Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.
40,369 vulnerabilities found (page 1071 of 1615)
| CVE ID | Plugin / Theme | Severity | CVSS | Description | Fixed In | Source |
|---|---|---|---|---|---|---|
| a5deac61-031f-452a-a478-d5d0c7953817 | < 1.3.1 |
MEDIUM | 5.4 | The Stop Referrer Spam plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including… | — | wordfence |
| a438ec56-8ddc-4cea-8d93-c8f79b46f47e | < 4.5.4 |
MEDIUM | 5.4 | The Publish to Schedule plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and includin… | — | wordfence |
| a3f7e1a4-88b2-4069-adb8-d51278b48234 | < 3.7.2 |
MEDIUM | 5.4 | The WooCommerce Enhanced Ecommerce Analytics Integration with Conversion Tracking plugin for WordPress is vulnerable to … | — | wordfence |
| a39679a6-21f1-41e2-aaf8-23f03b79ef33 | < 1.6.5 |
MEDIUM | 5.4 | The Design for Contact Form 7 Style WordPress Plugin β CF7 WOW Styler plugin for WordPress is vulnerable to unauthoriz… | — | wordfence |
| a36d1bb1-9446-4042-a1ec-08a3ffdcb744 | < 4.4.0 |
MEDIUM | 5.4 | The Social Warfare plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 4.… | — | wordfence |
| a32f50f7-d271-45f6-9a73-838a8dcb901f | < 7.3.6 |
MEDIUM | 5.4 | The Themify Ultra theme for WordPress is vulnerable to unauthorized use of functionality due to a missing capability che… | — | wordfence |
| a32dcf96-ec75-46b1-8f1d-608411ad5147 | < 2.8.5 |
MEDIUM | 5.4 | The AI Engine plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the mwai_chatbot shortcode 'id' para… | — | wordfence |
| a3233f6f-7488-43ed-a626-b2150c5516fc | < 3.1.32 |
MEDIUM | 5.4 | The Ditty plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 3.1.31… | — | wordfence |
| a2b809f5-0384-43f5-8839-67bf059360eb | MEDIUM | 5.4 | The Donation Button plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the … | — | wordfence | |
| a29b18d4-7b9b-48c9-aea8-88f6a6fc4b29 | MEDIUM | 5.4 | XSS exists in the amtyThumb amty-thumb-recent-post (aka amtyThumb posts or wp-thumb-post) plugin 8.1.3 for WordPress via… | — | wordfence | |
| a25a00b5-baf3-4175-b242-857c1f79b9a2 | MEDIUM | 5.4 | The Misiek Photo Album plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and inclu… | — | wordfence | |
| a1ab02c0-e083-4f0e-b6d4-1a10ade2c688 | < 3.30 |
MEDIUM | 5.4 | The Leyka plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 3.29.2. Thi… | — | wordfence |
| a19ef0d7-fd44-45ea-8fb1-b99c270072c4 | < 3.0.2 |
MEDIUM | 5.4 | wp-includes/capabilities.php in WordPress before 3.0.2, when a Multisite configuration is used, does not require the Sup… | — | wordfence |
| a1702bdd-1409-42f7-b7b8-cfd44505ecd6 | < 4.2.7.2 |
MEDIUM | 5.4 | The LearnPress β WordPress LMS Plugin plugin for WordPress is vulnerable to Open Redirect in all versions up to, and i… | — | wordfence |
| a156234f-2644-4d17-aaa5-4f088cf48f73 | < 6.4.4 |
MEDIUM | 5.4 | The ShortPixel Image Optimizer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the attachment post… | — | wordfence |
| a0ea0d46-a6aa-4704-8e4e-051bedd4994e | < 7.6.1.0 |
MEDIUM | 5.4 | Cross-site scripting (XSS) vulnerability in admin.php in the Shareaholic plugin before 7.6.1.0 for WordPress allows remo… | — | wordfence |
| a0707c92-96e9-444a-8a13-52d49c9e3f5c | < 3.2.1.1 |
MEDIUM | 5.4 | The Pods β Custom Content Types and Fields plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the P… | — | wordfence |
| 9fe7f4e4-3774-408b-8a2a-0db67bc34fcf | MEDIUM | 5.4 | The Pocket News Generator plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and in… | — | wordfence | |
| 9fdc9d20-a1cf-4a58-b250-4f3f56b77b69 | < 4.3.0 |
MEDIUM | 5.4 | The WP OAuth Server plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 4… | — | wordfence |
| 9fc1e720-46ba-4f57-8694-551936371e2c | < 1.7.6 |
MEDIUM | 5.4 | The Browser Screenshots WordPress plugin before 1.7.6 allowed authenticated users with a role as low as Contributor to p… | — | wordfence |
| 9f6b9a90-4fa8-4cd0-bec8-6fa69a1b4681 | < 3.5.2 |
MEDIUM | 5.4 | The HTTP API in WordPress before 3.5.2 allows remote attackers to send HTTP requests to intranet servers via unspecified… | — | wordfence |
| 9efbbb82-8127-4f11-84d4-2ce27f2cbefe | MEDIUM | 5.4 | The Word Search Puzzles game plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and in… | — | wordfence | |
| 9ea7ccb0-c0fb-4ef3-8041-9bf5abe36e3f | < 2.0.9 |
MEDIUM | 5.4 | The MailerLite β WooCommerce integration plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions … | — | wordfence |
| 9e60428e-1641-470f-a6f1-7c2b4140a6bf | < 6.1.8 |
MEDIUM | 5.4 | Cross-Site Request Forgery (CSRF) in Use Any Font (WordPress plugin) <= 6.1.7 allows an attacker to deactivate the API k… | — | wordfence |
| 9e1f94d9-8be6-4174-90a5-820c0207a2fa | < 25.2.1 |
MEDIUM | 5.4 | The Clever Fox β One Click Website Importer by Nayra Themes plugin for WordPress is vulnerable to unauthorized modific… | — | wordfence |
EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.
Scan My Website →