Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.
40,383 vulnerabilities found (page 1200 of 1616)
| CVE ID | Plugin / Theme | Severity | CVSS | Description | Fixed In | Source |
|---|---|---|---|---|---|---|
| 478d7c1e-35b9-4796-8ccd-eb02591a3a17 | < 3.0.7 |
MEDIUM | 5.3 | The wpForo Forum plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a functi… | — | wordfence |
| 4775d8f0-ae3b-41aa-a0d2-4284840f66f1 | < 1.3.8 |
MEDIUM | 5.3 | The Car Rental Manager β Online Vehicle Booking System plugin for WordPress is vulnerable to unauthorized access due t… | — | wordfence |
| 47681954-37ed-493b-b4da-9e9032e561b3 | < 2.4.3 |
MEDIUM | 5.3 | The got (JS Package) is vulnerable to Open Redirect in versions up to, and including, 11.8.4 as well as from 12 to below… | — | wordfence |
| 4756312e-2e34-4524-b978-fa37e3cafd1f | < 1.2 |
MEDIUM | 5.3 | The Awesome Responsive Photo Gallery β Image & Video Lightbox Gallery plugin for WordPress is vulnerable to unauthoriz… | — | wordfence |
| 4735c491-9595-42b8-bb1c-1b18c89fcf7a | < 5.2 |
MEDIUM | 5.3 | The BulletProof Security WordPress plugin is vulnerable to sensitive information disclosure due to a file path disclosur… | — | wordfence |
| 471e1080-e9bc-4241-ae71-8bfeac94b0b4 | MEDIUM | 5.3 | The Job Board Manager plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a f… | — | wordfence | |
| 470fb8d4-3d60-4a8e-a89b-2d64203c1f0b | < 4.2.2 |
MEDIUM | 5.3 | The Visual Website Collaboration, Feedback & Project Management β Atarim plugin for WordPress is vulnerable to Sensiti… | — | wordfence |
| 470d64e6-9dd5-4069-8b16-ea26a3b9f0e1 | < 1.3.4 |
MEDIUM | 5.3 | The The Tribal Plugin plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and in… | — | wordfence |
| 46b6dd7d-cbf7-4e8b-8ff5-347b966d8689 | MEDIUM | 5.3 | The Realbig plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in… | — | wordfence | |
| 46a36f2b-c352-4d76-b4c4-8a73ec5dd910 | < 0.1.6 |
MEDIUM | 5.3 | The 2Download Connector for 2DL Hosted Checkout plugin for WordPress is vulnerable to unauthorized access in all version… | — | wordfence |
| 467a9b16-b57c-417c-b4e1-9f3edc80b5df | < 1.6.3 |
MEDIUM | 5.3 | The Album and Image Gallery plus Lightbox plugin for WordPress is vulnerable to authorization bypass due to a missing ca… | — | wordfence |
| 4677042d-ff0a-4340-ada7-c82d2da0c01c | < 3.3.0 |
MEDIUM | 5.3 | The Klarna Payments for WooCommerce plugin for WordPress is vulnerable to unauthorized access due to a missing capabilit… | — | wordfence |
| 4662a842-88ba-4f01-8009-7248792d485b | MEDIUM | 5.3 | The Fascinate theme for WordPress is vulnerable to unauthorized access due to a missing capability check on a function i… | — | wordfence | |
| 4661566b-0729-4489-9a47-8e3e0ac73573 | MEDIUM | 5.3 | The Addonify Floating Cart For WooCommerce plugin for WordPress is vulnerable to unauthorized access due to a missing ca… | — | wordfence | |
| 4653f0fd-5369-4e3c-9bce-3f4200c0bddb | < 2.5.5 |
MEDIUM | 5.3 | The DELUCKS SEO plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability chec… | — | wordfence |
| 46525a06-f3a4-4c78-ba32-4b937e1dbac6 | < 1.15.21 |
MEDIUM | 5.3 | The Form Maker plugin for WordPress is vulnerable to Captcha Bypass in versions up to, and including, 1.15.20 due to ins… | — | wordfence |
| 464a41f6-5569-4306-be99-566e2354c73b | < 2.8.2 |
MEDIUM | 5.3 | An issue was discovered in the MailPoet Newsletters (aka wysija-newsletters) plugin before 2.8.2 for WordPress. The plug… | — | wordfence |
| 4638516e-d36f-4f31-9ed5-f733aeae03e2 | < 2.4.1 |
MEDIUM | 5.3 | The Hestia Nginx Cache plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on th… | — | wordfence |
| 461993a3-8d47-4c9e-8f5f-78058d96ab2a | < 1.9.1 |
MEDIUM | 5.3 | The Patreon WordPress plugin for WordPress is vulnerable to protection mechanism bypass in all versions up to, and inclu… | — | wordfence |
| 46186f8d-e50c-476a-9480-b6121412474a | < 2.1.0 |
MEDIUM | 5.3 | The PeproDev Ultimate Invoice plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up … | — | wordfence |
| 46122be7-5e88-4656-8944-a747f5cdc69e | < 1.1.1 |
MEDIUM | 5.3 | The CookieHub plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check … | — | wordfence |
| 4609e1a8-c766-4054-a5d0-eabff1089300 | < 5.1.3 |
MEDIUM | 5.3 | The User Registration & Membership β Free & Paid Memberships, Subscriptions, Content Restriction, User Profile, Custom… | — | wordfence |
| 4607dca0-d3b7-4fca-8f89-a0a739bd7551 | MEDIUM | 5.3 | The Birth Chart Compatibility plugin for WordPress is vulnerable to Full Path Disclosure in all versions up to, and incl… | — | wordfence | |
| 45f1e4b9-5ffb-4dca-aa79-09c664b46f00 | < 1.6.17 |
MEDIUM | 5.3 | The LocateAndFilter plugin for WordPress is vulnerable to unauthorized access of data due to insufficient verification o… | — | wordfence |
| 45ccc116-866e-467f-8ebb-8a3b6589c069 | MEDIUM | 5.3 | The Slek Gateway for WooCommerce plugin for WordPress is vulnerable to Information Exposure in version 1.0. This is due … | — | wordfence |
EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.
Scan My Website →