Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.
40,383 vulnerabilities found (page 1145 of 1616)
| CVE ID | Plugin / Theme | Severity | CVSS | Description | Fixed In | Source |
|---|---|---|---|---|---|---|
| b0a9f3d2-aa7f-4fc2-9cfd-b69ec3f63160 | MEDIUM | 5.3 | The WP eCommerce plugin for WordPress is vulnerable to unauthorized arbitrary post creation due to a missing capability … | — | wordfence | |
| b083cf9d-bcfe-4234-a816-2d216da28b57 | < 1.13.2 |
MEDIUM | 5.3 | The SureForms plugin for WordPress is vulnerable to Cross-Site Request Forgery Bypass in all versions up to, and includi… | — | wordfence |
| b078e446-61e7-4ce1-b9a9-480ccc388c72 | < 2.1.7 |
MEDIUM | 5.3 | The Perfmatters plugin for WordPress is vulnerable to unauthorized access, modification or loss of data due to a missing… | — | wordfence |
| b061facb-0411-4b81-adbd-b1419b7210df | < 6.8.2 |
MEDIUM | 5.3 | The Advanced Custom Fields (ACF®) plugin for WordPress is vulnerable to unauthorized access due to a missing capability… | — | wordfence |
| b05b0f6d-ffa4-40f4-b969-1153192c52d6 | < 2.3.2 |
MEDIUM | 5.3 | The Hide Category by User Role for WooCommerce plugin for WordPress is vulnerable to Missing Authorization in all versio… | — | wordfence |
| b04a7ef8-13bb-455e-8ca8-22f3eec15bcb | < 5.0.6 |
MEDIUM | 5.3 | The Guest posting / Frontend Posting / Front Editor – WP Front User Submit plugin for WordPress is vulnerable to Sensi… | — | wordfence |
| b030aa28-5310-4f69-8b86-7e0b0bae741b | < 8.2.7 |
MEDIUM | 5.3 | The WoodMart theme for WordPress is vulnerable to Improper Input Validation in all versions up to, and including, 8.2.6.… | — | wordfence |
| b024f6ce-c3ec-4ed9-a8ea-54f926e38443 | < 1.6 |
MEDIUM | 5.3 | The WooCommerce Email Test for WordPress is vulnerable to Sensitive Data Exposure in versions up to, and including, 1.5 … | — | wordfence |
| affe1bab-e534-4c79-a057-6b1268437575 | < 1.2.22 |
MEDIUM | 5.3 | The Ziina plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in a… | — | wordfence |
| afefe8fd-0078-4fd8-bdae-03e60fc33e87 | MEDIUM | 5.3 | The AnalyticsWP plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and includin… | — | wordfence | |
| afec4c8c-a18d-4907-8879-2412f8a1abed | < 5.4.0 |
MEDIUM | 5.3 | The LatePoint plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and includin… | — | wordfence |
| afe275b4-edc0-4b19-a91f-5099a085e8ce | < 5.0.4 |
MEDIUM | 5.3 | The WPC Smart Wishlist for WooCommerce plugin for WordPress is vulnerable to Insecure Direct Object Reference in all ver… | — | wordfence |
| afc9114b-80b7-4caf-ab6b-35747ff5057b | < 1.1.1 |
MEDIUM | 5.3 | The Frontend File Manager & Sharing – User Private Files plugin for WordPress is vulnerable to Sensitive Data Exposure… | — | wordfence |
| afc3531d-6134-4b45-b532-37430d96a8fb | < 2.0.0 |
MEDIUM | 5.3 | The Smart Appointment & Booking plugin for WordPress is vulnerable to unauthorized modification of data due to a missing… | — | wordfence |
| afbcee72-fe0c-4288-bcf7-e2eaea8029d6 | < 5.6.5 |
MEDIUM | 5.3 | The Eduma theme for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in al… | — | wordfence |
| af97a8aa-f42b-46c8-b79b-d1c3220fdf58 | < 3.19.10 |
MEDIUM | 5.3 | The 12 Step Meeting List plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and… | — | wordfence |
| af955f69-b18c-446e-b05e-6a57a5f16dfa | < 4.1.8 |
MEDIUM | 5.3 | The CMP – Coming Soon & Maintenance plugin for WordPress is vulnerable to Maintenance Mode Bypass in versions up to, a… | — | wordfence |
| af870e80-ad9e-4f45-952f-9ffb07ceca9c | < 1.4.4 |
MEDIUM | 5.3 | The Backup Migration plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and inc… | — | wordfence |
| af803612-96ae-41ee-8ad3-8f9319b147e8 | < 2.3.6 |
MEDIUM | 5.3 | The Button Generator – easily Button Builder plugin for WordPress is vulnerable to Cross-Site Request Forgery in versi… | — | wordfence |
| af54654b-60af-446d-b170-ee0a1ebed22c | < 2.9.7.1 |
MEDIUM | 5.3 | The myCred – Points Management System For Gamification, Ranks, Badges, and Loyalty Program plugin for WordPress is vul… | — | wordfence |
| af40f0e4-96cf-4eac-842b-6df6279cab44 | < 3.2.9 |
MEDIUM | 5.3 | The New User Approve plugin for WordPress is vulnerable to unauthorized access in all versions up to, and including, 3.2… | — | wordfence |
| af3105ed-d383-4ce6-9317-5762f97b14e3 | MEDIUM | 5.3 | The Client Dash plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a functio… | — | wordfence | |
| af2645cc-aa96-45b4-8f22-16d02224cb3b | MEDIUM | 5.3 | The Scientific and Interactive Blocks – inseri core plugin for WordPress is vulnerable to unauthorized access due to a… | — | wordfence | |
| af138d3c-9f43-4346-bcb5-cb408f10b253 | < 4.7.16 |
MEDIUM | 5.3 | The MasterStudy LMS Pro plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capabil… | — | wordfence |
| af01cba6-40df-4eb9-beec-4716909a671b | < 1.4.8 |
MEDIUM | 5.3 | The CloudSecure WP Security plugin for WordPress is vulnerable to Two-Factor Authentication Bypass in all versions up to… | — | wordfence |
EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.
Scan My Website →