Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.
39,409 vulnerabilities found (page 92 of 1577)
| CVE ID | Plugin / Theme | Severity | CVSS | Description | Fixed In | Source |
|---|---|---|---|---|---|---|
| 10b7a88f-ce46-42aa-ab5a-81f38288a659 | < 1.7 |
CRITICAL | 9.8 | The uListing plugin for WordPress is vulnerable to generic SQL Injection via the ‘listing_id’ parameter in versions … | — | wordfence |
| 109b4947-f690-4158-9e6a-00f2005a6938 | CRITICAL | 9.8 | The Adminer plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the adminer_… | — | wordfence | |
| 1069434a-b8cb-4e29-995d-f31b18d1843f | < 1.3.1 |
CRITICAL | 9.8 | Unrestricted file upload vulnerability in font-upload.php in the Font Uploader plugin 1.3 for WordPress allows remote at… | — | wordfence |
| 104badec-6e6e-44bb-936b-d135dd80890d | < 6.4 |
CRITICAL | 9.8 | The LiteSpeed Cache plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 6.3… | — | wordfence |
| 102ab838-9011-4da6-bc24-179be1328bcc | < 4.1 |
CRITICAL | 9.8 | SQL injection vulnerability in ecomm-sizes.php in the Photocrati theme up to and including version 4.0 for WordPress all… | — | wordfence |
| 102223a1-07f5-485b-a6af-49cf316d9797 | < 3.2.33 |
CRITICAL | 9.8 | The Front End Users plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in … | — | wordfence |
| 0ff16836-b333-4f2c-b998-04c95d3be9c2 | < 1.5.8 |
CRITICAL | 9.8 | The Formality plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.5.7. This m… | — | wordfence |
| 0fcb1237-5d96-47f6-9f0c-3a0fd72ca91f | < 3.0 |
CRITICAL | 9.8 | The dzs-zoomsounds plugin through 2.0 for WordPress has admin/upload.php arbitrary file upload. | — | wordfence |
| 0fc781bc-d0e6-4fce-95aa-ff34caa072da | CRITICAL | 9.8 | The Valen - Sport, Fashion WooCommerce WordPress Theme theme for WordPress is vulnerable to Local File Inclusion in vers… | — | wordfence | |
| 0fae8440-ce36-45ba-bed2-af30162e4c1b | CRITICAL | 9.8 | The Subscribe to Category plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 2.7.4 du… | — | wordfence | |
| 0f9b6979-2662-4d2f-9656-b880dd80832c | < 13.5.6 |
CRITICAL | 9.8 | The WPBot Pro Wordpress Chatbot plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type va… | — | wordfence |
| 0f6d3435-61b9-4986-9da9-b58d1bbc2271 | < 3.9.7 |
CRITICAL | 9.8 | The SMS Alert – SMS & OTP for WooCommerce, Order Notifications & Abandoned Cart Recovery plugin for WordPress is vulne… | — | wordfence |
| 0f54574f-e640-4cfb-b03e-fd23f3bd574b | < 3.9.1 |
CRITICAL | 9.8 | The Funnel Builder by FunnelKit plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and includ… | — | wordfence |
| 0f3b3c1a-1d45-4e2f-854a-171fe759257b | < 1.5.7 |
CRITICAL | 9.8 | The Cloudflare Image Resizing plugin for WordPress is vulnerable to Remote Code Execution due to missing authentication … | — | wordfence |
| 0f36a924-6a68-40ff-bf1a-9ebcad1c2fc6 | < 2.9.42.1 |
CRITICAL | 9.8 | Versions 2.9.36 to 2.9.42 of the Ninja Forms plugin contain an unauthenticated file upload vulnerability, allowing guest… | — | wordfence |
| 0f35cc8b-11be-4664-be48-12a8db872d66 | < 9.0.1 |
CRITICAL | 9.8 | The Title Experiments Free Plugin for WordPress is vulnerable to blind SQL Injection via the ‘wpex_titles' AJAX action… | — | wordfence |
| 0f23aa0e-eb1f-4310-9615-d67eb39389fe | < 2.9.2 |
CRITICAL | 9.8 | The Welcart e-Commerce for WordPress is vulnerable to SQL Injection via the ‘changeSort’ and 'switch' parameters in … | — | wordfence |
| 0f13b2dd-4832-4646-828c-ba2df1eb7d33 | < 4.0.1 |
CRITICAL | 9.8 | The plugin WP OAuth Server for WordPress is vulnerable to Authentication Bypass in versions up to, and including, 3.0.4.… | — | wordfence |
| 0f0051d5-b236-420c-ae65-14610d05c6d1 | < 13.1.6 |
CRITICAL | 9.8 | The WP Statistics WordPress plugin is vulnerable to SQL Injection due to insufficient escaping and parameterization of t… | — | wordfence |
| 0ee60943-b583-4a99-8e62-846b380c98aa | < 1.8.1.15 |
CRITICAL | 9.8 | The Donation Forms by Charitable – Donations Plugin & Fundraising Platform for WordPress plugin for WordPress is vulne… | — | wordfence |
| 0ee3b389-60c9-4f8e-9428-a71a6d9b20aa | < 2.0.7 |
CRITICAL | 9.8 | The B Blocks plugin for WordPress is vulnerable to Privilege Escalation due to missing authorization and improper input … | — | wordfence |
| 0eae9c5a-8a11-4293-a7e1-2c5d77c75284 | < 1.15.13 |
CRITICAL | 9.8 | The Asgaros Forum WordPress plugin before 1.15.13 does not validate and escape user input when subscribing to a topic be… | — | wordfence |
| 0e630401-0409-443c-944d-553a372d150d | < 1.1 |
CRITICAL | 9.8 | The Wachipi WP Events Calendar plugin 1.0 for WordPress has SQL Injection via the event_id parameter to event.php. | — | wordfence |
| 0e61c98d-a6f4-4ac0-b9f9-2b936c030413 | CRITICAL | 9.8 | The WP JobHunt plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, an… | — | wordfence | |
| 0e5617a2-5670-4d98-a36b-942f71634642 | < 3.1.2 |
CRITICAL | 9.8 | The Everest Forms – Contact Form, Quiz, Survey, Newsletter & Payment Form Builder for WordPress plugin for WordPress i… | — | wordfence |
EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.
Scan My Website →