Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.
40,383 vulnerabilities found (page 1140 of 1616)
| CVE ID | Plugin / Theme | Severity | CVSS | Description | Fixed In | Source |
|---|---|---|---|---|---|---|
| babf88c4-6328-4ba2-97e4-e1eaaa549dbb | < 2.8.16 |
MEDIUM | 5.3 | The Campaign Monitor for WordPress plugin for WordPress is vulnerable to Full Path Disclosure in all versions up to, and… | — | wordfence |
| baa16b34-760f-4033-a9ee-e14b35e79542 | < 5.2.4 |
MEDIUM | 5.3 | The MotoPress Hotel Booking plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and inclu… | — | wordfence |
| ba9b2d34-c1a3-47c2-9eee-51592faa8805 | < 4.2.24 |
MEDIUM | 5.3 | The MultiVendorX β WooCommerce Multivendor Marketplace Solutions plugin for WordPress is vulnerable to unauthorized ac… | — | wordfence |
| ba88964e-7487-4cd5-ab3e-bd33d14a61df | < 3.8.3 |
MEDIUM | 5.3 | The Simple Social Media Share Buttons plugin for WordPress is vulnerable to Sensitive Information Exposure in all versio… | — | wordfence |
| ba886cec-7c0c-40dd-a6eb-bc770d571974 | MEDIUM | 5.3 | The leadlovers forms plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a fu… | — | wordfence | |
| ba6f8837-813c-4e16-9adb-fdc90ccaf0ca | MEDIUM | 5.3 | The Content Audit Exporter plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, a… | — | wordfence | |
| ba670636-4b83-4915-969e-f02b9786b7d5 | < 1.01.6 |
MEDIUM | 5.3 | The Builder for WooCommerce reviews shortcodes β ReviewShort plugin for WordPress is vulnerable to unauthorized access… | — | wordfence |
| ba465ba0-70c2-4b34-9b55-96725e3ce5a4 | MEDIUM | 5.3 | The WP SendFox plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including… | — | wordfence | |
| ba2623b6-69b4-4596-a1af-cf37083706e8 | < 2.0.5 |
MEDIUM | 5.3 | The Addonify plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function i… | — | wordfence |
| ba027271-b7f9-4bdb-a62b-801fd07f28fd | MEDIUM | 5.3 | The OSMapper WordPress plugin through 2.1.5 contains an AJAX action to delete a plugin related post type named 'map' and… | — | wordfence | |
| b9f627f0-779c-4d57-a471-ce742e3a5dd5 | < 4.20.9 |
MEDIUM | 5.3 | The Leaky Paywall plugin for WordPress is vulnerable to price manipulation in all versions up to, and including, 4.20.8.… | — | wordfence |
| b9f2be74-fedd-4844-95a4-a84318489e58 | < 2.2.4 |
MEDIUM | 5.3 | The Payment Gateway Pix For GiveWP plugin for WordPress is vulnerable to unauthorized access due to a missing capability… | — | wordfence |
| b9e844c1-38c1-4b3c-98a4-71d87ca6293b | MEDIUM | 5.3 | WordPress Portable phpMyAdmin Plugin 1.4.1 and below has Multiple Security Bypass Vulnerabilities including /pma/phpinfo… | — | wordfence | |
| b9d288b8-a0de-493b-b677-3f9bf8211504 | < 2.0 |
MEDIUM | 5.3 | The Booking for Appointments and Events Calendar β Amelia plugin for WordPress is vulnerable to unauthorized access du… | — | wordfence |
| b9cf99e9-47fa-4ca0-8f6c-4b0e75d44008 | < 0.8.4 |
MEDIUM | 5.3 | The Brave β Create Popup, Optins, Lead Generation, Survey, Sticky Elements & Interactive Content plugin for WordPress … | — | wordfence |
| b9b21f8e-8d66-4d3e-a383-bea20a3c4498 | < 2.6.1 |
MEDIUM | 5.3 | The ListingPro - WordPress Directory & Listing Theme for WordPress is vulnerable to Sensitive Data Exposure in versions … | — | wordfence |
| b9961347-7c47-4fa1-af35-609c39a6cd8b | < 1.3.3 |
MEDIUM | 5.3 | The WPZOOM Addons for Elementor β Starter Templates & Widgets plugin for WordPress is vulnerable to unauthorized acces… | — | wordfence |
| b990915d-219b-4329-b7a8-e0c13cad7530 | < 10.1.0 |
MEDIUM | 5.3 | The SmartMag theme for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and excluding, 1… | — | wordfence |
| b9852f61-6502-4e27-9de4-ff1a79accd71 | < 2.1.10 |
MEDIUM | 5.3 | The Download After Email plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on … | — | wordfence |
| b94202ef-75d6-4b6f-96b5-f9760cc0a628 | < 3.0.4 |
MEDIUM | 5.3 | The Squaretype WordPress theme before 3.0.4 allows unauthenticated users to manipulate the query_vars used to retrieve t… | — | wordfence |
| b93f8036-4a89-45e6-b86f-9d57e1662a35 | MEDIUM | 5.3 | The Fantastic Content Protector Free plugin for WordPress is vulnerable to unauthorized plugin settings reset due to a m… | — | wordfence | |
| b92913fa-aa1e-40a0-9a48-d730b2102217 | < 2025.0 |
MEDIUM | 5.3 | The Advanced iFrame plugin for WordPress is vulnerable to unauthorized excessive creation of options on the aip_map_url_… | — | wordfence |
| b917c16f-cd0b-400a-b0e8-48ae32d18339 | < 270.5 |
MEDIUM | 5.3 | The ConveyThis plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function… | — | wordfence |
| b9047775-2d72-4eb5-9339-419f95aa19b2 | < 2.0.0 |
MEDIUM | 5.3 | The Acme Fix Images plugin for WordPress is vulnerable to unauthorized access to the acme_fix_images_ajax_callback funct… | — | wordfence |
| b8f82dad-cba6-484e-8e30-6370ec2ba2d8 | < 2.1.2 |
MEDIUM | 5.3 | The My Tickets β Accessible Event Ticketing plugin for WordPress is vulnerable to unauthorized access due to a missing… | — | wordfence |
EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.
Scan My Website →