Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.
40,383 vulnerabilities found (page 1125 of 1616)
| CVE ID | Plugin / Theme | Severity | CVSS | Description | Fixed In | Source |
|---|---|---|---|---|---|---|
| d42bf247-413b-4458-84f3-f503c7af907d | < 1.0.33 |
MEDIUM | 5.3 | The Secure Card Gateway for ePay Paycenter (Piraeus Bank) plugin for WordPress is vulnerable to unauthorized access due … | — | wordfence |
| d41f506a-b243-41e2-a67e-697fc34fba2e | < 2.5.4.1 |
MEDIUM | 5.3 | The Bookit β Booking & Appointment Calendar plugin for WordPress is vulnerable to unauthorized access due to a missing… | — | wordfence |
| d3f3fc78-0255-4c0a-8ee0-c2ccea28929f | < 1.0.13 |
MEDIUM | 5.3 | The Chama plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in v… | — | wordfence |
| d3e194c0-b35a-496b-b31a-666334312f20 | < 1.4.2 |
MEDIUM | 5.3 | The Paid Memberships Pro β Payfast Gateway Add On plugin for WordPress is vulnerable to Sensitive Information Exposure… | — | wordfence |
| d3adb4ba-cabd-4b16-bda6-5d5fc7582d5f | < 2.1.2 |
MEDIUM | 5.3 | The Wbcom Designs β Private Community for BuddyPress plugin for WordPress is vulnerable to unauthorized access due to … | — | wordfence |
| d3aa1f74-6372-4abe-894b-07ad3e81ea81 | MEDIUM | 5.3 | The Bulk Order Update for WooCommerce plugin for WordPress is vulnerable to Arbitrary File Read in versions up to, and i… | — | wordfence | |
| d39ec46d-58c4-40e4-b94a-e7a9fc99291a | < 3.7.1 |
MEDIUM | 5.3 | The WCFM Marketplace β Multivendor Marketplace for WooCommerce plugin for WordPress is vulnerable to Insecure Direct O… | — | wordfence |
| d396e47a-cabe-4498-9269-d67bdeb0c570 | < 1.1.4.6 |
MEDIUM | 5.3 | The OptinMonster plugin for WordPress is vulnerable to Remote Code Execution in versions up to, and including, 1.1.4.5 v… | — | wordfence |
| d390186e-b6a3-4c9c-8065-2ac4fff9be37 | < 6.0.12 |
MEDIUM | 5.3 | The Kirki plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in v… | — | wordfence |
| d38fd7d0-0d04-4d60-bb5b-7a68758df83c | < 2.4.1 |
MEDIUM | 5.3 | The GTM Kit β Google Tag Manager & GA4 integration plugin for WordPress is vulnerable to Sensitive Information Exposur… | — | wordfence |
| d36e869a-5bd4-4f59-8e28-01fa586024c5 | < 2.2.22 |
MEDIUM | 5.3 | The Super Progressive Web Apps plugin for WordPress is vulnerable to unauthorized modification of data due to a missing … | — | wordfence |
| d35faf39-4882-4393-9b77-57dc45ac9d04 | < 4.7.0 |
MEDIUM | 5.3 | The Popup and Slider Builder by Depicter β Add Email collecting Popup, Popup Modal, Coupon Popup, Image Slider, Carous… | — | wordfence |
| d34ba8b3-e8a8-4810-a0d9-8781bc7d1201 | < 2.0.1 |
MEDIUM | 5.3 | The Post/Page Copying Tool to Export and Import post/page for Cross site Migration plugin for WordPress is vulnerable t… | — | wordfence |
| d34701a0-c745-441c-8d6c-7befc877f8d0 | < 1.7.2 |
MEDIUM | 5.3 | The Hippoo Mobile App for WooCommerce plugin for WordPress is vulnerable to arbitrary file write via a missing authoriza… | — | wordfence |
| d3457b87-c860-4cf2-ac3d-2c6521b629ea | < 1.3.88 |
MEDIUM | 5.3 | The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to unauthorized post metadata update due to … | — | wordfence |
| d33b83d5-cfc0-48b6-a54e-1ae8ac52aae1 | < 1.0.8 |
MEDIUM | 5.3 | The Voidek Employee Portal plugin for WordPress is vulnerable to unauthorized access due to a missing capability check o… | — | wordfence |
| d3184996-655c-41d5-a3c5-6b36fbff58dc | < 6.4.6.1 |
MEDIUM | 5.3 | The PeepSo Core: File Uploads plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up … | — | wordfence |
| d317f2c7-06f3-4875-9f9b-eb7f450aa2f4 | < 2.0.5 |
MEDIUM | 5.3 | The Getwid β Gutenberg Blocks plugin for WordPress is vulnerable to CAPTCHA Bypass in versions up to, and including, 2… | — | wordfence |
| d3103345-ce26-4bb1-898f-764ab6cf0ea0 | < 24.7.0 |
MEDIUM | 5.3 | The WooCommerce Recover Abandoned Cart plugin for WordPress is vulnerable to unauthorized access due to a missing capabi… | — | wordfence |
| d300288e-f100-4c02-ba65-d728e3b1522e | < 8.1.2 |
MEDIUM | 5.3 | The Seers plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on m… | — | wordfence |
| d2d50c64-f4e2-4a5a-b37f-bbb636ee468d | < 1.2.43 |
MEDIUM | 5.3 | The Time Slots Booking Form plugin for WordPress is vulnerable to unauthorized access due to a missing capability check … | — | wordfence |
| d2d040d5-ffcb-4ab9-8606-c18a3d2ccad9 | < 3.6.3 |
MEDIUM | 5.3 | The Easy WordPress Funnel Builder To Collect Leads And Increase Sales β WPFunnels plugin for WordPress is vulnerable t… | — | wordfence |
| d2b74b9d-b296-4d3b-936f-419dad502d79 | < 1.1.9 |
MEDIUM | 5.3 | The Wheel of Life: Coaching and Assessment Tool for Life Coach plugin for WordPress is vulnerable to unauthorized access… | — | wordfence |
| d2b3279b-fd39-4c34-92e8-57d309f37a93 | < 1.10.9 |
MEDIUM | 5.3 | The Popup by Supsystic WordPress plugin before 1.10.9 does not have any authentication and authorisation in an AJAX acti… | — | wordfence |
| d2994fbb-29b0-4725-a046-edeca4bcbcd7 | < 2.2.8 |
MEDIUM | 5.3 | The EventON plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the g… | — | wordfence |
EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.
Scan My Website →