Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.
40,369 vulnerabilities found (page 1074 of 1615)
| CVE ID | Plugin / Theme | Severity | CVSS | Description | Fixed In | Source |
|---|---|---|---|---|---|---|
| 90e420be-fe6e-4a35-9c06-f0d360c9f9bf | < 1.4.64 |
MEDIUM | 5.4 | The Motors β Car Dealership & Classified Listings Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scrip… | — | wordfence |
| 9060bb2a-b9d9-466d-bb8d-14173a51d145 | < 2023.03.17 |
MEDIUM | 5.4 | The Daily Prayer Time plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including,… | — | wordfence |
| 8fd93c96-36e9-4e9b-a7ef-b4dc6b7221a8 | < 4.24.8 |
MEDIUM | 5.4 | The WordPress File Upload plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on… | — | wordfence |
| 8f8bd107-5459-4093-8593-deedec6ffcd6 | MEDIUM | 5.4 | The Universal Slider plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.… | — | wordfence | |
| 8f7626b3-86b5-4aa2-871b-07f84a43c47f | < 4.5.1 |
MEDIUM | 5.4 | The GEO my WordPress plugin for WordPress is vulnerable to unauthorized access to data due to a missing capability check… | — | wordfence |
| 8f6c20cb-b3a9-41d3-bccf-5b834424a59a | MEDIUM | 5.4 | The Amazon JS plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in version… | — | wordfence | |
| 8f03b4ef-e877-430e-a440-3af0feca818c | < 4.3.1 |
MEDIUM | 5.4 | The GiveWP β Donation Plugin and Fundraising Platform plugin for WordPress is vulnerable to unauthorized view and modi… | — | wordfence |
| 8eba82b9-20cd-4bf1-85bc-2daea4423ee8 | < 1.2.3 |
MEDIUM | 5.4 | The WP Map Block WordPress plugin before 1.2.3 does not escape some attributes of the WP Map Block, which could allow us… | — | wordfence |
| 8ea4617a-6211-4f8d-ab51-10ca509aaacf | < 3.4.0 |
MEDIUM | 5.4 | The Quill Forms | The Best Typeform Alternative | Create Conversational Multi Step Form, Survey, Quiz, Cost Estimation o… | — | wordfence |
| 8e4ad8fa-b04c-4821-aadb-3120f824557f | < 7.6.1 |
MEDIUM | 5.4 | The WooCommerce Stripe Payment Gateway plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions … | — | wordfence |
| 8e2a994f-7a42-4ccb-8fa0-77107ba1150c | MEDIUM | 5.4 | The The Shortcode Ajax plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and in… | — | wordfence | |
| 8e11fcc5-c9af-43e7-8c1d-803124e04e63 | < 2.9 |
MEDIUM | 5.4 | The Very Simple Google Maps plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode… | — | wordfence |
| 8de3d3c7-bde2-4455-8d60-20307f0a53ee | < 1.0.13 |
MEDIUM | 5.4 | The JetWidgets for Elementor plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and inc… | — | wordfence |
| 8dc16ba4-3c2e-43e2-82a0-b742276b9640 | < 3.9.0 |
MEDIUM | 5.4 | The Tutor LMS Pro β eLearning and online course solution plugin for WordPress is vulnerable to Insecure Direct Object … | — | wordfence |
| 8da42003-f2d8-4837-84b2-e0e7171fa3fe | MEDIUM | 5.4 | The LeadSquared Suite plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including,… | — | wordfence | |
| 8d6637f7-7035-4355-9c9d-193ea87c6e62 | MEDIUM | 5.4 | The Simple Notification plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a… | — | wordfence | |
| 8d4a546a-1c15-4fc5-a2ae-8640457a0c22 | < 1.5.11 |
MEDIUM | 5.4 | The dynamic-widgets plugin before 1.5.11 for WordPress has XSS via the wp-admin/admin-ajax.php?action=term_tree prefix o… | — | wordfence |
| 8d392d0b-f286-44da-aa32-a08d0279baed | < 2.18.17 |
MEDIUM | 5.4 | The Wicked Folders plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the a… | — | wordfence |
| 8cb37019-33f6-4f72-adfc-befbfbf69e47 | < 1.4.1.7 |
MEDIUM | 5.4 | The FOX β Currency Switcher Professional for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scrip… | — | wordfence |
| 8bde357d-e34a-4931-a1a4-bd3ed3b72cec | < 24.0 |
MEDIUM | 5.4 | The PPOM for WooCommerce WordPress plugin before 24.0 does not have authorisation and CSRF checks in the ppom_settings_p… | — | wordfence |
| 8bb3ee9d-084a-42f6-bf9c-e398ddde56ed | MEDIUM | 5.4 | The Blog Designer plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a funct… | — | wordfence | |
| 8bab0acc-5a5d-4dd4-9201-199b7f5aaa69 | < 2.0.6.5 |
MEDIUM | 5.4 | The Master Addons β Free Widgets, Hover Effects, Toggle, Conditions, Animations for Elementor plugin for WordPress is … | — | wordfence |
| 8b0a47e0-5be1-418c-afdf-8bb2d784bcc9 | < 5.3.6 |
MEDIUM | 5.4 | The Customer Reviews for WooCommerce plugin contains several AJAX actions that are not protected by capability or nonce … | — | wordfence |
| 8a7a6da3-d67c-42b3-8826-7e7fc9b938b4 | < 1.2.2 |
MEDIUM | 5.4 | The WP Directory Kit plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, … | — | wordfence |
| 8a345197-d8ba-47ef-a88c-c9e45ddc0319 | < 2.11.20 |
MEDIUM | 5.4 | The Melhor Envio plugin for WordPress is vulnerable to authenticated settings changes and Cross-Site Request Forgery in … | — | wordfence |
EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.
Scan My Website →