Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.
40,383 vulnerabilities found (page 1196 of 1616)
| CVE ID | Plugin / Theme | Severity | CVSS | Description | Fixed In | Source |
|---|---|---|---|---|---|---|
| 4f1d0a07-254c-4df9-90a4-966dff014df0 | < 1.3 |
MEDIUM | 5.3 | The User Management plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.2… | — | wordfence |
| 4f169b22-8bfd-490b-9e2c-49c2a045f35b | < 7.4.5 |
MEDIUM | 5.3 | The SEO Booster plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a functio… | — | wordfence |
| 4f111dc5-b8fa-4da9-b6f2-c6dd1d40a338 | < 1.5.9 |
MEDIUM | 5.3 | The Cargus plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.… | — | wordfence |
| 4ee149bf-ffa3-4906-8be2-9c3c40b28287 | < 2.9.2 |
MEDIUM | 5.3 | The Ultimate Member β User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin plu… | — | wordfence |
| 4ed7b13a-eec3-4035-8815-15228fb05af1 | < 8.7.0 |
MEDIUM | 5.3 | The Geo Controller plugin for WordPress is vulnerable to unauthorized shortcode execution due to missing authorization a… | — | wordfence |
| 4ec0fc39-1e26-44f1-827e-aabeb0347d0a | < 1.5.6 |
MEDIUM | 5.3 | The Event Tickets Manager for WooCommerce plugin for WordPress is vulnerable to unauthorized access due to a missing cap… | — | wordfence |
| 4ebe8b63-ea43-4e39-9fdf-e28fb4638433 | < 1.1.5 |
MEDIUM | 5.3 | The Appointment Booking and Scheduler Plugin β Truebooker plugin for WordPress is vulnerable to Sensitive Information … | — | wordfence |
| 4eb2ae42-584d-4da8-9184-461b5a37b7b6 | < 1.8.37 |
MEDIUM | 5.3 | The Photo Gallery by 10Web β Mobile-Friendly Image Gallery plugin for WordPress is vulnerable to unauthorized modifica… | — | wordfence |
| 4e93f1b0-3aa6-4328-aeb4-bfe561c5a113 | < 1.16.2 |
MEDIUM | 5.3 | The Interactive Content β H5P plugin for WordPress is vulnerable to unauthorized access due to a missing capability ch… | — | wordfence |
| 4e8c311e-7cf2-4aaf-8059-30f872475ee5 | < 2.6 |
MEDIUM | 5.3 | The Convertful β Your Ultimate On-Site Conversion Tool plugin for WordPress is vulnerable to unauthorized modification… | — | wordfence |
| 4e376c96-47a8-419f-ab45-f7c46510c767 | < 3.6.3 |
MEDIUM | 5.3 | The WPFunnels β The Easiest Funnel Builder For WordPress And WooCommerce To Collect Leads And Increase Sales plugin fo… | — | wordfence |
| 4e285ce1-0896-4eef-aa83-59fb6641960b | < 6.3.9.5 |
MEDIUM | 5.3 | The Quiz Maker plugin for WordPress is vulnerable to content spoofing in versions up to, and including 6.3.9.4. This mak… | — | wordfence |
| 4e261b0e-5ca3-4f5c-acc0-41abee31b148 | < 1.6.21 |
MEDIUM | 5.3 | The BA Book Everything plugin for WordPress is vulnerable to arbitrary password reset in all versions up to, and includi… | — | wordfence |
| 4df9918b-7201-4cd7-978d-4a1fa207a97c | < 1.8.1 |
MEDIUM | 5.3 | The Custom Related Posts plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and… | — | wordfence |
| 4decf597-1819-402f-ab28-2446a3e6215f | < 2.0.28 |
MEDIUM | 5.3 | The Listeo Core plugin for WordPress is vulnerable to unauthenticated arbitrary media upload in all versions up to, and … | — | wordfence |
| 4de0339b-8e04-4434-aa51-9c95f8562a7a | < 1.3 |
MEDIUM | 5.3 | The Visual Builder plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a func… | — | wordfence |
| 4dd3c146-534f-41be-b805-7eef2483614e | < 2.4.6 |
MEDIUM | 5.3 | The ConvertKit β Email Newsletter, Email Marketing, Subscribers and Landing Pages plugin for WordPress is vulnerable t… | — | wordfence |
| 4dc39c47-3b99-4e43-b25d-a025f3d228b5 | < 2.10.3 |
MEDIUM | 5.3 | The SimpleShop plugin for WordPress is vulnerable to unauthorized disconnection from SimpleShop due to a missing capabil… | — | wordfence |
| 4d9f2f77-c3e5-49ae-b091-698312056b9d | < 5.6.0 |
MEDIUM | 5.3 | The linkPizza-Manager plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a f… | — | wordfence |
| 4d7b2a7f-3c67-4df1-bb15-e7f4f0035953 | < 7.14.1 |
MEDIUM | 5.3 | The Social Share, Social Login and Social Comments Plugin β Super Socializer plugin for WordPress is vulnerable to Lim… | — | wordfence |
| 4d722bf7-1caa-4637-b512-af6e09c2b21e | < 4.8.4 |
MEDIUM | 5.3 | The Razorpay for WooCommerce plugin for WordPress is vulnerable to unauthorized access due to a missing capability check… | — | wordfence |
| 4d5d7c62-e420-4ef7-b6ac-4139536c222a | < 1.38.3 |
MEDIUM | 5.3 | The AI Product Search for WooCommerce β Motive Commerce Search plugin for WordPress is vulnerable to unauthorized acce… | — | wordfence |
| 4d357096-25da-4cbf-9c6c-261bf1b29a9f | < 3.10.9 |
MEDIUM | 5.3 | The SmartCrawl WordPress SEO checker, SEO analyzer, SEO optimizer plugin for WordPress is vulnerable to Full Path Disclo… | — | wordfence |
| 4d2518f6-3647-4bee-a98c-ce7f30375a62 | < 1.13.1 |
MEDIUM | 5.3 | The InfiniteWP Client plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 1.13.0 … | — | wordfence |
| 4d1a9b0d-f2be-4e60-a86f-aa5150403796 | MEDIUM | 5.3 | The Payment Gateway bKash for WC plugin for WordPress is vulnerable to unauthorized access due to a missing capability c… | — | wordfence |
EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.
Scan My Website →