Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.
40,369 vulnerabilities found (page 1056 of 1615)
| CVE ID | Plugin / Theme | Severity | CVSS | Description | Fixed In | Source |
|---|---|---|---|---|---|---|
| f5d42dc6-047f-45ff-9a7a-5a7738f7dcb5 | < 2.2.6 |
MEDIUM | 5.4 | The Safe SVG plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up t… | — | wordfence |
| f5ba832e-98bc-421d-9b60-e6260c408815 | < 1.0.274 |
MEDIUM | 5.4 | The Colibri Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'colibri-gal… | — | wordfence |
| f5b00784-9120-403d-9788-3cd3c3c020aa | < 2.3.16 |
MEDIUM | 5.4 | The WP Dynamic Keywords Injector plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and… | — | wordfence |
| f55a9d35-596c-4207-be11-ade1127df369 | < 7.3.7 |
MEDIUM | 5.4 | Reflected cross-site scripting vulnerability in Quiz And Survey Master versions prior to 7.3.7 allows a remote attacker … | — | wordfence |
| f4f96877-406b-4ec0-ac6b-ee1ffdb436e5 | < 3.1.8 |
MEDIUM | 5.4 | The MailChimp Forms by MailMunch plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and… | — | wordfence |
| f4dfb4b5-b2a5-40bd-9dfb-863baa563d06 | < 2.9.9.4.1 |
MEDIUM | 5.4 | The Pinpoint Booking System plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and incl… | — | wordfence |
| f4b13a45-9141-47e3-ba11-c0ce15235936 | < 1.2.57 |
MEDIUM | 5.4 | The WooCommerce Shipping β DPD baltic plugin for WordPress is vulnerable to authorization bypass due to a missing capa… | — | wordfence |
| f4955368-85bc-4a9c-8d3a-446e09955f6c | < 4.0.2 |
MEDIUM | 5.4 | The Parsi Date plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 4.… | — | wordfence |
| f434585c-8533-4788-b0bc-5650390c29a8 | < 4.5.2 |
MEDIUM | 5.4 | The Online Booking & Scheduling Calendar for WordPress by vcita plugin for WordPress is vulnerable to Cross-Site Request… | — | wordfence |
| f42dc6ab-4035-4e9e-b956-40395c7e309f | < 1.8.8 |
MEDIUM | 5.4 | Cross-site request forgery (CSRF) vulnerability in the WP Maintenance Mode plugin before 1.8.8 for WordPress allows remo… | — | wordfence |
| f419b83c-9253-4ca6-a02a-7daad1819581 | < 3.3.2 |
MEDIUM | 5.4 | wp-admin/plugins.php in WordPress before 3.3.2 allows remote authenticated site administrators to bypass intended access… | — | wordfence |
| f4083d48-a1a8-4ab7-a67f-308bbbbcb4d5 | < 1.9.3 |
MEDIUM | 5.4 | The USPS Shipping for WooCommerce β Live Rates plugin for WordPress is vulnerable to Cross-Site Request Forgery in all… | — | wordfence |
| f3d5bc99-2b55-4e19-8304-e56f3d4a2f1a | < 6.12.4 |
MEDIUM | 5.4 | The Ecwid Ecommerce Shopping Cart plugin for WordPress is vulnerable to unauthorized access of data and modification of … | — | wordfence |
| f3d4283e-ea57-41e1-baeb-f8f70cad3020 | < 2.6.4 |
MEDIUM | 5.4 | The myCred β Points, Rewards, Gamification, Ranks, Badges & Loyalty Plugin plugin for WordPress is vulnerable to Store… | — | wordfence |
| f3d243fe-062c-4f46-aa85-cb7662a7615a | < 1.1.1 |
MEDIUM | 5.4 | The Ultimate Watermark plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a … | — | wordfence |
| f3d08ac9-22f7-45f4-9896-05b90f5fce64 | < 3.0.9 |
MEDIUM | 5.4 | The The Ultimate WordPress Toolkit β WP Extended plugin for WordPress is vulnerable to unauthorized modification of us… | — | wordfence |
| f3b79fab-208f-4354-89ea-508290dcd851 | < 1.4.5 |
MEDIUM | 5.4 | The MailerLite β Signup forms plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and … | — | wordfence |
| f3a5bb9c-0fc3-4a1b-8b4d-a700cbf9dacc | < 1.1.22 |
MEDIUM | 5.4 | Cross-site scripting vulnerability in Event Calendar WD version 1.1.21 and earlier allows remote authenticated attackers… | — | wordfence |
| f397550a-08f6-47d5-8425-e715ad693d6e | < 1.3.9 |
MEDIUM | 5.4 | The LA-Studio Element Kit for Elementor plugin for WordPress is vulnerable to Local File Inclusion in all versions up to… | — | wordfence |
| f38fc5ed-d4e7-46a8-9983-9bf28444db99 | < 2.4.2 |
MEDIUM | 5.4 | The Brizy WordPress plugin before 2.4.2 does not sanitise and escape some element content, which could allow users with … | — | wordfence |
| f330fa5a-b471-45ee-a2a6-3ae8f3941bfe | < 0.8.6 |
MEDIUM | 5.4 | The Contact Form 7 + Telegram plugin for WordPress is vulnerable to unauthorized modification of data and loss of data d… | — | wordfence |
| f32c66b3-b26c-4fe3-9171-ca8780391a2a | MEDIUM | 5.4 | … | — | wordfence | |
| f321e41a-3945-47db-a215-aeb001b7b80b | < 2.0.87 |
MEDIUM | 5.4 | The Accept Stripe Payments plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's accept_str… | — | wordfence |
| f2ff2cc6-b584-442b-890b-033a0a047c24 | < 5.9.9 |
MEDIUM | 5.4 | The Essential Addons for Elementor β Best Elementor Templates, Widgets, Kits & WooCommerce Builders plugin for WordPre… | — | wordfence |
| f2a61a12-df0c-47a2-ba39-b70dbfaddf0a | < 1.5.4 |
MEDIUM | 5.4 | The Flat Preloader WordPress plugin before 1.5.4 does not enforce nonce checks when saving its settings, as well as does… | — | wordfence |
EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.
Scan My Website →