Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.
40,383 vulnerabilities found (page 1217 of 1616)
| CVE ID | Plugin / Theme | Severity | CVSS | Description | Fixed In | Source |
|---|---|---|---|---|---|---|
| 291b44d1-c63c-4278-b344-a361f88e82d1 | < 4.7.16 |
MEDIUM | 5.3 | The MasterStudy LMS Pro plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a… | — | wordfence |
| 29137748-91b1-4b01-9f05-63da592e941a | < 2.2.12 |
MEDIUM | 5.3 | The WP Club Manager plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability … | — | wordfence |
| 2903d15c-4f4d-497c-b6ed-4ae32c047a8a | < 7.6.10 |
MEDIUM | 5.3 | The Admin and Site Enhancements (ASE) plugin for WordPress is vulnerable to IP Address Spoofing in all versions up to, a… | — | wordfence |
| 28f22a48-7445-4104-9b76-60520e7a290e | < 6.4.2 |
MEDIUM | 5.3 | The Coupon Affiliates β Affiliate Plugin for WooCommerce plugin for WordPress is vulnerable to unauthorized access due… | — | wordfence |
| 28d9ab98-c1ab-45ee-a371-6598a8347b10 | MEDIUM | 5.3 | The WordPress Portfolio Builder β Portfolio Gallery plugin for WordPress is vulnerable to unauthorized modification of… | — | wordfence | |
| 28ca9590-dc0b-40c9-9de6-1480094ea8be | < 2.14.18 |
MEDIUM | 5.3 | The Import WP β Export and Import CSV and XML files to WordPress plugin for WordPress is vulnerable to Sensitive Infor… | — | wordfence |
| 28bcaf28-bb75-4d55-9e9b-afa760fc793e | < 2.7 |
MEDIUM | 5.3 | wp-admin/upgrade.php in WordPress up to and including 2.6.1, allows remote attackers to upgrade the application, and pos… | — | wordfence |
| 28a7b80c-8282-4f5c-b442-d6bce9fda25d | MEDIUM | 5.3 | The Ripe HD FLV plugin for WordPress is vulnerable to Sensitive Data Exposure in versions up to, and including, 1.1 via … | — | wordfence | |
| 28a3f382-3801-4e98-9004-56c27a85f0a2 | < 5.7.9 |
MEDIUM | 5.3 | The Shopping Cart & eCommerce Store plugin for WordPress is vulnerable to unauthorized modification of data due to a mis… | — | wordfence |
| 2880cde0-a278-4a41-97f7-c54c2b3aceb2 | < 2.4.30 |
MEDIUM | 5.3 | The Piotnet Addons For Elementor plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up… | — | wordfence |
| 2866122e-158e-4a60-9f80-3d88832bedc0 | < 2.2.0 |
MEDIUM | 5.3 | The Raychat plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in… | — | wordfence |
| 2862d7d6-4e27-4138-b4aa-789351edeac3 | MEDIUM | 5.3 | The Voting Contest plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a func… | — | wordfence | |
| 28206bc1-008f-407e-b1c9-e318abe09438 | < 2.3.0 |
MEDIUM | 5.3 | The Endless Posts Navigation plugin for WordPress is vulnerable to unauthorized access due to a missing capability check… | — | wordfence |
| 281a1c0e-bbd8-4cf6-94ca-b888c7d7e3af | < 10.14.11 |
MEDIUM | 5.3 | The Booking Calendar plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and inc… | — | wordfence |
| 280e9ba9-57a9-45ce-820c-c34cac41b350 | < 3.1.2 |
MEDIUM | 5.3 | The Events Made Easy plugin for WordPress is vulnerable to Payment Bypass in versions up to, and including, 3.1.1. This … | — | wordfence |
| 280da91d-f97e-49ad-811d-849943c8a9f1 | < 19.12.1 |
MEDIUM | 5.3 | The Poll, Survey & Quiz Maker Plugin by Opinion Stage plugin for WordPress is vulnerable to unauthorized access due to a… | — | wordfence |
| 27e4d519-bc98-44d3-a519-72674184e7f2 | < 3.2.11 |
MEDIUM | 5.3 | The MasterStudy LMS WordPress Plugin β for Online Courses and Education plugin for WordPress is vulnerable to Informat… | — | wordfence |
| 27e3dfe3-ad33-4d0c-a999-d0734df2f59b | < 5.104.0 |
MEDIUM | 5.3 | The Customer Reviews for WooCommerce plugin for WordPress is vulnerable to authentication bypass in all versions up to, … | — | wordfence |
| 27d0f627-aeee-46de-a319-861af00fdbf4 | < 7.2.8 |
MEDIUM | 5.3 | The Link Library WordPress plugin before 7.2.8 does not have authorisation in place when deleting links, allowing unauth… | — | wordfence |
| 27ca93a1-3dfc-4bbd-834a-1c04d9e22ebf | < 1.2.2 |
MEDIUM | 5.3 | The Vayu Blocks β Gutenberg Blocks for WordPress & WooCommerce plugin for WordPress is vulnerable to unauthorized acce… | — | wordfence |
| 27c728eb-db40-41e1-b73b-243661b15970 | MEDIUM | 5.3 | The Add Product Frontend for WooCommerce plugin for WordPress is vulnerable to unauthorized access due to a missing capa… | — | wordfence | |
| 279cebb5-4be4-485a-92c7-e0bcc961f93e | < 2.6.1 |
MEDIUM | 5.3 | The Fat Rat Collect plugin for WordPress is vulnerable to unauthorized action due to a missing capability check on the w… | — | wordfence |
| 2791bbd5-9101-4484-a352-0e4d2ce04e5d | < 6.1.0 |
MEDIUM | 5.3 | The Xendit Payment plugin for WordPress is vulnerable to unauthorized order status manipulation in all versions up to, a… | — | wordfence |
| 27517985-374a-40ef-8a90-575dfc9335f3 | MEDIUM | 5.3 | The Fix Media Library plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and in… | — | wordfence | |
| 2750936e-d366-44f2-82d2-74188261466e | < 1.5.13 |
MEDIUM | 5.3 | The Panda Pods Repeater Field plugin for WordPress is vulnerable to unauthorized access due to a missing capability chec… | — | wordfence |
EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.
Scan My Website →