Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.
40,383 vulnerabilities found (page 1144 of 1616)
| CVE ID | Plugin / Theme | Severity | CVSS | Description | Fixed In | Source |
|---|---|---|---|---|---|---|
| b2f9203f-15c7-4179-86ef-44b0e2788b3c | MEDIUM | 5.3 | The WP Virtual Assistant plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on … | — | wordfence | |
| b2c7fb39-d128-4285-8bc3-1e192e1e1196 | < 1.1.10 |
MEDIUM | 5.3 | The Float Payment Gateway plugin for WordPress is vulnerable to unauthorized modification of data due to improper error … | — | wordfence |
| b29dbd24-6c63-46d8-b245-7194cab17624 | < 1.7.6 |
MEDIUM | 5.3 | The SiteGround Email Marketing plugin for WordPress is vulnerable to unauthorized access due to a missing capability che… | — | wordfence |
| b29144f7-08cb-4703-a977-4fece763abbd | < 6.0.4 |
MEDIUM | 5.3 | The Democracy Poll plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a func… | — | wordfence |
| b28e313a-3527-468f-8e86-6e51962af950 | MEDIUM | 5.3 | The Altair theme for WordPress is vulnerable to unauthorized access in all versions up to, and including, 5.2.2. This is… | — | wordfence | |
| b23dec43-ad7d-45d9-910e-b024b3c750c9 | < 7.0.0 |
MEDIUM | 5.3 | The Post My CF7 Form plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a fu… | — | wordfence |
| b23de3eb-ae2a-4165-9251-7a135bc34b73 | < 6.4.14 |
MEDIUM | 5.3 | The Advanced Booking & Appointment System β Webba Booking Calendar plugin for WordPress is vulnerable to unauthorized … | — | wordfence |
| b23bdba3-8947-47e4-b208-55e42865ab72 | < 2.17.6 |
MEDIUM | 5.3 | The Contact Form by Bit Form: Multi Step Form, Calculation Contact Form, Payment Contact Form & Custom Contact Form buil… | — | wordfence |
| b23afc11-c31d-4569-8f4b-8141eef7b3d9 | < 4.1.1 |
MEDIUM | 5.3 | The Custom Login plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on an unkno… | — | wordfence |
| b1dea93c-437b-45ac-9dc3-07d3aa3f1c9f | < 4.0.3 |
MEDIUM | 5.3 | The Peach Payments Gateway plugin for WordPress is vulnerable to unauthorized access due to a missing capability check o… | — | wordfence |
| b1dd3845-a88d-41aa-acf4-66fd1a6819ff | < 3.0 |
MEDIUM | 5.3 | The Captcha Code plugin for WordPress is vulnerable to CAPTCHA Bypass in versions up to, and including, 2.9. This makes … | — | wordfence |
| b1be4b6c-ce48-49a2-8d2c-89c9611c8750 | < 1.3.14.0 |
MEDIUM | 5.3 | The Event Koi Lite β Events Calendar, Event Management, RSVP, and Tickets plugin for WordPress is vulnerable to Sensit… | — | wordfence |
| b192dd62-477d-463d-a284-9f3232db27ca | < 7.5.2 |
MEDIUM | 5.3 | The Complianz β GDPR/CCPA Cookie Consent plugin for WordPress is vulnerable to Sensitive Information Exposure in all v… | — | wordfence |
| b1892207-0e51-4b2e-bc71-d6a0111b7041 | < 7.8.1 |
MEDIUM | 5.3 | The Themify Builder plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 7.8… | — | wordfence |
| b1800f37-f9ab-454b-84f7-4d5eb5ed3acf | MEDIUM | 5.3 | The SearchPlus plugin for WordPress is vulnerable to unauthorized modification and deletion of data in versions up to, a… | — | wordfence | |
| b1715959-532a-4dd7-b384-0bd5f2673e2b | < 10.30.34 |
MEDIUM | 5.3 | The Salon Booking System β Free Version plugin for WordPress is vulnerable to unauthorized access due to a missing cap… | — | wordfence |
| b15d1992-ecf9-4253-b832-056b34f42b48 | < 1.2.8 |
MEDIUM | 5.3 | The QODE Wishlist for WooCommerce plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions… | — | wordfence |
| b14acbc6-a6af-43f0-8371-c85e5abcf8eb | MEDIUM | 5.3 | The WP-Recall β Registration, Profile, Commerce & More plugin for WordPress is vulnerable to unauthorized access due t… | — | wordfence | |
| b1469b02-c52d-4a02-a974-81dd1e2c1f97 | < 1.9.9.1 |
MEDIUM | 5.3 | The WPLMS plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in a… | — | wordfence |
| b1446daf-662d-479c-8fc5-80b27b04d6c4 | < 2.0.7 |
MEDIUM | 5.3 | WordPress 2.0.6, and 2.1Alpha 3 (SVN:4662), does not properly verify that the m parameter value has the string data type… | — | wordfence |
| b11b886e-72a7-4b27-a4ac-f4586c3ef722 | < 3.6.2 |
MEDIUM | 5.3 | The Order Listener for WooCommerce plugin for WordPress is vulnerable to unauthorized access due to a missing capability… | — | wordfence |
| b102af8f-2bc3-4548-9a90-d1280b058173 | MEDIUM | 5.3 | The Post Thumbnail Editor plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, an… | — | wordfence | |
| b0e1546b-c8cc-4d57-9909-153209e3a9c6 | < 3.0.1 |
MEDIUM | 5.3 | The Upsell Funnel Builder for WooCommerce plugin for WordPress is vulnerable to order manipulation in all versions up to… | — | wordfence |
| b0d4c009-d969-49bb-a56b-a704e5f89a86 | < 2.1.1 |
MEDIUM | 5.3 | The Storegrowth Sales Booster plugin for WordPress is vulnerable to Missing Authorization in versions up to and includin… | — | wordfence |
| b0c80f18-5319-436d-b989-e6f5e6ab58ea | < 2.0.1 |
MEDIUM | 5.3 | The Anti Spam and list cleaner β AcyChecker plugin for WordPress is vulnerable to unauthorized access due to a missing… | — | wordfence |
EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.
Scan My Website →