Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.
40,383 vulnerabilities found (page 1089 of 1616)
| CVE ID | Plugin / Theme | Severity | CVSS | Description | Fixed In | Source |
|---|---|---|---|---|---|---|
| 44583cb7-bc32-4e62-8431-f5f1f6baeff2 | < 10.0.2 |
MEDIUM | 5.4 | The PowerPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in versio… | — | wordfence |
| 443bae1e-21a0-44b3-bda0-a189f5c69a16 | MEDIUM | 5.4 | Multiple cross-site scripting (XSS) vulnerabilities in the WP Membership plugin 1.2.3 for WordPress allow remote authent… | — | wordfence | |
| 443a4afc-5dfc-499c-8701-249c71215b5a | < 2.73 |
MEDIUM | 5.4 | The Timed Content plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in ver… | — | wordfence |
| 44287d9f-93db-417c-bf88-6785e4ce3a9c | < 4.0.7 |
MEDIUM | 5.4 | The MainWP UpdraftPlus Extension plugin for WordPress is vulnerable to authorization bypass in versions up to, and inclu… | — | wordfence |
| 43c9b6f2-2b72-4326-8080-f41606c0880c | < 1.5.5 |
MEDIUM | 5.4 | The Simple Event Planner plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘&custom[add_seg][]… | — | wordfence |
| 43b43802-f301-4748-98b9-eea78a249355 | < 2.18.17 |
MEDIUM | 5.4 | The Wicked Folders plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.… | — | wordfence |
| 4352b2dc-d2a7-4cc9-a44f-1f5be46e2482 | < 1.0.22 |
MEDIUM | 5.4 | The ALD Dropping and Fulfillment for AliExpress and WooCommerce plugin for WordPress is vulnerable to Cross-Site Request… | — | wordfence |
| 43357daa-4dce-4851-b41b-48d3ffb8a387 | < 1.0.0 |
MEDIUM | 5.4 | The HTTP Auth plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 0.3.2. … | — | wordfence |
| 432effd4-5c94-4ef9-bc19-b4eacd082264 | < 1.0.7 |
MEDIUM | 5.4 | The Accessibility plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including,… | — | wordfence |
| 432df51f-2855-4bf2-8be1-77a893e3aa29 | < 4.8 |
MEDIUM | 5.4 | The WP-Chatbot for Messenger plugin for WordPress is vulnerable to unauthorized access and modification of data due to m… | — | wordfence |
| 431d352b-d79b-4a6b-91f9-95962be3049e | < 3.7.34 |
MEDIUM | 5.4 | In affected versions of WordPress, users with low privileges (like contributors and authors) can use the embed block in … | — | wordfence |
| 43100062-c6bd-4d08-a88b-fbcf24f7e605 | < 5.3.6 |
MEDIUM | 5.4 | The Customer Reviews for WooCommerce plugin contains several AJAX actions that are not protected by capability or nonce … | — | wordfence |
| 42e8129f-dbbd-4dd3-a7a5-c6242c43dfe8 | MEDIUM | 5.4 | The Auto-hyperlink URLs WordPress plugin through 5.4.1 does not set rel="noopener noreferer" on generated links, which c… | — | wordfence | |
| 422ae683-dbbe-43ef-b902-ae7570495f21 | MEDIUM | 5.4 | The HomeSweet - Real Estate WordPress Theme is vulnerable to Insecure Direct Object Reference via 'property_id=2769&remo… | — | wordfence | |
| 41d03524-7a53-40cd-a3d5-dafea4fc9a33 | < 121 |
MEDIUM | 5.4 | The Simple URLs plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 120. … | — | wordfence |
| 41b3a62c-9586-4c87-828a-584dfe386a37 | < 3.2.49 |
MEDIUM | 5.4 | The Download Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘title’ and 'label' p… | — | wordfence |
| 417baa1c-29f0-4fec-8008-5b52359b3328 | < 5.9.5 |
MEDIUM | 5.4 | The Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders plugin for WordPre… | — | wordfence |
| 4137b8a6-532a-42fb-aa16-7d1de0e2f11f | MEDIUM | 5.4 | The Advanced uploader WordPress plugin through 4.2 allows any authenticated users like subscriber to upload arbitrary fi… | — | wordfence | |
| 410ae439-dcee-4050-81a9-110a337016e6 | < 3.5.4 |
MEDIUM | 5.4 | The Simple Download Monitor plugin before 3.5.4 for WordPress has XSS via the sdm_upload (aka Downloadable File) paramet… | — | wordfence |
| 4104f69f-b185-498a-aabf-2126ffb94ab3 | < 2.18.17 |
MEDIUM | 5.4 | The Wicked Folders plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.… | — | wordfence |
| 40ba98a0-2193-4201-8370-34fd438dadb3 | < 1.7.4 |
MEDIUM | 5.4 | The Custom Related Posts plugin for WordPress is vulnerable to unauthorized access & modification of data due to a missi… | — | wordfence |
| 402bbe9c-cf4d-457c-97ac-149e14ea6f47 | < 7.3.0 |
MEDIUM | 5.4 | The BuddyPress plugin for WordPress is vulnerable to authorization bypass in versions up to, and including, 7.2.1. This … | — | wordfence |
| 401ea644-bab2-4578-ab1a-7851c2e710ce | < 4.0.8 |
MEDIUM | 5.4 | The MainWP Wordfence Extension plugin for WordPress is vulnerable to authorization bypass in versions up to, and includ… | — | wordfence |
| 3f6683c7-182a-4cd9-be6e-9832f01c3c71 | MEDIUM | 5.4 | The gocodes plugin through 1.3.5 for WordPress has wp-admin/tools.php deletegc XSS. | — | wordfence | |
| 3f635716-5748-48bf-bbfb-75d302a901e9 | < 4.31 |
MEDIUM | 5.4 | The CoDesigner plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function… | — | wordfence |
EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.
Scan My Website →