Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.
40,383 vulnerabilities found (page 1086 of 1616)
| CVE ID | Plugin / Theme | Severity | CVSS | Description | Fixed In | Source |
|---|---|---|---|---|---|---|
| 54f6a790-7cff-4910-a481-48ae13ba57c8 | < 3.0.10 |
MEDIUM | 5.4 | The Crowdsignal Dashboard plugin for WordPress is vulnerable to Authorization Bypass in versions up to, and including, 3… | — | wordfence |
| 540b2888-16fe-4791-8d08-f7772f71d511 | < 1.10.0 |
MEDIUM | 5.4 | The Lightbox slider β Responsive Lightbox Gallery plugin for WordPress is vulnerable to PHP Object Injection in all ve… | — | wordfence |
| 53a08b59-b7e0-419a-bfc3-528bcddb1ac2 | < 3.5.1.34 |
MEDIUM | 5.4 | The Smart Slider 3 plugin for WordPress is vulnerable to unauthorized access and modification of data due to missing cap… | — | wordfence |
| 53459a4d-6ffd-46bf-926a-761db4cfb50c | < 4.0.2 |
MEDIUM | 5.4 | The Custom Content Shortcode WordPress plugin before 4.0.2 does not escape custom fields before outputting them, which c… | — | wordfence |
| 52b1d515-4965-4ab9-80dd-526b4ebeb3a9 | < 2.4.10 |
MEDIUM | 5.4 | The PostX β Gutenberg Blocks for Post Grid WordPress plugin before 2.4.10 allows users with a role as low as Contribut… | — | wordfence |
| 5289f7a5-7b7b-4627-a313-b8480f88b158 | < 2.6.0 |
MEDIUM | 5.4 | The leenkme plugin before 2.6.0 for WordPress has stored XSS via facebook_message, facebook_linkname, facebook_caption, … | — | wordfence |
| 526aa2e5-06bd-4b4c-a331-315f8ab37858 | < 5.02 |
MEDIUM | 5.4 | The Social proof testimonials and reviews by Repuso plugin for WordPress is vulnerable to Cross-Site Request Forgery in … | — | wordfence |
| 525cb51c-23f1-446f-a247-0f69ec5029d8 | < 3.13.3 |
MEDIUM | 5.4 | The Elementor plugin for WordPress is vulnerable to the creation of emergent resources due to insufficient input validat… | — | wordfence |
| 524452b9-e617-4434-a23f-6026b6f55eeb | MEDIUM | 5.4 | The Polo Video Gallery β Best wordpress video gallery plugin WordPress plugin through 1.2 does not sanitise or validat… | — | wordfence | |
| 520598d7-863f-4bf3-ba74-fa9b2cc32767 | < 1.40.4 |
MEDIUM | 5.4 | The SuperFaktura WooCommerce plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, an… | — | wordfence |
| 51fab95e-336d-4544-8b8e-c4e9002321ec | < 4.10.31 |
MEDIUM | 5.4 | The Premium Addons Pro for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the maps widg… | — | wordfence |
| 51cfe955-f854-4f88-a009-93f92ae13d86 | < 5.16.2 |
MEDIUM | 5.4 | The Abandoned Cart Lite for WooCommerce plugin for WordPress is vulnerable to unauthorized access of data and modificati… | — | wordfence |
| 51b88442-3961-42e2-8ff4-7726819a7f0f | < 2.18.17 |
MEDIUM | 5.4 | The Wicked Folders plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.… | — | wordfence |
| 51b6c73d-fd4f-4469-9859-fbae61b5924c | < 1.4.5 |
MEDIUM | 5.4 | The WP Super Cache plugin for WordPress is vulnerable to Authenticated File Deletion in versions up to, and including, 1… | — | wordfence |
| 51810981-5d2b-471b-b602-35809e281a0b | < 3.1.1 |
MEDIUM | 5.4 | The The Hack Repair Guy's Plugin Archiver plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versio… | — | wordfence |
| 5122800d-f274-4129-84d4-02380269502c | < 1.3.975 |
MEDIUM | 5.4 | The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Form … | — | wordfence |
| 50b26952-bf59-4236-93b4-6b4928609c15 | < 2.7.16 |
MEDIUM | 5.4 | The WPFunnels plugin for WordPress is vulnerable to insecure direct object reference in versions up to, and including, 2… | — | wordfence |
| 50a89ad1-a3d0-49e3-8d2e-4cb81ac115ba | < 7.0.1 |
MEDIUM | 5.4 | The WP Shortcodes Plugin β Shortcodes Ultimate plugin for WordPress is vulnerable to Stored Cross-Site Scripting via t… | — | wordfence |
| 50726c57-8d42-4143-9e75-d30513d8d0e2 | < 2.10 |
MEDIUM | 5.4 | The Sublanguage plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the multi… | — | wordfence |
| 505e9ba4-a19c-4d51-8ba7-4891bbac603e | < 1.12 |
MEDIUM | 5.4 | The Bulk Datetime Change WordPress plugin before 1.12 does not enforce capability checks which allows users with Contrib… | — | wordfence |
| 50542e5e-da66-4223-a6bf-dc9381687ddd | < 1.2.6 |
MEDIUM | 5.4 | The Hive Support | AI-Powered Help Desk, Live Chat & AI Chat Bot Plugin for WordPress plugin for WordPress is vulnerable… | — | wordfence |
| 5015cfe7-9e5c-4745-b6c3-60e4aa99672d | < 3.7.5 |
MEDIUM | 5.4 | The Master Slider plugin for WordPress has XSS via the wp-admin/admin-ajax.php Name input field of the MSPanel.Settings … | — | wordfence |
| 4fdf49e7-c89e-4b05-9236-ca28e715bc4a | < 3.3.2 |
MEDIUM | 5.4 | wp-comments-post.php in WordPress before 3.3.2 supports offsite redirects, which makes it easier for remote attackers to… | — | wordfence |
| 4eff91bd-efc2-4e54-b871-df567ca99bca | < 2.6 |
MEDIUM | 5.4 | Multiple cross-site scripting (XSS) vulnerabilities in the Apptha WordPress Video Gallery (contus-video-gallery) plugin … | — | wordfence |
| 4eff0dfd-f7e6-4f5f-b1c8-00f69fa0df78 | < 5.3.1 |
MEDIUM | 5.4 | The MyRewards plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on several fun… | — | wordfence |
EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.
Scan My Website →