Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.
40,402 vulnerabilities found (page 1230 of 1617)
| CVE ID | Plugin / Theme | Severity | CVSS | Description | Fixed In | Source |
|---|---|---|---|---|---|---|
| 13088645-8233-40fb-8755-cbdf44c0eaf7 | < 3.2.13 |
MEDIUM | 5.3 | The CTT Expresso para WooCommerce plugin for WordPress is vulnerable to sensitive information exposure in all versions u… | — | wordfence |
| 12f9464b-d3d5-4000-8839-c63c77eca9b5 | < 1.1.6 |
MEDIUM | 5.3 | The Ai Image Alt Text Generator for WP plugin for WordPress is vulnerable to unauthorized access due to a missing capabi… | — | wordfence |
| 12f7c109-2752-4584-99e4-d94dafe3e81a | < 2.1.2 |
MEDIUM | 5.3 | The Connector Wizard (formerly LC Wizard) plugin for WordPress is vulnerable to unauthorized access due to a missing cap… | — | wordfence |
| 12da87e1-6a44-4b36-be7c-8d7ec51d71d7 | < 1.46 |
MEDIUM | 5.3 | The FAQ / Accordion / Docs / KB β Helpie WordPress FAQ Accordion plugin plugin for WordPress is vulnerable to Sensitiv… | — | wordfence |
| 12d465d2-cd89-476e-b70a-743151a23053 | MEDIUM | 5.3 | The Omnishop plugin for WordPress is vulnerable to Unauthenticated Registration Bypass in all versions up to, and includ… | — | wordfence | |
| 12bf1cd8-cd55-4771-b2bb-597797b1b949 | < 4.8.1 |
MEDIUM | 5.3 | The HM Books Gallery plugin for WordPress is vulnerable to Missing Authorization in versions up to and including 4.8.0. … | — | wordfence |
| 12a296db-ecc0-409b-8718-0c208504053a | < 2.1.5 |
MEDIUM | 5.3 | The Gravity SMTP plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and includi… | — | wordfence |
| 128c6ab5-ddcf-4775-b390-db49da79e548 | < 1.1.1 |
MEDIUM | 5.3 | The Sharable Password Protected Posts plugin for WordPress is vulnerable to Sensitive Information Exposure in all versio… | — | wordfence |
| 12837ce3-eeeb-4034-a90d-fc615056a818 | < 3.1.2 |
MEDIUM | 5.3 | An issue was discovered in the WP Security Audit Log plugin 3.1.1 for WordPress. Access to wp-content/uploads/wp-securit… | — | wordfence |
| 123ac22c-545b-4deb-b31a-29f6dba15018 | < 2.7.9 |
MEDIUM | 5.3 | The Easy Form plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function … | — | wordfence |
| 122b75d2-e882-45b9-baf1-acf847f8d60a | < 4.2.6.8.1 |
MEDIUM | 5.3 | The LearnPress β WordPress LMS Plugin plugin for WordPress is vulnerable to Sensitive Information Exposure in all vers… | — | wordfence |
| 12188a74-b1a6-4aa4-88b4-2d0d0dd32916 | < 1.1.4.2 |
MEDIUM | 5.3 | Multiple plugins and/or themes for WordPress are vulnerable to Cross-Site Request Forgery in various versions. This is d… | — | wordfence |
| 1208ac78-4a56-4daa-b935-d579f07f8e8e | < 3.0.2 |
MEDIUM | 5.3 | The Fense Proxy & VPN Blocker plugin for WordPress is vulnerable to unauthorized modification of data due to a missing c… | — | wordfence |
| 12072b77-fe68-4304-8230-7c137a8d05ac | < 3.0.2 |
MEDIUM | 5.3 | wp-includes/comment.php in WordPress before 3.0.2 does not properly whitelist trackbacks and pingbacks in the blogroll, … | — | wordfence |
| 11f3c5bf-19cd-422a-a7f8-358669c78db5 | < 1.1.1 |
MEDIUM | 5.3 | The Majestic Support β The Leading-Edge Help Desk & Customer Support Plugin plugin for WordPress is vulnerable to unau… | — | wordfence |
| 11ecc255-cf8a-4fa9-a04a-d17946b1f167 | < 2.3.2 |
MEDIUM | 5.3 | The Greek Multi Tool β Ultimate Greek Language Toolkit for WordPress plugin for WordPress is vulnerable to unauthorize… | — | wordfence |
| 11a61bef-da3b-46d6-8f78-0d4f9922f671 | < 3.1.4 |
MEDIUM | 5.3 | The Events Made Easy plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a fu… | — | wordfence |
| 11782a65-30b9-400e-8fe0-ab9f05ba5e42 | < 4.2.11 |
MEDIUM | 5.3 | The Passster β Password Protect Pages and Content plugin for WordPress is vulnerable to Sensitive Information Exposure… | — | wordfence |
| 1158081c-97da-4026-be16-994f4e41c92f | < 2.0.3 |
MEDIUM | 5.3 | The Getwid β Gutenberg Blocks plugin for WordPress is vulnerable to unauthorized arbitrary email sending due to insuff… | — | wordfence |
| 114ff636-6b51-43a2-b2c8-19e01e94176f | MEDIUM | 5.3 | The Vithy theme for WordPress is vulnerable to Sensitive Data Exposure in all versions via the index.php file. This can … | — | wordfence | |
| 1128aca9-329d-4a3f-b0b0-36a4172524c5 | < 1.1.0 |
MEDIUM | 5.3 | The GIFT4U β Gift Cards All in One for Woo plugin for WordPress is vulnerable to unauthorized access due to a missing … | — | wordfence |
| 1114a84e-3425-402f-bcdc-a2ee05b2dbc9 | MEDIUM | 5.3 | The KiotViet Sync plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and includ… | — | wordfence | |
| 1101bfe6-2075-4f44-933b-6d9f372100a2 | MEDIUM | 5.3 | The Pricing Deals for WooCommerce plugin for WordPress is vulnerable to unauthorized modification of data| due to a miss… | — | wordfence | |
| 10e1b3ac-f002-4108-9682-5fe300f07adb | < 1.2.0 |
MEDIUM | 5.3 | The HT Easy GA4 β Google Analytics WordPress Plugin plugin for WordPress is vulnerable to unauthorized modification of… | — | wordfence |
| 10d7a50c-41e9-41b7-a171-d72dbe08e7b7 | < 1.6.9.17 |
MEDIUM | 5.3 | The Appointment Booking Calendar β Simply Schedule Appointments Booking Plugin for WordPress is vulnerable to Sensitiv… | — | wordfence |
EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.
Scan My Website →