Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.
40,383 vulnerabilities found (page 1104 of 1616)
| CVE ID | Plugin / Theme | Severity | CVSS | Description | Fixed In | Source |
|---|---|---|---|---|---|---|
| f9f3250f-39a1-4ba1-b9a2-222926635ca0 | MEDIUM | 5.3 | The Reales WP STPT plugin for WordPress is vulnerable to unauthorized user registration in all versions up to, and inclu… | — | wordfence | |
| f9d11597-0bea-4f58-9dac-b4b82d07c2f6 | < 4.4.0 |
MEDIUM | 5.3 | The KiviCare β Clinic & Patient Management System (EHR) plugin for WordPress is vulnerable to unauthorized access due … | — | wordfence |
| f9cff7c4-7dc0-440b-bb1c-1087144d1ccf | < 1.1.1 |
MEDIUM | 5.3 | The Majestic Support β The Leading-Edge Help Desk & Customer Support Plugin plugin for WordPress is vulnerable to unau… | — | wordfence |
| f9be7798-31ac-4692-a6ac-ae7f129bcd6d | < 3.7.3 |
MEDIUM | 5.3 | The Premmerce Product Filter for WooCommerce plugin for WordPress is vulnerable to unauthorized access due to a missing … | — | wordfence |
| f9af0471-adb0-42c6-8a7b-da7d28e5e3aa | < 2.2.1 |
MEDIUM | 5.3 | The weDocs plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in … | — | wordfence |
| f989558e-8ba5-4c8e-b099-e919ebe966ac | < 1.1.5 |
MEDIUM | 5.3 | The One to one user Chat by WPGuppy plugin for WordPress is vulnerable to unauthorized access due to a missing capabilit… | — | wordfence |
| f9611732-67aa-4940-8df1-c0ed7baad985 | < 3.2.50 |
MEDIUM | 5.3 | The Download Manager plugin for WordPress is vulnerable to IP Blocking Bypass in versions up to, and including, 3.2.49 d… | — | wordfence |
| f9575875-0f0f-4069-87d1-9ed573a7c3d7 | < 5.3.2 |
MEDIUM | 5.3 | The Advanced File Manager plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capab… | — | wordfence |
| f9566fdd-c4ad-4971-b23b-bcf76c8b5cef | < 2.0.3 |
MEDIUM | 5.3 | The WaMate Confirm β Order Confirmation plugin for WordPress is vulnerable to unauthorized access in all versions up t… | — | wordfence |
| f8ddb7df-7f74-486d-a55f-9e2d1e91f112 | < 1.6.2 |
MEDIUM | 5.3 | The SearchWP Live Ajax Search plugin for WordPress is vulnerable to arbitrary post title disclosure in versions up to, … | — | wordfence |
| f8cd9f1a-84e5-432f-a07d-f5941b8d9dda | < 7.1.2 |
MEDIUM | 5.3 | The Print Invoice & Delivery Notes for WooCommerce plugin for WordPress is vulnerable to Sensitive Information Exposure … | — | wordfence |
| f894ce75-168c-4baa-8cae-d2e7f1a0a9ab | < 6.4.21 |
MEDIUM | 5.3 | The Business Directory Plugin for WordPress is vulnerable to authorization bypass due to a missing authorization check i… | — | wordfence |
| f889342e-03fb-44eb-b5cb-acf115a526c3 | < 1.1.3 |
MEDIUM | 5.3 | The Sight β Professional Image Gallery and Portfolio plugin for WordPress is vulnerable to unauthorized access of data… | — | wordfence |
| f87efb65-b53b-4e9c-b933-9303461487a3 | < 3.2.4 |
MEDIUM | 5.3 | The Booking calendar, Appointment Booking System plugin for WordPress is vulnerable to a bypass in all versions up to, a… | — | wordfence |
| f86602f7-8e19-4728-b614-263c36bda565 | MEDIUM | 5.3 | The InWave Jobs plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a functio… | — | wordfence | |
| f8650a2e-346f-45fb-b5f5-ee99a470b2fc | < 1.9.4 |
MEDIUM | 5.3 | The Jetpack plugin before 1.9 before 1.9.4, 2.0.x before 2.0.9, 2.1.x before 2.1.4, 2.2.x before 2.2.7, 2.3.x before 2.3… | — | wordfence |
| f85478c4-ea66-4bca-b501-2e55425396f7 | < 4.16.3 |
MEDIUM | 5.3 | The GiveWP β Donation Plugin and Fundraising Platform plugin for WordPress is vulnerable to Payment Bypass in all vers… | — | wordfence |
| f84ddc83-2079-45b9-8354-51094581b1f8 | < 4.3.9 |
MEDIUM | 5.3 | The miniOrange OTP Verification and SMS Notification for WooCommerce plugin for WordPress is vulnerable to unauthorized … | — | wordfence |
| f8457aeb-867b-4185-8271-a5452b7c5365 | < 3.0.11 |
MEDIUM | 5.3 | The Animator plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check o… | — | wordfence |
| f83a6631-ff6c-422e-8b6c-49576fadb89f | < 2.6.8 |
MEDIUM | 5.3 | The WP Project Manager plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on an… | — | wordfence |
| f82aca0a-a75f-4766-a808-004d13c77bac | < 1.4.110 |
MEDIUM | 5.3 | The Motors β Car Dealership & Classified Listings Plugin plugin for WordPress is vulnerable to unauthorized access due… | — | wordfence |
| f823ad14-754e-4fed-b991-6ee8594c7f86 | < 1.7.4 |
MEDIUM | 5.3 | The File Uploads Addon for WooCommerce plugin for WordPress is vulnerable to unauthorized access due to a missing capabi… | — | wordfence |
| f81d7451-352b-446e-965b-9b51031844ed | < 1.2.1 |
MEDIUM | 5.3 | The Opal Woo Custom Product Variation plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient … | — | wordfence |
| f810cc65-5a19-4ad7-a6b6-41a9b4f30f4c | < 3.6 |
MEDIUM | 5.3 | The affiliate-toolkit β WordPress Affiliate Plugin plugin for WordPress is vulnerable to Full Path Disclosure in all v… | — | wordfence |
| f80fa8b3-f345-4b3f-8a16-ee9f19b07a0b | < 5.1.4 |
MEDIUM | 5.3 | The SchedulePress β Auto Post & Publish, Auto Social Share, Schedule Posts with Editorial Calendar & Missed Schedule P… | — | wordfence |
EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.
Scan My Website →