Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.
40,383 vulnerabilities found (page 1083 of 1616)
| CVE ID | Plugin / Theme | Severity | CVSS | Description | Fixed In | Source |
|---|---|---|---|---|---|---|
| 63f1c60f-8f72-4c99-92af-340c67b7411f | MEDIUM | 5.4 | The Logaster Logo Generator plugin for WordPress is vulnerable to authorization bypass due to a missing capability check… | — | wordfence | |
| 63bced7f-89ec-4c52-9e58-63ef2d311b31 | < 2.7.1 |
MEDIUM | 5.4 | The Catch Web Tools plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the … | — | wordfence |
| 63b272f5-08d1-4c5b-a500-d919903793b7 | < 3.4.1 |
MEDIUM | 5.4 | The Yada Wiki WordPress plugin before 3.4.1 did not sanitise, validate or escape the anchor attribute of its shortcode, … | — | wordfence |
| 63779ab7-ba8b-459d-beb3-a32faf8f4394 | < 4.4.4 |
MEDIUM | 5.4 | The Simple Membership plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'swpm_paypal_su… | — | wordfence |
| 636c9d92-ee62-499d-8d73-33cd63bb5af8 | < 3.5.1 |
MEDIUM | 5.4 | The Easy Digital Downloads plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and i… | — | wordfence |
| 63590140-9723-4e91-884c-f2b11b67eb8d | < 3.7.30 |
MEDIUM | 5.4 | WordPress before 5.2.3 allows XSS in post previews by authenticated users. | — | wordfence |
| 6356e226-a449-4cd0-be60-2a1c9c70aa59 | < 1.1.123 |
MEDIUM | 5.4 | The WordPress plugin Image Slider is vulnerable to Cross-Site Request Forgery in versions up to, and including 1.1.121 d… | — | wordfence |
| 6346024c-61d5-4f73-b7f2-3a8fd3fb838e | < 3.7.6 |
MEDIUM | 5.4 | Cross-site scripting (XSS) vulnerability in the Ephox (formerly Moxiecode) plupload.flash.swf shim 2.1.2 in Plupload, as… | — | wordfence |
| 62ed278c-f914-4edd-aba1-4aaa099a869f | < 5.3.8 |
MEDIUM | 5.4 | The AutomatorWP – Automator plugin for no-code automations, webhooks & custom integrations in WordPress plugin for Wor… | — | wordfence |
| 62b56928-7125-4211-b233-07b5b51881c1 | < 2.18.17 |
MEDIUM | 5.4 | The Wicked Folders plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.… | — | wordfence |
| 62ac2725-0071-4a7d-8561-256e6a232de3 | MEDIUM | 5.4 | The Tiempo.com plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 0.1.2.… | — | wordfence | |
| 6231e47e-2120-4746-97c1-2aa80aa18f4e | < 3.93.0 |
MEDIUM | 5.4 | The WordPress Automatic Plugin plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, a… | — | wordfence |
| 61d3cb97-f12b-4480-88fc-2bdcbf4cdae3 | < 1.2 |
MEDIUM | 5.4 | The Chative Live chat and Chatbot plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to… | — | wordfence |
| 61c5253c-0c0c-4026-bf04-ea5bb2985358 | < 3.8.1 |
MEDIUM | 5.4 | The WCFM Marketplace plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions up to, and inclu… | — | wordfence |
| 61b590f5-7854-42f7-b5e2-e6feaaf03a73 | < 8.7.1 |
MEDIUM | 5.4 | The Blog2Social: Social Media Auto Post & Scheduler plugin for WordPress is vulnerable to unauthorized modification of d… | — | wordfence |
| 617dcc0e-e212-4da0-8918-e55e6b3895fa | < 7.3.4 |
MEDIUM | 5.4 | The Zotpress plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 7.3.… | — | wordfence |
| 61799fbc-05dc-4de9-90f9-8712ba554607 | < 2.10.0 |
MEDIUM | 5.4 | The Welcart e-Commerce plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on th… | — | wordfence |
| 616c8ab8-3200-41fb-9d31-5d36873742cb | < 1.1.0 |
MEDIUM | 5.4 | The Change WP Admin Login WordPress plugin before 1.1.0 does not properly check for authorisation and is also missing CS… | — | wordfence |
| 615d35dd-a92e-4910-b0fc-ac0a7d03741a | < 2.2.19 |
MEDIUM | 5.4 | The shapepress-dsgvo plugin before 2.2.19 for WordPress has wp-admin/admin-ajax.php?action=admin-common-settings&admin_e… | — | wordfence |
| 60c2e8eb-d01b-44f2-8e0d-009ff00887fd | < 1.0.47 |
MEDIUM | 5.4 | The Amelia WordPress plugin before 1.0.47 does not have proper authorisation when managing appointments, allowing any cu… | — | wordfence |
| 609d9ecf-4f91-4a78-ad8c-22e436c000ed | < 2.3.2 |
MEDIUM | 5.4 | The “Elementor Addons – PowerPack Addons for Elementor” WordPress Plugin before 2.3.2 for WordPress has several wi… | — | wordfence |
| 60830ed8-3ab8-44e8-899c-7032a187da8b | < 1.8.1 |
MEDIUM | 5.4 | The WP Duplicate Page plugin for WordPress is vulnerable to unauthorized modification of data due to missing capability … | — | wordfence |
| 60493635-b1b0-4e76-8f73-16c223d7b4d7 | < 1.1.35 |
MEDIUM | 5.4 | The Header Footer Code Manager plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and i… | — | wordfence |
| 5ff589ec-756d-4183-8bb8-61dae9be7c5d | < 2.9.2 |
MEDIUM | 5.4 | The Elements kit Elementor addons plugin for WordPress is vulnerable to unauthorized admin notice dismissal due to a mis… | — | wordfence |
| 5fa2ec9e-2859-4a96-9e33-9e22d37e544f | < 3.8.3 |
MEDIUM | 5.4 | The EmbedPress plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the … | — | wordfence |
EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.
Scan My Website →