Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.
40,402 vulnerabilities found (page 1239 of 1617)
| CVE ID | Plugin / Theme | Severity | CVSS | Description | Fixed In | Source |
|---|---|---|---|---|---|---|
| 037ac32a-dc2e-4e9f-9318-65dfee1c80e9 | MEDIUM | 5.3 | The AA Block Country plugin for WordPress is vulnerable to IP Address Spoofing in versions up to, and including, 1.0.1. … | — | wordfence | |
| 03774303-c9f4-4666-ac88-78f92aaf81dc | MEDIUM | 5.3 | The One to one user Chat by WPGuppy plugin for WordPress is vulnerable to unauthorized access of data due to a missing c… | — | wordfence | |
| 0360c5d9-5534-4f6c-9b54-61c09a5d76f5 | MEDIUM | 5.3 | The ListingPro Lead Form plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on … | — | wordfence | |
| 035f2be6-6c20-4f61-8302-bf36df633c80 | < 1.1.5 |
MEDIUM | 5.3 | The COMPE β WooCommerce Compare Products plugin for WordPress is vulnerable to Insecure Direct Object Reference in all… | — | wordfence |
| 034246b2-e123-480d-afaf-cce9d42f1f03 | < 1.4.9 |
MEDIUM | 5.3 | The Credova_Financial WordPress plugin discloses a site's associated Credova API account username and password in plaint… | — | wordfence |
| 0323b54b-c15b-4d2d-9e8f-3df87c84dd49 | < 4.5.13 |
MEDIUM | 5.3 | The WP Meta SEO plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and includin… | — | wordfence |
| 031df7ea-b341-40fc-981f-711883f08742 | < 1.18.1 |
MEDIUM | 5.3 | The Pochipp plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in… | — | wordfence |
| 0312cea9-8205-4d09-874d-aef319d15c65 | < 2.3.9 |
MEDIUM | 5.3 | The Booking and Rental Manager for Bike | Car | Resort | Appointment | Dress | Equipment plugin for WordPress is vulnera… | — | wordfence |
| 030bb667-b8e6-4987-8af2-83cfa4bed8a6 | MEDIUM | 5.3 | The EPROLO-Dropshipping plugin for WordPress is vulnerable to unauthorized access in all versions up to, and including, … | — | wordfence | |
| 02f4987d-575f-4ee7-a3b7-c76a16cf1fe2 | < 2.24.0 |
MEDIUM | 5.3 | The NextMove Lite β Thank You Page for WooCommerce plugin for WordPress is vulnerable to Insecure Direct Object Refere… | — | wordfence |
| 02d994b7-2891-47d0-92d3-c33c4eac54f0 | < 2.1.2 |
MEDIUM | 5.3 | The SharkDropship and Affiliate for AliExpress, eBay, Amazon, Etsy plugin for WordPress is vulnerable to unauthorized lo… | — | wordfence |
| 02d61a68-0bcf-4a6d-8e19-c1546b9e59d9 | < 1.11.4 |
MEDIUM | 5.3 | The Cooked plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in … | — | wordfence |
| 02c5e3ad-5cc3-40b1-a15a-10d53383abe6 | < 20260217 |
MEDIUM | 5.3 | The User Submitted Posts β Enable Users to Submit Posts from the Front End plugin for WordPress is vulnerable to Incor… | — | wordfence |
| 02b0d7d7-8a10-48de-b1e1-7e1f1fda6ffe | < 4.3.2 |
MEDIUM | 5.3 | The Dokan: AI Powered WooCommerce Multivendor Marketplace Solution plugin for WordPress is vulnerable to Sensitive Infor… | — | wordfence |
| 02af9eab-fe69-4adb-b6e8-bf710b00af3f | MEDIUM | 5.3 | The Book Previewer for Woocommerce plugin for WordPress is vulnerable to unauthorized access due to a missing capability… | — | wordfence | |
| 029b4554-518e-484e-9e3a-7275a5fe1f17 | < 4.11.3 |
MEDIUM | 5.3 | The udesign theme for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in … | — | wordfence |
| 02461b79-d372-493f-9445-62b30b1db4cd | < 4.2.7.0 |
MEDIUM | 5.3 | The EventPrime β Events Calendar, Bookings and Tickets plugin for WordPress is vulnerable to unauthorized access due t… | — | wordfence |
| 023bef79-a3ab-41f7-a287-955c6331c77e | < 3.10.3 |
MEDIUM | 5.3 | The Posti Shipping plugin for WordPress is vulnerable to Full Path Disclosure in all versions up to, and including, 3.10… | — | wordfence |
| 0232a3a5-e91e-4213-8c21-900fc805bad7 | < 1.4.6 |
MEDIUM | 5.3 | The Contact Builder by Themify plugin is vulnerable to email injection in versions up to, and including 1.4.5. This make… | — | wordfence |
| 0227e5f0-61fa-4e78-9bd4-918fdde7ab58 | < 1.6.3 |
MEDIUM | 5.3 | The WordPress Leads plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on mult… | — | wordfence |
| 02220c1d-a7f2-41eb-ac5f-f89d63c54a59 | < 4.7.1 |
MEDIUM | 5.3 | The Nexter Blocks β Gutenberg Blocks, Page Builder & AI Website Builder plugin for WordPress is vulnerable to Sensitiv… | — | wordfence |
| 021a25c9-7fad-425f-8104-bb4852603613 | < 7.6.1 |
MEDIUM | 5.3 | The WordPress Social Login and Register plugin for WordPress is vulnerable to Missing Authorization in versions up to, a… | — | wordfence |
| 0213cfce-6dee-4607-bc0f-2001fc208725 | MEDIUM | 5.3 | The Featured Video Plus plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and incl… | — | wordfence | |
| 0210ee40-543a-42ce-b7da-e5bbae19d852 | < 2.0.0 |
MEDIUM | 5.3 | The Heureka plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in… | — | wordfence |
| 020da86b-63d6-4687-bf2d-ab10fe19e9ce | < 2.0.46 |
MEDIUM | 5.3 | The User Verification by PickPlugins plugin for WordPress is vulnerable to unauthorized access due to a missing capabili… | — | wordfence |
EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.
Scan My Website →