Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.
40,369 vulnerabilities found (page 1055 of 1615)
| CVE ID | Plugin / Theme | Severity | CVSS | Description | Fixed In | Source |
|---|---|---|---|---|---|---|
| fd23b9cd-3492-4f6f-b90d-5215e175c1e3 | < 3.7.26 |
MEDIUM | 5.4 | Before WordPress 4.9.5, the redirection URL for the login page was not validated or sanitized if forced to use HTTPS. | — | wordfence |
| fd12ce4a-585d-4e26-88fb-1ab9dcc8727d | < 2.8.3.1 |
MEDIUM | 5.4 | The RestroPress plugin for WordPress is vulnerable to missing authorization in versions up to, and including, 2.8.3. Thi… | — | wordfence |
| fcfb3a6e-7b58-4568-8439-e9c68a2223b9 | < 5.1.9.3 |
MEDIUM | 5.4 | The RegistrationMagic plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including,… | — | wordfence |
| fcb1f4db-3dba-4031-8196-66eec3203752 | MEDIUM | 5.4 | The Facilita Form Tracker plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and in… | — | wordfence | |
| fc7bab78-4ebb-4be9-8891-1ac0e3ed0af3 | < 1.2.0 |
MEDIUM | 5.4 | The Comment Blacklist Updater plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and in… | — | wordfence |
| fc58c679-3e87-4bcc-b1bc-718ae52c291a | < 1.4.44 |
MEDIUM | 5.4 | The The Motors – Car Dealer, Classifieds & Listing plugin for WordPress is vulnerable to arbitrary shortcode execution… | — | wordfence |
| fc215aad-6988-434d-a623-be0b7f87189b | < 1.4 |
MEDIUM | 5.4 | The Qi Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 1.… | — | wordfence |
| fafdd087-9637-41df-bc5a-97e1a02ea744 | < 5.9.9 |
MEDIUM | 5.4 | The Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders plugin for WordPre… | — | wordfence |
| fa52034e-3d11-4be5-ab8b-8f7256be2a3e | < 2.5.1 |
MEDIUM | 5.4 | The Broken Link Checker | Finder plugin for WordPress is vulnerable to Blind Server-Side Request Forgery in all versions… | — | wordfence |
| f9844b47-427a-4f2f-9f42-00adcbcf133c | MEDIUM | 5.4 | The WCP Contact Form plugin for WordPress is vulnerable to unauthorized access and modification of data due to a missing… | — | wordfence | |
| f932e3ea-3d82-47af-924a-b2df15641611 | < 4.0.4 |
MEDIUM | 5.4 | The MainWP Staging Extension plugin for WordPress is vulnerable to authorization bypass in versions up to, and including… | — | wordfence |
| f9150e6b-2233-4fdb-95b7-1a5a8c083cad | < 4.0.3 |
MEDIUM | 5.4 | The MainWP WordPress SEO Extension plugin for WordPress is vulnerable to authorization bypass in versions up to, and inc… | — | wordfence |
| f884ea43-e1a5-4b44-8a24-f68f71b0fcfb | < 2.9.2 |
MEDIUM | 5.4 | The Gravity Forms plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘style_settings’ paramet… | — | wordfence |
| f882da12-2db7-481f-9a16-a54e1ab24af5 | < 2.4.9 |
MEDIUM | 5.4 | The Page View Count WordPress plugin before 2.4.9 does not escape the postid parameter of pvc_stats shortcode, allowing … | — | wordfence |
| f8575c46-e51d-4be9-85bf-024688c4607d | < 1.6 |
MEDIUM | 5.4 | The Advanced WordPress Reset plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘DBR_new_URI… | — | wordfence |
| f7ae863c-4638-49ab-bb1f-52346884c3aa | < 1.2.5 |
MEDIUM | 5.4 | The YourChannel plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.2.4… | — | wordfence |
| f71453d9-8bbf-4546-b69f-e86cc41da9bd | < 1.1.3 |
MEDIUM | 5.4 | The Smart App Banner plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, … | — | wordfence |
| f70221e6-59a4-4151-9688-f06e194f51ac | < 2.13.0 |
MEDIUM | 5.4 | The Sheets To WP Table Live Sync plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and… | — | wordfence |
| f6e2ab69-2714-4bf9-a9ad-035fc15450f2 | < 20220216 |
MEDIUM | 5.4 | The Simple Ajax Chat plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including,… | — | wordfence |
| f6a41a90-d116-4cb5-9627-08eb70f9654d | < 2.5.9 |
MEDIUM | 5.4 | The SVG Support plugin for WordPress is running a vulnerable dependency (svg-sanitize, 0.14.1) in all versions up to, an… | — | wordfence |
| f67ab0cf-340d-4234-a857-1883f91c3ab6 | < 1.1.39 |
MEDIUM | 5.4 | The Popup Builder (Easy Notify Lite) plugin for WordPress is vulnerable to unauthorized modification of data due to a mi… | — | wordfence |
| f62063c8-7559-492a-9caf-fae256052d1a | < 2.8.35 |
MEDIUM | 5.4 | The 10Web Booster plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the tw… | — | wordfence |
| f618a350-e089-40f7-b731-7ffb9ece30b3 | MEDIUM | 5.4 | The Contact Form With Captcha plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and in… | — | wordfence | |
| f603a25f-7d56-4cf4-89aa-de87ee49522a | < 4.9 |
MEDIUM | 5.4 | The Delete Duplicate Posts plugin for WordPress is vulnerable to unauthorized deletion of data due to a missing capabili… | — | wordfence |
| f5f59b16-b38a-451b-b220-044598872735 | < 1.7 |
MEDIUM | 5.4 | The Meta Slider and Carousel with Lightbox plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions … | — | wordfence |
EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.
Scan My Website →