Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.
40,369 vulnerabilities found (page 1061 of 1615)
| CVE ID | Plugin / Theme | Severity | CVSS | Description | Fixed In | Source |
|---|---|---|---|---|---|---|
| db5b5fa1-67b5-4103-93b0-682200199a71 | < 6.5.0 |
MEDIUM | 5.4 | The Uncanny Automator plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capabilit… | — | wordfence |
| db15295f-505f-4a0a-bb3a-3ff6daf73008 | < 2.3.2 |
MEDIUM | 5.4 | The Conditional Payments for WooCommerce plugin is vulnerable to Cross-Site Request Forgery in versions up to, and inclu… | — | wordfence |
| dafbf6e2-1160-4551-a987-5e94c9157ff2 | < 4.4.6 |
MEDIUM | 5.4 | The Return Refund and Exchange For WooCommerce β Return Management System, RMA Exchange, Wallet And Cancel Order Featu… | — | wordfence |
| daa9abc2-310f-4bd9-9b88-d6f3024ab5f1 | MEDIUM | 5.4 | The Psychological tests & quizzes plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, a… | — | wordfence | |
| daa48b64-6f89-40be-a31f-31d1481dfc91 | < 3.0.3 |
MEDIUM | 5.4 | The Folders Pro plugin for WordPress is vulnerable to Stored Cross-Site Scripting via a user's First Name and Last Name … | — | wordfence |
| da8af540-1623-42f2-a8af-4d3cadf1f5d0 | MEDIUM | 5.4 | The Woocommerce Products Price Bulk Edit plugin for WordPress is vulnerable to Cross-Site Scripting via the wp-admin/adm… | — | wordfence | |
| da607df4-1dbb-4b1e-ace6-b339cf9e8512 | < 3.4.6 |
MEDIUM | 5.4 | The WP-CRM System plugin for WordPress is vulnerable to unauthorized access due to missing capability checks on the wpcr… | — | wordfence |
| da3070aa-fae8-465a-95e5-ae92dcd89f66 | < 0.4 |
MEDIUM | 5.4 | There is a Cross-Site Scripting vulnerability in Microsoft Clarity version 0.3. The XSS payload executes whenever the us… | — | wordfence |
| d9b10db9-0c7c-4f13-9d98-6d407446cfb8 | < 5.0.4 |
MEDIUM | 5.4 | The The Classified Listing β Classified ads & Business Directory Plugin plugin for WordPress is vulnerable to arbitrar… | — | wordfence |
| d970a9f6-69f6-42d2-b863-82b8110e52c3 | < 3.4 |
MEDIUM | 5.4 | The Taggbox plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on an unknown fu… | — | wordfence |
| d9545264-0434-4976-b94e-4e520e5ae9c6 | < 1.9.41 |
MEDIUM | 5.4 | The Postie plugin 1.9.40 for WordPress allows XSS, as demonstrated by a certain payload with jaVasCript:/* at the beginn… | — | wordfence |
| d94f6cdd-8232-4e0c-b510-0e755c280b58 | < 6.6.0 |
MEDIUM | 5.4 | The Site Reviews plugin for WordPress is vulnerable to setting modification and information disclosure due to lack of ca… | — | wordfence |
| d93c70d6-c439-4bcd-a855-b71896bf9d22 | < 2.8 |
MEDIUM | 5.4 | The Prismatic WordPress plugin before 2.8 does not sanitise or validate some of its shortcode parameters, allowing users… | — | wordfence |
| d92bfa61-7ae2-427a-8f3a-82709471735b | < 2.5.1 |
MEDIUM | 5.4 | The WP Discord Invite plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to 2.5.1. This is … | — | wordfence |
| d8fab229-cd6b-45a3-9e80-a03a1704ad3e | < 2.7.8.1 |
MEDIUM | 5.4 | The Countdown, Coming Soon, Maintenance β Countdown & Clock plugin for WordPress is vulnerable to unauthorized access … | — | wordfence |
| d8cb9488-a73e-4e27-8927-3e6ac65b33c5 | MEDIUM | 5.4 | The Website Chat Button: Kommo integration plugin for WordPress is vulnerable to unauthorized access due to a missing ca… | — | wordfence | |
| d8c1823c-72be-4342-b4e9-0dc18afbb4a8 | < 6.3.2 |
MEDIUM | 5.4 | The Advanced Custom Fields Pro plugin for WordPress is vulnerable to unauthorized access due to a missing capability che… | — | wordfence |
| d8a12e1d-f46a-499e-bfd6-185d5b955071 | < 6.10.23 |
MEDIUM | 5.4 | The Ecwid Ecommerce Shopping Cart plugin for WordPress is vulnerable to Insufficient Access Control on Multiple AJAX Act… | — | wordfence |
| d888cd53-415c-4667-b35a-5b3bd2226eeb | < 1.0.1 |
MEDIUM | 5.4 | The Gutenberg PDF Viewer Block WordPress plugin before 1.0.1 does not sanitise and escape its block, which could allow u… | — | wordfence |
| d875514c-c7d3-4236-842b-6e772048448d | < 4.0.1 |
MEDIUM | 5.4 | The Post Type Switcher plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions up to, and inc… | — | wordfence |
| d80199a2-8a12-44f7-ba20-169d7af88c26 | < 2.18.1 |
MEDIUM | 5.4 | The Finale Lite β Sales Countdown Timer & Discount for WooCommerce plugin for WordPress is vulnerable to unauthorized … | — | wordfence |
| d7f2b39f-d2e1-459d-b02d-6d064c471ed2 | MEDIUM | 5.4 | The Ongkoskirim.id plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a func… | — | wordfence | |
| d7c639b8-35f5-4eaf-a663-1adab3ba2a16 | < 3.5.6 |
MEDIUM | 5.4 | The Gutentor β Gutenberg Blocks β Page Builder for Gutenberg Editor plugin for WordPress is vulnerable to Stored Cro… | — | wordfence |
| d7911337-57fa-4268-8366-d37ff13fae86 | MEDIUM | 5.4 | The Audio Merchant plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including… | — | wordfence | |
| d703abc2-3269-42b2-a75c-d163df62260d | < 6.5 |
MEDIUM | 5.4 | Jetpack up to 6.4.2 is vulnerable to stored Cross-Site Scripting. This allows attackers with contributor privileges to i… | — | wordfence |
EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.
Scan My Website →