Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.
40,383 vulnerabilities found (page 1098 of 1616)
| CVE ID | Plugin / Theme | Severity | CVSS | Description | Fixed In | Source |
|---|---|---|---|---|---|---|
| 0f01ee24-544b-45cb-9cf3-7db8263d8e54 | < 1.2.0 |
MEDIUM | 5.4 | The WP Directory Kit plugin for WordPress is vulnerable to Open Redirect in versions up to, and including, 1.1.9. This i… | — | wordfence |
| 0e7e7c70-4d07-4550-9cf8-5135b87b67ca | < 2.2.97 |
MEDIUM | 5.4 | The Accordion plugin for WordPress is vulnerable to unauthorized access of data and modification of data due to a missin… | — | wordfence |
| 0e4fec06-13d3-49ce-afe5-8dca15cf1f0a | < 2.5.15 |
MEDIUM | 5.4 | The Custom Field Suite plugin before 2.5.15 for WordPress has XSS for editors or admins. | — | wordfence |
| 0e475e02-494a-4ad0-a83c-d027c3a32989 | < 3.9.5 |
MEDIUM | 5.4 | The Tutor LMS β eLearning and online course solution plugin for WordPress is vulnerable to unauthorized attachment del… | — | wordfence |
| 0e240f4b-dfdf-4954-af39-34e24a05a2ed | < 5.22.3 |
MEDIUM | 5.4 | The Modern Events Calendar Lite WordPress plugin before 5.22.3 does not properly sanitize or escape values set by users … | — | wordfence |
| 0e05142e-04a3-483e-a4af-035df3609b9d | < 1.2.7.2 |
MEDIUM | 5.4 | The Chained Quiz WordPress plugin before 1.2.7.2 does not properly sanitize or escape inputs in the plugin's settings. | — | wordfence |
| 0dfe0947-5790-49ba-aa3d-6bc61c12b355 | < 1.4.0 |
MEDIUM | 5.4 | The BuddyTask plugin for WordPress is vulnerable to unauthorized access and modification of data due to a missing capabi… | — | wordfence |
| 0dc20a45-15b5-42d3-a484-988a394ee658 | < 2.17 |
MEDIUM | 5.4 | A flaw in the WordPress plugin, Minimal Coming Soon & Maintenance Mode through 2.15, allows authenticated users with bas… | — | wordfence |
| 0dbed7a2-730d-42f2-9d57-3f07900d33e3 | < 1.4 |
MEDIUM | 5.4 | The Video Player for YouTube WordPress plugin before 1.4 does not sanitise or validate the parameters from its shortcode… | — | wordfence |
| 0da6a080-260f-4b19-a32c-453d2781389a | < 8.3.5 |
MEDIUM | 5.4 | The Element Pack Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Open Str… | — | wordfence |
| 0d9cea4e-b619-4935-bb7c-a64ddf52d480 | < 7.0.18 |
MEDIUM | 5.4 | The Stylish Price List plugin for WordPress is vulnerable to unauthorized modification and loss of data due to a missing… | — | wordfence |
| 0d943691-66cf-4018-9eb6-5f20db0a95a9 | < 3.4 |
MEDIUM | 5.4 | The formcraft3 plugin before 3.4 for WordPress has stored XSS via the "New Form > Heading > Heading Text" field. | — | wordfence |
| 0d20bae1-5a94-402b-9001-725b433c9d55 | < 1.6.7 |
MEDIUM | 5.4 | The Advanced Booking Calendar WordPress plugin before 1.6.7 did not sanitise the calId GET parameter in the "Seasons & C… | — | wordfence |
| 0d017b2c-1e15-401a-ae57-4653ca41b7e6 | < 4.0.2 |
MEDIUM | 5.4 | The MainWP Buddy Extension plugin for WordPress is vulnerable to authorization bypass in versions up to, and including 4… | — | wordfence |
| 0cde6b5b-f760-467b-940f-06a1f983ddc4 | < 3.4.1 |
MEDIUM | 5.4 | A Stored Cross-Site Scripting vulnerability was discovered in the Yoast SEO WordPress plugin before 3.4.1, which had bui… | — | wordfence |
| 0cd72420-dca1-455d-92a6-a178b4b26eab | < 3.5.26 |
MEDIUM | 5.4 | The ConvertPlug plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability chec… | — | wordfence |
| 0cd6474f-72e1-4ec2-a056-3c05a0dfa173 | < 4.8.9 |
MEDIUM | 5.4 | The Newsletters plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 4.8.8… | — | wordfence |
| 0ccf1582-7d3d-4ca0-b241-d6deaa79a994 | MEDIUM | 5.4 | The Qubely plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in … | — | wordfence | |
| 0ca9e920-3c7a-4991-8c24-2e55c4f4767c | < 1.4.6 |
MEDIUM | 5.4 | The Motors β Car Dealer & Classified Ads plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions … | — | wordfence |
| 0c829230-7527-4ae2-a5c8-db2371e4cd5a | < 3.8 |
MEDIUM | 5.4 | The Amministrazione Aperta WordPress plugin through 3.7.3 does not validate the open parameter before using it in an inc… | — | wordfence |
| 0c173356-7228-4253-bb28-2c2e11af76fd | < 3.9.8 |
MEDIUM | 5.4 | The Tutor LMS β eLearning and online course solution plugin for WordPress is vulnerable to unauthorized private course… | — | wordfence |
| 0be428ae-40ae-4cc0-82ad-d121b6d2d27e | < 2.18.17 |
MEDIUM | 5.4 | The Wicked Folders plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the a… | — | wordfence |
| 0afcfe15-2d7d-4c96-a408-28f35577a927 | < 3.6.10 |
MEDIUM | 5.4 | The Image Photo Gallery Final Tiles Grid plugin for WordPress is vulnerable to unauthorized access and modification of d… | — | wordfence |
| 0af6e55d-def9-4bb1-ade9-56aa8184961c | < 6.0.1 |
MEDIUM | 5.4 | The Booster plugins (Booster, Booster Plus, and Booster Elite) for WordPress are vulnerable to Cross-Site Request Forger… | — | wordfence |
| 0aeb63e7-a24d-4d76-a8c7-f082dad87a55 | < 2.0.9 |
MEDIUM | 5.4 | The Themify Shortcodes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'themify_post_… | — | wordfence |
EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.
Scan My Website →