Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.
40,402 vulnerabilities found (page 1238 of 1617)
| CVE ID | Plugin / Theme | Severity | CVSS | Description | Fixed In | Source |
|---|---|---|---|---|---|---|
| 0578c49e-f820-42dd-bd53-f4a281843e69 | < 1.25.11 |
MEDIUM | 5.3 | The Happyforms plugin for WordPress is vulnerable to unauthorized access due to a missing capability check in all versio… | — | wordfence |
| 0556738f-5c3c-4ff6-9432-d666328dc5e5 | MEDIUM | 5.3 | The Post Grid plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and includin… | — | wordfence | |
| 05529ca0-09f5-4047-9972-c0a2872ea857 | < 1.4.3 |
MEDIUM | 5.3 | The Media File Manager plugin up to and including version 1.4.2 for WordPress allows directory listing via a ../ directo… | — | wordfence |
| 054bb123-132c-4c32-9fd1-a9f289cfdc35 | < 1.2.2 |
MEDIUM | 5.3 | The Ad Blocking Detector Plugin plugin for WordPress is vulnerable to information exposure in all versions up to, and in… | — | wordfence |
| 0505d023-a5b9-4c86-aa9b-57ce2335f127 | < 235 |
MEDIUM | 5.3 | The Language Translate Widget for WordPress β ConveyThis plugin for WordPress is vulnerable to unauthorized modificati… | — | wordfence |
| 05056d99-ce19-4d41-844f-7757361fbe24 | < 026.02.10.20 |
MEDIUM | 5.3 | The Cnvrse plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and excluding, … | — | wordfence |
| 0500c57a-3983-46e4-92fa-85f7fd47eba8 | < 4.7.4 |
MEDIUM | 5.3 | The Backup, Restore and Migrate WordPress Sites With the XCloner Plugin plugin for WordPress is vulnerable to Full Path … | — | wordfence |
| 04f0bffb-07bd-41f1-8e65-17ded38a8e2e | < 1.9.7 |
MEDIUM | 5.3 | The WP-LESS plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1… | — | wordfence |
| 04eb82e4-1738-44c7-980e-8e33a7a3a23a | < 4.6 |
MEDIUM | 5.3 | The STRABL β A checkout solution plugin for WordPress is vulnerable to Missing Authentication in all versions up to an… | — | wordfence |
| 04e0ddff-16af-4c85-b5b0-cf767684ee08 | < 4.2.6.8.2 |
MEDIUM | 5.3 | The LearnPress β WordPress LMS Plugin plugin for WordPress is vulnerable to unauthorized user registration due to a mi… | — | wordfence |
| 049b7e92-c648-49e5-bab9-1b893d44faf9 | MEDIUM | 5.3 | The Leadrebel plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function … | — | wordfence | |
| 0490667e-4b82-4687-9354-205c37f13331 | < 4.0.7 |
MEDIUM | 5.3 | The BestWebSoft Captcha plugin before 4.0.7 for WordPress allows remote attackers to bypass the CAPTCHA protection mecha… | — | wordfence |
| 048c37c2-0ace-4bf1-8cb8-554c4645be21 | < 5.5 |
MEDIUM | 5.3 | The WPQA Builder WordPress plugin before 5.4 which is a companion to the Discy and Himer , lacks authentication in a RES… | — | wordfence |
| 048bc117-88df-44b3-a30c-692bad23050f | < 1.8.6 |
MEDIUM | 5.3 | The Manage Notification E-mails plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and i… | — | wordfence |
| 047c1519-4dc1-496c-b494-41ce1009e703 | < 2.2.54 |
MEDIUM | 5.3 | The BerqWP β Automated All-In-One Page Speed Optimization for Core Web Vitals, Cache, CDN, Images, CSS, and JavaScript… | — | wordfence |
| 0462df4d-1be5-4834-817a-8df0300d3188 | MEDIUM | 5.3 | The Payment QR WooCommerce plugin for WordPress is vulnerable to unauthorized access due to a missing capability check o… | — | wordfence | |
| 041851d8-99ce-48a6-8ff5-85418d8807be | < 1.7.6 |
MEDIUM | 5.3 | The Document Embedder WordPress plugin before 1.7.6 contains a REST endpoint, which could allow unauthenticated users to… | — | wordfence |
| 0407223a-cd41-43d1-87b0-d6b83b57d4b3 | < 2.3.7 |
MEDIUM | 5.3 | The Post Grid and Gutenberg Blocks β ComboBlocks plugin for WordPress is vulnerable to Sensitive Information Exposure … | — | wordfence |
| 04013d96-d1b2-4d97-ad10-c2739eb9bc30 | < 4.0 |
MEDIUM | 5.3 | The WPLifeCycle plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a functio… | — | wordfence |
| 03f3d048-5099-406e-b386-31cbbbf4df14 | MEDIUM | 5.3 | The Team 118GROUP Agent plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a… | — | wordfence | |
| 03e96aea-30a2-4cd3-8967-52e1870cc293 | < 2.3.0 |
MEDIUM | 5.3 | The WooCommerce Warranty Requests plugin for WordPress is vulnerable to unauthorized access due to a missing capability … | — | wordfence |
| 03ccd474-42f4-4cbb-823e-93fe4db1bf80 | < 9.5 |
MEDIUM | 5.3 | The WP Cerber Security plugin for WordPress is vulnerable to IP Protection bypass in versions up to, and including 9.4 d… | — | wordfence |
| 03b1d518-0e5d-4c28-af04-52611ad583a8 | < 3.0.1 |
MEDIUM | 5.3 | The Product Filter by WBW plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capab… | — | wordfence |
| 03aed95b-26a1-4903-b5aa-35abc889295d | MEDIUM | 5.3 | The Share, Print and PDF Products for WooCommerce plugin for WordPress is vulnerable to unauthorized access due to a mis… | — | wordfence | |
| 039ac1d9-ccb5-43d0-8b17-10d12b7df90e | < 1.8.1 |
MEDIUM | 5.3 | The Fluent Support plugin for WordPress is vulnerable to unauthorized email verification due to insufficient validation … | — | wordfence |
EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.
Scan My Website →