Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.
41,762 vulnerabilities found (page 92 of 1671)
| CVE ID | Plugin / Theme | Severity | CVSS | Description | Fixed In | Source |
|---|---|---|---|---|---|---|
| 205a3e43-8ac6-4a0d-86d3-bb433a992e3d | < 1.9 |
CRITICAL | 9.8 | The RokIntroScroller plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in… | — | wordfence |
| 20188fd3-c330-4c76-912b-72731e14c450 | < 1.6.0 |
CRITICAL | 9.8 | The Pix for WooCommerce plugin for WordPress is vulnerable to arbitrary file uploads due to missing capability check and… | — | wordfence |
| 200f724e-7911-46d0-82c0-ffa207d8ee17 | < 2.4.0 |
CRITICAL | 9.8 | The Printcart Web to Print Product Designer for WooCommerce plugin for WordPress is vulnerable to arbitrary file uploads… | — | wordfence |
| 20077e55-fe75-49c7-ba3f-ccd683a3f722 | CRITICAL | 9.8 | The Vithy theme for WordPress is vulnerable to arbitrary file uploads due to missing file type validation via the upload… | — | wordfence | |
| 1fa39169-1cba-43ce-aa29-adf7ce09ce75 | < 1.6.0 |
CRITICAL | 9.8 | The Bello - Directory & Listing WordPress theme before 1.6.0 did not sanitise the bt_bb_listing_field_price_range_to, bt… | — | wordfence |
| 1f93ecf7-ba49-47f6-abe3-33e3bc6e7054 | < 1.1.7 |
CRITICAL | 9.8 | Multiple SQL injection vulnerabilities in dex_reservations.php in the CP Reservation Calendar plugin before 1.1.7 for Wo… | — | wordfence |
| 1f891b68-72c4-4f94-bd49-52576ad710f9 | CRITICAL | 9.8 | The Spreadsheet Price Changer for WooCommerce and WP E-commerce – Light plugin for WordPress is vulnerable to Missing … | — | wordfence | |
| 1f714f97-5e1a-498a-9722-1e4bb883c5c7 | < 1.2.1 |
CRITICAL | 9.8 | Minimist <=1.2.5 is vulnerable to Prototype Pollution via file index.js, function setKey() (lines 69-95). Fixed in 1.2.6… | — | wordfence |
| 1f5b4f9a-4067-4514-9027-b645921d807f | < 1.3.0 |
CRITICAL | 9.8 | Multiple directory traversal vulnerabilities in (1) includes/MapImportCSV2.php and (2) includes/MapImportCSV.php in the … | — | wordfence |
| 1f4f66fd-189a-4036-8e44-c401647bc655 | < 2.1.1 |
CRITICAL | 9.8 | The Medicare theme for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 2.1.0 via deser… | — | wordfence |
| 1ef13f92-ae45-411a-b7b4-cdaf299afc8a | CRITICAL | 9.8 | The CoSchool LMS – A complete Learning Management System to Create and Sell Your Courses Online plugin for WordPress i… | — | wordfence | |
| 1ec14b1e-6d1a-4451-9fce-ac064623d92f | < 1.4.0 |
CRITICAL | 9.8 | The Themes Coder – Create Android & iOS Apps For Your Woocommerce Site plugin for WordPress is vulnerable to privilege… | — | wordfence |
| 1ead6a38-b495-47d2-8d40-1f17e64fd1ff | < 1.8.10.2 |
CRITICAL | 9.8 | SQL injection vulnerability in the Contextual Related Posts plugin before 1.8.10.2 for WordPress allows remote attackers… | — | wordfence |
| 1e8f71cc-3197-4cdb-9e3b-a544f689df2d | CRITICAL | 9.8 | The Pathomation plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in all … | — | wordfence | |
| 1e65922a-3498-4946-8415-3d922e85e46a | < 4.5.0.2 |
CRITICAL | 9.8 | The GEO my WP plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 4.5.0.1 v… | — | wordfence |
| 1e61cc33-d58e-425e-9835-4d45461edbac | CRITICAL | 9.8 | The Nasa Core plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 6.3.2. This m… | — | wordfence | |
| 1e37e54b-9c00-4d04-9c81-791242d45d6c | CRITICAL | 9.8 | The iDump iPhone to WordPress Photo Uploader for WordPress is vulnerable to arbitrary file uploads due to missing file t… | — | wordfence | |
| 1decdfd8-a2e8-49af-ade8-01d19814b6fb | CRITICAL | 9.8 | The Flagallery-skins plugin for WordPress is vulnerable to generic SQL Injection via the ‘playlist’ parameter in all… | — | wordfence | |
| 1de9183c-95b9-4500-85e2-08dcee956360 | < 1.0.5 |
CRITICAL | 9.8 | The Wordpress Plugin Smart Product Review plugin for WordPress is vulnerable to arbitrary file uploads due to missing fi… | — | wordfence |
| 1d9ffbf3-520a-4563-85e1-27c1cc544856 | CRITICAL | 9.8 | The Users Ultra WordPress plugin through 3.1.0 fails to properly sanitize and escape the data_target parameter before it… | — | wordfence | |
| 1d8d393e-764c-491d-8afb-7d4f8d0c387a | < 2.1.0 |
CRITICAL | 9.8 | The Single Sign On For TNG plugin for WordPress is vulnerable to Authentication Bypass via unauthenticated password rese… | — | wordfence |
| 1d87d225-7de4-49f8-9cba-391d718af7fd | CRITICAL | 9.8 | The Arigato Autoresponder and Newsletter (aka bft-autoresponder) v2.5.1.7 plugin for WordPress allows remote attackers t… | — | wordfence | |
| 1d7f1283-a274-49a2-8bec-da178771b13a | < 4.11.2 |
CRITICAL | 9.8 | The Hotel Booking Lite plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, … | — | wordfence |
| 1d779ad1-fdbe-444c-85c5-99146a1a03d8 | < 1.0.5 |
CRITICAL | 9.8 | The WPBookit plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the ima… | — | wordfence |
| 1d640d8e-7730-47e1-9f01-b9656f1ebb1c | < 1.6.1 |
CRITICAL | 9.8 | The GrandPrix theme for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.6. This make… | — | wordfence |
EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.
Scan My Website →