Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.
40,383 vulnerabilities found (page 1143 of 1616)
| CVE ID | Plugin / Theme | Severity | CVSS | Description | Fixed In | Source |
|---|---|---|---|---|---|---|
| b4f32ec5-c744-45ca-a7a2-3d4a241f82c1 | MEDIUM | 5.3 | The Snow Effect plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a functio… | — | wordfence | |
| b4d9acfb-bb9d-4b00-b439-c7ccea751f8d | < 3.22.2 |
MEDIUM | 5.3 | The GiveWP β Donation Plugin and Fundraising Platform plugin for WordPress is vulnerable to Sensitive Information Expo… | — | wordfence |
| b4ce6cb2-a02a-4b4c-8887-22ee6115509f | < 3.5.7 |
MEDIUM | 5.3 | In the AccessAlly WordPress plugin before 3.5.7, the file "resource/frontend/product/product-shortcode.php" responsible … | — | wordfence |
| b4cb5ec6-34f5-419d-a1eb-3a75dd63cb60 | MEDIUM | 5.3 | The WooCommerce Appointments plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and… | — | wordfence | |
| b4a88c2f-12d2-46c5-a14a-dfec6382a81b | MEDIUM | 5.3 | The Import YouTube videos as WP Posts plugin for WordPress is vulnerable to unauthorized access due to a missing capabil… | — | wordfence | |
| b49ce4a2-52ad-4824-86fc-5edd2e33802d | < 1.1.28 |
MEDIUM | 5.3 | The Hydra Booking β Appointment Scheduling & Booking Calendar plugin for WordPress is vulnerable to missing payment ve… | — | wordfence |
| b49978c1-9254-4229-8d32-e12896301f3d | < 2.6 |
MEDIUM | 5.3 | The User Registration Using Contact Form 7 plugin for WordPress is vulnerable to unauthorized access of data due to a mi… | — | wordfence |
| b4956173-b306-401c-b966-df884e8979e0 | < 4.0.19 |
MEDIUM | 5.3 | The CMP WordPress plugin before 4.0.19 allows any user, even not logged in, to arbitrarily change the coming soon page l… | — | wordfence |
| b48e5973-6923-47cc-a660-ecc989f540f8 | < 14.1.0 |
MEDIUM | 5.3 | The JM Twitter Cards plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 14… | — | wordfence |
| b48b9170-4dd9-4004-a081-488cafbc7597 | < 3.3.27 |
MEDIUM | 5.3 | The eCommerce Product Catalog Plugin for WordPress plugin for WordPress is vulnerable to Sensitive Information Exposure … | — | wordfence |
| b4570948-1625-44b3-8af6-73765d9710ee | < 3.11 |
MEDIUM | 5.3 | The WordPress Email Marketing Plugin β WP Email Capture plugin for WordPress is vulnerable to Sensitive Information Ex… | — | wordfence |
| b4363600-666a-4a75-a817-4af679ab400c | < 5.9.3 |
MEDIUM | 5.3 | The ARMember Premium plugin for WordPress is vulnerable to unauthorized access of data, modification of data, or loss of… | — | wordfence |
| b424f25d-66c7-4c1b-9712-7b857806f7e4 | < 2.8.4 |
MEDIUM | 5.3 | The Password Protected plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and inclu… | — | wordfence |
| b3e03668-c9ee-4c4b-8240-998ef45a5326 | < 3.1.3 |
MEDIUM | 5.3 | The WP STAGING WordPress Backup Plugin Free and Pro plugin for WordPress is vulnerable to Sensitive Information Exposure… | — | wordfence |
| b3cc3835-25f5-43b3-82be-397b8b3bd369 | < 1.53.2 |
MEDIUM | 5.3 | The Broadstreet plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and includin… | — | wordfence |
| b3c6ba21-7631-4bbd-b08e-926d2f129cc3 | < 7.7 |
MEDIUM | 5.3 | The SEOPress β On-site SEO plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to,… | — | wordfence |
| b3c17ba3-4fc8-439c-8ce3-bd95d7ed2474 | < 2.1 |
MEDIUM | 5.3 | The coreActivity: Activity Logging plugin for WordPress plugin for WordPress is vulnerable to IP Address Spoofing in all… | — | wordfence |
| b3c15924-d430-48e3-9804-fa83605b9c24 | < 2.0.1 |
MEDIUM | 5.3 | The Pretty Google Calendar plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability… | — | wordfence |
| b3940953-fdd4-4759-8476-a421cfbbbd30 | < 1.1.1 |
MEDIUM | 5.3 | The Appointment Booking and Scheduler Plugin β Truebooker plugin for WordPress is vulnerable to unauthorized access du… | — | wordfence |
| b3325317-4ce7-468d-aee7-9b40fdf61d3c | < 6.0.3.4 |
MEDIUM | 5.3 | The FV Flowplayer Video Player plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the βpageβ para… | — | wordfence |
| b311b404-f808-40fc-9f09-4eac05bce798 | MEDIUM | 5.3 | The Wisly plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 1… | — | wordfence | |
| b30ac1b0-eae2-4194-bf8e-ae73b4236965 | < 7.6.4 |
MEDIUM | 5.3 | The wpDiscuz plugin for WordPress is vulnerable to unauthorized modification of data due to a missing authorization chec… | — | wordfence |
| b308c032-14a1-42f7-866c-adacc7d9402e | MEDIUM | 5.3 | The JobHunt Job Alerts plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a … | — | wordfence | |
| b3075193-41ae-4e3d-acf7-b94105b67456 | MEDIUM | 5.3 | The Allada T-shirt Designer for Woocommerce β Custom Product Designer for T-shirt personalization and design plugin fo… | — | wordfence | |
| b2fc119c-6545-48a5-aa27-852edce50b39 | < 2.2.1 |
MEDIUM | 5.3 | The VW Education Lite theme for WordPress is vulnerable to unauthorized access due to a missing capability check on a fu… | — | wordfence |
EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.
Scan My Website →