Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.
40,383 vulnerabilities found (page 1137 of 1616)
| CVE ID | Plugin / Theme | Severity | CVSS | Description | Fixed In | Source |
|---|---|---|---|---|---|---|
| bf2b8b9e-755f-4b24-99c8-0d221c9c19a7 | < 3.0.0 |
MEDIUM | 5.3 | The Membership For WooCommerce β WordPress Membership Plugin, Restrict Content, Build Online Communities, Paywall & Co… | — | wordfence |
| bf22affe-13b9-4f88-aaff-24eaa8df7e5d | < 1.3.13 |
MEDIUM | 5.3 | The User Registration Stripe plugin for WordPress is vulnerable to unauthorized access due to a missing capability check… | — | wordfence |
| befc6373-1833-4e5b-9500-19fbc3aa110e | MEDIUM | 5.3 | The Coming Soon Page β Responsive Coming Soon & Maintenance Mode plugin for WordPress is vulnerable to Sensitive Infor… | — | wordfence | |
| befc1787-7617-410a-b897-7089c2d9b413 | < 1.1.31 |
MEDIUM | 5.3 | The Tablesome plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function … | — | wordfence |
| bef84287-cbff-41c8-8cf8-3e0e12b0311b | < 2.0.9 |
MEDIUM | 5.3 | The Miraculous - Multi Vendor Online Music Store Elementor WordPress Theme theme for WordPress is vulnerable to unauthor… | — | wordfence |
| bee2e520-46cc-4b54-9849-fafb9b37ba19 | < 5.0.0 |
MEDIUM | 5.3 | The WP ULike plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including… | — | wordfence |
| beb8ea66-3cd7-452f-9e64-8439de0ddc55 | < 2.21.0 |
MEDIUM | 5.3 | The Quform - WordPress Form Builder plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions… | — | wordfence |
| beae9073-5293-4a89-8c9a-8c5276891684 | < 4.19.0 |
MEDIUM | 5.3 | The MStore API β Create Native Android & iOS Apps On The Cloud plugin for WordPress is vulnerable to unauthorized acce… | — | wordfence |
| be9522c8-3561-48fe-89ef-62e0fcb085b0 | < 4.7.9 |
MEDIUM | 5.3 | The ChatBot plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 4.7.8. Th… | — | wordfence |
| be826d7f-6f8e-4942-81d5-2b00debd56fc | < 9.5.10.1 |
MEDIUM | 5.3 | The Really Simple Security β Simple and Performant Security (formerly Really Simple SSL) plugin for WordPress is vulne… | — | wordfence |
| be6db702-43bc-4d1f-a222-d323c70c6bb3 | < 1.7.1053 |
MEDIUM | 5.3 | The Royal Addons for Elementor β Addons and Templates Kit for Elementor plugin for WordPress is vulnerable to unauthor… | — | wordfence |
| be5cc744-e88e-4a8b-81d1-3e05abba19d8 | < 1.0.47 |
MEDIUM | 5.3 | The Checkout for PayPal plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a… | — | wordfence |
| be4fac77-93f3-4c5d-b139-66e799143533 | MEDIUM | 5.3 | The Sala - Startup & SaaS WordPress Theme theme for WordPress is vulnerable to unauthorized access due to a missing capa… | — | wordfence | |
| be3411ec-0e34-4b0b-a04c-98ac94396989 | < 2.7.1 |
MEDIUM | 5.3 | The AI ChatBot with ChatGPT and Content Generator by AYS plugin for WordPress is vulnerable to unauthorized access due t… | — | wordfence |
| be33065e-dae8-44cf-9f8a-f9971f2743ff | < 3.9.9 |
MEDIUM | 5.3 | The EmbedPress plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the handle… | — | wordfence |
| be23d61f-1e7f-40fb-88ca-dd0ed226a7c5 | < 2.15.0 |
MEDIUM | 5.3 | The Better Messages β Chat Rooms, Group Chat, Private Messages & AI Chat Bots plugin for WordPress is vulnerable to In… | — | wordfence |
| be07fa12-7c2a-48f6-9792-17d8b2f5d209 | MEDIUM | 5.3 | The Viral Loops WP Integration plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up t… | — | wordfence | |
| be01ffb6-9ef0-41a1-870c-fbeee48d886f | < 3.3.1 |
MEDIUM | 5.3 | The WPC Order Tip for WooCommerce plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to… | — | wordfence |
| bdeb5494-3239-417c-86dc-488e35f1b7f9 | < 13.7.1 |
MEDIUM | 5.3 | The Indeed Membership Pro plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on… | — | wordfence |
| bdde4399-af90-4528-92a4-5176dfa5e453 | MEDIUM | 5.3 | The Contact Form vCard Generator plugin for WordPress is vulnerable to unauthorized access of data due to a missing capa… | — | wordfence | |
| bdd1bb49-5a0f-434c-bb05-03c4a548dec1 | MEDIUM | 5.3 | The ShipDepot for WooCommerce plugin for WordPress is vulnerable to unauthorized access due to a missing capability chec… | — | wordfence | |
| bdc84664-2a04-4cc6-ac3f-48bfd432691f | < 4.7.27 |
MEDIUM | 5.3 | WordPress Core is vulnerable to Denial of Service via Cache Poisoning in versions between 4.7.0 and 6.3.1. In cases wher… | — | wordfence |
| bdbd3a1a-a206-4e50-893d-1b2d6c8d153a | < 3.0.6 |
MEDIUM | 5.3 | The Visual Form Builder WordPress plugin before 3.0.6 is vulnerable to CSV injection allowing a user with low level or n… | — | wordfence |
| bdaa32cd-a148-4554-9fd5-f5b0a5b2d1c3 | < 5.5.1 |
MEDIUM | 5.3 | The LatePoint plugin for WordPress is vulnerable to Account Takeover via Weak Password Recovery Mechanism in the unauthe… | — | wordfence |
| bd9336ba-0a91-4fe5-b564-1adf739f4193 | < 4.7.2 |
MEDIUM | 5.3 | The Simple Membership plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a f… | — | wordfence |
EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.
Scan My Website →