Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.
39,409 vulnerabilities found (page 98 of 1577)
| CVE ID | Plugin / Theme | Severity | CVSS | Description | Fixed In | Source |
|---|---|---|---|---|---|---|
| c79a173d-b9c3-4554-95e7-2a4b87382079 | CRITICAL | 9.6 | The OpenBook Book Data WordPress plugin through 3.5.2 does not have CSRF check in place when updating its settings, whic… | — | wordfence | |
| b5490dd9-20d5-4cd6-bc09-5da94d3e702f | < 4.1.5.3 |
CRITICAL | 9.6 | The All in One SEO WordPress plugin before 4.1.5.3 is affected by an authenticated SQL injection issue, which was discov… | — | wordfence |
| a50531df-e876-463c-a06b-16b2f30aeefe | < 3.7.29 |
CRITICAL | 9.6 | WordPress before 5.1.1 does not properly filter comment content, leading to Remote Code Execution by unauthenticated use… | — | wordfence |
| 9e6365ab-30c5-4bec-a5f3-b0812ae8a609 | < 2.4.1 |
CRITICAL | 9.6 | The New User Approve WordPress plugin before 2.4.1 does not have CSRF check in place when updating its settings and addi… | — | wordfence |
| 9e3f199b-b75d-43a2-a20c-957fb1b512e1 | CRITICAL | 9.6 | The Hot Linked Image Cacher WordPress plugin through 1.16 is vulnerable to CSRF. This can be used to store / cache image… | — | wordfence | |
| 92d59dd4-7338-40ac-9a73-37e9e85351d7 | < 3.1.1 |
CRITICAL | 9.6 | Multiple cross-site request forgery (CSRF) vulnerabilities in XCloner Standalone 3.1.0 and earlier allow remote attacker… | — | wordfence |
| 8f4ae82c-f249-4094-a0ef-568c3a30d16b | CRITICAL | 9.6 | The HC Custom WP-Admin URL WordPress plugin through 1.4 does not have CSRF check in place when updating its settings, wh… | — | wordfence | |
| 8df77bb7-4453-403d-8d35-66251f6d399c | CRITICAL | 9.6 | The Sideblog WordPress plugin through 6.0 does not have CSRF check in place when updating its settings, which could allo… | — | wordfence | |
| 8b776a8a-b071-4caf-9e67-6f08ace4da2a | < 2.5 |
CRITICAL | 9.6 | The ND Booking plugin for WordPress is vulnerable to arbitrary options update in versions up to, and including 2.4, due … | — | wordfence |
| 82acefe0-a839-4721-858d-120326e45664 | < 3.1.4 |
CRITICAL | 9.6 | The Post Snippets WordPress plugin before 3.1.4 does not have CSRF check when importing files, allowing attacker to make… | — | wordfence |
| 812d99bc-8d86-44a9-bafa-be8ce979229c | < 3.7.10 |
CRITICAL | 9.6 | Cross-site request forgery (CSRF) vulnerability in wp-admin/post.php in WordPress before 4.2.4 allows remote attackers t… | — | wordfence |
| 7ffac29d-d1cc-4d5d-aff8-0cb639a1e3d7 | < 2.8.5 |
CRITICAL | 9.6 | EWWW Image Optimizer before 2.8.5 allows remote command execution because it relies on a protection mechanism involving … | — | wordfence |
| 7ea13a80-c744-4de3-ac19-178b67e1afc4 | CRITICAL | 9.6 | The MyAnime Widget plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.… | — | wordfence | |
| 7817a840-325a-4709-8374-84bb32d98d0e | < 1.25.0 |
CRITICAL | 9.6 | The Web Stories plugin for WordPress is vulnerable to Server-Side Request Forgery in versions up to, and including 1.24.… | — | wordfence |
| 6eb3ad80-3510-4018-91af-b733ef62e28f | < 2.1 |
CRITICAL | 9.6 | The Favicon Generator plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including,… | — | wordfence |
| 65b2b72a-5c76-463e-9513-26b400b40a65 | CRITICAL | 9.6 | The One Click Plugin Updater WordPress plugin through 2.4.14 does not have CSRF check in place when updating its setting… | — | wordfence | |
| 655e6486-e35f-4e7b-b894-55606d3eba56 | < 1.5 |
CRITICAL | 9.6 | The WP Fast Cache plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.4… | — | wordfence |
| 63b67652-d10e-4a5a-97d5-04e6c848b752 | < 1.7.2 |
CRITICAL | 9.6 | The Jetpack Scan team identified a Reflected Cross-Site Scripting in the Login Form of the Patreon WordPress plugin befo… | — | wordfence |
| 5b3f4ccb-fcc6-42ec-8e9e-03d69ae7acf2 | < 4.9.1 |
CRITICAL | 9.6 | The AI ChatBot plugin for WordPress is vulnerable to Arbitrary File Deletion in versions up to, and including, 4.8.9 as … | — | wordfence |
| 585d0368-7557-46aa-9ea3-26cd6d7df51b | < 4.57 |
CRITICAL | 9.6 | The SP Project & Document Manager plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, an… | — | wordfence |
| 5717b835-7feb-4bb8-8f1b-1f44d4630cd3 | < 3.4.5 |
CRITICAL | 9.6 | The Ali2Woo Lite plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 3.4.… | — | wordfence |
| 2fd58397-7598-4d98-a6b3-c5837cb3b73e | < 1.5.7 |
CRITICAL | 9.6 | The Armour Honeypot Anti Spam plugin for WordPress is vulnerable to Cross-Site Request Forgery due to missing nonce vali… | — | wordfence |
| 2be6c7d8-6dd4-4701-9baa-694496e7388a | CRITICAL | 9.6 | The RB Internal Links WordPress plugin through 2.0.16 does not have CSRF check in place when updating its settings, whic… | — | wordfence | |
| 2b897790-43f7-4ca4-8abe-9dc736a7c011 | CRITICAL | 9.6 | The WP-chgFontSize WordPress plugin through 1.8 does not have CSRF check in place when updating its settings, which coul… | — | wordfence | |
| 25199281-5286-4d75-8d27-26ce215e0993 | < 4.9.1 |
CRITICAL | 9.6 | The AI ChatBot for WordPress is vulnerable to Directory Traversal in versions up to, and including, 4.8.9 as well as 4.9… | — | wordfence |
EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.
Scan My Website →