Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.
40,383 vulnerabilities found (page 1204 of 1616)
| CVE ID | Plugin / Theme | Severity | CVSS | Description | Fixed In | Source |
|---|---|---|---|---|---|---|
| 4077dd33-bd3c-4369-b9ed-b6b6b017248d | < 6.8.5 |
MEDIUM | 5.3 | The Travel Engine plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions up to, and includin… | — | wordfence |
| 40725a33-353e-443a-b1f1-ac7c3e4a1323 | < 1.1.6 |
MEDIUM | 5.3 | The Coachify theme for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in… | — | wordfence |
| 40588454-66f3-4c84-98b4-11b81e019908 | < 5.0.11 |
MEDIUM | 5.3 | The MultiVendorX β WooCommerce Multivendor Marketplace AI Powered Solutions plugin for WordPress is vulnerable to unau… | — | wordfence |
| 40570bb7-1638-4305-876e-86ad4c336944 | < 1.4.8 |
MEDIUM | 5.3 | The WordPress Backup & Migration plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up… | — | wordfence |
| 4051a7f1-0564-41eb-8ef4-0ee1c8af57cb | MEDIUM | 5.3 | The Clockinator Lite plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a fu… | — | wordfence | |
| 4048ae11-fece-42aa-baf3-c636c4875635 | < 1.4.6 |
MEDIUM | 5.3 | The Database for Contact Form 7, WPforms, Elementor forms plugin for WordPress is vulnerable to authorization bypass due… | — | wordfence |
| 4045575a-35f0-46e5-afb7-93eee9be3a97 | MEDIUM | 5.3 | The Infinite-Scroll plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and includin… | — | wordfence | |
| 4031f857-9712-4f4a-93e8-0b01f9a9c32d | < 0.9.9 |
MEDIUM | 5.3 | The Database Cleaner: Clean, Optimize & Repair plugin for WordPress is vulnerable to Sensitive Information Exposure in a… | — | wordfence |
| 402f1f9f-35c7-4304-891b-a07f3e84c189 | < 2.7.5 |
MEDIUM | 5.3 | The CorvusPay WooCommerce Payment Gateway plugin for WordPress is vulnerable to authorization bypass in all versions up … | — | wordfence |
| 4000c0e4-6ffd-4161-b488-429e0e863f68 | < 1.0.45 |
MEDIUM | 5.3 | The Appointment Booking Calendar β WP Timetics Booking Plugin plugin for WordPress is vulnerable to unauthorized acces… | — | wordfence |
| 3ff90774-f5f6-4d9c-9565-1cff31f9bec4 | MEDIUM | 5.3 | The DAP to Autoresponders Email Syncing plugin for WordPress is vulnerable to Sensitive Information Exposure in all vers… | — | wordfence | |
| 3ff3c560-26b6-4139-97dc-670ea9b8bb33 | < 4.11.0 |
MEDIUM | 5.3 | The Co-Authors, Multiple Authors and Guest Authors in an Author Box with PublishPress Authors plugin for WordPress is vu… | — | wordfence |
| 3fe1313c-1368-4bcb-9d11-25b948da5547 | MEDIUM | 5.3 | The Advanced Text Widget plugin for WordPress is vulnerable to unauthorized admin notice dismisssal due to a missing ca… | — | wordfence | |
| 3fc683c5-6939-4750-aba2-0e1f3b33ab5a | < 3.7.40 |
MEDIUM | 5.3 | The MasterStudy LMS WordPress Plugin β for Online Courses and Education plugin for WordPress is vulnerable to unauthor… | — | wordfence |
| 3fbda86c-188c-4705-a7eb-77b201f91a18 | MEDIUM | 5.3 | The Nuss - Hotel Booking WordPress theme for WordPress is vulnerable to unauthorized access due to a missing capability … | — | wordfence | |
| 3fa78f4e-ede2-4863-a2d7-99bd8c7b5912 | < 2.25.2 |
MEDIUM | 5.3 | The Relevanssi β A Better Search plugin for WordPress is vulnerable to Information Exposure in all versions up to, and… | — | wordfence |
| 3fa5ddd8-8166-45eb-9576-8683c1d12cc6 | MEDIUM | 5.3 | The Advanced Contact Form 7 - Compact DB plugin for WordPress is vulnerable to unauthorized deletion of data due to a mi… | — | wordfence | |
| 3fa1afa6-f9b5-4153-ab0b-8fd5291f63d7 | < 3.6.4 |
MEDIUM | 5.3 | The Virtuaria PagBank / PagSeguro para Woocommerce plugin for WordPress is vulnerable to unauthorized access due to a mi… | — | wordfence |
| 3fa0dbad-fc00-46f1-bcc4-b41116d1c4ae | < 2.3.12 |
MEDIUM | 5.3 | The ZoloBlocks β Gutenberg Block Editor Plugin with Advanced Blocks, Dynamic Content, Templates & Patterns plugin for … | — | wordfence |
| 3f95c288-7710-46aa-898b-a923afa7a4ab | < 1.8.3 |
MEDIUM | 5.3 | The AI Power: Complete AI Pack β Powered by GPT-4 plugin for WordPress is vulnerable to unauthorized access due to a m… | — | wordfence |
| 3f82427e-5731-4694-8d90-4d14c01f19fb | < 1.8.17.0 |
MEDIUM | 5.3 | The WP Mailster plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and includin… | — | wordfence |
| 3f7088ce-961c-4cf3-ab94-3ef9a626006b | < 1.6.0 |
MEDIUM | 5.3 | The Chat Widget: Floating Customer Support Button for 30+ Channels, Supporting SMS, Calls, and Chat β Bit Assist plugi… | — | wordfence |
| 3f6412bf-65ec-445f-a1fe-27aeb8330712 | < 8.4.6 |
MEDIUM | 5.3 | The Soledad theme for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in … | — | wordfence |
| 3f6058e2-a5ec-43b2-9cb7-9efcf0853ffc | < 1.10.36 |
MEDIUM | 5.3 | The WS Form LITE β Drag & Drop Contact Form Builder for WordPress plugin for WordPress is vulnerable to unauthorized a… | — | wordfence |
| 3f445e0e-c32d-4c46-85ac-fa21f99d30ec | MEDIUM | 5.3 | The WP2Speed Faster β Optimize PageSpeed Insights Score 90-100 plugin for WordPress is vulnerable to Sensitive Informa… | — | wordfence |
EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.
Scan My Website →