Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.
40,383 vulnerabilities found (page 1185 of 1616)
| CVE ID | Plugin / Theme | Severity | CVSS | Description | Fixed In | Source |
|---|---|---|---|---|---|---|
| 63fd62b2-455e-449b-b46a-78c5d2b86cde | < 2.1 |
MEDIUM | 5.3 | WordPress 2.0.11 and earlier allows remote attackers to obtain sensitive information via an empty value of the page para… | — | wordfence |
| 63fc381e-ce72-4c90-bb35-daba520be40d | < 5.2.5 |
MEDIUM | 5.3 | The All-In-One Security (AIOS) β Security and Firewall plugin for WordPress is vulnerable to protection bypass on the … | — | wordfence |
| 63f98fd6-eee8-4281-98ea-a267d0442c85 | MEDIUM | 5.3 | The Page Restrict plugin for WordPress is vulnerable to information disclosure in all versions up to, and including, 2.5… | — | wordfence | |
| 63c7bb29-c8b2-49ee-8ac4-1046b61b7e6a | < 1.0.11 |
MEDIUM | 5.3 | The User Feedback plugin for WordPress is vulnerable to unauthorized access of data due to insufficient authorization c… | — | wordfence |
| 639bf20c-04d4-49e5-8da1-685421a6f63a | < 2.8.8 |
MEDIUM | 5.3 | The Download Manager plugin for WordPress is vulnerable to Directory Listing in versions up to, and including, 2.8.7. Th… | — | wordfence |
| 6387f210-ed4f-4f98-9e16-30f80c2889a2 | < 1.0.11 |
MEDIUM | 5.3 | The Blockbooster theme for WordPress is vulnerable to unauthorized modification of data due to a missing capability chec… | — | wordfence |
| 638217c4-7a37-49e4-8660-5510ace692ec | < 1.3.97 |
MEDIUM | 5.3 | The Appointment Booking Calendar plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and … | — | wordfence |
| 635787ad-6cbd-4144-84f8-30124ac1bf9f | < 2.1.2 |
MEDIUM | 5.3 | The Miraculous - Multi Vendor Online Music Store Elementor WordPress Theme theme for WordPress is vulnerable to unauthor… | — | wordfence |
| 63530cc4-aa9e-4b7a-b320-519028dec540 | < 5.290 |
MEDIUM | 5.3 | The security-ninja-premium plugin for WordPress is vulnerable to 2-Factor Authentication Bypass in all versions up to, a… | — | wordfence |
| 630d5dcc-ee51-4c2d-b4fb-191637311d6b | MEDIUM | 5.3 | The Woo Total Sales plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check … | — | wordfence | |
| 6307864b-e89f-42ba-9efa-358a71e0a6c8 | < 1.6.5.584 |
MEDIUM | 5.3 | The Surfer β WordPress Plugin plugin for WordPress is vulnerable to unauthorized access due to a missing capability ch… | — | wordfence |
| 62e30cef-ce5d-4450-989e-f08f09b7638f | MEDIUM | 5.3 | Several themes for WordPress are vulnerable to Cross-Site Request Forgery due to missing nonce validation on the activat… | — | wordfence | |
| 62e25985-ac19-41a5-8027-eb053f4a6490 | < 7.5.1 |
MEDIUM | 5.3 | The Breadcrumb NavXT plugin for WordPress is vulnerable to authorization bypass through user-controlled key in versions … | — | wordfence |
| 62c80ca5-9007-4916-b4e8-a436dc1cfaf2 | < 2.11.0 |
MEDIUM | 5.3 | The WP Terms Popup β Terms and Conditions and Privacy Policy WordPress Popups plugin for WordPress is vulnerable to un… | — | wordfence |
| 62c3f54c-6bfb-4f11-9457-a09d28f83175 | < 4.5.1 |
MEDIUM | 5.3 | The AppPresser β Mobile App Framework plugin for WordPress is vulnerable to unauthorized access of data due to a missi… | — | wordfence |
| 62b29721-0580-4e1d-824d-9b8355890248 | < 4.4.3 |
MEDIUM | 5.3 | The Popup Builder β Create highly converting, mobile friendly marketing popups. plugin for WordPress is vulnerable to … | — | wordfence |
| 62ae0ad0-fc66-4c89-b1eb-36b815f5d0a9 | < 1.5.1.1 |
MEDIUM | 5.3 | The JetTricks for Elementor plugin for WordPress is vulnerable to unauthorized access due to a missing capability check … | — | wordfence |
| 62a831ac-3bec-43b0-915e-b6858757cb1c | < 6.0.12 |
MEDIUM | 5.3 | The Kirki plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions up to, and including, 6.0.1… | — | wordfence |
| 62a37eab-a278-4c6f-bc61-b9157c840cf0 | < 2.2.5 |
MEDIUM | 5.3 | The miniOrange Discord Integration plugin for WordPress is vulnerable to unauthorized access due to a missing capability… | — | wordfence |
| 6280f40e-2998-43d4-a78f-b393e4f36df5 | < 1.2.8 |
MEDIUM | 5.3 | The AI Agent by SiteGround plugin for WordPress is vulnerable to authorization bypass in all versions up to, and includi… | — | wordfence |
| 627c5dbc-2196-487c-82b0-756468bb9ec4 | < 4.3.6 |
MEDIUM | 5.3 | The Content Protector (Passster) plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to,… | — | wordfence |
| 62731e0e-8843-4f79-b887-c595fbefae26 | < 1.4.11 |
MEDIUM | 5.3 | The Motors β Car Dealer, Classifieds & Listing plugin for WordPress is vulnerable to unauthorized modification of data… | — | wordfence |
| 624f1107-6bcb-485a-8474-012ae63cb14a | < 7.0.6 |
MEDIUM | 5.3 | The YOP Poll plugin for WordPress is vulnerable to IP Spoofing in versions 7.0.0 to 7.0.5. This makes it possible for un… | — | wordfence |
| 621ac54b-b73e-41e4-94b1-10f18c77a09d | < 4.0.8.6 |
MEDIUM | 5.3 | The loginwp-pro plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a functio… | — | wordfence |
| 62061cf9-cdbf-4cb2-9890-36bdcbc65c21 | MEDIUM | 5.3 | The Stop Spam Comments plugin for WordPress is vulnerable to protection mechanism bypass on the p_ssc_process() function… | — | wordfence |
EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.
Scan My Website →