Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.
40,383 vulnerabilities found (page 1177 of 1616)
| CVE ID | Plugin / Theme | Severity | CVSS | Description | Fixed In | Source |
|---|---|---|---|---|---|---|
| 746265fa-151b-4ea8-8871-8828b878da62 | < 1.6.1 |
MEDIUM | 5.3 | The Unlimited Timeline plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a … | — | wordfence |
| 7448e2bd-07f2-49fe-b094-9d55ea7cbe35 | < 2.8.0 |
MEDIUM | 5.3 | The The Grid plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function i… | — | wordfence |
| 7430594c-3a71-4b24-875b-014e03be868f | < 2.4.13 |
MEDIUM | 5.3 | The GutenKit Blocks plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check … | — | wordfence |
| 7422e7c6-fe0a-49be-ba9e-d14f66e328d0 | < 1.16.17 |
MEDIUM | 5.3 | The 3D FlipBook β PDF Embedder, PDF Flipbook Viewer, Flipbook Image Gallery plugin for WordPress is vulnerable to Sens… | — | wordfence |
| 74160271-b27d-49fe-9550-e3949ecad048 | < 2.7.3 |
MEDIUM | 5.3 | The Bitly's WordPress Plugin plugin for WordPress is vulnerable to unauthorized access due to a missing capability check… | — | wordfence |
| 73f0e8f0-88cd-4994-ad85-a0cf3e825a7b | < 4.13.0 |
MEDIUM | 5.3 | The YITH WooCommerce Wishlist plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up … | — | wordfence |
| 73dd286e-5338-42d2-9928-1e14150ccf56 | < 2.3.9 |
MEDIUM | 5.3 | The Button Generator β easily Button Builder plugin for WordPress is vulnerable to unauthorized modification of data d… | — | wordfence |
| 73d8135e-7324-4830-bb73-184b627d4106 | < 2.3.2 |
MEDIUM | 5.3 | The CryptoCloud β Crypto Payment Gateway plugin for WordPress is vulnerable to unauthorized access due to a missing ca… | — | wordfence |
| 73d188a5-97b4-4f54-8cb4-f26481ddcb56 | < 1.1.21 |
MEDIUM | 5.3 | The SePay Gateway plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and includ… | — | wordfence |
| 73b4e081-caa8-4055-91e2-11979df20159 | < 2.1.6 |
MEDIUM | 5.3 | The Masteriyo LMS β Online Course Builder for eLearning, LMS & Education plugin for WordPress is vulnerable to unautho… | — | wordfence |
| 739abe9a-bcc2-4014-8441-38b326802a70 | < 3.3.8 |
MEDIUM | 5.3 | The Instantio β WooCommerce Quick Checkout | Direct Checkout, Floating Cart, Side Cart & Popup Cart plugin for WordPre… | — | wordfence |
| 7399f8f3-70ee-44ed-b8c8-211ae22aa86b | < 1.3.61 |
MEDIUM | 5.3 | The Contact Form Email plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and… | — | wordfence |
| 7391dd8c-0170-48c6-8451-9e7a00e268d0 | < 2.0.7 |
MEDIUM | 5.3 | The Aruba HiSpeed Cache plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and … | — | wordfence |
| 737aa726-b0df-47ac-aad1-0acf4bb1abdb | < 1.0.1.9 |
MEDIUM | 5.3 | The Gou Manage My Account Menu plugin for WordPress is vulnerable to unauthorized modification of data due to a missing … | — | wordfence |
| 73720e67-79e5-4b4c-8720-e28ad718b2b3 | < 3.2.11 |
MEDIUM | 5.3 | The Ultimate Addons for Contact Form 7 plugin for WordPress is vulnerable to unauthorized access of data due to a missin… | — | wordfence |
| 7364f803-9808-4337-8922-2d7c88849361 | MEDIUM | 5.3 | The Civi Framework plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a func… | — | wordfence | |
| 73643d45-9542-4372-a7a2-0a443819b8a2 | < 2.33.1 |
MEDIUM | 5.3 | The 404 Solution plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and includi… | — | wordfence |
| 7363b5de-db30-4b35-b701-5c8f2835ec6c | < 4.4.8 |
MEDIUM | 5.3 | The Secure Copy Content Protection and Content Locking plugin for WordPress is vulnerable to unauthorized access of data… | — | wordfence |
| 735b20ff-a708-4e1c-b96e-bcdec72aad95 | < 20.8.11 |
MEDIUM | 5.3 | The Client Invoicing by Sprout Invoices plugin for WordPress is vulnerable to unauthorized access due to a missing capab… | — | wordfence |
| 73445d8f-1f9c-4ba7-9e3c-3e6221f3b23e | < 2.1.1 |
MEDIUM | 5.3 | The Bricksforge plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a functio… | — | wordfence |
| 7319293e-f921-46d1-aea6-2578d1a251a7 | < 3.0.9 |
MEDIUM | 5.3 | The avalex β Automatisch sichere Rechtstexte plugin for WordPress is vulnerable to unauthorized modifcation of data du… | — | wordfence |
| 73163743-2bff-459d-bed9-593f6ce837fa | < 3.1.3 |
MEDIUM | 5.3 | WordPress 3.1 before 3.1.3 and 3.2 before Beta 2 allows remote attackers to determine usernames of non-authors via canon… | — | wordfence |
| 72f3925d-6b3a-43bf-bfd1-fef7e71d5e43 | < 8.6.01.005 |
MEDIUM | 5.3 | The WP Photo Album Plus plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, an… | — | wordfence |
| 72e92bd8-9060-4312-800c-e637e6881aa5 | MEDIUM | 5.3 | The ShopSmart Loyalty for WooCommerce plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions… | — | wordfence | |
| 72baf0b2-48c1-437a-9570-9ecbaaca742a | < 4.3.0 |
MEDIUM | 5.3 | The Jobify - Job Board WordPress Theme theme for WordPress is vulnerable to unauthorized access of functionality due to … | — | wordfence |
EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.
Scan My Website →