Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.
40,383 vulnerabilities found (page 1220 of 1616)
| CVE ID | Plugin / Theme | Severity | CVSS | Description | Fixed In | Source |
|---|---|---|---|---|---|---|
| 23d5e2ba-3a8a-4ded-aba9-fa0a7228a398 | < 1.8.1 |
MEDIUM | 5.3 | The Slideshow Gallery LITE plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, a… | — | wordfence |
| 23d49ee8-9afb-479a-85e7-a83cd5ae5186 | < 1.7.9 |
MEDIUM | 5.3 | The WooCommerce POS β Point of Sale plugin for WordPress is vulnerable to unauthorized access due to a missing capabil… | — | wordfence |
| 23a9b6ee-55d9-4e44-926b-f253e83ca78c | MEDIUM | 5.3 | The HomeFix Elementor Portfolio plugin for WordPress is vulnerable to unauthorized access due to a missing capability ch… | — | wordfence | |
| 23a1dad4-599e-4d3f-b1d5-c77ec1bbcf22 | < 4.0.8 |
MEDIUM | 5.3 | The Cookie Banner, Cookie Consent, Consent Log, Cookie Scanner, Script Blocker (for GDPR, CCPA & ePrivacy) : WP Cookie C… | — | wordfence |
| 2389f614-a9e6-479c-a713-71271d3a35c6 | < 2.2.13 |
MEDIUM | 5.3 | The Sign-up Sheets plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability c… | — | wordfence |
| 234df811-92d9-4645-b242-eb2c09bc6202 | < 6.1.8 |
MEDIUM | 5.3 | The Awesome Support plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a fun… | — | wordfence |
| 233f3415-9d4f-4ddb-af69-55c832ff67a1 | < 4.3.8 |
MEDIUM | 5.3 | The User Frontend: AI Powered Frontend Post Submission, User Directory, User Profile, Membership & User Registration plu… | — | wordfence |
| 233aab46-ec09-4c26-b4fc-2f095c225754 | < 2.3.9 |
MEDIUM | 5.3 | The Everest Backup plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a func… | — | wordfence |
| 231f1e11-661d-40e4-a139-0ee2be95d551 | < 3.2.13 |
MEDIUM | 5.3 | The MasterStudy LMS plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability … | — | wordfence |
| 2305462c-0a00-4423-8dc2-e32628c4864d | < 7.8.11 |
MEDIUM | 5.3 | The Hustle β Email Marketing, Lead Generation, Optins, Popups plugin for WordPress is vulnerable to unauthorized modif… | — | wordfence |
| 22f58318-90ce-4f98-991c-1270d6768f5c | MEDIUM | 5.3 | The Register Plus plugin 3.5.11 and earlier for WordPress allows remote attackers to obtain sensitive information via a … | — | wordfence | |
| 22f54e4b-2f9a-40b2-b1d2-38f046b71a05 | < 2.162 |
MEDIUM | 5.3 | The MyCryptoCheckout β Bitcoin, Ethereum, and 100+ altcoins for WooCommerce plugin for WordPress is vulnerable to unau… | — | wordfence |
| 22e1be31-7a05-4089-9830-c27b70176e76 | MEDIUM | 5.3 | The EscortWP theme for WordPress contains a backdoor in all versions up to, and including, 3.6.2. This makes it possible… | — | wordfence | |
| 22b17fcb-0c97-462d-b67c-6da2919478d5 | < 1.30.1 |
MEDIUM | 5.3 | The Social Pug plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check… | — | wordfence |
| 22a73d1a-02ba-4453-a2c8-0b79a75313f6 | < 4.9.0 |
MEDIUM | 5.3 | The CoCart β Headless REST API for WooCommerce plugin for WordPress is vulnerable to unauthorized access due to a miss… | — | wordfence |
| 2294251f-ef51-4ef7-ad7a-905cc2bc00b3 | < 3.3.9 |
MEDIUM | 5.3 | The Yet Another Stars Rating plugin for WordPress is vulnerable to vote tampering in versions up to, and including, 3.3.… | — | wordfence |
| 228a3c72-fbb0-48bc-8066-6ca954a14421 | < 1.64 |
MEDIUM | 5.3 | The Push Notification for Post and BuddyPress plugin for WordPress is vulnerable to unauthorized modification of data du… | — | wordfence |
| 2283b147-b904-4086-8cb1-6d8969ccbaf6 | < 1.50.3 |
MEDIUM | 5.3 | The Forminator plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function… | — | wordfence |
| 228079da-3c69-423c-b69b-f1a670258772 | MEDIUM | 5.3 | The Obfuscate Email plugin for WordPress is vulnerable to Full Path Disclosure in all versions up to, and including, 3.8… | — | wordfence | |
| 22738841-b25c-4519-9b94-e64a3fdf6cea | < 2.1.0 |
MEDIUM | 5.3 | The Minimum and Maximum Quantity for WooCommerce plugin for WordPress is vulnerable to unauthorized access due to a miss… | — | wordfence |
| 226c312e-38f0-4dac-bf5a-bce6df24aacc | < 2.2.1 |
MEDIUM | 5.3 | The Pixel Tag Manager for WooCommerce β Google Analytics 4, Google Ads, and More Pixels plugin for WordPress is vulner… | — | wordfence |
| 224a3ca4-954e-4e39-adc7-2a37d1a7a026 | MEDIUM | 5.3 | The Javo Core plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function … | — | wordfence | |
| 22345e9c-e654-4c72-b452-ed340f9ef6c1 | MEDIUM | 5.3 | The GDPR Cookie Notice plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a … | — | wordfence | |
| 223373fc-9d78-47f0-b283-109f8e00b802 | MEDIUM | 5.3 | The Transposh WordPress Translation plugin for WordPress is vulnerable to unauthorized setting changes by unauthenticate… | — | wordfence | |
| 222f9d6b-2b97-4531-b085-bf3c8f9d89d7 | < 4.8.122 |
MEDIUM | 5.3 | The Masterstudy - Education WordPress Theme theme for WordPress is vulnerable to unauthorized access due to a missing ca… | — | wordfence |
EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.
Scan My Website →