Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.
40,369 vulnerabilities found (page 1068 of 1615)
| CVE ID | Plugin / Theme | Severity | CVSS | Description | Fixed In | Source |
|---|---|---|---|---|---|---|
| b5086b8d-6c74-4970-9937-5ddc5b528495 | < 5.5.0 |
MEDIUM | 5.4 | The WooCommerce Weight Based Shipping plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to… | — | wordfence |
| b4bb3067-7953-466d-a469-8a101450f133 | MEDIUM | 5.4 | The Nexa Blocks – Gutenberg Blocks, Page Builder for Gutenberg Editor & FSE plugin for WordPress is vulnerable to Serv… | — | wordfence | |
| b47f9624-1829-42b7-8afb-fe25b234df72 | < 3.6 |
MEDIUM | 5.4 | Multiple XSS vulnerabilities in the Easy Testimonials plugin before 3.6 for WordPress allow remote attackers to inject a… | — | wordfence |
| b415f998-b0e5-4f22-817c-02bfdc0c405d | MEDIUM | 5.4 | The Custom top bar plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including… | — | wordfence | |
| b3a83683-c159-4af1-b3ba-881a107d9ad6 | < 2.0.0 |
MEDIUM | 5.4 | The Joli Table of Contents plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and inclu… | — | wordfence |
| b380b053-9847-48a8-ba12-d07db9df2baf | < 2.1.4 |
MEDIUM | 5.4 | The WC Price History for Omnibus plugin for WordPress is vulnerable to unauthorized access due to a missing capability c… | — | wordfence |
| b37766e2-95d2-4a95-9381-ed65ce09b3d6 | < 2.6.3 |
MEDIUM | 5.4 | The Workreap theme for WordPress is vulnerable to Insecure Direct Object Reference in versions up to, but not including,… | — | wordfence |
| b33bf55c-0397-44a2-8c18-ea5f8f1e2ec9 | < 4.4.8 |
MEDIUM | 5.4 | The AI ChatBot plugin for WordPress is vulnerable to unauthorized data modification due to a missing capability check on… | — | wordfence |
| b335fc19-2998-4711-8813-6cb68d7447bd | < 5.5.2 |
MEDIUM | 5.4 | The ProfileGrid plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability chec… | — | wordfence |
| b2d75e43-cd46-4c23-bea4-3564e0334a32 | < 3.3.9 |
MEDIUM | 5.4 | The ShopLentor - WooCommerce Builder for Elementor & Gutenberg plugin for WordPress is vulnerable to Stored Cross-Site S… | — | wordfence |
| b2ca838d-165d-4670-94ad-652eedf512ea | < 4.971 |
MEDIUM | 5.4 | The WPLMS theme for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in v… | — | wordfence |
| b2833265-f1e5-4cfd-ad2f-ca28a59de82f | < 3.1.5 |
MEDIUM | 5.4 | The Responsive Plus – Starter Templates, Advanced Features and Customizer Settings for Responsive Theme plugin for Wor… | — | wordfence |
| b27b2e40-c703-4fa0-bff0-788e7a0351c6 | < 2.8.4 |
MEDIUM | 5.4 | The Welcart e-Commerce plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on a… | — | wordfence |
| b2340ae3-3b22-4b14-9fce-4b845f2866b1 | < 6.8 |
MEDIUM | 5.4 | The “Livemesh Addons for Elementor” WordPress Plugin before 6.8 has several widgets that are vulnerable to stored Cr… | — | wordfence |
| b1faf343-1859-4bee-a2d5-f494f44c70ad | < 3.4.34 |
MEDIUM | 5.4 | The wp_ajax_nf_oauth_disconnect from the Ninja Forms Contact Form – The Drag and Drop Form Builder for WordPress WordP… | — | wordfence |
| b1faa178-e4b1-4d2e-85f1-b852fbf3ab17 | < 1.2.0 |
MEDIUM | 5.4 | The Linkz.ai plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check o… | — | wordfence |
| b1e421fb-4839-4e2d-911f-e2fa8c756744 | < 3.0.9 |
MEDIUM | 5.4 | The The Ultimate WordPress Toolkit – WP Extended plugin for WordPress is vulnerable to Insecure Direct Object Referenc… | — | wordfence |
| b19ce745-2cc4-48eb-b5f3-5011be7cceec | < 0.9.7.4 |
MEDIUM | 5.4 | The W3 Total Cache plugin for WordPress is vulnerable to Server Side Request Forgery in versions up to, and including 0.… | — | wordfence |
| b1977c26-ae70-43ce-92c4-9d61ffd4e116 | MEDIUM | 5.4 | The Photography theme for WordPress is vulnerable to unauthorized access due to a missing capability check on a function… | — | wordfence | |
| b1749bef-0952-4530-b607-4574765d2700 | < 2.2.2 |
MEDIUM | 5.4 | The Total theme for WordPress is vulnerable to Stored Cross-Site Scripting via post titles in versions up to, and includ… | — | wordfence |
| b1355e9f-fa3a-439a-a13f-49b10dd4473a | < 1.2.3 |
MEDIUM | 5.4 | The Staff / Employee Business Directory for Active Directory plugin for WordPress is vulnerable to improper LDAP value e… | — | wordfence |
| b12a7e57-a45f-407a-9dd9-843a628d73ac | < 2.0.6.1 |
MEDIUM | 5.4 | The Library Viewer plugin for WordPress is vulnerable to Open Redirect in versions up to, and including, 2.0.6. This is … | — | wordfence |
| b0bfe80d-f9d5-4fc0-a8dd-717c31020b8d | < 1.2.4 |
MEDIUM | 5.4 | The Logo Showcase with Slick Slider WordPress plugin before 1.2.4 does not sanitise the Grid Settings, which could allow… | — | wordfence |
| b08531b2-968e-4a00-ad7a-7abfe8cf0bd3 | < 1.6.8 |
MEDIUM | 5.4 | The VikBooking Hotel Booking Engine & PMS plugin for WordPress is vulnerable to unauthorized access due to insufficient … | — | wordfence |
| afd05b33-a347-49f6-81f0-879606819ca6 | < 3.1.1 |
MEDIUM | 5.4 | Cross-site request forgery (CSRF) vulnerability in the XCloner plugin before 3.1.1 for WordPress allows remote attackers… | — | wordfence |
EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.
Scan My Website →