Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.
40,383 vulnerabilities found (page 1197 of 1616)
| CVE ID | Plugin / Theme | Severity | CVSS | Description | Fixed In | Source |
|---|---|---|---|---|---|---|
| 4d0afd4c-b525-48de-a411-c0d974c76fc2 | < 2.5.6 |
MEDIUM | 5.3 | The WebAuthn Provider for Two Factor plugin for WordPress is vulnerable to Two-Factor Authentication Bypass in all versi… | — | wordfence |
| 4d0a0aa7-7bd9-4883-85b6-b7abf338aa75 | MEDIUM | 5.3 | The Get Quote For Woocommerce β Request A Quote For Woocommerce plugin for WordPress is vulnerable to unauthorized acc… | — | wordfence | |
| 4cee3426-63f4-47c3-9668-64217994752c | < 1.2.0 |
MEDIUM | 5.3 | The Magic Export & Import plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, an… | — | wordfence |
| 4cd27ece-2554-4363-9f3f-161486bfb3ac | < 4.19.0 |
MEDIUM | 5.3 | The MStore API β Create Native Android & iOS Apps On The Cloud plugin for WordPress is vulnerable to unauthorized acce… | — | wordfence |
| 4cc5c663-d1e3-4656-ac69-0d610eeaf774 | < 14.8 |
MEDIUM | 5.3 | The VS Contact Form plugin for WordPress is vulnerable to CAPTCHA Bypass in versions up to, and including, 14.7. This ma… | — | wordfence |
| 4cbc0dd4-4dea-4890-95d0-9531a669b95d | MEDIUM | 5.3 | The Frontend File Manager plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on… | — | wordfence | |
| 4cb3d2d4-256c-4128-9397-8b9c7be1b9c8 | MEDIUM | 5.3 | The Pricing Table plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including,… | — | wordfence | |
| 4c7faa73-2d6b-4bf6-9ba3-f511450d6e6e | < 1.9.12 |
MEDIUM | 5.3 | The Cart Weight for WooCommerce plugin for WordPress is vulnerable to unauthorized access due to a missing capability ch… | — | wordfence |
| 4c7b4361-75ac-4f09-9f69-afb5898cff0c | < 5.2.0 |
MEDIUM | 5.3 | The User Registration & Membership plugin for WordPress is vulnerable to Payment Bypass in versions up to, and including… | — | wordfence |
| 4c65a595-b7c6-461f-b08c-d3793c3d84de | < 3.0.2 |
MEDIUM | 5.3 | The Builderall for WordPress plugin for WordPress is vulnerable to unauthorized access due to a missing capability check… | — | wordfence |
| 4c63154e-9413-47ea-a740-441618266adf | < 3.5.3 |
MEDIUM | 5.3 | The Easy Digital Downloads plugin for WordPress is vulnerable to Order Manipulation in all versions up to, and including… | — | wordfence |
| 4c5dd7a4-0e9c-4e1e-8385-2e76b7b9b02e | MEDIUM | 5.3 | The Chocolate WP β Responsive Photography Theme for WordPress is vulnerable to Sensitive Data Exposure in all versions… | — | wordfence | |
| 4c4e1d2c-bb20-40b7-90a3-96df68d083b8 | < 1.8.6 |
MEDIUM | 5.3 | The Gutenverse plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check… | — | wordfence |
| 4c4cf43f-ea9a-419d-8f62-a7cbec4310da | MEDIUM | 5.3 | The JNews - WordPress Newspaper Magazine Blog AMP Theme theme for WordPress is vulnerable to unauthorized access due to … | — | wordfence | |
| 4c3aa6e7-9aac-4815-b441-3dbabac9d47d | < 1.3.15 |
MEDIUM | 5.3 | The User Registration Stripe plugin for WordPress is vulnerable to unauthorized access due to a missing capability check… | — | wordfence |
| 4c305546-1548-4b77-a484-d7c51d829792 | MEDIUM | 5.3 | The WP Private Content Plus plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, … | — | wordfence | |
| 4c2ce19e-17b2-4638-9a59-6a6de0370ef8 | < 1.0.30 |
MEDIUM | 5.3 | The Appointment Booking and Scheduling Calendar Plugin β WP Timetics plugin for WordPress is vulnerable to unauthorize… | — | wordfence |
| 4bf3248a-f235-472c-b751-96ac9838b27f | < 2.8.0 |
MEDIUM | 5.3 | The Japanized for WooCommerce plugin for WordPress is vulnerable to unauthorized modification of data due to a missing c… | — | wordfence |
| 4bdac6c7-ae50-44e8-aab6-5d8597111d71 | < 1.16.8 |
MEDIUM | 5.3 | The ERP plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in ver… | — | wordfence |
| 4bc58312-ef3d-487b-87fb-9a15a8c6559f | < 14.11 |
MEDIUM | 5.3 | The CformsII plugin for WordPress is vulnerable to CAPTCHA Bypass in versions up to, and including, 14.10.1. This is due… | — | wordfence |
| 4bb9f98e-c223-4ee4-a2da-b1a62d995410 | < 1.0.11 |
MEDIUM | 5.3 | The Connector to CiviCRM with CiviMcRestFace plugin for WordPress is vulnerable to unauthorized access due to a missing … | — | wordfence |
| 4bb43aad-e3ac-4b32-a3c3-e3b6fce209fe | < 6.1.1 |
MEDIUM | 5.3 | The Event Post plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function… | — | wordfence |
| 4bb046c1-a0dd-4d2f-952f-953c5be0a7a2 | < 3.0.2 |
MEDIUM | 5.3 | The wpForo Forum plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a functi… | — | wordfence |
| 4b9abbf1-d9f5-4406-9d0c-bc2f9891d0e8 | < 3.1.0 |
MEDIUM | 5.3 | The WP Cookie Consent ( for GDPR, CCPA & ePrivacy ) plugin for WordPress is vulnerable to unauthorized loss of data due … | — | wordfence |
| 4b71a48c-f041-47be-b2e7-6e8b2951e526 | MEDIUM | 5.3 | The HotStar β MultiPurpose Business WordPress Theme theme for WordPress is vulnerable to unauthorized access due to a … | — | wordfence |
EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.
Scan My Website →