Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.
40,383 vulnerabilities found (page 1091 of 1616)
| CVE ID | Plugin / Theme | Severity | CVSS | Description | Fixed In | Source |
|---|---|---|---|---|---|---|
| 3b798c64-3434-427d-b578-5abbdac8cd0e | MEDIUM | 5.4 | The 0mk Shortener plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 0.2… | — | wordfence | |
| 3b7108fc-0eb2-4f9f-b747-3b83c57a1b53 | < 0.14.11 |
MEDIUM | 5.4 | The webp-express plugin before 0.14.8 for WordPress has stored XSS. | — | wordfence |
| 3b378256-2d9b-4aad-abfe-fecfc76f0bb4 | MEDIUM | 5.4 | The SVG Shortcode plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions… | — | wordfence | |
| 3ad60a11-e307-4ec9-9099-091a87ff1d3b | < 2.18.17 |
MEDIUM | 5.4 | The Wicked Folders plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the a… | — | wordfence |
| 3abe2de8-9127-4ef0-9194-cf331b20868a | < 2.3.14 |
MEDIUM | 5.4 | The Responsive Gallery Grid plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and incl… | — | wordfence |
| 3a71b8da-73dd-488e-b553-77116731f13f | < 3.7.11 |
MEDIUM | 5.4 | The mw_editPost function in wp-includes/class-wp-xmlrpc-server.php in the XMLRPC subsystem in WordPress before 4.3.1 all… | — | wordfence |
| 39e501d8-88a0-4625-aeb0-aa33fc89a8d4 | < 4.6.0 |
MEDIUM | 5.4 | The GiveWP β Donation Plugin and Fundraising Platform plugin for WordPress is vulnerable to Stored Cross-Site Scriptin… | — | wordfence |
| 39bbe18a-0212-4bfe-861f-2a213d67baec | < 1.2.11 |
MEDIUM | 5.4 | The Fast Flow WordPress plugin before 1.2.11 does not sanitise and escape the page parameter before outputting back in a… | — | wordfence |
| 389277fd-e47e-42df-9305-61ceedbcfb29 | < 4.2.3.1 |
MEDIUM | 5.4 | The LearnPress plugin for WordPress is vulnerable to unauthorized access of user data due to a missing capability check… | — | wordfence |
| 387d28fa-f582-4d68-a781-fc210ef5bd30 | < 3.1.7 |
MEDIUM | 5.4 | The Ultimate Blocks β WordPress Blocks Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via th… | — | wordfence |
| 385c6324-3d8e-4dc7-b8ca-309b05e7bdcc | < 1.6.0 |
MEDIUM | 5.4 | The VikBooking Hotel Booking Engine & PMS plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions u… | — | wordfence |
| 36d37997-ac50-4d00-bc12-f3904483e15f | < 5.7.8 |
MEDIUM | 5.4 | The advanced-custom-fields (aka Elliot Condon Advanced Custom Fields) plugin before 5.7.8 for WordPress has XSS by autho… | — | wordfence |
| 360010f3-9053-4c69-a4e8-12f0c77ba746 | < 7.5.45.7212 |
MEDIUM | 5.4 | The FV Flowplayer Video Player plugin for WordPress is vulnerable to unauthorized redirects in all versions up to, and i… | — | wordfence |
| 35fb658f-6ffa-4df7-bfcd-25307d89fc26 | < 2.18.17 |
MEDIUM | 5.4 | The Wicked Folders plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the a… | — | wordfence |
| 34fb64d5-e152-4950-9ef4-6d53a97a56fb | < 3.3.2 |
MEDIUM | 5.4 | The Categories Images plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including… | — | wordfence |
| 34d396b2-f19f-47b3-bf9e-f2f14dd0b9be | MEDIUM | 5.4 | The URL Shortener plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on an unk… | — | wordfence | |
| 34c98bb0-2e28-4ed4-8848-04edb66eef96 | MEDIUM | 5.4 | The Debug Meta Data plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, … | — | wordfence | |
| 346a5b00-fb76-4413-a935-a2df4dc51984 | < 6.15.13.1 |
MEDIUM | 5.4 | The The Events Calendar plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on t… | — | wordfence |
| 345f3354-d2cb-4b92-a25d-9551a5992919 | < 4.17.0 |
MEDIUM | 5.4 | The The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content β Profi… | — | wordfence |
| 34021007-b5d3-479b-a0d4-50e301f22c9c | < 2.09 |
MEDIUM | 5.4 | The Login Lockdown β Protect Login Form plugin for WordPress is vulnerable to unauthorized access of data due to a mis… | — | wordfence |
| 33d70481-4652-44f4-99cf-67cc1ffab66a | < 5.1.11 |
MEDIUM | 5.4 | The Download Monitor plugin for WordPress is vulnerable to Cross-Site Request Forgery in the `actions_handler()` and `bu… | — | wordfence |
| 33585791-be40-438c-bebc-8852e7cf8ae5 | < 6.4.6.2 |
MEDIUM | 5.4 | The Community by PeepSo β Social Network, Membership, Registration, User Profiles, Premium β Mobile App plugin for W… | — | wordfence |
| 334ff8d7-1313-4c19-aed3-0c4625b895ab | < 1.0.354 |
MEDIUM | 5.4 | The Calculated Fields Form plugin through 1.0.353 for WordPress suffers from multiple Stored XSS vulnerabilities present… | — | wordfence |
| 332c0829-316d-4037-8c50-02d6c92cdb10 | < 7.3.7 |
MEDIUM | 5.4 | The Quiz And Survey Master plugin for WordPress is vulnerable to insecure direct object reference in versions up to, and… | — | wordfence |
| 32ca6e56-add9-4024-831f-5dfa5130a7d8 | < 2.4.7 |
MEDIUM | 5.4 | The Easy Custom Auto Excerpt plugin 2.4.6 for WordPress has XSS via the tonjoo_ecae_options[custom_css] parameter to the… | — | wordfence |
EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.
Scan My Website →