Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.
40,383 vulnerabilities found (page 1202 of 1616)
| CVE ID | Plugin / Theme | Severity | CVSS | Description | Fixed In | Source |
|---|---|---|---|---|---|---|
| 4419f975-fb8d-4603-9e16-122fbd7cfdae | < 1.7.7 |
MEDIUM | 5.3 | The FundEngine β Donation and Crowdfunding Platform plugin for WordPress is vulnerable to unauthorized access due to a… | — | wordfence |
| 440e2618-5b45-4bad-8a97-2fb1a6e991ea | < 1.4.0 |
MEDIUM | 5.3 | The Backup Bolt plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and includin… | — | wordfence |
| 4402fb12-326b-4332-83e6-493a65743c61 | < 2.2.4 |
MEDIUM | 5.3 | The Audio Editor & Recorder plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, … | — | wordfence |
| 43f38a87-ac2c-4b5a-9559-d529c4b2799c | < 3.9.6 |
MEDIUM | 5.3 | The Simple Download Monitor WordPress plugin before 3.9.6 saves logs in a predictable location, and does not have any au… | — | wordfence |
| 43f34d3b-ed55-48d1-9074-b33f166e333e | < 3.16.6 |
MEDIUM | 5.3 | The 12 Step Meeting List plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and… | — | wordfence |
| 43daaaf7-8086-448a-be99-ee1959ef0fb4 | < 5.4.9 |
MEDIUM | 5.3 | The Woffice Core plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a functi… | — | wordfence |
| 43d8904f-3bc9-4c67-b44b-8d78762b6b30 | < 3.6.1 |
MEDIUM | 5.3 | The WP Private Content Plus plugin for WordPress is vulnerable to information disclosure in all versions up to, and incl… | — | wordfence |
| 43d1264a-2265-4423-a643-7ef6436d3764 | < 3.30 |
MEDIUM | 5.3 | The Media Library Assistant plugin for WordPress is vulnerable to limited file reading in all versions up to, and includ… | — | wordfence |
| 43c781c3-dc3e-4258-b594-689d0035cab0 | < 3.7.5 |
MEDIUM | 5.3 | wp-includes/class-phpass.php in WordPress before 3.7.5, 3.8.x before 3.8.5, 3.9.x before 3.9.3, and 4.x before 4.0.1 all… | — | wordfence |
| 439ce99c-79d3-4e1c-8f6e-7f68b017ac8c | MEDIUM | 5.3 | The The E-Commerce ERP: Purchasing, Inventory, Fulfillment, Manufacturing, BOM, Accounting, Sales Analysis plugin for Wo… | — | wordfence | |
| 438dfea4-21f1-4796-9c1b-81aebd8842f2 | < 5.27.6.1 |
MEDIUM | 5.3 | The Event Tickets and Registration plugin for WordPress is vulnerable to unauthorized access due to a missing capability… | — | wordfence |
| 4360f293-201c-40c1-9603-931d72cc79bc | MEDIUM | 5.3 | The Reuters Direct plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability c… | — | wordfence | |
| 432ac3b1-8f1d-442f-8e8d-62a1f26ba259 | < 3.4.1 |
MEDIUM | 5.3 | The ElementsKit Elementor addons plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up… | — | wordfence |
| 4319fa2e-8826-4100-9156-cbe80582367e | < 3.4.9.4 |
MEDIUM | 5.3 | The WP-Members Membership Plugin plugin for WordPress is vulnerable to Information Exposure in all versions up to, and i… | — | wordfence |
| 42dacd44-f676-4d2d-ad7d-9dc5b4af6d8a | < 2.0.9 |
MEDIUM | 5.3 | The All In One Login β WP Admin Login Page Security and Customization with Google reCAPTCHA, Social Login, Limit Login… | — | wordfence |
| 42cd1b53-400f-4933-b3cc-2fd9079e241c | < 2.3.8 |
MEDIUM | 5.3 | The WP Express Checkout (Accept PayPal Payments) plugin for WordPress is vulnerable to price manipulation in all version… | — | wordfence |
| 42aa82ff-0d37-4040-b8fc-84d29534a4b7 | < 4.2.8.5 |
MEDIUM | 5.3 | The EventPrime plugin for WordPress is vulnerable to unauthorized image file upload in all versions up to, and including… | — | wordfence |
| 428feddb-c8c3-49a7-8e01-dc548c184229 | < 1.24.7 |
MEDIUM | 5.3 | The Import and export users and customers plugin for WordPress is vulnerable to unauthorized modification of data due to… | — | wordfence |
| 4279efe9-df57-405a-85a0-6c22e912662c | < 4.7.0 |
MEDIUM | 5.3 | The WooCommerce plugin before 4.7.0 for WordPress allows remote attackers to view the status of arbitrary orders via the… | — | wordfence |
| 426554d8-e6dc-496f-adce-61a22880a4c2 | < 3.71.0 |
MEDIUM | 5.3 | The FG Drupal to WordPress plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, a… | — | wordfence |
| 4261bc62-a091-408b-8643-e6fa61d62103 | < 2.2.23 |
MEDIUM | 5.3 | The WPCafe plugin for WordPress is vulnerable to unauthorized access, modification, or loss of data due to a missing cap… | — | wordfence |
| 424cf586-f225-4ce3-9b66-b0bece394f1f | < 3.1.1 |
MEDIUM | 5.3 | The wpForo Forum plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a functi… | — | wordfence |
| 424b0de2-98ac-434f-98be-d2b0eec308ce | MEDIUM | 5.3 | The Saoshyant Page Builder plugin for WordPress is vulnerable to unauthorized access due to a missing capability check o… | — | wordfence | |
| 41de0cf6-d093-4c33-8123-a097ba3e0add | < 1.7.6 |
MEDIUM | 5.3 | The TrackShip for WooCommerce plugin for WordPress is vulnerable to unauthorized access due to a missing capability chec… | — | wordfence |
| 41db1af4-7a49-4d10-8538-151d3bb7af8f | < 3.1.4 |
MEDIUM | 5.3 | The avalex β Automatisch sichere Rechtstexte plugin for WordPress is vulnerable to unauthorized access due to a missin… | — | wordfence |
EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.
Scan My Website →