Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.
40,383 vulnerabilities found (page 1100 of 1616)
| CVE ID | Plugin / Theme | Severity | CVSS | Description | Fixed In | Source |
|---|---|---|---|---|---|---|
| 053b72c6-07bb-4e9f-ae25-da4bce91ae6e | < 2.0.26 |
MEDIUM | 5.4 | The Simple SEO plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.0.25… | — | wordfence |
| 04a79a78-a6d3-40ef-9b26-8e2e00534b7a | < 4.2.9 |
MEDIUM | 5.4 | The ChatBot plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 4.2.8. Th… | — | wordfence |
| 0488a421-e725-4b64-94ee-3a81f4bc5451 | < 3.8.8 |
MEDIUM | 5.4 | The App Builder β Create Native Android & iOS Apps On The Flight plugin for WordPress is vulnerable to Open Redirect i… | — | wordfence |
| 0482d9c6-aa74-4d47-885c-17f14b38be6f | < 2.3.4 |
MEDIUM | 5.4 | The Request a Quote WordPress plugin before 2.3.4 did not sanitise and escape some of its quote fields when adding/editi… | — | wordfence |
| 04708871-a8eb-4afe-981f-aab965f6ea16 | MEDIUM | 5.4 | The Metrika plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.2. … | — | wordfence | |
| 04601634-d707-44a7-9b5f-46c4b9687469 | < 7.2.1 |
MEDIUM | 5.4 | The BuddyPress plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the buddy… | — | wordfence |
| 040005bc-bdc3-4085-8192-cd0a7e38fee0 | MEDIUM | 5.4 | The WP Bootstrap Gallery plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on… | — | wordfence | |
| 03eed366-c018-44b9-bb72-56911e9957b8 | < 1.4.6 |
MEDIUM | 5.4 | The Robots.txt optimization plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and incl… | — | wordfence |
| 0388853e-4bf8-4627-876a-b842e7016de3 | < 8.9.1 |
MEDIUM | 5.4 | The MonsterInsights plugin for WordPress is vulnerable to Stored Cross-Site Scripting via post titles and pages in versi… | — | wordfence |
| 036cf299-80c2-48a8-befc-02899ab96e3c | < 2.7.15 |
MEDIUM | 5.4 | The PowerPack Addons for Elementor (Free Widgets, Extensions and Templates) plugin for WordPress is vulnerable to Stored… | — | wordfence |
| 031c31b2-6e27-47bb-9f63-2bbaa1edbbb2 | < 11.0.7 |
MEDIUM | 5.4 | The PowerPress plugin for WordPress is vulnerable to Server-Side Request Forgery in versions up to, and including, 11.0.… | — | wordfence |
| 02649a9e-036a-47fe-ab1a-26caf4f2be27 | < 5.5.5 |
MEDIUM | 5.4 | The Formidable Form Builder plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and incl… | — | wordfence |
| 0254cd1b-f8f6-400e-a48e-81bd553fe8d1 | < 1.2.6 |
MEDIUM | 5.4 | The Broken Link Checker by AIOSEO β Easily Fix/Monitor Internal and External links plugin for WordPress is vulnerable … | — | wordfence |
| 01f60df7-0602-4a00-9905-a91348811dfe | < 3.4.5 |
MEDIUM | 5.4 | The Popup box plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'ays_pb_tab' parameter in ver… | — | wordfence |
| 01dfb46a-5721-415f-8a92-e874c46b8e47 | < 2.2.0 |
MEDIUM | 5.4 | The April's Call Posts plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and … | — | wordfence |
| 01cfd7db-f62d-4110-b9a4-49ff1e4e5e68 | < 5.0.4 |
MEDIUM | 5.4 | The ProfileGrid β User Profiles, Memberships, Groups and Communities plugin for WordPress is vulnerable to authorizati… | — | wordfence |
| 019f4735-a25c-46c7-8a7d-55351197bdf2 | < 2.2.0.7 |
MEDIUM | 5.4 | The Easing Slider plugin for WordPress is vulnerable to Cross-Site Scripting in versions up to, and including, 2.2.0.6 v… | — | wordfence |
| 01889c7b-f47b-4caf-8e35-4f8af188426e | < 4.1.1 |
MEDIUM | 5.4 | The Smash Balloon Social Post Feed WordPress plugin before 4.1.1 was affected by a reflected XSS in custom-facebook-feed… | — | wordfence |
| 0131921b-6f60-4da1-b5d9-d44a33d35cae | < 2.0.1 |
MEDIUM | 5.4 | The JS Job Manager plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.… | — | wordfence |
| 012e019f-9146-45bc-b4d7-aa724dbebdc6 | < 2.2.3 |
MEDIUM | 5.4 | The Visual Link Preview WordPress plugin before 2.2.3 does not enforce authorisation on several AJAX actions and has the… | — | wordfence |
| 00d69e80-36fa-4b74-8138-56c0bf576e44 | < 2.0.7 |
MEDIUM | 5.4 | The WP Maintenance Mode plugin before 2.0.7 for WordPress allows remote authenticated subscriber users to bypass intende… | — | wordfence |
| 00cb5ce9-cca2-4e41-8d00-1d2ca7770dce | < 1.5.63 |
MEDIUM | 5.4 | The users-ultra plugin before 1.5.63 for WordPress has XSS via the p_name parameter. | — | wordfence |
| 007af51b-95b5-4b12-9f74-abf31f6de341 | < 3.3.5 |
MEDIUM | 5.4 | The Real Estate 7 theme for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 3.3.… | — | wordfence |
| ffe32701-4cfe-42f1-bf00-8de653d6568a | < 1.5.0 |
MEDIUM | 5.3 | The Ultimate Maps by Supsystic plugin for WordPress is vulnerable to unauthorized access in all versions up to 1.5.0. Th… | — | wordfence |
| ffdb95ac-6b22-44a9-bd5c-b802a2d908d7 | < 4.10.1 |
MEDIUM | 5.3 | The YITH WooCommerce Wishlist plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up … | — | wordfence |
EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.
Scan My Website →