Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.
40,383 vulnerabilities found (page 1097 of 1616)
| CVE ID | Plugin / Theme | Severity | CVSS | Description | Fixed In | Source |
|---|---|---|---|---|---|---|
| 15b4b132-1e27-454d-9ba0-9d1a552e1844 | < 7.3.0 |
MEDIUM | 5.4 | The BuddyPress plugin for WordPress is vulnerable to authorization bypass in versions up to, and including, 7.2.1. This … | — | wordfence |
| 15b30ecb-e3ce-4092-841b-3a1b2553596a | < 2.8.10 |
MEDIUM | 5.4 | The Enhanced Media Library plugin for WordPress is vulnerable to Stored Cross-Site Scripting via media upload functional… | — | wordfence |
| 158958ca-2e56-4102-9bcd-b235c7f49b65 | < 7.4.0 |
MEDIUM | 5.4 | The FloristPress β Customize your Woo store for your Florist plugin for WordPress is vulnerable to unauthorized modifi… | — | wordfence |
| 15477c00-0764-4850-8bce-d65b6b1cbe4c | < 3.1.2 |
MEDIUM | 5.4 | The Ziggeo plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 3.1.1. The … | — | wordfence |
| 1518653c-e64d-4aba-b7f8-a928b8f2cbe3 | MEDIUM | 5.4 | The Social Login WP plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 5… | — | wordfence | |
| 14c9dc08-6965-4a22-a97a-5afc8152887d | < 2.7.2 |
MEDIUM | 5.4 | The SportsPress plugin before 2.7.2 for WordPress allows XSS. | — | wordfence |
| 1410d37a-fa8d-41e1-bed7-1c1436b52a83 | < 2.2.4 |
MEDIUM | 5.4 | The WPSchoolPress plugin for WordPress is vulnerable to unauthorized use of functionality due to a missing capability ch… | — | wordfence |
| 13c07b63-f436-45ae-9c00-d1e593a32754 | < 2.2.0 |
MEDIUM | 5.4 | The WP 2FA β Two-factor authentication for WordPress plugin for WordPress make it possible for attackers to disable ot… | — | wordfence |
| 139d4ec2-1147-4332-a56d-633890f32560 | < 1.4.1.5 |
MEDIUM | 5.4 | The WOOCS β WooCommerce Currency Switcher plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions… | — | wordfence |
| 1398e296-9b20-4f8e-85f2-896888abc67e | < 1.2 |
MEDIUM | 5.4 | The Wordfence Theme My Login 2FA is vulnerable to 2FA brute-forcing in version up to, but excluding, 1.2. This allows un… | — | wordfence |
| 138e0a38-c922-44d1-9fe6-2439ec32cf39 | < 1.0.42.2 |
MEDIUM | 5.4 | The Rank Math SEO plugin for WordPress is vulnerable to authorization bypass due to missing access controls on its "disa… | — | wordfence |
| 136d63c4-c985-413f-8d8b-b57e11d1d230 | < 2.6.1 |
MEDIUM | 5.4 | The WPshop 2 β E-Commerce plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions 2.0.0 to … | — | wordfence |
| 133a6fe8-e011-4749-b95d-e41a03a50aab | < 2.3.2 |
MEDIUM | 5.4 | The Debug Log Manager plugin for WordPress is vulnerable to unauthorized access and modification of data due to a missin… | — | wordfence |
| 132a6661-c21b-4ba6-955a-2c905425de6a | < 1.4.5 |
MEDIUM | 5.4 | The WP Offload SES Lite WordPress plugin before 1.4.5 did not escape some of the fields in the Activity page of the admi… | — | wordfence |
| 1322e229-5e0b-4c3d-ae96-e211a2831842 | < 4.0.3 |
MEDIUM | 5.4 | The LearnPress - Export/Import Courses plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'lea… | — | wordfence |
| 12a576ee-f8a9-4740-b87b-091a46970d53 | < 2.1 |
MEDIUM | 5.4 | The WP Quick Post Duplicator plugin for WordPress is vulnerable to unauthorized access of data due to a missing capabili… | — | wordfence |
| 12643dd9-3b5e-45ea-9a64-a5b00c9202c8 | < 7.7 |
MEDIUM | 5.4 | The WP JobHunt plugin for WordPress, used by the JobCareer theme, is vulnerable to authorization bypass in all versions … | — | wordfence |
| 121022ad-a569-4a80-96ee-c7911db81a30 | < 4.7 |
MEDIUM | 5.4 | The eID Easy WordPress plugin is vulnerable to Reflected Cross-Site Scripting via the error parameter found in the ~/adm… | — | wordfence |
| 11b640a9-a031-4061-a4d2-93decd634acf | MEDIUM | 5.4 | The WP HTML Author Bio WordPress plugin through 1.2.0 does not sanitise the HTML allowed in the Bio of users, allowing t… | — | wordfence | |
| 11795557-74c0-469a-9751-adc759f9214b | MEDIUM | 5.4 | The Download canvasio3D Light plugin for WordPress is vulnerable to unauthorized access & modification of data due to a … | — | wordfence | |
| 114ea55e-a3a4-420e-9202-73ebbd95d7b4 | < 3.9.3 |
MEDIUM | 5.4 | Unvalidated input and lack of output encoding in the ThirstyAffiliates Affiliate Link Manager WordPress plugin, versions… | — | wordfence |
| 114cf149-e923-4e21-9eb0-e38941799304 | < 2.0.1 |
MEDIUM | 5.4 | The Post View Count plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2… | — | wordfence |
| 10ede689-4434-47fc-bf94-ca6da678ae01 | < 1.1.1.9 |
MEDIUM | 5.4 | The Easy Contact Form Pro plugin for WordPress is vulnerable to Stored Cross-Site Scripting did not properly sanitise th… | — | wordfence |
| 10409673-43dc-4c05-a996-120d753ebd6d | < 2.2.5 |
MEDIUM | 5.4 | The Yaad Sarig Payment Gateway For WC plugin for WordPress is vulnerable to unauthorized modification & access of data d… | — | wordfence |
| 101a3dfd-101e-4ae2-85d1-a6b3c9d6ca71 | < 2.9.8 |
MEDIUM | 5.4 | The Shortcodes and extra features for Phlox WordPress plugin before 2.9.8 does not sanitise and escape a parameter befo… | — | wordfence |
EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.
Scan My Website →