Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.
40,383 vulnerabilities found (page 1095 of 1616)
| CVE ID | Plugin / Theme | Severity | CVSS | Description | Fixed In | Source |
|---|---|---|---|---|---|---|
| 21b6748a-43fb-4326-ac1f-d3ae2a6700f2 | MEDIUM | 5.4 | The Slippy Slider β Responsive Touch Navigation Slider plugin for WordPress is vulnerable to Stored Cross-Site Scripti… | — | wordfence | |
| 200baebd-7fd1-4df6-99ab-71f999b4e85a | < 1.0.13 |
MEDIUM | 5.4 | The Bosa Elementor Addons and Templates for WooCommerce plugin for WordPress is vulnerable to unauthorized access of dat… | — | wordfence |
| 1fc447bc-841c-443f-9949-a0d852762fd9 | < 3.12.4 |
MEDIUM | 5.4 | The Happy Addons for Elementor plugin for WordPress is vulnerable to unauthorized access of data due to a missing capabi… | — | wordfence |
| 1fc3f65e-5fbe-403b-b7cd-dde16a7e5778 | < 4.1.39 |
MEDIUM | 5.4 | WordPress Core is vulnerable to arbitrary shortcode execution in versions up to, and including, 6.3.1 due to a lack of i… | — | wordfence |
| 1f9b02c1-2cd7-48ee-b568-4c42bc0ded96 | < 3.5 |
MEDIUM | 5.4 | A cross-site scripting (XSS) attack can cause arbitrary code (JavaScript) to run in a user's browser and can use an appl… | — | wordfence |
| 1f8f8378-676e-455a-aaad-b80c1a4dc717 | < 2.4.2 |
MEDIUM | 5.4 | The Brizy WordPress plugin before 2.4.2 does not sanitise and escape some element URL, which could allow users with a ro… | — | wordfence |
| 1f7e9eb5-e222-43fa-a14f-b9cbced6b8f5 | < 6.3.5 |
MEDIUM | 5.4 | The ShortPixel Image Optimizer β Optimize Images, Convert WebP & AVIF plugin for WordPress is vulnerable to unauthoriz… | — | wordfence |
| 1f545c20-5be1-42bc-9268-640590ee4bf2 | MEDIUM | 5.4 | The WordPress Mobile Pack plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and includ… | — | wordfence | |
| 1f528c89-2b8c-4750-b9eb-47ebd8c1630e | < 2.6.5 |
MEDIUM | 5.4 | The Kubio AI Page Builder plugin for WordPress is vulnerable to unauthorized plugin installation due to a missing capabi… | — | wordfence |
| 1f4bd246-5632-4701-aa57-3855e73e6eb6 | < 2.0.6 |
MEDIUM | 5.4 | Multiple Cross-Site Request Forgery (CSRF) vulnerabilities in WordPress uListing plugin (versions <= 2.0.5) as it lacks … | — | wordfence |
| 1ededa54-654f-48dc-87d5-7321e041e6fb | MEDIUM | 5.4 | The Whizzy plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, … | — | wordfence | |
| 1ebb6ebe-3a66-4ad8-9bba-c09354810159 | < 2.1.0 |
MEDIUM | 5.4 | The Portfolio Gallery, Product Catalog WordPress plugin before 2.1.0 does not have authorisation and CSRF checks in vari… | — | wordfence |
| 1e6c1e98-72a2-4e74-bfd4-4054187d4d19 | < 6.2.1 |
MEDIUM | 5.4 | The WooCommerce plugin for WordPress is vulnerable to authorization bypass due to an insufficient capability check on th… | — | wordfence |
| 1dffbb2d-69d1-495c-8c96-64c5fd878fcd | < 2.9.12 |
MEDIUM | 5.4 | The Stock Quotes List plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode in ve… | — | wordfence |
| 1de6c0d9-efa8-4c86-9d57-7aa92a0eda96 | < 3.0.5 |
MEDIUM | 5.4 | The Cliengo β Chatbot plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and incl… | — | wordfence |
| 1d5d2217-306c-4ea2-9727-5c02f7d67c2d | < 1.1.11 |
MEDIUM | 5.4 | The Cart All In One For WooCommerce plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, … | — | wordfence |
| 1cf2739f-9001-409a-9b7f-024931729da3 | < 3.9.11 |
MEDIUM | 5.4 | The Simple Download Monitor WordPress plugin before 3.9.11 could allow users with a role as low as Contributor to perfor… | — | wordfence |
| 1c866d8d-399c-4bda-a3c9-17c7e5d2ffb8 | < 3.3.1 |
MEDIUM | 5.4 | The Metform Elementor Contact Form Builder for WordPress is vulnerable to Cross-Site Scripting by using the 'mf' shortco… | — | wordfence |
| 1c8152c5-7d72-48a1-9140-8b0341c86023 | < 3.5.1 |
MEDIUM | 5.4 | The Wbcom Designs β BuddyPress Activity Social Share plugin for WordPress is vulnerable to Cross-Site Request Forgery … | — | wordfence |
| 1c75edd2-fc38-48b1-b58c-1d19c95c3db8 | MEDIUM | 5.4 | The WP Forms Puzzle Captcha plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and incl… | — | wordfence | |
| 1c6a1956-73aa-4ac3-ae1c-ef5f62bad718 | MEDIUM | 5.4 | The Simple Ecommerce Shopping Cart Plugin- Sell products through Paypal plugin for WordPress is vulnerable to unauthoriz… | — | wordfence | |
| 1c5108f3-d80c-4646-8d40-3bdd1361c6ab | < 1.4.6 |
MEDIUM | 5.4 | The Accordion and Accordion Slider plugin for WordPress is vulnerable to authorization bypass in all versions up to, and… | — | wordfence |
| 1c40c28f-554f-42d0-9f6d-a899d8f61519 | < 10.0.2 |
MEDIUM | 5.4 | The PowerPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in versio… | — | wordfence |
| 1c387b07-baf6-4c62-943e-4bd121160ceb | < 1.7.25 |
MEDIUM | 5.4 | The Contact Form by Supsystic plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and in… | — | wordfence |
| 1b660260-e335-4be0-a266-0cdc9a4d7504 | < 1.7.8 |
MEDIUM | 5.4 | The Qubely WordPress plugin before 1.7.8 does not have authorisation and CSRF check on the qubely_delete_saved_block AJA… | — | wordfence |
EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.
Scan My Website →