Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.
39,409 vulnerabilities found (page 94 of 1577)
| CVE ID | Plugin / Theme | Severity | CVSS | Description | Fixed In | Source |
|---|---|---|---|---|---|---|
| 0ae243af-619f-4405-b1e0-9b44c1869501 | < 1.0.84 |
CRITICAL | 9.8 | The Ultimate Member plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the … | — | wordfence |
| 0a8aa964-d18c-420d-864b-9ee5cb5e2f0f | CRITICAL | 9.8 | The Instant Chat Floating Button for WordPress Websites plugin for WordPress is vulnerable to Local File Inclusion in al… | — | wordfence | |
| 0a4aad30-ff74-43ef-9739-225602624255 | < 1.3.10 |
CRITICAL | 9.8 | The Aora theme for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.3.9. This makes i… | — | wordfence |
| 0a3ae696-f67d-4ed2-b307-d2f36b6f188c | < 1.4.0 |
CRITICAL | 9.8 | The Backup Migration plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 1.3.9 vi… | — | wordfence |
| 09c59fb5-8264-4277-a821-dbfee0900f64 | < 3.3.4 |
CRITICAL | 9.8 | Unrestricted file upload vulnerability in frames/upload-images.php in the Complete Gallery Manager plugin before 3.3.4 r… | — | wordfence |
| 09adfe7e-f154-4143-827f-957ded3ffc8f | < 1.3.8 |
CRITICAL | 9.8 | The AIHub theme for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the generat… | — | wordfence |
| 097b1530-64fa-45b2-85f3-c6a2311405b5 | CRITICAL | 9.8 | The Instant Appointment plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation… | — | wordfence | |
| 09679bd2-c416-4037-bfa4-d56ba862113c | < 2.6.7 |
CRITICAL | 9.8 | The Paid Memberships Pro WordPress plugin before 2.6.7 does not escape the discount_code in one of its REST route (avail… | — | wordfence |
| 094c5011-41f6-420b-b566-e77fd55d9011 | < 1.2.2 |
CRITICAL | 9.8 | The Gmedia Photo Gallery plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validatio… | — | wordfence |
| 094aa8ea-42f0-484f-80fe-a0bf3a110adc | < 3.2.3 |
CRITICAL | 9.8 | The Search & Replace plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 3.… | — | wordfence |
| 094972e6-7e02-4060-b069-e39c8cde9331 | < 3.6.0 |
CRITICAL | 9.8 | The Recover WooCommerce Cart Abandonment, Newsletter, Email Marketing, Marketing Automation By FunnelKit plugin for Word… | — | wordfence |
| 09437329-f01a-4998-90ec-e4b2e271e896 | < 2.15.0 |
CRITICAL | 9.8 | The Shortcodes and extra features for Phlox theme plugin for WordPress is vulnerable to Local File Inclusion in all vers… | — | wordfence |
| 093058f1-c717-424f-9bd5-4838df8d20a1 | < 4.2.7 |
CRITICAL | 9.8 | The Podlove Podcast Publisher plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type vali… | — | wordfence |
| 08efd1c4-8024-465f-9f29-02e78c4228ab | < 2.12.0 |
CRITICAL | 9.8 | The STAGGS – Product Configurator Toolkit plugin for WordPress is vulnerable to arbitrary file uploads due to missing … | — | wordfence |
| 08e9a8f1-e5ed-4af7-ab37-31bab8850dbd | < 1.6.5 |
CRITICAL | 9.8 | The Petito theme for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.6.4. This makes… | — | wordfence |
| 08cb8ba1-1976-438b-8e0b-0a8be08aad6c | < 5.1.3 |
CRITICAL | 9.8 | The InfusedWoo Pro plugin for WordPress is vulnerable to privilege escalation via missing authorization in all versions … | — | wordfence |
| 08ca186a-2486-4a58-9c53-03e9eba13e66 | < 7.6.5 |
CRITICAL | 9.8 | The WordPress Social Login and Register (Discord, Google, Twitter, LinkedIn) plugin for WordPress is vulnerable to authe… | — | wordfence |
| 08c14611-c785-484d-9fdf-7d71c39f63df | < 0.15.2 |
CRITICAL | 9.8 | The Global Flash Gallery plugin for WordPress is vulnerable to generic SQL Injection via the ‘popup.php id' parameter … | — | wordfence |
| 0870de2d-bca5-4d57-a07f-877a416ce0d5 | < 2.10.1 |
CRITICAL | 9.8 | THe WCFM Membership plugin for WordPress is vulnerable to privilege escalation in versions up to, and including 2.10.0, … | — | wordfence |
| 086b51b5-c9f6-4b30-8fa1-4bcc005c66ab | < 3.1.9.1 |
CRITICAL | 9.8 | SQL injection vulnerability in the WPML plugin before 3.1.9.1 for WordPress allows remote attackers to execute arbitrary… | — | wordfence |
| 081f2603-229b-42f2-b5b1-f89d105a31d5 | < 2.9.5 |
CRITICAL | 9.8 | The ListingPro Plugin plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 2… | — | wordfence |
| 07eb71fc-6588-490d-8947-3077ec4a9045 | < 3.28.30 |
CRITICAL | 9.8 | The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and i… | — | wordfence |
| 07eab536-6f20-45ec-9f9e-70ab35555db2 | < 6.0.0 |
CRITICAL | 9.8 | The WappPress – Create Mobile App for any WordPress site with our Mobile App Builder in just 1 minute plugin for WordP… | — | wordfence |
| 07ac1921-6d3b-44b3-ad8d-66e18698c025 | < 0.1.2 |
CRITICAL | 9.8 | The Note Press plugin for WordPress before 0.1.2 has a SQL injection vulnerability via the s parameter. This can be expl… | — | wordfence |
| 079d60c1-a15a-4d3e-b295-8c1e024b74ef | < 3.0.0 |
CRITICAL | 9.8 | The Web3 – Crypto wallet Login & NFT token gating plugin for WordPress is vulnerable to authenticated bypass in all ve… | — | wordfence |
EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.
Scan My Website →