Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.
40,383 vulnerabilities found (page 1207 of 1616)
| CVE ID | Plugin / Theme | Severity | CVSS | Description | Fixed In | Source |
|---|---|---|---|---|---|---|
| 3bd5652e-1c26-4952-9119-1d7f7eff7d55 | MEDIUM | 5.3 | The Diet Calorie Calculator plugin for WordPress is vulnerable to unauthorized access due to a missing capability check … | — | wordfence | |
| 3bd3e797-5e31-4f54-a28f-2525fb5e367e | MEDIUM | 5.3 | The WooCommerce Coupon Popup, SmartBar, Slide In | MyShopKit plugin for WordPress is vulnerable to Sensitive Information… | — | wordfence | |
| 3bc9f344-b605-4257-8d77-e073f85fe344 | < 2.7.5 |
MEDIUM | 5.3 | The CorvusPay WooCommerce Payment Gateway plugin for WordPress is vulnerable to Payment Bypass via Improper Verification… | — | wordfence |
| 3bb15611-85a4-4efb-81e5-7352c348c4a9 | < 2.0.29 |
MEDIUM | 5.3 | The Blocksy Companion plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and includ… | — | wordfence |
| 3ba3cf12-facb-479b-8077-fd279c40607e | < 1.3.81 |
MEDIUM | 5.3 | The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to unauthorized access of data due to a miss… | — | wordfence |
| 3b6b1b7e-2ba4-4b72-9e3d-b54c00437cac | < 2.33.2 |
MEDIUM | 5.3 | The GiveWP plugin for WordPress is vulnerable to unauthorized donation form access due to a missing check on the handleB… | — | wordfence |
| 3b5fc0ac-7a33-48da-8b0f-566b9eb0f17f | < 0.17 |
MEDIUM | 5.3 | The If Menu plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on… | — | wordfence |
| 3b44d23c-4872-491f-8a91-b0feb888ac54 | < 3.1.3 |
MEDIUM | 5.3 | The WP Dummy Content Generator plugin for WordPress is vulnerable to unauthorized modification of data due to missing ca… | — | wordfence |
| 3b2f8726-c4c4-4ed6-aa8d-4412cf5be061 | < 7.8.6 |
MEDIUM | 5.3 | The Hustle – Email Marketing, Lead Generation, Optins, Popups plugin for WordPress is vulnerable to unauthorized form … | — | wordfence |
| 3af5f238-9b2f-47d0-89e6-30ac09227041 | < 6.0.9.4 |
MEDIUM | 5.3 | The RegistrationMagic – Custom Registration Forms, User Registration, Payment, and User Login plugin for WordPress is … | — | wordfence |
| 3aecea73-d905-428f-95e5-40f18db09edc | < 1.2.0 |
MEDIUM | 5.3 | The Bopo – WooCommerce Product Bundle Builder plugin for WordPress is vulnerable to Sensitive Information Exposure in … | — | wordfence |
| 3ae457da-a276-4bca-ae3f-c2f3e4fc45a0 | MEDIUM | 5.3 | The WP Genealogy – Your Family History Website plugin for WordPress is vulnerable to unauthorized access due to a miss… | — | wordfence | |
| 3acab2e6-c6ce-4e87-aa6d-ce9d027cd774 | < 1.7.07 |
MEDIUM | 5.3 | The Booking Package plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a fun… | — | wordfence |
| 3aa1964e-97e9-4166-89d5-788b336790b6 | MEDIUM | 5.3 | The Find Unused Images plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check… | — | wordfence | |
| 3a998de7-fa46-495c-a4ca-15df4e59457f | < 3.3.2 |
MEDIUM | 5.3 | The Block Plugin Update plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and includin… | — | wordfence |
| 3a7e8afa-d250-41b1-aa34-555fb458e359 | < 2.13 |
MEDIUM | 5.3 | Multiple plugins for WordPress are vulnerable to Sensitive Information Exposure in various versions via invoices. This m… | — | wordfence |
| 3a7524ce-cd8c-45af-b07b-616f63a62bd5 | < 3.5.0 |
MEDIUM | 5.3 | The Everest Forms plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and including,… | — | wordfence |
| 3a703fc4-6c61-442e-a637-515e9f501575 | < 5.6.4 |
MEDIUM | 5.3 | The Element Pack Elementor Addons (Header Footer, Template Library, Dynamic Grid & Carousel, Remote Arrows) plugin for W… | — | wordfence |
| 3a6221e3-e26b-46b2-8e67-b2afe65bc3d9 | MEDIUM | 5.3 | The Paymob for WooCommerce plugin for WordPress is vulnerable to unauthorized access due to a missing capability check o… | — | wordfence | |
| 3a4c36d4-5d0f-4e73-b356-0b7326fcb524 | < 2.7.6 |
MEDIUM | 5.3 | The Smush Image Compression and Optimization plugin before 2.7.6 for WordPress allows directory traversal. | — | wordfence |
| 3a442498-0f80-4373-a90c-155966c04945 | MEDIUM | 5.3 | The Social Share, Social Login and Social Comments Plugin – Super Socializer plugin for WordPress is vulnerable to una… | — | wordfence | |
| 3a3597fa-71e2-4753-b226-5d95e576947a | MEDIUM | 5.3 | The Store Locator Plus® for WordPress plugin for WordPress is vulnerable to Sensitive Information Exposure in all versi… | — | wordfence | |
| 3a337765-b6ea-4c2a-9f1a-e408a9444b88 | < 7.3.15.727 |
MEDIUM | 5.3 | The FV Flowplayer Video Player plugin before 7.3.15.727 for WordPress allows guests to obtain the email subscription lis… | — | wordfence |
| 3a1f192c-de8d-47e7-8055-bb64394e9a29 | MEDIUM | 5.3 | The Chaplin theme for WordPress is vulnerable to unauthorized access in all versions up to, and including, 2.6.8. This i… | — | wordfence | |
| 3a1d0432-aff0-477e-aa6e-4de3e4d789cb | MEDIUM | 5.3 | The Simple User Capabilities plugin for WordPress is vulnerable to unauthorized modification of data due to a missing ca… | — | wordfence |
EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.
Scan My Website →