Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.
40,383 vulnerabilities found (page 1094 of 1616)
| CVE ID | Plugin / Theme | Severity | CVSS | Description | Fixed In | Source |
|---|---|---|---|---|---|---|
| 27857a17-8cf0-40b3-894f-8dd7cf5108dd | MEDIUM | 5.4 | The Social Media WPCF7 Stop Words plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to… | — | wordfence | |
| 2764b360-228d-48c1-8a29-d3764e532799 | < 2.18.17 |
MEDIUM | 5.4 | The Wicked Folders plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the a… | — | wordfence |
| 27337cf2-18a0-4f26-a674-3ab2003b4838 | < 3.3 |
MEDIUM | 5.4 | The WooCommerce Anti-Fraud plugin for WordPress is vulnerable to Insecure Direct Object Reference (IDOR) due to insuffic… | — | wordfence |
| 272c6fbb-bc85-46d9-b139-87534b2a0842 | < 4.1.6 |
MEDIUM | 5.4 | The Advanced Dynamic Pricing for WooCommerce plugin for WordPress is vulnerable to Cross-Site Request Forgery in version… | — | wordfence |
| 2719739a-90dc-470b-9270-8578e0cead59 | < 3.7.7 |
MEDIUM | 5.4 | The MasterStudy LMS WordPress Plugin β for Online Courses and Education plugin for WordPress is vulnerable to unauthor… | — | wordfence |
| 26d9dfc7-151c-4b32-9ae4-3085d08f137c | < 1.8.1 |
MEDIUM | 5.4 | The Embed Privacy plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'embed_privacy_opt_… | — | wordfence |
| 26bfef74-214f-4257-afc7-730e82e80946 | < 2.7.4.3 |
MEDIUM | 5.4 | The Beaver Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Icon Widget 'fl_builder_dat… | — | wordfence |
| 262dcea7-3ac4-43ee-90d7-91f200c3496c | < 6.5.5 |
MEDIUM | 5.4 | The Easy Social Feed β Social Photos Gallery β Post Feed β Like Box plugin for WordPress is vulnerable to Cross-Si… | — | wordfence |
| 26253942-7948-4016-947d-8c98f01525ab | < 3.0 |
MEDIUM | 5.4 | The Paid Memberships Pro β Content Restriction, User Registration, & Paid Subscriptions plugin for WordPress is vulner… | — | wordfence |
| 261a1bf0-a147-48c8-878e-f9b725ac74d8 | < 2.18.17 |
MEDIUM | 5.4 | The Wicked Folders plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.… | — | wordfence |
| 25a80b0b-2636-45c1-92e5-bd62c8a4ab20 | < 1.0.49 |
MEDIUM | 5.4 | The Amelia WordPress plugin before 1.0.49 does not have proper authorisation when managing appointments, allowing any cu… | — | wordfence |
| 25200656-a6a2-42f2-a607-26d4ff502cbf | < 3.3.1 |
MEDIUM | 5.4 | The Metform Elementor Contact Form Builder for WordPress is vulnerable to Cross-Site Scripting by using the 'mf_last_nam… | — | wordfence |
| 2497837d-dec6-4a1d-be88-5c0e659eeb46 | < 2.6.8 |
MEDIUM | 5.4 | TheKraken.io Image Optimizer plugin for WordPress is vulnerable to authorization bypass due to a missing capability chec… | — | wordfence |
| 241da621-b892-4263-8409-a40ac5a1ade3 | MEDIUM | 5.4 | The Add Local Avatar plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, … | — | wordfence | |
| 24142bf8-15e7-460d-83a3-52dc57537498 | < 6.5.2 |
MEDIUM | 5.4 | The WP Affiliate Platform plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and in… | — | wordfence |
| 23e47daa-79e7-4ed3-a88a-0f090e9aa277 | < 6.9.1 |
MEDIUM | 5.4 | The Smash Balloon Social Photo Feed β Easy Social Feeds Plugin plugin for WordPress is vulnerable to Stored Cross-Site… | — | wordfence |
| 23a94578-f395-4ec1-8a08-52ca233cc832 | < 1.2.4 |
MEDIUM | 5.4 | The Meks Easy Photo Feed Widget WordPress plugin before 1.2.4 does not have capability and CSRF checks in the meks_save_… | — | wordfence |
| 2372e851-97dd-449b-b356-f43f6fd409df | < 1.0.4 |
MEDIUM | 5.4 | The Pixel WordPress Form BuilderPlugin & Autoresponder plugin for WordPress is vulnerable to Cross-Site Request Forgery … | — | wordfence |
| 230b6a10-1505-4f66-ba98-df6257a80668 | < 1.9.6 |
MEDIUM | 5.4 | MicroPayments - Paid Author Subscriptions, Content, Downloads, Membership versions prior to 1.9.6 are vulnerable to Cros… | — | wordfence |
| 2304e4dc-0dc6-4ded-b8e6-8d76d70f63d7 | < 1.7.7 |
MEDIUM | 5.4 | The Digital Publications by Supsystic plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to… | — | wordfence |
| 22b3ee70-7ba6-4f8a-add4-3c7f4765b3d1 | < 3.7.10 |
MEDIUM | 5.4 | Cross-site scripting (XSS) vulnerability in the refreshAdvancedAccessibilityOfItem function in wp-admin/js/nav-menu.js i… | — | wordfence |
| 229490c3-d820-4831-b105-a429512c2c60 | < 7.2.8 |
MEDIUM | 5.4 | The Image Optimizer, Resizer and CDN β Sirv plugin for WordPress is vulnerable to unauthorized plugin settings modific… | — | wordfence |
| 22506d45-40db-47c4-91b2-ab4f49703bf9 | < 2.7.11.1 |
MEDIUM | 5.4 | The Groundhogg plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.7.11… | — | wordfence |
| 22420c2d-788c-4577-ae54-7b48f6063f5d | < 2.6.1 |
MEDIUM | 5.4 | The Tutor LMS β eLearning and online course solution plugin for WordPress is vulnerable to HTML Injection in all versi… | — | wordfence |
| 21cc3f71-7591-4111-a58a-d863df74587f | < 5.6.6 |
MEDIUM | 5.4 | The Booster plugins (Booster, Booster Plus, and Booster Elite) for WordPress are vulnerable to Cross-Site Request Forger… | — | wordfence |
EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.
Scan My Website →