Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.
40,383 vulnerabilities found (page 1109 of 1616)
| CVE ID | Plugin / Theme | Severity | CVSS | Description | Fixed In | Source |
|---|---|---|---|---|---|---|
| f188a5e6-699e-4e1a-b4e4-7fb4056b0bee | < 8.8.2 |
MEDIUM | 5.3 | The NEX-Forms β Ultimate Form Builder β Contact forms and much more plugin for WordPress is vulnerable to Sensitive … | — | wordfence |
| f162e046-a7d3-4f2c-899d-6c46cb92c8ee | < 17.3 |
MEDIUM | 5.3 | The Yoast SEO plugin for WordPress is vulnerable to Sensitive Data Exposure in versions up to, and including, 17.2 via t… | — | wordfence |
| f125a9d4-7399-47ae-9b5d-4cfe12c4c177 | < 3.0.0 |
MEDIUM | 5.3 | The Sahifa theme for WordPress is vulnerable to Full Path Disclosure in versions up to, and including, 2.4.0 via the 'ca… | — | wordfence |
| f11926c8-2b31-4ad5-9fd0-225071a91b2a | < 4.2 |
MEDIUM | 5.3 | The Login With Ajax plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on an un… | — | wordfence |
| f0e2d690-7562-438a-aa9f-d2711ddd7d2c | < 3.26.7 |
MEDIUM | 5.3 | The Wishlist Member plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check … | — | wordfence |
| f0b6c41d-833e-4ad4-bdb6-c38fef3eb7f4 | < 2.5.3 |
MEDIUM | 5.3 | The Breeze plugin for WordPress is vulnerable to Exposure of Sensitive Information to an Unauthorized Actor in all versi… | — | wordfence |
| f0a31fee-ccc2-4c3b-b198-6cb750188113 | < 1.7.24 |
MEDIUM | 5.3 | The Multi Step Form plugin for WordPress is vulnerable to unauthorized limited file upload due to a missing capability c… | — | wordfence |
| f09d7c11-3e4d-431d-91f2-0b77f51974f6 | < 1.1.4 |
MEDIUM | 5.3 | The Leadpages plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function … | — | wordfence |
| f09d722e-e4eb-4d0b-844f-3a687eb454bf | < 6.2.6 |
MEDIUM | 5.3 | The miniOrange 2FA β Two Factor Authentication for WordPress (OTP, SMS, Email, Google Authenticator) plugin for WordPr… | — | wordfence |
| f093f44e-972c-407a-ab6b-4dd8acda5b95 | MEDIUM | 5.3 | The Conditional CAPTCHA plugin for WordPress is vulnerable to Open Redirect in all versions up to, and including, 4.0.0.… | — | wordfence | |
| f06f0492-c03d-44d7-9441-4d79f89e5c1f | < 1.1 |
MEDIUM | 5.3 | The Appius theme for WordPress is vulnerable to Sensitive Data Exposure in versions up to, and including, 1.0. This coul… | — | wordfence |
| f0691a2a-734e-4726-97a1-9e0c796c2fb5 | < 3.7.40 |
MEDIUM | 5.3 | WordPress Core is vulnerable to Information Disclosure of in versions up to 6.0.3. When the post by email functionality … | — | wordfence |
| f062ef94-e558-478e-bbfd-06616aeb566b | < 3.0.0 |
MEDIUM | 5.3 | The Crypto plugin for WordPress is vulnerable to Information exposure in all versions up to, and including, 2.22. This i… | — | wordfence |
| f04dee5b-d16f-4ef0-88a4-1567e2287bd5 | < 4.12 |
MEDIUM | 5.3 | The Category Discount Woocommerce plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to… | — | wordfence |
| f04765fb-7144-4e6f-ab5a-5a06b45dbb17 | < 1.6.5 |
MEDIUM | 5.3 | The Security Optimizer β The All-In-One Protection Plugin plugin for WordPress is vulnerable to IP Allowlist Bypass in… | — | wordfence |
| f03dfbd4-b34a-46ab-b8aa-e37fb0321e8e | MEDIUM | 5.3 | The SendPress Newsletters plugin for WordPress is vulnerable to unauthorized modification of due to a missing capability… | — | wordfence | |
| f0343861-a376-43ea-826e-277c2a5ea635 | < 3.1.5 |
MEDIUM | 5.3 | The JetFormBuilder β Dynamic Blocks Form Builder plugin for WordPress is vulnerable to content injection in all versio… | — | wordfence |
| f008d502-e554-489d-bb97-fed18fa6547d | < 1.9.2 |
MEDIUM | 5.3 | The Patreon WordPress plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a f… | — | wordfence |
| f0077624-c111-468f-ae24-d730642b676c | < 14.4.0 |
MEDIUM | 5.3 | The BuddyPress plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function… | — | wordfence |
| f00763e2-f5a0-495b-949d-0012f278d4ed | MEDIUM | 5.3 | The Motors - Car Dealer, Rental & Listing WordPress theme theme for WordPress is vulnerable to unauthorized access due t… | — | wordfence | |
| eff4cb35-492b-448a-8d16-b9210917c567 | < 2.8 |
MEDIUM | 5.3 | The WP Simple HTML Sitemap plugin for WordPress is vulnerable to unauthorized access due to a missing capability check o… | — | wordfence |
| efe7c5d6-80ee-4214-b179-805df79ce1fc | < 1.12.19 |
MEDIUM | 5.3 | The Giveaways and Contests by RafflePress β Get More Website Traffic, Email Subscribers, and Social Followers plugin f… | — | wordfence |
| efe4223a-5c1a-401e-a46b-0278e96d2d71 | < 4.5.0 |
MEDIUM | 5.3 | The KiviCare β Clinic & Patient Management System (EHR) plugin for WordPress is vulnerable to authorization bypass in … | — | wordfence |
| efc53d78-a664-48d0-a752-00c56b3f792f | MEDIUM | 5.3 | The No CAPTCHA reCAPTCHA for WooCommerce plugin for WordPress is vulnerable to unauthorized modification of data due to … | — | wordfence | |
| efb6fc8e-5eed-4751-881f-0600c817ba6a | < 2.0.1 |
MEDIUM | 5.3 | The Simple GDPR Cookie Compliance plugin for WordPress is vulnerable to unauthorized access due to a missing capability … | — | wordfence |
EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.
Scan My Website →