Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.
39,409 vulnerabilities found (page 97 of 1577)
| CVE ID | Plugin / Theme | Severity | CVSS | Description | Fixed In | Source |
|---|---|---|---|---|---|---|
| 02b75034-8db1-465b-837e-014e2c2e8b4d | < 2.8.0 |
CRITICAL | 9.8 | The Asgaros Forum plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 2.7.2… | — | wordfence |
| 02998107-9415-433a-8c64-5838324bdcc3 | CRITICAL | 9.8 | The Essential Real Estate plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 5… | — | wordfence | |
| 0254726d-ce5b-454c-ab8b-d778beb375d4 | CRITICAL | 9.8 | The Evon theme for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 3.4. This makes it … | — | wordfence | |
| 023910d0-c2eb-41cd-9d42-606c4cbb8059 | < 1.3.3.3 |
CRITICAL | 9.8 | The drag-and-drop-multiple-file-upload-contact-form-7 plugin before 1.3.3.3 for WordPress allows Unrestricted File Uploa… | — | wordfence |
| 022f6239-67f2-4680-aeed-34c98c953bea | < 1.0 |
CRITICAL | 9.8 | The BJ Lazy Load plugin v0.7.5 for WordPress has Remote File Inclusion vulnerability via TimThumb. | — | wordfence |
| 0209c6ab-cc49-4929-851d-b12c5decf975 | < 7.0 |
CRITICAL | 9.8 | The AR For WordPress plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in… | — | wordfence |
| 01f4318f-b56b-4a34-987b-05edeee5da69 | < 2.2.4 |
CRITICAL | 9.8 | The wpForo Forum plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 2.2.3.… | — | wordfence |
| 0152bcc9-6d24-4475-848d-71fe88aa7e2a | < 3.30.3 |
CRITICAL | 9.8 | The Leyka plugin for WordPress is vulnerable to Privilege Escalation in versions up to, and including, 3.30.2. This allo… | — | wordfence |
| 014f1aae-10a0-4bc8-b176-dbdad94a6ad8 | < 5.0.5 |
CRITICAL | 9.8 | The Essential Addons for Elementor WordPress plugin before 5.0.5 does not validate and sanitise some template data befor… | — | wordfence |
| 01427553-bc1d-4927-9110-0facd301d976 | CRITICAL | 9.8 | The Quick Learn plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 1.0.1 via d… | — | wordfence | |
| 0111a73e-3d5a-4dd5-8974-dc43aafb5050 | < 4.9.9 |
CRITICAL | 9.8 | The WooCommerce - PDF Vouchers plugin for WordPress is vulnerable to authentication bypass in all versions up to 4.9.9 (… | — | wordfence |
| 010300f9-adef-4958-ac77-6ff981833e9e | CRITICAL | 9.8 | The Blaze Slide Show plugin for Wordpress is vulnerable to arbitrary file uploads due to missing file type validation in… | — | wordfence | |
| 010183f3-d614-4fe7-aa70-56d6b3fc5ddc | CRITICAL | 9.8 | The WizShop plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 3.0.2. This mak… | — | wordfence | |
| 00ae6b57-6ce2-4e39-91c9-7b2c5b38124b | CRITICAL | 9.8 | The is-human plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 1.4.2 via… | — | wordfence | |
| 005fa621-3c49-4c23-add5-d6b7a9110055 | < 2.8.3 |
CRITICAL | 9.8 | The Ultimate Member β User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin plu… | — | wordfence |
| 005d1abc-761d-4f9a-bc21-aad63e8efd66 | < 1.8 |
CRITICAL | 9.8 | The Career Section plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 1.7… | — | wordfence |
| ffaf7a75-de27-4361-ba04-ff17151b7eb5 | CRITICAL | 9.6 | The Site Offline or Coming Soon WordPress plugin through 1.6.6 does not have CSRF check in place when updating its setti… | — | wordfence | |
| fc9dfe96-2d43-4b7b-a91a-87cdaaab8e49 | < 1.7.2 |
CRITICAL | 9.6 | The Jetpack Scan team identified a Reflected Cross-Site Scripting via the patreon_save_attachment_patreon_level AJAX act… | — | wordfence |
| f908837d-2bba-45db-b005-f685a33cd71e | CRITICAL | 9.6 | The postTabs WordPress plugin through 2.10.6 does not have CSRF check in place when updating its settings, which could a… | — | wordfence | |
| f8bcf51a-36ee-4d4d-b9d6-d9db0dafd791 | < 2.32.11 |
CRITICAL | 9.6 | The 10Web Booster β Website speed optimization, Cache & Page Speed optimizer plugin for WordPress is vulnerable to arb… | — | wordfence |
| f4703ca7-0677-4128-b9b7-31132ff1804d | < 4.2 |
CRITICAL | 9.6 | The Jetpack β WP Security, Backup, Speed, & Growth plugin for WordPress is vulnerable to CSV Injection in versions up … | — | wordfence |
| ef5028a0-6a5a-40ad-92df-ffc988cad389 | < 4.09.05 |
CRITICAL | 9.6 | The Formidable Form Builder WordPress plugin before 4.09.05 allows to inject certain HTML Tags like <audio>,<video>,<img… | — | wordfence |
| d8e23501-9fc4-484b-b308-a9c51494bc9d | CRITICAL | 9.6 | The LaTeX for WordPress plugin through 3.4.10 does not have CSRF check in place when updating its settings, which could … | — | wordfence | |
| cacd31bd-ccc6-49fa-89f1-09f3c5cd9072 | < 4.4.5 |
CRITICAL | 9.6 | The Captcha plugin for WordPress contained a backdoor that injected SEO spam into unsuspecting users WordPress sites in … | — | wordfence |
| c8abcc7b-6c68-4fc8-81af-e88624e417dd | < 5.1.0 |
CRITICAL | 9.6 | The AutomatorWP β Automator plugin for no-code automations, webhooks & custom integrations in WordPress plugin for Wor… | — | wordfence |
EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.
Scan My Website →