Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.
40,369 vulnerabilities found (page 1069 of 1615)
| CVE ID | Plugin / Theme | Severity | CVSS | Description | Fixed In | Source |
|---|---|---|---|---|---|---|
| af73240c-b711-4e91-9998-5f7e6a9a4fb9 | < 2.7.10 |
MEDIUM | 5.4 | The Groundhogg plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.7.9.… | — | wordfence |
| af695224-24e7-4d5b-b472-dee53eb6073f | < 1.3.9 |
MEDIUM | 5.4 | The Podlove Subscribe button plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and inc… | — | wordfence |
| af468138-c10a-4f9b-b714-0425d52f0210 | < 4.16.5 |
MEDIUM | 5.4 | The MStore API β Create Native Android & iOS Apps On The Cloud plugin for WordPress is vulnerable to Stored Cross-Site… | — | wordfence |
| af3675c9-3a6b-4139-85e8-2fc57f290e82 | < 4.3.0 |
MEDIUM | 5.4 | The Ultimate WordPress Auction Plugin plugin for WordPress is vulnerable to unauthorized access to functionality in all … | — | wordfence |
| af0579f3-09f8-46cc-9ba8-647a8ec83076 | < 1.4.11 |
MEDIUM | 5.4 | The Stripe Payments For WooCommerce plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, … | — | wordfence |
| aefb192a-ed42-44a9-bbd1-5906909a419c | < 2025 |
MEDIUM | 5.4 | The Anti-Spam: Spam Protection | Block Spam Users, Comments, Forms plugin for WordPress is vulnerable to Cross-Site Requ… | — | wordfence |
| ae8dbf54-ea62-4901-b34f-079b708ca0b5 | < 2.18.17 |
MEDIUM | 5.4 | The Wicked Folders plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.… | — | wordfence |
| ae7549db-9a4b-4dee-8023-d7863dc3b4c8 | < 3.3.1 |
MEDIUM | 5.4 | The Metform Elementor Contact Form Builder for WordPress is vulnerable to Cross-Site Scripting by using the 'mf_first_na… | — | wordfence |
| ae6d07eb-3e64-45ee-ad5d-92b41ef11e43 | < 4.11.71 |
MEDIUM | 5.4 | The Premium Addons for Elementor β Powerful Elementor Templates & Widgets plugin for WordPress is vulnerable to Stored… | — | wordfence |
| ae6a00ef-1a3f-47cd-9e55-f28b74999198 | < 4.1.1 |
MEDIUM | 5.4 | The Estatik Real Estate Plugin plugin for WordPress is vulnerable to unauthorized modification of data due to a missing … | — | wordfence |
| ae46eea5-4b7a-4cf5-97ff-c65b7e8e3261 | < 4.0.1 |
MEDIUM | 5.4 | Unvalidated input and lack of output encoding in the Testimonials Widget WordPress plugin, versions before 4.0.0, lead t… | — | wordfence |
| ae40fd4a-8448-48ea-9b31-067643972b44 | < 10.4.37 |
MEDIUM | 5.4 | The Connections Business Directory plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'connection… | — | wordfence |
| adfc5084-ed33-4600-bd34-d3516f1a1b96 | < 1.4.2 |
MEDIUM | 5.4 | The WordPress Backup & Migration plugin for WordPress is vulnerable to unauthorized modification of data due to a missin… | — | wordfence |
| adb84461-6675-497f-ac53-cf72bd4c17bc | < 2.0.6 |
MEDIUM | 5.4 | The WPFront Scroll Top WordPress plugin before 2.0.5 does not sanitise or escape its Image ALT setting before outputting… | — | wordfence |
| ada3a69c-d113-4f92-b716-641bd5d20940 | < 4.9.1 |
MEDIUM | 5.4 | Cross-Site Request Forgery (CSRF) vulnerability leading to event deletion was discovered in Spiffy Calendar WordPress pl… | — | wordfence |
| ad979f36-319f-48ce-a620-5ea9ae5401eb | < 1.4.0 |
MEDIUM | 5.4 | The Enable SVG WordPress plugin before 1.4.0 does not sanitise uploaded SVG files, which could allow users with a role a… | — | wordfence |
| ad50e216-f522-4294-a4dc-7f3bd52820b3 | < 2.1.1 |
MEDIUM | 5.4 | The Doofinder for WooCommerce plugin for WordPress is vulnerable to unauthorized modification of data and loss of data d… | — | wordfence |
| ad359327-9d53-4c8e-bd09-7a337711cfbd | < 2.3.19 |
MEDIUM | 5.4 | The Timetable and Event Schedule by MotoPress WordPress plugin before 2.3.19 does not sanitise some of its parameters, w… | — | wordfence |
| acbe1c36-04e7-49af-90fa-d8acbe351b57 | < 2.0.52 |
MEDIUM | 5.4 | The ultimate-member plugin before 2.0.52 for WordPress has XSS during an account upgrade. | — | wordfence |
| ac9a3848-f486-475b-b2c7-ea1007bb30d3 | < 2.12 |
MEDIUM | 5.4 | The Login Lockdown & Protection plugin for WordPress is vulnerable to unauthorized nonce access due to a missing capabil… | — | wordfence |
| ac86043d-caf9-4c25-86b2-0e063c21b2d7 | < 5.2.7 |
MEDIUM | 5.4 | Cross-Site Request Forgery (CSRF) vulnerabilities leading to single or bulk e-mail entries deletion discovered in Email … | — | wordfence |
| ac8214af-00d0-4dde-a3e7-f657decc4b93 | < 2.7.27 |
MEDIUM | 5.4 | The Pods β Custom Content Types and Fields WordPress plugin before 2.7.27 was vulnerable to an Authenticated Stored Cr… | — | wordfence |
| ac763936-7147-4100-8a46-4c6d2f2224b4 | MEDIUM | 5.4 | The idbbee plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'idbbee' shortcode in vers… | — | wordfence | |
| ac10b30d-1fe3-46f4-a4fc-fa2acd7f9db4 | < 1.3.40 |
MEDIUM | 5.4 | The Falang multilanguage plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and includi… | — | wordfence |
| abf4cfb9-745a-4b4f-8862-54ef561904d6 | < 3.0.0 |
MEDIUM | 5.4 | The Mass Delete Unused Tags plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and incl… | — | wordfence |
EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.
Scan My Website →