Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.
40,383 vulnerabilities found (page 1120 of 1616)
| CVE ID | Plugin / Theme | Severity | CVSS | Description | Fixed In | Source |
|---|---|---|---|---|---|---|
| de043a2e-6eb0-4eb4-8c20-4efd3fa965d8 | < 2.1.5 |
MEDIUM | 5.3 | The Razorpay Payment Links for WooCommerce plugin for WordPress is vulnerable to unauthorized access due to a missing ca… | — | wordfence |
| ddfa5a3d-fef2-4049-915c-51c3e28153bf | < 9.1.9 |
MEDIUM | 5.3 | The NEX-Forms โ Ultimate Forms Plugin for WordPress is vulnerable to unauthorized access of data due to a missing capa… | — | wordfence |
| ddf9a043-5eb6-46fd-88c2-0f5a04f73fc9 | < 4.10.1 |
MEDIUM | 5.3 | The GiveWP โ Donation Plugin and Fundraising Platform plugin for WordPress is vulnerable to unauthorized modification … | — | wordfence |
| ddb2290d-d4bd-4f70-9fe9-927f49721811 | < 6.8.2 |
MEDIUM | 5.3 | The Advanced Custom Fields (ACFยฎ) plugin for WordPress is vulnerable to authorization bypass in all versions up to, and… | — | wordfence |
| dd77f939-cd1c-4624-9a0c-d8f89a8e5221 | < 2.1.5 |
MEDIUM | 5.3 | The weDocs plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on … | — | wordfence |
| dd35a017-3b80-483d-8144-3986ea064669 | MEDIUM | 5.3 | The WC Plus plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on… | — | wordfence | |
| dd340ecc-d698-43e1-a15c-479088fb8cf4 | < 5.0 |
MEDIUM | 5.3 | The Easy Accept Payments via PayPal plugin for WordPress is vulnerable to unauthorized access due to a missing capabilit… | — | wordfence |
| dd22276b-41d4-4795-a79e-d770d0cf4b76 | < 1.3.6 |
MEDIUM | 5.3 | The WPGraphQL plugin for WordPress is vulnerable to Denial of Service via field duplication in versions up to, and inclu… | — | wordfence |
| dd090b6b-e428-4bfa-b3d0-9fb6de92cf9d | < 1.4 |
MEDIUM | 5.3 | The Easy PayPal Events & Tickets plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions up t… | — | wordfence |
| dd072774-6f85-42de-a9d4-6826703ad839 | < 1.0.271.1 |
MEDIUM | 5.3 | The Rank Math SEO โ AI SEO Tools to Dominate SEO Rankings plugin for WordPress is vulnerable to unauthorized access du… | — | wordfence |
| dcfead67-d75d-46ae-ac68-a34643ac2f52 | < 4.4.9 |
MEDIUM | 5.3 | The BuddyPress Members Only plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, … | — | wordfence |
| dcd24b90-94ff-4625-8e3e-9c90e38683f9 | < 3.30.7.1 |
MEDIUM | 5.3 | The Leyka plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and including, 3.30.7 … | — | wordfence |
| dccc2710-fdaf-40d6-ab07-51f3e8c2f382 | MEDIUM | 5.3 | The Reuters Direct plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a func… | — | wordfence | |
| dcbb6a4c-120f-43d1-8ec9-dac52186d81a | < 6.1.15 |
MEDIUM | 5.3 | The Simple File List plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 6.1… | — | wordfence |
| dcb33d02-d384-4dff-91e1-c49e86b97d6e | < 2.2.1 |
MEDIUM | 5.3 | The Flynax Bridge plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on t… | — | wordfence |
| dca7b232-db12-48a7-9f32-4451f4ced1af | < 20.8.9 |
MEDIUM | 5.3 | The Client Invoicing by Sprout Invoices plugin for WordPress is vulnerable to unauthorized access due to a missing capab… | — | wordfence |
| dca56345-0ac6-4e1a-9832-8ba428667913 | MEDIUM | 5.3 | The Top Bar plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in… | — | wordfence | |
| dc9602fb-59d0-43bb-aa13-adfc2319db8e | < 3.6.26 |
MEDIUM | 5.3 | The DirectoryPress โ Business Directory And Classified Ad Listing plugin for WordPress is vulnerable to unauthorized a… | — | wordfence |
| dc72d99b-f29b-4ac4-8228-eea2837ab457 | MEDIUM | 5.3 | The JS Job Manager plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a func… | — | wordfence | |
| dc7211fc-2c16-4080-a0b6-2090e1e4601c | < 2.0.23 |
MEDIUM | 5.3 | The Distance Based Shipping Calculator plugin for WordPress is vulnerable to unauthorized access due to a missing capabi… | — | wordfence |
| dc428f4b-fe82-419a-aee3-38f0bb582506 | < 5.8.1 |
MEDIUM | 5.3 | The WooCommerce Predictive Search plugin for WordPress is vulnerable to unauthorized modification of data due to a missi… | — | wordfence |
| dc36ee53-81a9-416e-8e74-31d9c8802d6c | < 8.5.7 |
MEDIUM | 5.3 | The WPBot โ AI ChatBot for Live Support, Lead Generation, AI Services plugin for WordPress is vulnerable to authorizat… | — | wordfence |
| dc319d4e-06d5-4fba-9f7a-2eb8c2e089f4 | < 4.0.16 |
MEDIUM | 5.3 | The WhyDonate โ FREE Donate button โ Crowdfunding โ Fundraising plugin for WordPress is vulnerable to unauthorized… | — | wordfence |
| dc18a5c4-6e63-4ad1-a90e-8337b5a86c48 | < 1.3.2 |
MEDIUM | 5.3 | The Download Attachments plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, a… | — | wordfence |
| dbf0f614-e5e9-486c-a0dd-cd494708a2a8 | MEDIUM | 5.3 | The WP Repost plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check … | — | wordfence |
EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.
Scan My Website →