Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.
40,383 vulnerabilities found (page 1218 of 1616)
| CVE ID | Plugin / Theme | Severity | CVSS | Description | Fixed In | Source |
|---|---|---|---|---|---|---|
| 274563e0-7480-460b-bd95-daa64ad45d83 | < 4.4.2 |
MEDIUM | 5.3 | The GetGenie β AI Content Writer with Keyword Research & SEO Tracking plugin for WordPress is vulnerable to Sensitive … | — | wordfence |
| 2737f24e-acba-4d4b-897b-338a69a83d72 | < 1.4.24 |
MEDIUM | 5.3 | The Support Genix β Helpdesk & Customer Support Ticket System plugin for WordPress is vulnerable to unauthorized acces… | — | wordfence |
| 26f34aa0-8584-4156-b084-d34a0ab0a997 | < 1.3.0 |
MEDIUM | 5.3 | The Helpfulcrowd Product Reviews plugin for WordPress is vulnerable to Authorization Bypass via PHP Type Juggling in ver… | — | wordfence |
| 26df8fba-6185-42d1-b137-91cae2674a3e | < 2.9.3 |
MEDIUM | 5.3 | The HT Contact Form β Drag & Drop Form Builder for WordPress plugin for WordPress is vulnerable to Sensitive Informati… | — | wordfence |
| 26dea1d5-31aa-47a8-927c-98391fbc9506 | MEDIUM | 5.3 | The Bulk Assign Linked Products For WooCommerce plugin for WordPress is vulnerable to unauthorized access due to a missi… | — | wordfence | |
| 26db2d25-01b8-49c5-a4d6-284780ac97bb | < 1.5.6 |
MEDIUM | 5.3 | The GP Unique ID plugin for WordPress is vulnerable to Unique ID Modification in all versions up to, and including, 1.5.… | — | wordfence |
| 26c19bd3-32ea-4e28-9cde-1a6653acf6f1 | < 3.6.3.1 |
MEDIUM | 5.3 | The JetFormBuilder β Dynamic Blocks Form Builder plugin for WordPress is vulnerable to authorization bypass in all ver… | — | wordfence |
| 26c17858-90b9-48ec-bb0c-7e797822dec5 | < 2.0.1 |
MEDIUM | 5.3 | The Jetpack Debug Helper plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on … | — | wordfence |
| 26bd4058-ef00-48c8-8ab5-01535f0238a4 | < 8.5.7 |
MEDIUM | 5.3 | The NEX-Forms β Ultimate Form Builder β Contact forms and much more plugin for WordPress is vulnerable to unauthoriz… | — | wordfence |
| 26b13067-540f-4ac2-904a-5c9e39622280 | < 3.1.0 |
MEDIUM | 5.3 | The JetReviews plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and including, 3.… | — | wordfence |
| 26a7f3e9-de7b-43bd-8bb8-972b0df75324 | < 3.2.23 |
MEDIUM | 5.3 | The Membership Plugin β Restrict Content plugin for WordPress is vulnerable to unauthorized access due to a missing ca… | — | wordfence |
| 26963b32-db2c-430b-99e5-65a2cc7d478d | < 4.7.3 |
MEDIUM | 5.3 | The Defender Security plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capabilit… | — | wordfence |
| 268148ec-ab8a-4912-8250-1d40062b01a8 | < 3.5.2 |
MEDIUM | 5.3 | The SupportCandy β AI Customer Support Ticket System & Live Chatbot Agent plugin for WordPress is vulnerable to unauth… | — | wordfence |
| 2638bb80-7066-45c0-ab74-4ba407d50cae | < 1.6.4 |
MEDIUM | 5.3 | guzzlehttp/psr7 is a PSR-7 HTTP message library implementation in PHP. Affected versions are subject to improper header … | — | wordfence |
| 263324cb-31b7-40ad-ad7d-4582e128cd75 | < 2.8.8 |
MEDIUM | 5.3 | The ShopLentor (formerly WooLentor) plugin for WordPress is vulnerable to unauthorized access of data due to a missing c… | — | wordfence |
| 26289a93-063b-469a-9d09-c286d76fce0c | < 3.9.0 |
MEDIUM | 5.3 | The Tutor LMS β eLearning and online course solution plugin for WordPress is vulnerable to unauthorized modification o… | — | wordfence |
| 2626db42-0047-4801-bbcb-e236440c1677 | < 1.3.95 |
MEDIUM | 5.3 | The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to IP Address Spoofing in all versions up to… | — | wordfence |
| 26255cd9-2361-4d17-8d1b-9bdadcc69043 | < 2.11.25 |
MEDIUM | 5.3 | The Welcart e-Commerce plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability che… | — | wordfence |
| 261d6d44-8e3b-4715-96c0-1c42d08662fa | < 1.9.0 |
MEDIUM | 5.3 | The Subscriptions for WooCommerce plugin for WordPress is vulnerable to unauthorized access due to a missing capability … | — | wordfence |
| 260119d4-7373-4329-ab31-a3cb3a1500f3 | MEDIUM | 5.3 | The HelloLeads CRM Form Shortcode plugin for WordPress is vulnerable to unauthorized modification of data due to a missi… | — | wordfence | |
| 25d5735a-8eed-4b4a-9bbe-9e42fb18ddf2 | < 1.2.8 |
MEDIUM | 5.3 | The FormCraft plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check … | — | wordfence |
| 25d56d0f-2995-4a46-94e7-17a945ec4353 | MEDIUM | 5.3 | The Block Spam By Math Reloaded plugin for WordPress is vulnerable to unauthorized use of functionality due to a missing… | — | wordfence | |
| 25adfac4-acba-4ba9-a824-eb8661b2a557 | MEDIUM | 5.3 | The Prowess theme for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in … | — | wordfence | |
| 25acd3d9-0c1a-426e-b670-b842f031bdc5 | MEDIUM | 5.3 | The Propovoice: All-in-One Client Management System plugin for WordPress is vulnerable to Insecure Direct Object Referen… | — | wordfence | |
| 25abca87-1be2-427e-ab01-377d52917052 | < 2.5.1 |
MEDIUM | 5.3 | The Debug Log Manager β Conveniently Monitor and Inspect Errors plugin for WordPress is vulnerable to Improper Output … | — | wordfence |
EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.
Scan My Website →