Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.
40,383 vulnerabilities found (page 1099 of 1616)
| CVE ID | Plugin / Theme | Severity | CVSS | Description | Fixed In | Source |
|---|---|---|---|---|---|---|
| 0ada25c7-a636-45cd-b2ee-984b8f676011 | < 4.8.7.2 |
MEDIUM | 5.4 | The All In One SEO Pack plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a… | — | wordfence |
| 0aa925c8-7c65-45a4-95ca-a37290d74e86 | < 4.0.1 |
MEDIUM | 5.4 | The Media Hygiene plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on several… | — | wordfence |
| 0a49d74a-01a6-4bd9-bc93-0006f9fe9503 | < 1.3.9 |
MEDIUM | 5.4 | The plugin BuddyForms Hook Fields for WordPress is vulnerable to Cross-Site Scripting in versions up to, and including, … | — | wordfence |
| 0a23e40d-9b9e-42ee-9319-c088e1024313 | < 3.7.8 |
MEDIUM | 5.4 | The Fonts plugin for WordPress is vulnerable to unauthorized access and modification of data due to a missing capability… | — | wordfence |
| 0a13e87d-51cd-43b0-a658-900a174738fc | < 3.0.3 |
MEDIUM | 5.4 | The Cliengo – Chatbot plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capabil… | — | wordfence |
| 09bdfade-85d0-4922-a83a-3e213adfa4ed | < 2.0.2 |
MEDIUM | 5.4 | The WooCommerce Product Stock Alert plugin for WordPress is vulnerable to unauthorized access of data due to a missing c… | — | wordfence |
| 095cc3dc-7a3e-473f-a762-de327c7ef28b | < 5.2.0 |
MEDIUM | 5.4 | The WordPress Slider Block Gutenslider plugin before 5.2.0 does not escape the minWidth attribute of a Gutenburg block, … | — | wordfence |
| 08c957fb-05e8-489e-846e-1afb0ca6750f | < 1.2.9 |
MEDIUM | 5.4 | The Gallery PhotoBlocks plugin for WordPress is vulnerable to authorization bypass in versions up to, and including 1.2.… | — | wordfence |
| 08c0ea6c-7e2f-482f-b30c-0e3bcd992159 | < 2.18.17 |
MEDIUM | 5.4 | The Wicked Folders plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.… | — | wordfence |
| 0897d622-8e73-4bc0-a5f9-77bf8ddb4f93 | < .51.1 |
MEDIUM | 5.4 | CVE-2014-7958: Cross-site scripting (XSS) vulnerability in admin/htaccess/bpsunlock.php in the BulletProof Security plug… | — | wordfence |
| 082b57a9-4703-4908-9119-47fc4034c35d | < 5.2 |
MEDIUM | 5.4 | The WPQA Builder Plugin WordPress plugin before 5.2, used as a companion plugin for the Discy and Himer , does not sanit… | — | wordfence |
| 0802e074-be51-4440-856f-e372e0821adb | < 2.7.0 |
MEDIUM | 5.4 | The Jeg Kit for Elementor – Powerful Elementor Addons, Widgets & Templates for WordPress plugin for WordPress is vulne… | — | wordfence |
| 07f7ef07-0f14-4b74-8d47-d5dece4954b0 | < 14.13.4 |
MEDIUM | 5.4 | The WP Statistics – The Most Popular Privacy-Friendly Analytics Plugin plugin for WordPress is vulnerable to unauthori… | — | wordfence |
| 07b6aad4-fbaf-4c0c-b2b7-6e264a1afb9b | < 1.10.0 |
MEDIUM | 5.4 | The IgnitionDeck Crowdfunding Platform plugin for WordPress is vulnerable to Missing Authorization in versions up to, an… | — | wordfence |
| 078d06ad-555b-4de4-a032-d81440c7dfb5 | < 4.0.2 |
MEDIUM | 5.4 | The Smart SEO Tool-WordPress SEO优化æ’ä»¶ plugin for WordPress is vulnerable to Cross-Site Request Forgery in version… | — | wordfence |
| 06b6c668-5f5d-4cf6-a3c6-4af755c72bca | < 1.5.4 |
MEDIUM | 5.4 | The Panda Pods Repeater Field for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'podid' parameter in… | — | wordfence |
| 06a92619-5281-414e-8846-be0db38df89d | MEDIUM | 5.4 | The Appointment Calendar plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and inc… | — | wordfence | |
| 06a7e784-49c3-44fd-882b-c76ab8d871e2 | < 20220216 |
MEDIUM | 5.4 | Cross-Site Request Forgery (CSRF) in Simple Ajax Chat (WordPress plugin) <= 20220115 allows an attacker to clear the cha… | — | wordfence |
| 067a5f6c-7ad1-49ac-a581-b50fa89a5f39 | < 4.3 |
MEDIUM | 5.4 | The Admin Columns Free WordPress plugin before 4.3 and Admin Columns Pro WordPress plugin before 5.5.1, rendered input o… | — | wordfence |
| 06752651-4c7f-48dd-989c-c254c6ca7ae4 | < 2.4.2 |
MEDIUM | 5.4 | The Pronamic Google Maps plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the description field in … | — | wordfence |
| 0615d1be-f9fa-45b3-9d5b-3ad1f36be8e1 | < 1.1.8 |
MEDIUM | 5.4 | The Wheel of Life: Coaching and Assessment Tool for Life Coach plugin for WordPress is vulnerable to unauthorized modifi… | — | wordfence |
| 060f31ab-cfa4-4ca8-846a-de76848b28fb | < 4.4 |
MEDIUM | 5.4 | The Paytium: Mollie payment forms & donations plugin for WordPress is vulnerable to unauthorized subscription cancellati… | — | wordfence |
| 05f175e6-08a9-4199-948c-5bd8b3caaa39 | < 4.6 |
MEDIUM | 5.4 | The Yoast Duplicate Post plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capabi… | — | wordfence |
| 05b15f33-0f95-458f-8c21-16c0dd98c8bc | < 2.4.6 |
MEDIUM | 5.4 | The wpForo Forum plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions … | — | wordfence |
| 0594ed62-0a41-4819-89b8-ea31afbcac73 | < 1.1.14 |
MEDIUM | 5.4 | The Booking Ultra Pro Appointments Booking Calendar Plugin plugin for WordPress is vulnerable to unauthorized modificati… | — | wordfence |
EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.
Scan My Website →