Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.
39,409 vulnerabilities found (page 96 of 1577)
| CVE ID | Plugin / Theme | Severity | CVSS | Description | Fixed In | Source |
|---|---|---|---|---|---|---|
| 05431aaa-5d8f-422c-b7ce-955a778f7f55 | CRITICAL | 9.8 | The Showbiz Pro plugin through 1.7.1 for WordPress has PHP code execution by uploading a .php file within a ZIP archive. | — | wordfence | |
| 053bb01c-9e87-4836-ae1c-567272b21118 | < 2.0.16 |
CRITICAL | 9.8 | The Registration Forms β User Profile, Custom Registration Form, Login Form, Invitation-Based Registrations plugin for… | — | wordfence |
| 05178bf3-3040-41aa-ba43-779376d30298 | < 1.7.6 |
CRITICAL | 9.8 | The WPCOM Member plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 1.7.5… | — | wordfence |
| 0502c622-975f-4218-8b53-efd776fe9d99 | < 1.0.6 |
CRITICAL | 9.8 | The newstatpress plugin before 1.0.6 for WordPress has SQL injection related to an IMG element. | — | wordfence |
| 04d8b1bf-d514-4908-a30e-6ff7b8e03f82 | < 1.2.2 |
CRITICAL | 9.8 | The sharebar plugin before 1.2.2 for WordPress has SQL injection via id parameter. | — | wordfence |
| 04bc8101-2676-4695-a498-f79be8221617 | < 2.6.8 |
CRITICAL | 9.8 | The JobSearch WP Job Board plugin for WordPress is vulnerable to privilege escalation in all versions up to, and includi… | — | wordfence |
| 04b7a2ba-e299-4781-8ee6-644938bf9629 | < 3.4.5 |
CRITICAL | 9.8 | The MStore API plugin for WordPress is vulnerable to arbitrary file uploads due to missing authorization via the api/flu… | — | wordfence |
| 0491b8b3-014e-4ef2-b3b6-9570063fffc5 | < 3.8.3.3 |
CRITICAL | 9.8 | The Pie Register Premium plugin for WordPress is vulnerable to arbitrary file uploads in all versions up to 3.8.3.3 (exc… | — | wordfence |
| 0486fca3-49d4-4edb-9b32-952a20ffa59f | < 2.4 |
CRITICAL | 9.8 | The DSK theme for WordPress is vulnerable to Local File Inclusion in versions up to, and excluding, 2.4. This makes it p… | — | wordfence |
| 0451a7b8-7657-4b73-9ef1-cc3791349e59 | < 1.1.1 |
CRITICAL | 9.8 | The Selio - Real Estate Directory theme for WordPress is vulnerable to generic SQL Injection via the βisβ parameter … | — | wordfence |
| 04033a28-b58a-4584-926b-f43036b23247 | CRITICAL | 9.8 | The Multi Purpose Mail Form plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type valida… | — | wordfence | |
| 04003542-fd62-4587-9834-70e7fe8f08ef | < 2.0.7 |
CRITICAL | 9.8 | The WordPress Mega Menu plugin for WordPress is vulnerable to Arbitrary File Creation in versions up to, and including, … | — | wordfence |
| 03be4344-d388-4357-8a2e-c3b9c8b83017 | < 1.5.6.8 |
CRITICAL | 9.8 | The e-signature plugin for WordPress is vulnerable to Remote Code Execution in versions before 1.5.6.8. This allows unau… | — | wordfence |
| 03b9187e-022a-48c1-a79c-c4629357de5a | CRITICAL | 9.8 | Vulnerability in wordpress plugin DTracker v1.5, In file ./dtracker/delete.php user input isn't sanitized via the contac… | — | wordfence | |
| 038deaeb-633f-49de-92d8-e593ceb47b1e | < 1.0.5 |
CRITICAL | 9.8 | The RewardsWP β Loyalty Points & Referral Program for WooCommerce plugin for WordPress is vulnerable to Privilege Esca… | — | wordfence |
| 038ddfcd-093b-4234-a0b8-a3bf9a3d329f | CRITICAL | 9.8 | The Ads Pro Plugin - Multi-Purpose WordPress Advertising Manager plugin for WordPress is vulnerable to Local File Inclus… | — | wordfence | |
| 0386ed09-296d-4f33-9fe0-964c0c0a9652 | < 1.7.0 |
CRITICAL | 9.8 | The RingCentral Communications plugin for WordPress is vulnerable to Authentication Bypass due to improper validation wi… | — | wordfence |
| 037a8b06-18be-4443-b54c-22f50c89d5b4 | < 4.0.9 |
CRITICAL | 9.8 | The all-in-one-wp-security-and-firewall plugin before 4.0.9 for WordPress has multiple SQL injection issues. | — | wordfence |
| 034ea306-148f-4a67-abac-a2c6a280745c | CRITICAL | 9.8 | The WP Vehicle Manager plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 3.1.… | — | wordfence | |
| 033e8326-38ed-4d36-8a29-06f9c8a5e808 | < 2.0.3.2 |
CRITICAL | 9.8 | The Wholesale Lead Capture Plugin for WooCommerce plugin for WordPress is vulnerable to Privilege Escalation in all vers… | — | wordfence |
| 030b26ac-344f-4919-9d2d-b85e5e1599f6 | < 2.8.6 |
CRITICAL | 9.8 | The Event Tickets with Ticket Scanner plugin for WordPress is vulnerable to Remote Code Execution in all versions up to,… | — | wordfence |
| 02fe4a33-d059-461c-a03f-b7306ce6193f | < 5 |
CRITICAL | 9.8 | The GeoPlaces 4 Theme for WordPress is vulnerable to arbitrary file uploads due to missing file type validation via the … | — | wordfence |
| 02d6e9c3-f040-4a41-a803-4bbe5f86c29b | < 5.4.12 |
CRITICAL | 9.8 | The Woffice CRM theme for WordPress is vulnerable to privilege escalation in all versions up to, and including, 5.4.10. … | — | wordfence |
| 02cf0e1a-bd12-44b1-9bc5-1a5ec332b000 | < 1.2.0 |
CRITICAL | 9.8 | The Simpler Checkout plugin for WordPress is vulnerable to Authentication Bypass in versions 0.7.0 to 1.1.13. This is du… | — | wordfence |
| 02bb12db-0bc9-4c13-918f-1f90b500c165 | < 1.4.26 |
CRITICAL | 9.8 | The PropertyHive plugin for WordPress is vulnerable to Remote Code Execution in versions up to, and including, 1.4.25 vi… | — | wordfence |
EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.
Scan My Website →