Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.
39,409 vulnerabilities found (page 99 of 1577)
| CVE ID | Plugin / Theme | Severity | CVSS | Description | Fixed In | Source |
|---|---|---|---|---|---|---|
| 24d08127-67b6-434a-8dbe-233a47854f9b | CRITICAL | 9.6 | The Add Post URL WordPress plugin through 2.1.0 does not have CSRF check in place when updating its settings, which coul… | — | wordfence | |
| 22b539c8-a6f1-4543-9e63-08ee4d468ee0 | < 1.0.5 |
CRITICAL | 9.6 | The Google Authenticator WordPress plugin before 1.0.5 does not have CSRF check when saving its settings, and does not s… | — | wordfence |
| 19b4a27d-d9de-4567-86cd-8ec821ee299a | < 2.5 |
CRITICAL | 9.6 | Multiple cross-site request forgery (CSRF) vulnerabilities in the Pods plugin before 2.5 for WordPress allow remote atta… | — | wordfence |
| 0a9b4c03-e7ec-48d6-87fe-67e8a5780703 | < 2.2.0 |
CRITICAL | 9.6 | The a3 Responsive Slider plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and includi… | — | wordfence |
| 618f644b-a92c-4f7f-aaea-c03ee7d6e0f9 | < 2.0.46 |
CRITICAL | 9.4 | The Ultimate Member β User Profile, User Registration, Login & Membership Plugin plugin for WordPress is vulnerable to… | — | wordfence |
| f6f91414-5035-4cab-81ad-18558fe43500 | < 2.2.3 |
CRITICAL | 9.3 | The Better Search plugin for WordPress is vulnerable to SQL Injection via an unknown parameter in versions up to, and in… | — | wordfence |
| ca38c423-2df8-4f20-bd95-2ecd84167a7f | < 4.0.1 |
CRITICAL | 9.3 | The Membership Plugin β Kadence Memberships plugin for WordPress (formerly Restrict Content) is vulnerable to password… | — | wordfence |
| 9729ebf5-ef78-4ef4-81d4-165f422c3847 | < 7.3.15.727 |
CRITICAL | 9.3 | The FV Flowplayer Video Player plugin for WordPress is vulnerable to SQL injection in versions up to, and including, 7.3… | — | wordfence |
| 54a425b0-592a-433d-b9e7-776760536668 | < 3.3.1 |
CRITICAL | 9.3 | A blind SSRF vulnerability exists in the Visualizer plugin before 3.3.1 for WordPress via wp-json/visualizer/v1/upload-d… | — | wordfence |
| 23d762e9-d43f-4520-a6f1-c920417a2436 | < 2.8.9 |
CRITICAL | 9.3 | The Post Form β Registration Form β Profile Form for User Profiles β Frontend Content Forms for User Submissions (… | — | wordfence |
| 224a2d6d-7fdc-43a8-a8c9-26213b604433 | CRITICAL | 9.3 | The WordPress Picture / Portfolio / Media Gallery plugin for WordPress is vulnerable to Server-Side Request Forgery in a… | — | wordfence | |
| fdd1359f-ce16-4cfe-a6a8-245a21ad16c9 | < 18.5 |
CRITICAL | 9.1 | The WooCommerce Support Ticket System plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient … | — | wordfence |
| fb85aacf-a8cf-4054-97fd-b285fcc2a7f9 | CRITICAL | 9.1 | The WP Pipes plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in a… | — | wordfence | |
| faed1198-b8c4-46b1-b6a6-5fc35cd7bdf8 | < 2.0.22 |
CRITICAL | 9.1 | The Formidable Form Builder plugin for WordPress is vulnerable to authorization bypass in versions up to, and including,… | — | wordfence |
| f9de8e90-5bda-4ab1-aa78-2748cd717376 | < 2.2.4 |
CRITICAL | 9.1 | The Madara - Core plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation… | — | wordfence |
| f624c9a0-b48f-49f5-ba63-276805904945 | < 5.1.3 |
CRITICAL | 9.1 | The InfusedWoo Pro plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 5.1.… | — | wordfence |
| f529b981-623f-4bd3-9155-ebfab4c65d1d | < 3.2 |
CRITICAL | 9.1 | The WordPress Simple HTML Sitemap plugin for WordPress is vulnerable to SQL Injection via the 'id' parameter in all vers… | — | wordfence |
| f4831e75-dc0e-4d6f-b2cb-8498d8629319 | CRITICAL | 9.1 | The Simple Coherent Form plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path val… | — | wordfence | |
| f28ca2dc-404d-4abf-9d44-1b1f8309e9ee | < 2.0.13 |
CRITICAL | 9.1 | The Post Grid plugin for WordPress is vulnerable to Arbitrary File Deletion in versions up to, and including, 2.0.12. Th… | — | wordfence |
| f0c23687-2e79-460a-96eb-7d11bf883ced | CRITICAL | 9.1 | The Pk Favicon Manager plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation … | — | wordfence | |
| ed053a6b-4163-4e82-a180-619a7841899a | < 5.8.0 |
CRITICAL | 9.1 | The WP Travel Engine plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 5.7.9 due to … | — | wordfence |
| eccc47cb-9078-405b-9b09-2e14e72ee005 | < 2.0.3 |
CRITICAL | 9.1 | The Import XML and RSS Feeds plugin for WordPress is vulnerable to Server-Side Request Forgery in versions up to, and in… | — | wordfence |
| ecbc7f05-fc4f-4276-968e-04222a64e55a | < 4.5.5 |
CRITICAL | 9.1 | The GEO my WP plugin for WordPress was vulnerable to SQL Injection via the 'distance', 'lat', and 'lng' parameters in ve… | — | wordfence |
| eb562efb-eb17-4366-9f6d-02653df6ece1 | < 1.8.25 |
CRITICAL | 9.1 | Functions/EWD_UFAQ_Import.php in the ultimate-faqs plugin through 1.8.24 for WordPress allows unauthenticated options im… | — | wordfence |
| ead5b943-731d-484a-a6b0-ca4f27eccff0 | < 4.9.6 |
CRITICAL | 9.1 | The Newsletters plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in all … | — | wordfence |
EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.
Scan My Website →