Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.
40,369 vulnerabilities found (page 1060 of 1615)
| CVE ID | Plugin / Theme | Severity | CVSS | Description | Fixed In | Source |
|---|---|---|---|---|---|---|
| e087817e-9edb-4c93-96c6-e8d8e99d4d9b | MEDIUM | 5.4 | The WP All Backup plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.4… | — | wordfence | |
| e033dd4a-bc82-403a-82aa-cd8516290f4a | < 1.2.1 |
MEDIUM | 5.4 | The Export Post Info plugin for WordPress is vulnerable to CSV Injection. This allows authenticated users with author pe… | — | wordfence |
| dfa2af3d-ef5a-484b-83a3-552b03b16f4b | MEDIUM | 5.4 | The BxSlider WP plugin for WordPress is vulnerable to Stored Cross-Site Scripting via an unknown parameter in versions u… | — | wordfence | |
| df9b0578-d5fb-459b-b857-d907e4ca22b4 | < 1.1.7 |
MEDIUM | 5.4 | Themify Portfolio Post WordPress plugin before 1.1.7 does not sanitise and escape the num_of_pages parameter before outp… | — | wordfence |
| df6e5aee-e79d-4c3f-a0c4-47436ae7c1da | < 2.9.1 |
MEDIUM | 5.4 | The Premium Addons PRO plugin for WordPress is vulnerable to unauthorized use of functionality due to a missing capabili… | — | wordfence |
| debe6f54-0f56-4bc9-a0cd-4f2caa1ed9e3 | MEDIUM | 5.4 | The Newsmag theme for WordPress is vulnerable to Stored Cross-Site Scripting via an unknown parameter in versions up to,… | — | wordfence | |
| dea1e775-68b4-45e6-9d90-41e39d5d0dfd | < 1.3.5 |
MEDIUM | 5.4 | The Gravity Forms Google Sheet Connector plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up… | — | wordfence |
| de9a945b-31fb-4d0d-9dd1-23bcef1399c2 | < 1.3.0 |
MEDIUM | 5.4 | The Show-Hide / Collapse-Expand plugin for WordPress is vulnerable to authorization bypass due to a missing capability c… | — | wordfence |
| de91c6f1-12b6-4759-90b0-507c9736b3d4 | < 30.1 |
MEDIUM | 5.4 | The WooCommerce Customers Manager plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to… | — | wordfence |
| de614bbd-42ae-4c2a-aec6-31245124de76 | < 4.5.4 |
MEDIUM | 5.4 | The Essential Addons for Elementor Lite WordPress Plugin before 4.5.4 has two widgets that are vulnerable to stored Cros… | — | wordfence |
| de5397c2-b23c-412a-b419-e36023daa989 | MEDIUM | 5.4 | The DNUI plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.8.1. This … | — | wordfence | |
| de4ba999-3312-4bcc-ab87-574b7994e07e | MEDIUM | 5.4 | The RingCentral Communications Plugin β FREE plugin for WordPress is vulnerable to Cross-Site Request Forgery in all v… | — | wordfence | |
| de3a6e77-47ee-4989-81a0-5447a73185bb | MEDIUM | 5.4 | The Activity Reactions For Buddypress plugin for WordPress is vulnerable to missing authorization checks in versions up … | — | wordfence | |
| de1742d4-f498-4ad4-b6a1-88cb60e83afc | < 3.20.2 |
MEDIUM | 5.4 | The Elementor Website Builder Pro plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Pos… | — | wordfence |
| ddf67d69-f362-4380-a396-300c7edbd9f3 | < 4.7.70 |
MEDIUM | 5.4 | The Download Monitor plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and includi… | — | wordfence |
| ddd1ccda-e96a-4dd7-a68f-b42c40619bf6 | < 4.48 |
MEDIUM | 5.4 | The Car Dealer plugin for WordPress is vulnerable to unauthorized access to data due to a missing capability check on th… | — | wordfence |
| dd9e6ba7-f107-4d7c-a7da-35e603f3a1a8 | < 3.3.13 |
MEDIUM | 5.4 | The Download Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versi… | — | wordfence |
| dd56cb73-1c40-44b1-b713-c0291832d988 | MEDIUM | 5.4 | The Page Builder by AZEXO plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capab… | — | wordfence | |
| dcd59ae6-4e5a-4efb-9abb-43c482e41b16 | MEDIUM | 5.4 | The BNS Twitter Follow Button plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, a… | — | wordfence | |
| dcd05142-9700-46a8-9ca6-f85e81dfee0d | < 1.6.8 |
MEDIUM | 5.4 | The Short URL plugin for WordPress is vulnerable to unauthorized access of data, modification of data, and loss of data … | — | wordfence |
| dc01108f-e781-484b-997a-c1d4e218a3f4 | < 2.18.17 |
MEDIUM | 5.4 | The Wicked Folders plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.… | — | wordfence |
| dba0a90b-f13c-4914-b6b7-278227ffc122 | < 3.9.15 |
MEDIUM | 5.4 | The Locatoraid Store Locator plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcod… | — | wordfence |
| db952443-2588-4da0-87d8-5bd2d3be039c | < 2.5.2 |
MEDIUM | 5.4 | The ShopLentor plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.5.1.… | — | wordfence |
| db7903ef-f4e5-452b-b88a-a3933ced833f | < 1.2.5 |
MEDIUM | 5.4 | The Grid Gallery β Photo Image Grid Gallery WordPress plugin before 1.2.5 does not properly sanitize the title field f… | — | wordfence |
| db6bec6c-77d1-4dab-9893-cf33a2fac629 | < 6.2.6 |
MEDIUM | 5.4 | The Photo Engine plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions up to, and including… | — | wordfence |
EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.
Scan My Website →