Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.
40,402 vulnerabilities found (page 1225 of 1617)
| CVE ID | Plugin / Theme | Severity | CVSS | Description | Fixed In | Source |
|---|---|---|---|---|---|---|
| 1c8de019-4ec1-49fd-9b0b-c2b1b6908ba8 | MEDIUM | 5.3 | The DominoKit plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the wp_ajax… | — | wordfence | |
| 1c8b8391-8d18-49ad-a5ee-2ba7a9090e6b | < 1.5.4 |
MEDIUM | 5.3 | The Video Gallery β Api Gallery, YouTube and Vimeo, Link Gallery plugin for WordPress is vulnerable to unauthorized ac… | — | wordfence |
| 1c4fcaa5-357a-4b70-8653-3874a234f07d | < 5.4.4 |
MEDIUM | 5.3 | The kk Star Ratings plugin for WordPress is vulnerable to IP Address Spoofing in versions up to, and including, 5.4.3. T… | — | wordfence |
| 1c2b9858-eb0c-42bd-bc32-c58c0f809fc8 | < 1.1.10 |
MEDIUM | 5.3 | The Networker - Tech News WordPress Theme with Dark Mode theme for WordPress is vulnerable to unauthorized modification … | — | wordfence |
| 1c220091-4094-4f72-aaf1-a426f07aef5b | < 10.30.12 |
MEDIUM | 5.3 | The Salon Booking System Pro plugin for WordPress is vulnerable to unauthorized access due to a missing capability check… | — | wordfence |
| 1c0d18d3-8758-41ae-b104-dac69eee4ac9 | < 1.1.2 |
MEDIUM | 5.3 | The TH Side Cart and Menu Cart for Woocommerce plugin for WordPress is vulnerable to unauthorized plugin settings update… | — | wordfence |
| 1c09fa88-8981-414e-ad24-7460b81ea295 | < 3.14.0 |
MEDIUM | 5.3 | The Seriously Simple Podcasting plugin for WordPress is vulnerable to unauthorized access due to a missing capability ch… | — | wordfence |
| 1befba2d-cd16-48d1-8499-d848a649cf9d | < 1.3.3 |
MEDIUM | 5.3 | The Spa and Salon theme for WordPress is vulnerable to unauthorized access due to a missing capability check on a functi… | — | wordfence |
| 1bbbec13-50ea-4dd1-ab6e-f44814813edb | < 1.2.8 |
MEDIUM | 5.3 | The Book Landing Page theme for WordPress is vulnerable to unauthorized access due to a missing capability check on a fu… | — | wordfence |
| 1bb25412-8f63-4a9d-84bd-44fac59c6eed | < 1.1.8 |
MEDIUM | 5.3 | The YourMembership Single Sign On β YM SSO Login plugin for WordPress is vulnerable to unauthorized access of data due… | — | wordfence |
| 1b9f3e68-b069-4f41-87a1-ffaa287215b9 | < 6.11.6 |
MEDIUM | 5.3 | The Simple:Press Forum plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on th… | — | wordfence |
| 1b8d866e-e187-4ff5-bed7-b03e2a213c11 | < 4.4.5 |
MEDIUM | 5.3 | The Church Admin plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability che… | — | wordfence |
| 1b847857-5dc9-4793-b9d6-759f27377fe3 | < 2.2 |
MEDIUM | 5.3 | The Void Elementor Post Grid Addon for Elementor Page builder plugin for WordPress is vulnerable to unauthorized modific… | — | wordfence |
| 1b693646-efdb-44c7-a8d8-48315d19fe23 | MEDIUM | 5.3 | The EduBlink theme for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in… | — | wordfence | |
| 1b54ce63-ea6e-40e0-a66b-9a08e81f77be | MEDIUM | 5.3 | The WDV One Page Docs plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a f… | — | wordfence | |
| 1b4eb0a1-69ad-4e0d-9760-752ec0589314 | < 2.0.8 |
MEDIUM | 5.3 | The Jetpack Carousel module of the JetPack WordPress plugin before 9.8 allows users to create a "carousel" type image ga… | — | wordfence |
| 1b245791-6aac-4ee3-9278-5b7c01f13263 | < 3.43.0 |
MEDIUM | 5.3 | The WP Fusion Lite β Marketing Automation and CRM Integration for WordPress plugin for WordPress is vulnerable to Sens… | — | wordfence |
| 1b21bdfd-42ec-43fe-b581-04276b86c50b | MEDIUM | 5.3 | The Rupantorpay plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability chec… | — | wordfence | |
| 1b1268ae-51b0-4243-9cc8-c8564c121ff2 | < 3.7.21 |
MEDIUM | 5.3 | The iZooto plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in … | — | wordfence |
| 1b05191b-4f4a-487a-9fbf-843a4787511e | MEDIUM | 5.3 | The CGC Maintenance Mode plugin for WordPress is vulnerable to IP Address Spoofing in all versions up to, and including,… | — | wordfence | |
| 1b00e42b-9c03-4a3c-86b7-1552f7700b2f | < 1.1.6 |
MEDIUM | 5.3 | The CRM Perks Forms plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability … | — | wordfence |
| 1afb94ab-b3ba-4598-8ff4-f9ffc6717371 | < 1.52.1 |
MEDIUM | 5.3 | The Forminator plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.52.0. … | — | wordfence |
| 1af442f7-b57c-47bd-9733-5e6bb5c89443 | < 5.4.6 |
MEDIUM | 5.3 | The kk Star Ratings plugin for WordPress is vulnerable to unauthorized use of functionality due to a missing capability … | — | wordfence |
| 1add47ea-6a7b-443a-b31d-3bb6c0d5d72d | < 2.11.0 |
MEDIUM | 5.3 | The Drag and Drop Multiple File Upload PRO plugin for WordPress is vulnerable to Path Traversal in versions up to, and i… | — | wordfence |
| 1ac39498-3171-4d91-a911-381c8ed751dc | < 3.9.2 |
MEDIUM | 5.3 | getID3() before 1.9.8, as used in ownCloud Server before 5.0.15 and 6.0.x before 6.0.2, allows remote attackers to read … | — | wordfence |
EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.
Scan My Website →