Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.
39,409 vulnerabilities found (page 95 of 1577)
| CVE ID | Plugin / Theme | Severity | CVSS | Description | Fixed In | Source |
|---|---|---|---|---|---|---|
| 073a3b48-7c21-4511-a8e4-3443ef05fd0b | CRITICAL | 9.8 | The MainWP Broken Link Checker plugin for WordPress is vulnerable to SQL Injection via several parameters in versions up… | — | wordfence | |
| 0728e7ac-2091-41de-90a0-e231c4b99ab0 | < 1.3.2 |
CRITICAL | 9.8 | The WooFramework, used for all WooThemes for WordPress, is vulnerable to Remote Code Execution in versions up to, and in… | — | wordfence |
| 071195d6-3452-4241-a8d3-92efc84e4850 | < 5.1.17 |
CRITICAL | 9.8 | The Contact Form Plugin by Fluent Forms for Quiz, Survey, and Drag & Drop WP Form Builder plugin for WordPress is vulner… | — | wordfence |
| 07067eb5-d15e-4342-914f-5e2a08ea8bb4 | < 4.4.0 |
CRITICAL | 9.8 | The WP Live Chat Support plugin for WordPress is vulnerable to blind SQL Injection via the 'cid' and 'status' parameter … | — | wordfence |
| 06eaf624-aedf-453d-8457-d03a572fac0d | < 3.1.4 |
CRITICAL | 9.8 | The AI Engine plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including,… | — | wordfence |
| 06e90f64-f64e-4871-9106-1d7af02f13d2 | CRITICAL | 9.8 | The Nuance theme for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'VALUM… | — | wordfence | |
| 06dfc3da-6f61-433c-a1e1-48749b654fcd | < 2.8.1 |
CRITICAL | 9.8 | The Forms plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in all versio… | — | wordfence |
| 06b92517-5431-43ed-ad3b-80bfd0981b93 | < 4.0.7 |
CRITICAL | 9.8 | The all-in-one-wp-security-and-firewall plugin before 4.0.7 for WordPress has multiple SQL injection issues. | — | wordfence |
| 06a7ff0b-ec6b-490c-9bb0-fbb5c1c337c4 | < 3.19.4 |
CRITICAL | 9.8 | The GiveWP β Donation Plugin and Fundraising Platform plugin for WordPress is vulnerable to PHP Object Injection in al… | — | wordfence |
| 068da172-629d-422a-bcd5-1b73af2a5933 | < 1.1.8 |
CRITICAL | 9.8 | The Recip.ly Plugin plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in … | — | wordfence |
| 068d9502-705e-45dc-a7fb-e75866226fdd | CRITICAL | 9.8 | The Videos sync PDF plugin for WordPress is vulnerable to Local File Inclusion in versions up to an equal to 1.7.4 via t… | — | wordfence | |
| 06881386-3c92-426b-948d-58e8a8bee624 | CRITICAL | 9.8 | The Wechat Social login plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient file type valid… | — | wordfence | |
| 0685abc6-eac6-46c5-87ae-52e2af9301c2 | CRITICAL | 9.8 | The WP REST API FNS Plugin plugin for WordPress is vulnerable to arbitrary file uploads in all versions up to, and inclu… | — | wordfence | |
| 06382aab-8a92-43a2-a4fa-7bbd21967326 | < 2.2.3 |
CRITICAL | 9.8 | The miniOrange Discord Integration plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and inc… | — | wordfence |
| 063826cc-7ff3-4869-9831-f6a4a4bbe74c | < 18.5.10 |
CRITICAL | 9.8 | The Shield Security β Smart Bot Blocking & Intrusion Prevention Security plugin for WordPress is vulnerable to Local F… | — | wordfence |
| 061f022b-b922-4499-bb34-8ea91ba5ace3 | CRITICAL | 9.8 | The AS Password Field In Default Registration Form plugin for WordPress is vulnerable to privilege escalation via accoun… | — | wordfence | |
| 05ea5a3c-084a-458f-b0b1-8a9b82e4656a | CRITICAL | 9.8 | The Comment Rating plugin for WordPress is vulnerable to generic SQL Injection via the 'ck_ips' parameter in versions up… | — | wordfence | |
| 05d32a0f-b299-4dfd-8d92-4bd0a9872a0b | CRITICAL | 9.8 | The ABC APP CREATOR plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1.1… | — | wordfence | |
| 05c68377-feb6-442d-a3a0-1fbc246c7cbf | < 3.10 |
CRITICAL | 9.8 | The Media Library Assistant plugin for WordPress is vulnerable to Local File Inclusion and Remote Code Execution in vers… | — | wordfence |
| 05c40628-b8fc-48ff-8819-c0955d69fce0 | < 4.8.0 |
CRITICAL | 9.8 | The Pipdig Power Pack(p3) plugin for WordPress is contained a backdoor in versions before 4.8.0. Obfuscated code was pre… | — | wordfence |
| 05a81b0e-2d25-44b5-b791-5b2aed94bbab | CRITICAL | 9.8 | The MyFTP plugin for WordPress is vulnerable to generic SQL Injection in versions up to, and including, 1.1 due to insuf… | — | wordfence | |
| 0578f4d1-5953-4fbe-8bc3-0569bee57a1a | < 2.7.2 |
CRITICAL | 9.8 | The Houzez theme for WordPress is vulnerable to privilege escalation in versions up to, and including, 2.7.1. This is du… | — | wordfence |
| 05776ec2-b432-40f6-bd75-4e6ec103c497 | CRITICAL | 9.8 | The Arlo theme for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 6.0.3. This makes i… | — | wordfence | |
| 056d26da-6e43-4cc6-b2fd-13a5947a814e | CRITICAL | 9.8 | The SAICO theme for WordPress is vulnerable to arbitrary file uploads due to missing file type validation via the php.ph… | — | wordfence | |
| 05544f69-bc9b-4270-80c9-96afe4793cb6 | < 1.6.2 |
CRITICAL | 9.8 | PHP remote file inclusion vulnerability in firestats-wordpress.php in the FireStats plugin before 1.6.2-stable for WordP… | — | wordfence |
EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.
Scan My Website →