Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.
40,369 vulnerabilities found (page 1057 of 1615)
| CVE ID | Plugin / Theme | Severity | CVSS | Description | Fixed In | Source |
|---|---|---|---|---|---|---|
| f28e36e9-7d02-48fc-8f20-64a951af75e0 | MEDIUM | 5.4 | Hermit 音乐播放器 <= 3.1.6 is vulnerable to Cross-Site Request Forgery. This allow attackers to delete cache, delet… | — | wordfence | |
| f28afb93-b72a-4a56-994b-144124202147 | < 1.13.5 |
MEDIUM | 5.4 | The Custom Post Type UI for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.13… | — | wordfence |
| f288b68a-2455-4ee7-b217-5cb46fb79caf | MEDIUM | 5.4 | The JW-Player plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via multiple parameters in versions u… | — | wordfence | |
| f26fcef3-6d94-46f6-9832-bdb03b6cb867 | < 1.3.02 |
MEDIUM | 5.4 | The "CP Contact Form with PayPal" plugin before 1.2.99 for WordPress has XSS in the publishing wizard via the wp-admin/a… | — | wordfence |
| f2448450-9d0e-42bc-bfdb-66861b2f212c | < 1.9.7 |
MEDIUM | 5.4 | The Gravityforms plugin for WordPress is vulnerable to Cross-Site Scripting in versions up to, and including, 1.9.6 due … | — | wordfence |
| f21100f4-f655-41e6-a31c-70ce4dfb1ba6 | MEDIUM | 5.4 | The Ceceppa Multilingua plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'tab' GET parameter… | — | wordfence | |
| f1d72e60-182f-4210-a190-e0a7f0237ed1 | < 1.9.31 |
MEDIUM | 5.4 | The Text To Speech TTS Accessibility plugin for WordPress is vulnerable to unauthorized access due to a missing capabili… | — | wordfence |
| f15af4eb-5752-4a85-babd-cee7e89c329d | < 2.0.0 |
MEDIUM | 5.4 | The Auto Prune Posts plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, … | — | wordfence |
| f0b95670-0767-4325-88d0-4ae6d7302558 | < 1.3.1 |
MEDIUM | 5.4 | The Funnel Builder plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the a… | — | wordfence |
| f0859e21-851a-4a6d-aa6c-9f759c5866d9 | < 8.9.1 |
MEDIUM | 5.4 | The Blog2Social: Social Media Auto Post & Scheduler plugin for WordPress is vulnerable to Missing Authorization in all v… | — | wordfence |
| f06d1b9e-e27d-4c43-a69b-7641518e4615 | < 1.3.33 |
MEDIUM | 5.4 | The 2J-SlideShow Plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the 'tw… | — | wordfence |
| f040d5b9-0db2-467b-91fa-98aede9f7280 | MEDIUM | 5.4 | The Subscribe to Category plugin for WordPress is vulnerable to authorization bypass due to a missing capability check o… | — | wordfence | |
| efe846aa-6de2-40f0-81c6-f7ca98a55f23 | MEDIUM | 5.4 | The Popup Surveys & Polls for WordPress (Mare.io) plugin for WordPress is vulnerable to unauthorized access due to a mis… | — | wordfence | |
| ef5859b7-0f15-43ad-9f45-aa846d045f5d | < 2.4.14 |
MEDIUM | 5.4 | The WP Project Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and includin… | — | wordfence |
| ef2f1ad1-1e2e-4b56-b16c-d87956b142ad | MEDIUM | 5.4 | The AM LottiePlayer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via uploaded SVG files in all vers… | — | wordfence | |
| ef0dc868-f617-408f-9333-ebfee4897701 | < 1.9 |
MEDIUM | 5.4 | The BruteBank plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.8. Th… | — | wordfence |
| eeac5489-7eba-43b6-b7fb-1ce062285948 | MEDIUM | 5.4 | The Fence URL wp-login.php plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and i… | — | wordfence | |
| ee78642c-ad2a-4012-94e8-e01f71863791 | < 2.0.6 |
MEDIUM | 5.4 | The wpForo Forum plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions up to, and including… | — | wordfence |
| ee74d229-499e-4f9a-ad7d-c707f6eeac6e | < 2.9.22 |
MEDIUM | 5.4 | The Ninja Forms Contact Form plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and… | — | wordfence |
| ee52c6c0-c69e-46c4-9e4b-94aa69c00737 | < 1.11.8 |
MEDIUM | 5.4 | The Easy Google Maps plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, … | — | wordfence |
| ee520664-0c1f-4af0-8cdf-a33c1dfaaca7 | < 1.2.0 |
MEDIUM | 5.4 | The Rife Elementor Extensions & Templates plugin for WordPress is vulnerable to missing authorization due to a missing … | — | wordfence |
| ee1ee4c4-871d-4a3d-8ca6-3675d248d5e8 | < 8.2.6 |
MEDIUM | 5.4 | The Soledad plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on one of its f… | — | wordfence |
| edf5ba29-2fc5-4839-abde-999f6b686749 | MEDIUM | 5.4 | The Attendance Manager plugin for WordPress is vulnerable to SQL Injection via the 'attmgr_off' parameter in all version… | — | wordfence | |
| edcf46b6-368e-49c0-b2c3-99bf6e2d358f | < 4.1.38 |
MEDIUM | 5.4 | WordPress Core is vulnerable to Directory Traversal in versions up to, and including, 6.2, via the ‘wp_lang’ paramet… | — | wordfence |
| ed79e382-acb4-4348-9bc6-b44ec0d75fb5 | < 1.9.1 |
MEDIUM | 5.4 | The Depicter Slider plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on multi… | — | wordfence |
EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.
Scan My Website →