Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.
41,761 vulnerabilities found (page 95 of 1671)
| CVE ID | Plugin / Theme | Severity | CVSS | Description | Fixed In | Source |
|---|---|---|---|---|---|---|
| 1814537d-8307-4d1f-86c8-801519172be5 | < 1.7 |
CRITICAL | 9.8 | The uListing plugin for WordPress is vulnerable to authorization bypass via Ajax due to missing capability checks, missi… | — | wordfence |
| 17dcacaf-0e2a-4bef-b944-fb7e43d25777 | < 2.7.3 |
CRITICAL | 9.8 | The Country State City Dropdown CF7 plugin for WordPress is vulnerable to SQL Injection via the ‘cnt’ and 'sid' para… | — | wordfence |
| 17d8e2e9-5e3f-433b-be1a-6ea765eba547 | < 4.15.0 |
CRITICAL | 9.8 | The MStore API – Create Native Android & iOS Apps On The Cloud plugin for WordPress is vulnerable to authentication by… | — | wordfence |
| 17ccf3f5-ac71-4827-bf11-9a5199f8752e | CRITICAL | 9.8 | The AJAX Random Posts plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 0.3.3… | — | wordfence | |
| 17cc137e-da04-42ea-9336-24c4e0b9264a | CRITICAL | 9.8 | The Devexhub Gallery plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in… | — | wordfence | |
| 1789b78a-4733-40b9-b28f-f63aeb4c0f0b | < 2.10.0 |
CRITICAL | 9.8 | The TI WooCommerce Wishlist plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type valida… | — | wordfence |
| 178911d9-0552-4f44-aae5-06fc9734cfac | < 5.9.6 |
CRITICAL | 9.8 | The Event post plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 5.9.5 vi… | — | wordfence |
| 17641096-1c7f-43f7-90d6-14c368c95d72 | CRITICAL | 9.8 | The Advanced Personalization plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including… | — | wordfence | |
| 16e3ca1b-817d-4f03-92ae-346a56271c47 | < 3.2.0 |
CRITICAL | 9.8 | A business logic issue in the MStore API WordPress plugin, versions before 3.2.0, had an authentication bypass with Sign… | — | wordfence |
| 16c0a3b7-25b0-457e-b883-a780bc6a29a7 | CRITICAL | 9.8 | The Member Hero WordPress plugin through 1.0.9 lacks authorization checks, and does not validate the a request parameter… | — | wordfence | |
| 16bce38a-07fa-43b7-aacb-6c932c3d0987 | < 7.7.2 |
CRITICAL | 9.8 | The Simple Link Directory WordPress plugin before 7.7.2 does not validate and escape the post_id parameter before using … | — | wordfence |
| 16af4d96-e7e0-4b13-90a5-ddf62909271a | CRITICAL | 9.8 | The Contus Video Comments plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validati… | — | wordfence | |
| 169d06e1-055b-422a-a466-155ec43e0dbb | < 6.8 |
CRITICAL | 9.8 | The Simple User Registration plugin for WordPress is vulnerable to privilege escalation due to a missing capability chec… | — | wordfence |
| 167436b7-3d2b-46fc-a1bc-2bcfd899182e | < 4.7.6 |
CRITICAL | 9.8 | The Noo JobMonster theme for WordPress is vulnerable to privilege escalation in all versions up to, and including, 4.7.5… | — | wordfence |
| 1672e8fb-900b-4c2a-b9fd-e64dbb1046af | CRITICAL | 9.8 | The user files plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in all v… | — | wordfence | |
| 162a9203-d169-4d96-9839-110f6a9e4ad3 | < 1.5.3 |
CRITICAL | 9.8 | The Poll, Survey, Questionnaire and Voting system WordPress plugin before 1.5.3 did not sanitise, escape or validate the… | — | wordfence |
| 15fecefa-f1f1-47f3-8ad7-ec7772ecafc4 | CRITICAL | 9.8 | Unrestricted file upload vulnerability in admin/upload-file.php in the Holding Pattern theme (aka holding_pattern) 0.6 a… | — | wordfence | |
| 15deb0db-5a13-4018-88e5-5f5cb61bd495 | < 1.2 |
CRITICAL | 9.8 | The wp-ultimate-exporter plugin through 1.1 for WordPress has SQL injection via the export_type_name parameter. | — | wordfence |
| 159304a1-b015-44cd-9540-88b3e306dcc8 | < 1.5.19.1 |
CRITICAL | 9.8 | The Kadence WooCommerce Email Designer plugin for WordPress is vulnerable to Privilege Escalation in all versions up to,… | — | wordfence |
| 1560b740-4018-4b08-9399-2fc87e16ea7b | < 1.1.1 |
CRITICAL | 9.8 | The limit-attempts plugin before 1.1.1 for WordPress has SQL injection during IP address handling. | — | wordfence |
| 155e3de1-e115-4683-bb4d-a0c5667dc3d3 | < 3.3.0 |
CRITICAL | 9.8 | The WP Post Author plugin for WordPress is vulnerable to privilege escalation in versions up to, and including, 3.2.3. T… | — | wordfence |
| 1540bf3e-2928-476c-8e5b-241b80dd699f | < 4.3.7 |
CRITICAL | 9.8 | The RealHomes theme for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 4.3.6. Thi… | — | wordfence |
| 153e435b-9986-4242-a89b-12e8f1552803 | < 1.0.1 |
CRITICAL | 9.8 | The Zendrop – Global Dropshipping plugin for WordPress is vulnerable to generic SQL Injection via the setMetaData func… | — | wordfence |
| 14f86410-a21c-43ee-8d78-6fcce3a5b99b | CRITICAL | 9.8 | The Uploader plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the '/u… | — | wordfence | |
| 14d48a81-c6b5-415f-8c82-5fd40b2e790a | < 1.7.0 |
CRITICAL | 9.8 | A SQL injection vulnerability exists in the Vsourz Digital Advanced CF7 DB plugin through 1.6.1 for WordPress. Successfu… | — | wordfence |
EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.
Scan My Website →