Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.
40,383 vulnerabilities found (page 1092 of 1616)
| CVE ID | Plugin / Theme | Severity | CVSS | Description | Fixed In | Source |
|---|---|---|---|---|---|---|
| 32bcff2d-e322-4c9c-b1c2-f07aa54faff9 | < 5.9.10 |
MEDIUM | 5.4 | The Event post plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'events_list' shortcod… | — | wordfence |
| 32aa1fdc-2fca-4486-b704-eabe4668361e | < 6.2.0 |
MEDIUM | 5.4 | The Modern Events Calendar Lite WordPress plugin before 6.2.0 alloed any logged-in user, even a subscriber user, may add… | — | wordfence |
| 328438ba-128d-4094-83a5-bfd6e1616fa4 | < 8.1.12 |
MEDIUM | 5.4 | The WP Google Maps WordPress plugin before 8.1.12 did not sanitise, validate of escape the Map Name when output in the M… | — | wordfence |
| 3282244f-2b5f-4795-9f3f-461c4fd2e296 | < 1.3.7 |
MEDIUM | 5.4 | The DW Question & Answer Pro WordPress plugin through 1.3.6 does not properly check for Cross-Site Request Forgery in so… | — | wordfence |
| 324fc401-04ca-4707-8727-b8c3a66f7fd6 | < 2.7.0 |
MEDIUM | 5.4 | The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to Stored Cross-Site Scripting… | — | wordfence |
| 31dff395-c3ce-4ebe-8d38-5243fc4510d6 | MEDIUM | 5.4 | The ImageMapper plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the… | — | wordfence | |
| 315dbb77-d872-4cc4-bb4c-9d4763a6ff8f | < 2.4.2 |
MEDIUM | 5.4 | The LWS Tools plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.4.1. … | — | wordfence |
| 310afe02-3a51-4633-b359-65ae58d0c032 | < 1.1.3 |
MEDIUM | 5.4 | The Thank You Page Customizer for WooCommerce – Increase Your Sales plugin for WordPress is vulnerable to unauthorized… | — | wordfence |
| 30fd2425-ee48-4777-91c1-03906d63793a | < 3.8.2 |
MEDIUM | 5.4 | The Metform Elementor Contact Form Builder plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versi… | — | wordfence |
| 30e89955-9f2b-42e4-a7cf-558edd2e736c | < 7.0.4 |
MEDIUM | 5.4 | The Stylish Cost Calculator WordPress plugin before 7.0.4 does not have any authorisation and CSRF checks on some of its… | — | wordfence |
| 30a89e75-2ab1-4e65-8646-b100efed5dbd | < 1.3.981 |
MEDIUM | 5.4 | The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to External Entity Injection in all versions… | — | wordfence |
| 307e3e47-fac8-400d-9b90-b75b39ee14c3 | < 1.1.16 |
MEDIUM | 5.4 | The CubeWP – All-in-One Dynamic Content Framework plugin for WordPress is vulnerable to unauthorized access due to a m… | — | wordfence |
| 306b23ee-7dcb-4281-a218-21168998c4b9 | < 4.4.4 |
MEDIUM | 5.4 | The NextScripts: Social Networks Auto-Poster plugin for WordPress is vulnerable to Cross-Site Request Forgery in all ver… | — | wordfence |
| 3044bd14-b914-4a2a-8e45-1129ac25a38a | MEDIUM | 5.4 | The yPHPlista plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.1… | — | wordfence | |
| 2ff866c0-1b4c-4ad8-bde3-353ed0f44f42 | MEDIUM | 5.4 | The copy-me plugin 1.0.0 for WordPress has CSRF for copying non-public posts to a public location. Edit: The affecte… | — | wordfence | |
| 2fa2fcda-69f4-4095-b23c-6e6f1613adb0 | < 1.0.7 |
MEDIUM | 5.4 | The HT Easy GA4 ( Google Analytics 4 ) plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up t… | — | wordfence |
| 2f760821-98d4-4154-a4ae-861283f991f8 | MEDIUM | 5.4 | The wp tell a friend popup form plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and … | — | wordfence | |
| 2f4e5f34-c107-44da-9f73-e7b25f83e803 | < 6.3.1 |
MEDIUM | 5.4 | The YOP Poll WordPress plugin before 6.3.1 is affected by a stored Cross-Site Scripting vulnerability, which exists in t… | — | wordfence |
| 2ed83916-3cf7-4fc6-a16f-45b40cedc721 | < 2.8.8.3 |
MEDIUM | 5.4 | The Prevent Direct Access – Protect WordPress Files plugin for WordPress is vulnerable to unauthorized access and modi… | — | wordfence |
| 2e9d7776-aa96-47c8-9e31-5484ab65bc66 | < 2.4.9 |
MEDIUM | 5.4 | The Discussion Board plugin for WordPress is vulnerable to Content Injection in versions up to, and including, 2.4.8 via… | — | wordfence |
| 2e9bee86-f491-4f68-b10b-051e0fb1a67b | < 4.4 |
MEDIUM | 5.4 | The Paytium: Mollie payment forms & donations plugin for WordPress is vulnerable to unauthorized data modification due t… | — | wordfence |
| 2e78a4dd-af96-4317-aee4-9aae4fd6c066 | MEDIUM | 5.4 | The Hide WP Toolbar plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a fun… | — | wordfence | |
| 2e6a78dc-9b67-4ab5-83f9-be82d05d3a13 | < 1.2.4 |
MEDIUM | 5.4 | The Shoppable Images plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, … | — | wordfence |
| 2e45ac7f-faab-4004-8c1b-b9b68f9dfe4c | < 4.2.8 |
MEDIUM | 5.4 | The “Premium Addons for Elementor” WordPress Plugin before 4.2.8 has several widgets that are vulnerable to stored C… | — | wordfence |
| 2e2ab3b3-0d24-4b3d-8668-cc2bcf08d12f | MEDIUM | 5.4 | The Tiled Gallery Carousel Without JetPack plugin for WordPress is vulnerable to stored cross-site scripting via the 'da… | — | wordfence |
EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.
Scan My Website →