Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.
40,383 vulnerabilities found (page 1147 of 1616)
| CVE ID | Plugin / Theme | Severity | CVSS | Description | Fixed In | Source |
|---|---|---|---|---|---|---|
| ad5782d6-f36b-4b7d-b6c0-b9329fb8725c | < 3.1.25 |
MEDIUM | 5.3 | The Icegram plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on… | — | wordfence |
| ad4e5243-e41a-4624-b9cd-47ab79637560 | < 3.9.9 |
MEDIUM | 5.3 | The Tutor LMS Pro plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a funct… | — | wordfence |
| ad2d5070-ddc6-4478-abe5-776e197a4507 | < 3.2.8 |
MEDIUM | 5.3 | The Membership Plugin β Restrict Content plugin for WordPress is vulnerable to Sensitive Information Exposure in all v… | — | wordfence |
| ad2b053b-12c0-42fa-b3da-31c824f04848 | < 0.7.9 |
MEDIUM | 5.3 | The Link Whisper Free plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and in… | — | wordfence |
| ad2af511-a038-47bf-b9ec-b464cb28593d | MEDIUM | 5.3 | The Bux Woocommerce plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a fun… | — | wordfence | |
| ad12941f-8cbf-41c6-a261-b47075198d26 | MEDIUM | 5.3 | The Sandbox theme for WordPress is vulnerable to Full Path Disclosure in versions up to, and including 1.6.1 via the che… | — | wordfence | |
| acd85c0c-7f48-4b09-a44f-7f0858c68616 | MEDIUM | 5.3 | The Funnelforms Free plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a fu… | — | wordfence | |
| acc88688-76e0-4477-8b7c-eeff541881ab | < 0.3.9 |
MEDIUM | 5.3 | The Payaza plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on … | — | wordfence |
| acb5b0e2-7a12-4c7e-b316-b03ae9b605fc | MEDIUM | 5.3 | The Restore PayPal Standard for WooCommerce plugin for WordPress is vulnerable to Payment Bypass in versions up to, and … | — | wordfence | |
| ac7d08e6-b04d-4b8c-af43-1abe8b531f7c | < 4.7.8 |
MEDIUM | 5.3 | The Simple Membership plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a f… | — | wordfence |
| ac5f5093-a0c6-43bd-8e89-7fe5d90a779b | < 1.6.9 |
MEDIUM | 5.3 | The Product Addons and Product Options With Custom Fields β WowAddons plugin for WordPress is vulnerable to unauthoriz… | — | wordfence |
| ac402867-baa3-412c-b5de-c01e6a790ded | MEDIUM | 5.3 | wp-php-widget.php in the WP PHP widget plugin 1.0.2 for WordPress allows remote attackers to obtain sensitive informatio… | — | wordfence | |
| ac11bd41-d6bf-47e7-87a7-b45d7cb80639 | < 2.1.7 |
MEDIUM | 5.3 | The Kit (formerly ConvertKit) for WooCommerce plugin for WordPress is vulnerable to Sensitive Information Exposure in al… | — | wordfence |
| ac06b9d9-51de-4f7a-87b8-c7b46a8475ee | < 1.5.3 |
MEDIUM | 5.3 | The Site Offline plugin for WordPress is vulnerable to Maintenance Mode Bypass in versions up to, and including, 1.4.9. … | — | wordfence |
| abeb13ac-d835-4e02-baaf-30e8dc4bd86b | < 4.2.9 |
MEDIUM | 5.3 | The Primer MyData for Woocommerce plugin for WordPress is vulnerable to Path Traversal in all versions up to, and includ… | — | wordfence |
| abe1b727-cd92-43aa-8b6e-e02befa53195 | < 1.0.8 |
MEDIUM | 5.3 | The WPBookit plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function i… | — | wordfence |
| abc983c6-aa30-4d1b-b6af-99b5ba1c8481 | < 1.2.19 |
MEDIUM | 5.3 | The iQ Block Country plugin for WordPress is vulnerable to Country Blocking Bypass in versions up to, and including, 1.2… | — | wordfence |
| abc3f352-8568-4649-bf3c-dd0ce0295589 | < 2.9.31 |
MEDIUM | 5.3 | The Affiliates Manager plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and i… | — | wordfence |
| abc0d9c0-ed5a-4bb8-9ff1-d2833dd04d31 | < 20260217 |
MEDIUM | 5.3 | The Simple Ajax Chat β Add a Fast, Secure Chat Box plugin for WordPress is vulnerable to Sensitive Information Exposur… | — | wordfence |
| abb41236-d711-41d3-a1cd-2c23467e269a | < 2.0 |
MEDIUM | 5.3 | The Aspose Cloud eBook Generator plugin for WordPress is vulnerable to Directory Traversal in versions up to, and includ… | — | wordfence |
| abb362f1-8782-4217-a231-c9b258da6964 | < 34.0.0 |
MEDIUM | 5.3 | The PPOM β Product Addons & Custom Fields for WooCommerce plugin for WordPress is vulnerable to unauthorized access du… | — | wordfence |
| ab96123e-17aa-461f-b460-e8eba82c78e1 | MEDIUM | 5.3 | The Localize Remote Images plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and inclu… | — | wordfence | |
| ab8bb8b3-59a6-424a-bc7b-b8740c936637 | < 1.33.1 |
MEDIUM | 5.3 | The Hubbub Lite β Fast, Reliable Social Sharing Buttons plugin for WordPress is vulnerable to Sensitive Information Ex… | — | wordfence |
| ab87321b-d326-498d-9a75-44692258cae6 | < 4.21.0 |
MEDIUM | 5.3 | The FG Joomla to WordPress plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, a… | — | wordfence |
| ab87210f-1f21-4208-ab50-4f62ec8e02fb | < 5.1.1 |
MEDIUM | 5.3 | The Simple Social Media Share Buttons β Social Sharing for Everyone plugin for WordPress is vulnerable to Sensitive In… | — | wordfence |
EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.
Scan My Website →