Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.
40,383 vulnerabilities found (page 1108 of 1616)
| CVE ID | Plugin / Theme | Severity | CVSS | Description | Fixed In | Source |
|---|---|---|---|---|---|---|
| f33bcc8d-3d21-4de8-87ac-a5e334bb641d | < 2.0.1 |
MEDIUM | 5.3 | The WPGraphQL Smart Cache plugin for WordPress is vulnerable to Information Exposure in all versions up to 2.0.1 (exclus… | — | wordfence |
| f3341c29-a69e-4618-a8a5-11f4141ff88f | MEDIUM | 5.3 | The Feedback Modal for Website plugin for WordPress is vulnerable to unauthorized access of data due to a missing capabi… | — | wordfence | |
| f32ae42d-dd1f-41d7-8ae4-ddec56d78ae6 | < 3.9.9 |
MEDIUM | 5.3 | The Tutor LMS β eLearning and online course solution plugin for WordPress is vulnerable to unauthorized course content… | — | wordfence |
| f30af3c4-82be-40d5-be9f-82631b8f3ee2 | < 1.0.8 |
MEDIUM | 5.3 | The Simple History plugin for WordPress is vulnerable to Sensitive Data Exposure in versions up to, and including, 1.0.7… | — | wordfence |
| f30810d4-415c-4001-919d-eac753715474 | < 4.3.4 |
MEDIUM | 5.3 | The Estatik Real Estate Plugin plugin for WordPress is vulnerable to mail relay in all versions up to 4.3.4 (exclusive).… | — | wordfence |
| f304b0c2-ddea-4638-8a0b-c1483c944d30 | < 1.1.3 |
MEDIUM | 5.3 | The Majestic Support plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a fu… | — | wordfence |
| f2e8062a-d185-4834-a8cf-1f505ee2e91e | < 1.5.6.3 |
MEDIUM | 5.3 | The LA-Studio Element Kit for Elementor plugin for WordPress is vulnerable to unauthorized access due to a missing capab… | — | wordfence |
| f2d69d59-390d-4f3c-96ba-487707cac7a6 | < 6.9.5 |
MEDIUM | 5.3 | The WP Visitor Statistics (Real Time Traffic) plugin for WordPress is vulnerable to Sensitive Information Exposure in al… | — | wordfence |
| f2c70d5f-beb3-480e-8ea8-c3ab01ce5a20 | MEDIUM | 5.3 | The OneStore Sites plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and includin… | — | wordfence | |
| f2c3b646-d865-4425-bc8f-00b3555a3d74 | < 8.5.7 |
MEDIUM | 5.3 | The NEX-Forms β Ultimate Form Builder β Contact forms and much more plugin for WordPress is vulnerable to unauthoriz… | — | wordfence |
| f2bcaff9-bf04-4d8e-9422-c433264067ff | < 4.0.25 |
MEDIUM | 5.3 | The Event Manager, Events Calendar, Tickets, Registrations β Eventin plugin for WordPress is vulnerable to unauthorize… | — | wordfence |
| f2aa33cc-c1c4-42d4-9c2f-54648426ee4b | < 11.1.1 |
MEDIUM | 5.3 | The Quiz And Survey Master plugin for WordPress is vulnerable to Arbitrary Shortcode Execution in versions up to and inc… | — | wordfence |
| f28d7659-9244-4da8-97e9-4539d7d874f7 | < 1.0.72 |
MEDIUM | 5.3 | The Polls CP plugin for WordPress is vulnerable to content injection in all versions up to, and including, 1.0.71. This … | — | wordfence |
| f28c47e6-a37d-4328-afb2-6a9e6b3fe20a | MEDIUM | 5.3 | The Under Construction / Maintenance Mode from Acurax plugin for WordPress is vulnerable to Sensitive Information Exposu… | — | wordfence | |
| f2856011-0080-4786-9ef0-14f323d54962 | MEDIUM | 5.3 | The Sandwich Adsense plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a fu… | — | wordfence | |
| f26b0dc2-2b24-46e6-a7e8-f87e970df042 | < 1.4.1 |
MEDIUM | 5.3 | The WP Directory Kit plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a fu… | — | wordfence |
| f265955d-a209-4193-9fb8-962b1b562249 | < 5.4 |
MEDIUM | 5.3 | The Apptivo Business Site CRM plugin for WordPress is vulnerable to unauthorized access due to a missing capability chec… | — | wordfence |
| f25dcd7e-8fb1-471e-bd22-782409de45c4 | < 1.17.2 |
MEDIUM | 5.3 | The Total Upkeep β WordPress Backup Plugin plus Restore & Migrate by BoldGrid plugin for WordPress is vulnerable to un… | — | wordfence |
| f25d0409-dbca-4c5a-9f43-fc03e5307d0f | < 1.5.1.3 |
MEDIUM | 5.3 | wp-login.php in WordPress 1.5.1.2 and earlier allows remote attackers to change the content of the forgotten password e-… | — | wordfence |
| f23bb22c-2f7b-4940-b0bc-1e5f2b8d0ed2 | < 1.0.1 |
MEDIUM | 5.3 | The Byteflows Travel & Hotel Booking plugin for WordPress is vulnerable to Sensitive Information Exposure in all version… | — | wordfence |
| f23ba80e-94d7-40a1-beb8-da9ec0c9f7d7 | < 2.4.5 |
MEDIUM | 5.3 | The EventON β Events Calendar plugin for WordPress is vulnerable to unauthorized access due to a missing capability ch… | — | wordfence |
| f2122fa2-0500-4c4e-aec5-eb440e8cc585 | < 5.5.79 |
MEDIUM | 5.3 | The Data Access plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a functio… | — | wordfence |
| f1fa1999-685c-4b68-927d-617abf9143d7 | < 2.9.1 |
MEDIUM | 5.3 | The Premium Addons PRO plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and inclu… | — | wordfence |
| f1e5438f-1309-4d39-a9b4-cda27b652d93 | < 2.0.8 |
MEDIUM | 5.3 | The E-cab Taxi Booking Manager for Woocommerce plugin for WordPress is vulnerable to unauthorized access in all versions… | — | wordfence |
| f1ad41b4-c97b-4b3d-a82d-b39570ffe82f | < 1.0.25 |
MEDIUM | 5.3 | The Agency Toolkit plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a func… | — | wordfence |
EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.
Scan My Website →