Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.
40,369 vulnerabilities found (page 1062 of 1615)
| CVE ID | Plugin / Theme | Severity | CVSS | Description | Fixed In | Source |
|---|---|---|---|---|---|---|
| d6f20fc3-41e5-4220-ac8b-54eb11719f07 | < 1.8 |
MEDIUM | 5.4 | The Freshdesk (official) Plugin for WordPress is vulnerable to Open Redirect in versions up to, and including, 1.7. This… | — | wordfence |
| d6a51962-fe99-4911-85c9-a75bd18e74c2 | < 3.7.31 |
MEDIUM | 5.4 | WordPress before 5.2.4 has a Server Side Request Forgery (SSRF) vulnerability because Windows paths are mishandled durin… | — | wordfence |
| d66665b6-8cb2-4bc0-929d-4a8689bada9e | < 3.0.3 |
MEDIUM | 5.4 | The WooSwipe WooCommerce Gallery plugin for WordPress is vulnerable to authorization bypass due to a missing capability … | — | wordfence |
| d62d0971-c4bc-40f7-80b4-a3d54ce4f3ac | < 2021.08.10 |
MEDIUM | 5.4 | The Daily Prayer Time WordPress plugin before 2021.08.10 does not sanitise or escape some of its settings before outputt… | — | wordfence |
| d60f3da1-1184-4629-880c-ce3893fb55a5 | < 5.36.1 |
MEDIUM | 5.4 | The Customer Reviews for WooCommerce plugin for WordPress is vulnerable to unauthorized access of data and modification … | — | wordfence |
| d608a4c0-14ba-4801-aa5a-0b4dab0acd65 | < 2.0.2 |
MEDIUM | 5.4 | The PDF.js Viewer WordPress plugin before 2.0.2 does not escape some of its shortcode and Gutenberg Block attributes, wh… | — | wordfence |
| d5d12ecc-862f-4ecd-9c7b-25dc557abb8d | MEDIUM | 5.4 | The ARforms plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check in… | — | wordfence | |
| d5a6e9f4-dbc3-4af0-b9e4-4c9ad7b5fe9f | < 5.1.5 |
MEDIUM | 5.4 | The Filebird plugin for WordPress is vulnerable to unauthorized SPI key generation due to a missing capability check on … | — | wordfence |
| d57b8c89-109c-4b3b-bea4-adfe7dbfb26d | MEDIUM | 5.4 | The Ultimate NoFollow WordPress plugin through 1.4.8 does not sanitise and escape the href attribute of its shortcodes, … | — | wordfence | |
| d5688bb7-cd2d-42c6-b8cf-d908448ccfc1 | MEDIUM | 5.4 | The Order Your Posts Manually plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'cat_id' para… | — | wordfence | |
| d55c832b-f558-4e8a-8301-33dd38d39ef1 | < 1.15.22 |
MEDIUM | 5.4 | The Form Maker by 10Web β Mobile-Friendly Drag & Drop Contact Form Builder plugin for WordPress is vulnerable to Cross… | — | wordfence |
| d47f5d90-dc7d-4500-a6e6-e585e4a5c11b | MEDIUM | 5.4 | The Change WooCommerce Add To Cart Button Text plugin for WordPress is vulnerable to unauthorized modification of data d… | — | wordfence | |
| d46d6493-8b89-4258-9d83-79e5946cd76f | < 1.0.5 |
MEDIUM | 5.4 | The My Social Feeds β Social Feeds Embedder plugin for WordPress is vulnerable to Sensitive Information Exposure in al… | — | wordfence |
| d40d6228-dacd-4f94-b6a3-a402c4e24554 | < 2.1.2 |
MEDIUM | 5.4 | The Helpdesk Support Ticket System for WooCommerce plugin for WordPress is vulnerable to unauthorized access due to a mi… | — | wordfence |
| d3beee75-0480-4504-a177-45f8cd32cf36 | < 0.6.2.9 |
MEDIUM | 5.4 | The WP Accessibility Helper (WAH) plugin for WordPress is vulnerable to unauthorized modification of data due to a missi… | — | wordfence |
| d31b9022-ae45-4bc2-b820-fb88faf0796f | MEDIUM | 5.4 | The IMPress Listings plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multiple listing fields in ve… | — | wordfence | |
| d2d34c84-473c-49f8-b55c-c869b5479974 | < 1.3.3 |
MEDIUM | 5.4 | The Grid Plus plugin for WordPress is vulnerable to unauthorized modification of data and loss of data due to a missing … | — | wordfence |
| d2594cef-6bde-425f-9412-fd4ed3da312e | < 1.6.0 |
MEDIUM | 5.4 | The VikBooking Hotel Booking Engine & PMS plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions u… | — | wordfence |
| d1e38cdc-7bc5-4963-9ebe-efd6c6ea228d | < 1.1.7 |
MEDIUM | 5.4 | The Easy Media Download WordPress plugin before 1.1.7 does not escape the text argument of its shortcode, which could al… | — | wordfence |
| d1c43e93-69a3-407e-860e-ab25af5d7177 | < 2.18.17 |
MEDIUM | 5.4 | The Wicked Folders plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the a… | — | wordfence |
| d14c8890-482c-4d43-a68f-0d04c4feca8f | < 1.7.9 |
MEDIUM | 5.4 | The Page Builder: Pagelayer β Drag and Drop website builder plugin for WordPress is vulnerable to Stored Cross-Site Sc… | — | wordfence |
| d0dcf95e-1540-48ed-a4a2-f803d67ea141 | < 5.0.6 |
MEDIUM | 5.4 | The Multi Rating for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 5.0.5. This… | — | wordfence |
| d0ca9780-8918-40ff-80c0-62ce483adbae | < 7.3.0 |
MEDIUM | 5.4 | The BuddyPress plugin for WordPress is vulnerable to authorization bypass in versions up to, and including, 7.2.1. This … | — | wordfence |
| d0c724a4-7783-4d2a-938e-800960c2be64 | MEDIUM | 5.4 | The Pet Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, … | — | wordfence | |
| d0631ac6-2d85-4073-be2c-05480deecf97 | < 1.6.0 |
MEDIUM | 5.4 | The VikBooking Hotel Booking Engine & PMS plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions u… | — | wordfence |
EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.
Scan My Website →