Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.
40,383 vulnerabilities found (page 1079 of 1616)
| CVE ID | Plugin / Theme | Severity | CVSS | Description | Fixed In | Source |
|---|---|---|---|---|---|---|
| 79766bb2-a796-48b4-afb5-520303a73739 | < 1.0.6 |
MEDIUM | 5.4 | The Product Configurator for WooCommerce plugin for WordPress is vulnerable to arbitrary file deletions in versions up t… | — | wordfence |
| 797554c9-7008-451a-8e8d-3242a207347e | < 3.3.4 |
MEDIUM | 5.4 | The Load More Anything plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capabili… | — | wordfence |
| 793082f8-5b5e-4973-819c-d2f11d1a596e | < 1.2.6 |
MEDIUM | 5.4 | The BetterLinks WordPress plugin before 1.2.6 does not sanitise and escape some of imported link fields, which could lea… | — | wordfence |
| 791ae60d-f2b7-4a53-9008-35cd2d465124 | < 1.7.46 |
MEDIUM | 5.4 | The AddToAny Share Buttons WordPress plugin before 1.7.46 does not sanitise its Sharing Header setting when outputting i… | — | wordfence |
| 78d8ddc9-69ad-4d69-ac23-5a31dfeafd54 | < 1.5.108 |
MEDIUM | 5.4 | The Unlimited Elements For Elementor (Free Widgets, Addons, Templates) plugin for WordPress is vulnerable to Stored Cros… | — | wordfence |
| 78ca8110-fd39-4fcb-bac7-94732c14aee2 | < 5.3.0 |
MEDIUM | 5.4 | The PixelYourSite plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including,… | — | wordfence |
| 78af6e06-4b4c-4f56-a6f8-f98e8f681976 | < 7.3.0 |
MEDIUM | 5.4 | The WP Shortcodes Plugin — Shortcodes Ultimate plugin for WordPress is vulnerable to Stored Cross-Site Scripting via t… | — | wordfence |
| 788fdee8-2eae-437e-8a8d-1d01776cbe6b | < 0.9.1 |
MEDIUM | 5.4 | The Easyship WooCommerce Shipping Rates plugin for WordPress is vulnerable to unauthorized modification and deletion of … | — | wordfence |
| 787a19cf-a553-4aec-96c5-978956826756 | < 9.13 |
MEDIUM | 5.4 | The WP Spell Check plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 9.… | — | wordfence |
| 786d147b-2013-476b-a684-d070f07a166d | < 0.3.5 |
MEDIUM | 5.4 | The AnyComment plugin for WordPress is vulnerable to Open Redirect in versions up to, and including, 0.3.4. This is due … | — | wordfence |
| 77d8d29b-b730-46be-a354-7abfa83ac664 | < 2.5.1 |
MEDIUM | 5.4 | The Simple Page Ordering plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability c… | — | wordfence |
| 774776dc-3780-496c-907a-0d1f86a5d0ac | < 1.99 |
MEDIUM | 5.4 | The Share This Image plugin for WordPress is vulnerable to Open Redirect in all versions up to, and including, 1.98. Thi… | — | wordfence |
| 7717cd0f-6aac-4cb0-b27e-2517d5d7ecd9 | < 1.7.0-0cde1c2 |
MEDIUM | 5.4 | The Worthy – VG WORT Integration für WordPress plugin for WordPress is vulnerable to Cross-Site Request Forgery in ve… | — | wordfence |
| 7707ca04-e136-4d4b-869b-cd270359991e | < 2.0.6 |
MEDIUM | 5.4 | The “The Plus Addons for Elementor Page Builder Lite” WordPress Plugin before 2.0.6 has four widgets that are vulner… | — | wordfence |
| 7681a661-21bd-42fb-ac97-1da808435520 | < 1.7.9 |
MEDIUM | 5.4 | The Qubely plugin for WordPress contains a missing authorization weakness that makes it possible for subscriber-level us… | — | wordfence |
| 766b0bde-c555-40c1-b174-20045bd89c11 | < 3.2.38 |
MEDIUM | 5.4 | The Gutenberg Blocks by Kadence Blocks – Page Builder Features plugin for WordPress is vulnerable to Stored Cross-Site… | — | wordfence |
| 7661d648-543e-46c8-a859-fb722a0c3fc2 | < 3.10.5 |
MEDIUM | 5.4 | The ThirstyAffiliates Affiliate Link Manager WordPress plugin before 3.10.5 does not have authorisation and Cross-Site R… | — | wordfence |
| 76516f23-487f-48f6-82c0-88df651ddc65 | < 3.7.24 |
MEDIUM | 5.4 | wp-admin/user-new.php in WordPress before 4.9.1 sets the newbloguser key to a string that can be directly derived from t… | — | wordfence |
| 75d5366e-2908-4b8d-9ee2-1f11e483add1 | < 2.2.0 |
MEDIUM | 5.4 | The Elements Kit Lite and Elements Kit Pro WordPress Plugins before 2.2.0 have a number of widgets that are vulnerable t… | — | wordfence |
| 7566beda-649f-4dfc-860f-fb1c48809461 | MEDIUM | 5.4 | The Word Search Puzzles game plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and in… | — | wordfence | |
| 75424878-5976-4dc6-8a09-8eb46a7425b8 | < 2.1.7 |
MEDIUM | 5.4 | The plugin Mail Subscribe List for WordPress is vulnerable to Stored Cross-Site Scripting via several parameters in vers… | — | wordfence |
| 7534f2e5-a296-4c54-99e3-d84f5c9a5b51 | < 4.16.4 |
MEDIUM | 5.4 | The WordPress File Upload plugin for WordPress is vulnerable to Cross-Site Scripting in versions up to, and including, 4… | — | wordfence |
| 74fac72d-6f16-475c-bc80-e77968dd23ad | < 4.0.1 |
MEDIUM | 5.4 | The Smash Balloon Social Post Feed WordPress plugin before 4.0.1 did not have any privilege or nonce validation before s… | — | wordfence |
| 74fa5a77-3c66-4aa5-aa58-3e608e3cba70 | < 4.4.0 |
MEDIUM | 5.4 | The Essential Real Estate plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on… | — | wordfence |
| 74a280e1-e4b6-4bd9-882b-d9f185332d61 | MEDIUM | 5.4 | The BadgeOS plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in versions … | — | wordfence |
EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.
Scan My Website →