Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.
40,402 vulnerabilities found (page 1228 of 1617)
| CVE ID | Plugin / Theme | Severity | CVSS | Description | Fixed In | Source |
|---|---|---|---|---|---|---|
| 1753ce91-762e-4fb7-a164-ee5bc9dcd323 | < 3.11.3 |
MEDIUM | 5.3 | The YMC Smart Filter plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and includi… | — | wordfence |
| 17452a29-bcef-451a-9893-a436ac5d3b80 | < 2.2.1 |
MEDIUM | 5.3 | The Responsive Blocks β Page Builder for Blocks & Patterns plugin for WordPress is vulnerable to Unauthenticated Open … | — | wordfence |
| 1701275d-8d29-449b-9804-f8f35c550e94 | < 2.9.3 |
MEDIUM | 5.3 | The JS Help Desk β The Ultimate Help Desk & Support Plugin plugin for WordPress is vulnerable to unauthorized access d… | — | wordfence |
| 16fd140b-c976-4425-8ac5-a524b8cf1a42 | < 5.3.0 |
MEDIUM | 5.3 | The Custom Query Blocks plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability ch… | — | wordfence |
| 16e1d37a-4eb7-45dc-8993-a501fb2aaf73 | < 1.1.1 |
MEDIUM | 5.3 | The ERI File Library plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check… | — | wordfence |
| 16a4665a-df79-4def-8215-df44dffdd332 | < 3.16.6 |
MEDIUM | 5.3 | The User Profile Builder β Beautiful User Registration Forms, User Profiles & User Role Editor plugin for WordPress is… | — | wordfence |
| 16a3469d-6264-4ed7-b6ae-fdd7a80c8ca5 | < 2.3.8 |
MEDIUM | 5.3 | The UPS, Mondial Relay & Chronopost for WooCommerce β WCMultiShipping plugin for WordPress is vulnerable to unauthoriz… | — | wordfence |
| 16988713-a4d4-4d6a-bafb-3441ab54f14b | < 3.0.9 |
MEDIUM | 5.3 | The Newspack Blocks plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and incl… | — | wordfence |
| 168dd2d4-bffb-4187-afc7-02fef8cb51a7 | < 1.3.4.1 |
MEDIUM | 5.3 | The Social Rocket β Social Sharing Plugin plugin for WordPress is vulnerable to unauthorized modification of data due … | — | wordfence |
| 16735e63-d652-4b0e-b454-2bd13368d8a7 | < 2.8.11 |
MEDIUM | 5.3 | The Checkbox plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the 'w… | — | wordfence |
| 166dfe2c-6efd-48ad-bbcd-e3dc0e9ede05 | < 1.1.16 |
MEDIUM | 5.3 | The Block for Mailchimp β Add Email Subscription Forms and Collect Leads plugin for WordPress is vulnerable to unautho… | — | wordfence |
| 1665bf5a-3bf0-4907-a7df-a2fe26f11869 | < 1.15.45 |
MEDIUM | 5.3 | The Form Maker by 10Web β Mobile-Friendly Drag & Drop Contact Form Builder plugin for WordPress is vulnerable to blind… | — | wordfence |
| 165a3c28-ea89-44bd-9de0-38d931f98de2 | < 8.2.1 |
MEDIUM | 5.3 | The Newsletter β Send awesome emails from WordPress plugin for WordPress is vulnerable to IP Address Spoofing in all v… | — | wordfence |
| 163d42df-148f-431c-891e-dbdc09bf2ae1 | < 4.7.9 |
MEDIUM | 5.3 | The Razorpay for WooCommerce plugin for WordPress is vulnerable to unauthorized modification of data due to a missing ca… | — | wordfence |
| 1612b10d-1ee7-4ea1-93f3-bde2f1667e1b | < 1.26 |
MEDIUM | 5.3 | The WordPress RokStories plugin is vulnerable to Denial of Service via the 'src' parameter in the 'thumb.php' file in ve… | — | wordfence |
| 15f38b3e-69fe-436f-ba4b-7985ec9dac00 | < 2.0.1 |
MEDIUM | 5.3 | The BigBuy Dropshipping Connector for WooCommerce plugin for WordPress is vulnerable to Full Path Disclosure in all vers… | — | wordfence |
| 15eaba51-e46f-4725-a6f9-7969bf00db5a | < 7.1.1 |
MEDIUM | 5.3 | The Advanced Access Manager β Access Governance for WordPress plugin for WordPress is vulnerable to unauthorized acces… | — | wordfence |
| 15d5a7e9-7fae-447b-880f-a1bc45ec43c4 | < 2.22.6 |
MEDIUM | 5.3 | The Tourfic β AI Powered Travel Booking, Hotel Booking & Car Rental WordPress Plugin plugin for WordPress is vulnerabl… | — | wordfence |
| 15d29d58-9e28-4e18-aeb9-9c63cb308673 | < 4.1.1.2 |
MEDIUM | 5.3 | The QA Analytics β Web Analytics Tool with Heatmaps & Session Replay Across All Pages plugin for WordPress is vulnerab… | — | wordfence |
| 15b831eb-ab28-4e42-940b-6943d836d230 | < 3.0.6 |
MEDIUM | 5.3 | The Calendarista Basic Edition plugin for WordPress is vulnerable to unauthorized access due to a missing capability che… | — | wordfence |
| 159d031b-0362-4625-9d98-3908401c8ee8 | < 1.5.1 |
MEDIUM | 5.3 | The MailerPress β Newsletter, email marketing & AI automation plugin for WordPress is vulnerable to unauthorized acces… | — | wordfence |
| 159b5565-f4d8-4514-9397-20b6a0890475 | < 2.0.4 |
MEDIUM | 5.3 | WordPress 2.0.3 allows remote attackers to obtain the installation path via a direct request to various files, such as t… | — | wordfence |
| 157847ac-f893-47fb-9e26-697f0ec124f0 | < 4.1.2.1 |
MEDIUM | 5.3 | The JetBooking plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function… | — | wordfence |
| 156581cb-f3d8-4253-af4d-cdc59b95d763 | < 8.4.0 |
MEDIUM | 5.3 | The Woodmart theme for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 8… | — | wordfence |
| 154fc656-3a33-4783-a941-10bb848244b3 | < 6.2.0 |
MEDIUM | 5.3 | The Fluent Forms β Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder plugin for WordPress is vul… | — | wordfence |
EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.
Scan My Website →