Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.
40,369 vulnerabilities found (page 1077 of 1615)
| CVE ID | Plugin / Theme | Severity | CVSS | Description | Fixed In | Source |
|---|---|---|---|---|---|---|
| 805e3eba-639e-48a1-a867-a2c56fa01081 | < 1.1 |
MEDIUM | 5.4 | The wplegalpages plugin before 1.1 for WordPress has CSRF with resultant XSS via wp-admin/admin.php?page=legal-pages lp-… | — | wordfence |
| 804dafd1-0f18-4248-a243-8b26d161bc85 | < 1.2.2 |
MEDIUM | 5.4 | Cross-Site Request Forgery (CSRF) vulnerability in API KEY for Google Maps plugin <= 1.2.1 at WordPress leading to Googl… | — | wordfence |
| 8030c334-458a-4d21-9a64-3f5df715ba97 | < 4.3.3 |
MEDIUM | 5.4 | The GetGenie plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including… | — | wordfence |
| 801d6f21-1f52-48d4-9f8e-5c971dd037f7 | < 3.7.21 |
MEDIUM | 5.4 | In WordPress before 4.7.5, there is a lack of capability checks for post meta data in the XML-RPC API. | — | wordfence |
| 7fdb93fa-e9b4-4d00-8bb3-ff171a916b65 | < 4.0.3 |
MEDIUM | 5.4 | The MainWP Page Speed Extension plugin for WordPress is vulnerable to authorization bypass in versions up to, and includ… | — | wordfence |
| 7fbbd0d7-882f-4bc8-a67a-4d6dc05cb796 | < 1.8.2.2 |
MEDIUM | 5.4 | The LearnDash LMS – Reports plugin for WordPress is vulnerable to unauthorized modification of data due to a missing c… | — | wordfence |
| 7fa5ac48-57b6-4367-81a0-8310360d0c7d | < 1.5.5 |
MEDIUM | 5.4 | The Ultimate Addons for Beaver Builder – Lite plugin for WordPress is vulnerable to Cross-Site Request Forgery in vers… | — | wordfence |
| 7f787c75-7b27-4256-ac0c-abc2988ea7c8 | < 6.2.1.6 |
MEDIUM | 5.4 | The Auto Affiliate Links plugin for WordPress is vulnerable to improper access control via multiple AJAX actions in vers… | — | wordfence |
| 7f4c0bd6-f289-4a52-ac11-345076c32d84 | < 2.5.4 |
MEDIUM | 5.4 | The Responsive Lightbox & Gallery plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up t… | — | wordfence |
| 7f17e055-ad49-4115-89c5-dd76b6c531f7 | < 4.0.3 |
MEDIUM | 5.4 | The Visual Website Collaboration, Feedback & Project Management – Atarim plugin for WordPress is vulnerable to unautho… | — | wordfence |
| 7f01ad95-7a51-408c-917f-4350dbeabb2b | < 3.8.0 |
MEDIUM | 5.4 | The Editorial Calendar plugin for WordPress is vulnerable to insecure direct object reference in versions up to, and inc… | — | wordfence |
| 7ee188cc-2c3f-45e7-b7ce-928242035e37 | < 2.9.1.7 |
MEDIUM | 5.4 | The Uncode theme for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘mle-description’ parameter in a… | — | wordfence |
| 7edad4f6-e470-4a72-b618-d2dad64e0ac1 | < 6.3.1 |
MEDIUM | 5.4 | The YOP Poll WordPress plugin before 6.3.1 is affected by a stored Cross-Site Scripting vulnerability which exists in th… | — | wordfence |
| 7dfd0246-4265-4dde-8a1e-18b7042eae74 | < 1.1.4 |
MEDIUM | 5.4 | The BEAR for WordPress is vulnerable to Missing Authorization in versions up to, and including, 1.1.3.3. This is due to … | — | wordfence |
| 7dcd3452-a340-44e5-b292-347dc69ab863 | MEDIUM | 5.4 | The Regina Lite theme for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘id’ parameter in versio… | — | wordfence | |
| 7dc6d1db-37ae-4198-84bd-944dad4926c7 | < 1.3.83 |
MEDIUM | 5.4 | The Appointment Booking Calendar plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to,… | — | wordfence |
| 7d500729-3b1a-4ece-81de-4c1f9afbf798 | < 1.1.5 |
MEDIUM | 5.4 | The Redirect Redirection plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and includi… | — | wordfence |
| 7d4ae4a7-aec1-4cc1-bea0-61dde44027fc | < 5.7.35 |
MEDIUM | 5.4 | The Email Subscribers by Icegram Express – Email Marketing, Newsletters, Automation for WordPress & WooCommerce plugin… | — | wordfence |
| 7d30e813-010f-4881-8b8e-f3d62d928c57 | < 3.7.1 |
MEDIUM | 5.4 | The Easy Affiliate Links plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's block settin… | — | wordfence |
| 7d19800a-bff3-414f-a809-0159f49d263a | < 1.4.1 |
MEDIUM | 5.4 | The Custom Order Numbers for WooCommerce plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up… | — | wordfence |
| 7cc96e83-28d9-4c6e-876f-23f1836ffd74 | < 2.1.4 |
MEDIUM | 5.4 | The Google Maps plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'id' URL parameter in versi… | — | wordfence |
| 7cbc157b-4f1b-4212-9e5c-dd10dd443df7 | < 2.8.0 |
MEDIUM | 5.4 | The Scratch & Win – Giveaways and Contests. Boost subscribers, traffic, repeat visits, referrals, sales and more plug… | — | wordfence |
| 7c9b9ab3-ecfa-49d0-820f-4edb5abae9ee | MEDIUM | 5.4 | The Image Hover Effects – Elementor Addon plugin for WordPress is vulnerable to unauthorized access due to a missing c… | — | wordfence | |
| 7c89eb8e-bbd1-4c26-84ed-74456a6157a1 | MEDIUM | 5.4 | The Oshine Core plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a functio… | — | wordfence | |
| 7c6fe986-df68-4a62-9a43-5632c622b5fc | < 1.11.2 |
MEDIUM | 5.4 | The “Elementor Addon Elements” WordPress Plugin before 1.11.2 has several widgets that are vulnerable to stored Cros… | — | wordfence |
EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.
Scan My Website →