Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.
40,369 vulnerabilities found (page 1076 of 1615)
| CVE ID | Plugin / Theme | Severity | CVSS | Description | Fixed In | Source |
|---|---|---|---|---|---|---|
| 858d8641-7455-47c2-9639-480ce4ec3540 | < 1.9.2 |
MEDIUM | 5.4 | The Responsive Contact Form Builder & Lead Generation Plugin plugin for WordPress is vulnerable to arbitrary shortcode e… | — | wordfence |
| 84cd2529-7b9b-47c2-9e9c-72bb208a60e6 | MEDIUM | 5.4 | The WP Triggers Lite plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and inc… | — | wordfence | |
| 84b616fa-ff64-49e8-8c4a-7d7bfdf758be | < 2.5.7 |
MEDIUM | 5.4 | The Jeg Elementor Kit plugin for WordPress is vulnerable to authorization bypass in various AJAX actions in versions up … | — | wordfence |
| 84846d95-792d-4569-b0eb-876d82d0beee | < 5.0.05 |
MEDIUM | 5.4 | The AIKTP plugin for WordPress is vulnerable to unauthorized modification of data due to missing authorization checks on… | — | wordfence |
| 840ba5b2-838a-455a-b39d-865f89c05249 | < 9.0.47 |
MEDIUM | 5.4 | The WP Go Maps (formerly WP Google Maps) plugin for WordPress is vulnerable to Cross-Site Request Forgery (CSRF) in all … | — | wordfence |
| 83dfd6a2-2944-42a9-9e3d-60836ebfb106 | < 6.7.5 |
MEDIUM | 5.4 | The AI ChatBot for WordPress β WPBot plugin for WordPress is vulnerable to unauthorized access due to a missing capabi… | — | wordfence |
| 83d63545-00f3-411b-9d4a-6837759bc3af | MEDIUM | 5.4 | The Better Author Bio plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including,… | — | wordfence | |
| 83cb1333-3c74-426d-9838-a5cb90be29b2 | < 2.1.0 |
MEDIUM | 5.4 | The wpForo Forum plugin for WordPress is vulnerable to HTML Injection in versions up to, and including, 2.0.9. This is d… | — | wordfence |
| 8390ab61-197a-4eb7-a589-47bf46a0e123 | < 2.46.1 |
MEDIUM | 5.4 | The Simple Giveaways plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, … | — | wordfence |
| 834c4ca9-7173-4c84-8287-9916ec72935d | < 2.6.2 |
MEDIUM | 5.4 | The Tutor LMS β eLearning and online course solution plugin for WordPress is vulnerable to unauthorized loss of data d… | — | wordfence |
| 830663b6-0786-48c7-9ffd-ac3ba2bd3e0c | < 3.6.8 |
MEDIUM | 5.4 | The Image Photo Gallery Final Tiles Grid plugin for WordPress is vulnerable to authorization bypass in all versions up t… | — | wordfence |
| 82cee07d-871a-4579-aa53-ca0d14315458 | < 13.3 |
MEDIUM | 5.4 | The Admin and Customer Messages After Order for WooCommerce: OrderConvo plugin for WordPress is vulnerable to limited fi… | — | wordfence |
| 82cde234-ae87-438f-911e-bdd0e3ac1132 | < 5.6.4 |
MEDIUM | 5.4 | The FileBird β WordPress Media Library Folders & File Manager plugin for WordPress is vulnerable to Insecure Direct Ob… | — | wordfence |
| 824ec2ba-b701-46e9-b237-53cd7d0e46da | < 3.14.2 |
MEDIUM | 5.4 | The GiveWP β Donation Plugin and Fundraising Platform plugin for WordPress is vulnerable to unauthorized access and de… | — | wordfence |
| 824b27e8-1f07-4cd0-9335-5860d1b58562 | MEDIUM | 5.4 | The bookmarkify plugin 1.1.3 for WordPress has CSRF with resultant XSS via wp-admin/options-general.php?page=bookmarkify… | — | wordfence | |
| 822a3b3b-db39-4edc-ae68-80fb82359316 | < 1.6.8 |
MEDIUM | 5.4 | The WordPress RSS Feed Retriever plugin for WordPress is vulnerable to authorization bypass due to a missing capability … | — | wordfence |
| 819e2a4a-d282-4c52-852a-e3a2051a04e9 | < 2.0.10 |
MEDIUM | 5.4 | The Klarna Checkout for WooCommerce plugin for WordPress is vulnerable to Arbitrary Plugin Installation, Activation and … | — | wordfence |
| 8198d81a-40c0-49c1-8c38-f5ef6fb911ad | < 4.9.4 |
MEDIUM | 5.4 | The Schedule Post Changes With PublishPress Future plugin for WordPress is vulnerable to authorization bypass in all ver… | — | wordfence |
| 818d3418-8e14-49b9-a112-8eab9eb3c283 | < 4.8.1 |
MEDIUM | 5.4 | The Bold Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Icon Link in al… | — | wordfence |
| 8175ff00-e588-46cf-a743-9c4d4717657a | MEDIUM | 5.4 | The Amazon affiliate lite Plugin plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to,… | — | wordfence | |
| 816bcd51-2424-41a1-8a0d-583268d8c6cd | < 3.6.6 |
MEDIUM | 5.4 | The The Textmetrics plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and inclu… | — | wordfence |
| 8149103e-105d-401d-8a15-b07d131baaac | < 1.32.1 |
MEDIUM | 5.4 | The FiboSearch β Ajax Search for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the… | — | wordfence |
| 80bb4009-7857-4af4-9c55-0ef69b538e6f | < 2.2.5 |
MEDIUM | 5.4 | The BuddyPress Docs plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and in… | — | wordfence |
| 80ae05c4-64de-48df-b302-6110403b79d0 | < 1.7.3 |
MEDIUM | 5.4 | The Easy PayPal Buy Now Button plugin for WordPress is vulnerable to Cross-Site Request Forgery to Cross-Site Scripting … | — | wordfence |
| 80797183-c69f-4dce-a2e0-52a395ceffaa | < 2.18.17 |
MEDIUM | 5.4 | The Wicked Folders plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.… | — | wordfence |
EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.
Scan My Website →