Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.
40,383 vulnerabilities found (page 1080 of 1616)
| CVE ID | Plugin / Theme | Severity | CVSS | Description | Fixed In | Source |
|---|---|---|---|---|---|---|
| 7449ed1e-cc09-4b8b-8226-7cdc70be2b36 | < 4.2.6.9 |
MEDIUM | 5.4 | The LearnPress β WordPress LMS Plugin plugin for WordPress is vulnerable to Insecure Direct Object Reference in all ve… | — | wordfence |
| 7414779e-7241-4ab2-9b1f-34c3e1acc66b | < 2.0.0 |
MEDIUM | 5.4 | The Doofinder for WooCommerce plugin for WordPress is vulnerable to Open Redirect in versions up to, and including, 1.5.… | — | wordfence |
| 73b93a44-1d91-4755-ae48-73f74a6fe415 | < 3.2.3 |
MEDIUM | 5.4 | The Simple Social Media Share Buttons β Social Sharing for Everyone WordPress plugin before 3.2.3 did not escape the a… | — | wordfence |
| 738a9651-974e-4861-be7a-2d9b191d582b | < 5.9 |
MEDIUM | 5.4 | Cross-site scripting vulnerability in Events Manager plugin prior to version 5.9 for WordPress allows remote attackers t… | — | wordfence |
| 736d08ca-3f65-4232-96a9-303bafbf3471 | < 4.0.0 |
MEDIUM | 5.4 | The Feed Them Social plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, … | — | wordfence |
| 731cbeed-d4aa-448f-878a-8c51a3da4e18 | < 4.3.0 |
MEDIUM | 5.4 | The Online Booking & Scheduling Calendar for WordPress by vcita plugin for WordPress is vulnerable to unauthorized modif… | — | wordfence |
| 72fa6b56-dfbf-4c27-a6f3-418d1ab5dc0f | < 2.0.5 |
MEDIUM | 5.4 | lara-google-analytics.php in Lara Google Analytics plugin through 2.0.4 for WordPress allows authenticated stored XSS. | — | wordfence |
| 72dc919a-c13d-49b4-927d-a0bb837b63dd | < 17.9 |
MEDIUM | 5.4 | The WooCommerce Support Ticket System plugin for WordPress is vulnerable to unauthorized access and loss of data due to … | — | wordfence |
| 72bcfd2a-6803-4073-8fa9-62bcf0a10571 | < 2.5.8 |
MEDIUM | 5.4 | The SVG Support plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the SVG upload feature in all vers… | — | wordfence |
| 72934d2f-fd52-46d1-8cf9-9a20968899f7 | < 5.3.15 |
MEDIUM | 5.4 | The Social Auto Poster plugin for WordPress is vulnerable to unauthorized modification of data to a missing capability c… | — | wordfence |
| 71f58781-3fb3-4eba-8e5a-f98f006f4607 | < 4.4.3 |
MEDIUM | 5.4 | The WP Google Map Plugin plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and includi… | — | wordfence |
| 71d916aa-5382-495b-8142-80de0a0912e7 | < 1.1.6 |
MEDIUM | 5.4 | Unvalidated input and lack of output encoding in the Themify Portfolio Post WordPress plugin, versions before 1.1.6, lea… | — | wordfence |
| 71b3bec2-3fb2-4b0a-aa6d-5c761d0796e2 | < 1.13.5 |
MEDIUM | 5.4 | The updraftplus plugin before 1.13.5 for WordPress has XSS in rare cases where an attacker controls a string logged to a… | — | wordfence |
| 711d2c4d-700d-4d6e-911f-99abf86eff32 | < 3.0.4 |
MEDIUM | 5.4 | The CBX Currency Converter plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and inclu… | — | wordfence |
| 71114965-c8e3-4f2f-b308-f75adc7f2d31 | < 0.9.4.1 |
MEDIUM | 5.4 | Cross-site scripting (XSS) vulnerability in the W3 Total Cache plugin before 0.9.4.1 for WordPress, when debug mode is e… | — | wordfence |
| 70cd028d-122d-4e3c-ac09-150dec07a2cd | < 2.4.3.2 |
MEDIUM | 5.4 | The Permalink Manager Lite plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capa… | — | wordfence |
| 70434876-4876-4da8-9af1-6f6ef5632f26 | < 1.1.20 |
MEDIUM | 5.4 | The Same Category Posts plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the widget title placehold… | — | wordfence |
| 7036400d-022c-4e7e-a463-6ac6f5373474 | MEDIUM | 5.4 | Multiple cross-site scripting (XSS) vulnerabilities in the esb-csv-import-export plugin through 1.1 for WordPress allow … | — | wordfence | |
| 702f9d3b-5d33-4215-ac76-9aae3162d775 | < 4.5.4 |
MEDIUM | 5.4 | The WP Meta SEO plugin for WordPress is vulnerable to unauthorized options update due to a missing capability check on t… | — | wordfence |
| 6fd4fa08-e326-47ab-96b1-be7b702a32ff | MEDIUM | 5.4 | Cross-Site Request Forgery (CSRF) vulnerability in Alexander Stokmann's Code Snippets Extended plugin <= 1.4.7 on WordPr… | — | wordfence | |
| 6fb9c8c3-e491-4bca-adeb-b87d9f8f3b32 | < 1.3.9 |
MEDIUM | 5.4 | The Legal Pages plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.3.8… | — | wordfence |
| 6f6ece0e-7c7c-4c9b-b860-3b279e98c087 | < 2.8.3 |
MEDIUM | 5.4 | The Recipe Card Blocks by WPZOOM plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, an… | — | wordfence |
| 6f17d54b-4890-455b-832f-9fa2376ab819 | < 6.7 |
MEDIUM | 5.4 | The Hercules Core plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability ch… | — | wordfence |
| 6f14f19d-95b3-474b-a2ea-d846c85644cd | MEDIUM | 5.4 | The Maintenance Switch plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including… | — | wordfence | |
| 6f01ecab-2dfe-45d2-9d9a-ba1e30c7d75f | < 4.7.4 |
MEDIUM | 5.4 | The Molongui plugin for WordPress is vulnerable to unauthorized modification and access of data due to missing capabilit… | — | wordfence |
EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.
Scan My Website →