITICAL | 9.8 | The Uploader plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the '/u… | — | wordfence | |
| 14d48a81-c6b5-415f-8c82-5fd40b2e790a | < 1.7.0 |
CRITICAL | 9.8 | A SQL injection vulnerability exists in the Vsourz Digital Advanced CF7 DB plugin through 1.6.1 for WordPress. Successfu… | — | wordfence |
| 14a1b8af-bd32-4245-92d6-549cae68c626 | < 6.9.0 |
CRITICAL | 9.8 | The WPCargo Track & Trace WordPress plugin before 6.9.0 contains a file which could allow unauthenticated attackers to w… | — | wordfence |
| 14981949-271c-4f98-a6a1-b00619f1436d | < 1.1 |
CRITICAL | 9.8 | The FindAll Listing plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.0… | — | wordfence |
| 146c8783-ba59-41da-9e95-7401865b7b8c | < 2.5.17 |
CRITICAL | 9.8 | SQL injection vulnerability in view.php in the Google Doc Embedder plugin before 2.5.15 for WordPress allows remote atta… | — | wordfence |
| 144df910-67d2-4e3b-9ccf-04ebd5d1bf8b | < 1.5.4.9 |
CRITICAL | 9.8 | SQL injection vulnerability in the Export CSV page in the Participants Database plugin before 1.5.4.9 for WordPress allo… | — | wordfence |
| 13b4efa1-3f52-476c-80fe-b36ccb62a24b | < 3.0.5 |
CRITICAL | 9.8 | The Podcasting Plugin by TSG plugin for WordPress is vulnerable to Remote File Inclusion of media files in versions up t… | — | wordfence |
| 13b2fb59-35ef-40de-a48a-2972777d2682 | < 3.2.0 |
CRITICAL | 9.8 | The WordPress Contact Form, Drag and Drop Form Builder Plugin β Live Forms plugin for WordPress is vulnerable to gener… | — | wordfence |
| 1374b266-4b20-4706-a4d2-482122964693 | CRITICAL | 9.8 | The WordPress Gallery Plugin plugin for WordPress is vulnerable to Remote File Inclusion in versions up to, and includin… | — | wordfence | |
| 136eb400-d5cf-4b73-a8e4-9484faa81049 | CRITICAL | 9.8 | The WPAMS - Apartment Management System for wordpress plugin for WordPress is vulnerable to arbitrary file uploads due t… | — | wordfence | |
| 13629598-d45d-4ff5-aeb5-6ac881d25183 | < 5.7.26 |
CRITICAL | 9.8 | The Email Subscribers by Icegram Express β Email Marketing, Newsletters, Automation for WordPress & WooCommerce plugin… | — | wordfence |
| 135ab17b-5b91-484a-8bec-6f77d694ae62 | CRITICAL | 9.8 | The WPE Indoshipping for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the up… | — | wordfence | |
| 13031db7-aeac-4d44-94f9-1cdb84781a55 | < 1.3.7 |
CRITICAL | 9.8 | The ultimate-form-builder-lite plugin before 1.3.7 for WordPress has SQL Injection, with resultant PHP Object Injection,… | — | wordfence |
| 12f319df-41eb-484a-8fca-af6ae76f4179 | < 1.1 |
CRITICAL | 9.8 | The Biagiotti Membership plugin for WordPress is vulnerable to authentication bypass in all versions up to, and includin… | — | wordfence |
| 12bb4bb9-e908-43ad-8fb1-59418580f5e1 | < 3.2.6 |
CRITICAL | 9.8 | The ShopLentor β WooCommerce Builder for Elementor & Gutenberg +21 Modules β All in One Solution (formerly WooLentor… | — | wordfence |
| 129f810d-ff83-4428-9f98-6a6aa8817783 | < 1.4.4 |
CRITICAL | 9.8 | The Database for Contact Form 7, WPforms, Elementor forms plugin for WordPress is vulnerable to PHP Object Injection in … | — | wordfence |
| 1283e839-8588-4a76-9c1e-61562526166d | < 2.6.8.2 |
CRITICAL | 9.8 | The Crawlomatic Multipage Scraper Post Generator plugin for WordPress is vulnerable to arbitrary file uploads due to mis… | — | wordfence |
| 12660851-c899-4ec2-b40e-e62391dafdbf | < 1.25 |
CRITICAL | 9.8 | The Lead Generated WordPress Plugin, version <= 1.23, was affected by an unauthenticated insecure deserialization issue.… | — | wordfence |
| 125277bc-5232-49bd-8f29-3aa8e0ee354b | CRITICAL | 9.8 | The Fami WooCommerce Compare plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including… | — | wordfence | |
| 121afcc4-754c-4f4b-8b02-9b5a4a248041 | CRITICAL | 9.8 | The N5 Upload Form WordPress plugin through 1.0 suffers from an arbitrary file upload issue in page where a Form from th… | — | wordfence | |
| 121160a3-b090-4a33-9615-fa4626631bec | < 4.0.7 |
CRITICAL | 9.8 | The Mailster - Email Newsletter Plugin for WordPress plugin for WordPress is vulnerable to Local File Inclusion in all v… | — | wordfence |
| 117e797a-1878-4b5f-9846-4a73b5396ece | < 1.3 |
CRITICAL | 9.8 | Unrestricted file upload vulnerability in ajaxfilemanager.php in the Wp-FileManager 1.2 plugin for WordPress allows remo… | — | wordfence |
| 113554f9-b8f0-4bdd-be90-0093fb520022 | CRITICAL | 9.8 | The Duplicate Page and Post plugin for WordPress is vulnerable to a developer-created backdoor in versions up to, and in… | — | wordfence | |
| 11349bc4-b432-4225-82a4-30bc9d0057f9 | < 1.5.8 |
CRITICAL | 9.8 | The Leaflet Maps Marker Pro plugin for WordPress is vulnerable to SQL Injection via an unknown parameter in versions up … | — | wordfence |
| 111c46c3-7c70-454b-8e99-1552cf0104e2 | CRITICAL | 9.8 | The WP Front-End Repository Manager plugin for WordPress is vulnerable to arbitrary file uploads due to missing file typ… | — | wordfence |
EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.
Scan My Website →