Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.
40,402 vulnerabilities found (page 1240 of 1617)
| CVE ID | Plugin / Theme | Severity | CVSS | Description | Fixed In | Source |
|---|---|---|---|---|---|---|
| 0201d430-1254-4b09-b7a0-1443861ddf42 | < 5.3.9 |
MEDIUM | 5.3 | The WooCommerce Multilingual & Multicurrency with WPML plugin for WordPress is vulnerable to unauthorized access due to … | — | wordfence |
| 01d040c8-5fd9-4dc7-af30-10c58571b16f | < 1.2.7 |
MEDIUM | 5.3 | The TrueBooker β Appointment Booking and Scheduler System plugin for WordPress is vulnerable to unauthorized access in… | — | wordfence |
| 019cfdff-c67b-4451-984d-a7b6973ab61d | < 1.0.3 |
MEDIUM | 5.3 | The Blogpoet theme for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on… | — | wordfence |
| 0195f3db-cf36-40ab-a818-9c00a269f065 | MEDIUM | 5.3 | The Shown Connector plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a fun… | — | wordfence | |
| 018fafb9-0e86-47b2-b747-04aab1c1d5e0 | MEDIUM | 5.3 | The Wava Payment plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a functi… | — | wordfence | |
| 017fe804-a1a5-4f8d-a531-e928d668dbc4 | < 8.6.01.005 |
MEDIUM | 5.3 | The WP Photo Album Plus plugin for WordPress is vulnerable to IP Address Spoofing in versions up to, and including, 8.5.… | — | wordfence |
| 0173e2a3-452d-490b-8ed7-a049a476d137 | < 1.7.4 |
MEDIUM | 5.3 | The Masteriyo LMS β eLearning and Online Course Builder for WordPress plugin for WordPress is vulnerable to Insecure D… | — | wordfence |
| 01707346-86c2-45c8-a2c9-81a147506fa4 | < 2.1 |
MEDIUM | 5.3 | The Remember Me Controls plugin for WordPress is vulnerable to Full Path Disclosure in all versions up to, and including… | — | wordfence |
| 015942ef-fb6c-4b58-ab67-f7e903321f32 | < 3.5.35 |
MEDIUM | 5.3 | The Ultra Addons for Contact Form 7 plugin for WordPress is vulnerable to unauthorized access due to a missing capabilit… | — | wordfence |
| 013ff32d-b3ea-4d36-87c3-a31de447e699 | MEDIUM | 5.3 | The BizReview plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function … | — | wordfence | |
| 013f7c26-8348-4c54-af61-473a720a5095 | < 5.5.7 |
MEDIUM | 5.3 | The Ivory Search β WordPress Search Plugin plugin for WordPress is vulnerable to Information Exposure in all versions … | — | wordfence |
| 012b5334-afdc-47bd-8eaf-967b40fef59b | < 2.8.1 |
MEDIUM | 5.3 | The Popup Anything β Popup for opt-ins and Lead Generation Conversions plugin for WordPress is vulnerable to unauthori… | — | wordfence |
| 01299aba-0dff-47fd-9e90-ee84f00a0f3b | < 1.3.0 |
MEDIUM | 5.3 | The Guest Support plugin for WordPress is vulnerable to User Email Disclosure in versions up to, and including, 1.2.3. T… | — | wordfence |
| 010590bc-98fb-4afe-9c5e-80ad4c50a34e | < 1.4.8 |
MEDIUM | 5.3 | The Hash Elements plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on… | — | wordfence |
| 00ff9034-d890-4d56-8f07-d66672e79983 | < 11.1.3 |
MEDIUM | 5.3 | The Quiz and Survey Master (QSM) β Quiz Maker & Survey Maker plugin for WordPress is vulnerable to User Enumeration in… | — | wordfence |
| 00ec7251-3be1-411a-b38e-1782d1691e18 | < 1.3.8.6 |
MEDIUM | 5.3 | The Drag and Drop Multiple File Upload β Contact Form 7 plugin for WordPress is vulnerable to limited arbitrary file d… | — | wordfence |
| 00ba5eae-668a-4452-9562-9f49b730daaa | MEDIUM | 5.3 | The Contact Form Builder, Contact Widget plugin for WordPress is vulnerable to protection bypass in all versions up to, … | — | wordfence | |
| 00b81467-8d00-4816-895a-89d67c541c17 | < 4.2.6.3 |
MEDIUM | 5.3 | The Passster β Password Protect Pages and Content plugin for WordPress is vulnerable to Sensitive Information Exposure… | — | wordfence |
| 00a33386-c401-4942-9dca-82555d2e87c6 | MEDIUM | 5.3 | The NOWPayments for WooCommerce β Crypto Payment Gateway plugin for WordPress is vulnerable to unauthorized access due… | — | wordfence | |
| 0088a97c-5a06-4500-a923-242499596aca | < 4.10.1 |
MEDIUM | 5.3 | The YITH WooCommerce Wishlist plugin for WordPress is vulnerable to authorization bypass in all versions up to, and incl… | — | wordfence |
| 0064244b-72a4-486d-aaad-be1f57e4a8a1 | < 2.5 |
MEDIUM | 5.3 | The Add Admin CSS plugin for WordPress is vulnerable to Full Path Disclosure in all versions up to, and including, 2.0.1… | — | wordfence |
| 0049583a-0ad3-45e4-a29e-4b8c33d09857 | < 4.3.8 |
MEDIUM | 5.3 | The User Frontend: AI Powered Frontend Posting, User Directory, Profile, Membership & User Registration plugin for WordP… | — | wordfence |
| 003694f8-23be-4c94-899d-76b9b8488202 | < 5.4.6 |
MEDIUM | 5.3 | The kk Star Ratings plugin for WordPress is vulnerable to a race condition in all versions up to, and including, 5.4.5. … | — | wordfence |
| 00130f32-36eb-4a76-bac5-b6407edf1c48 | < 4.3.1 |
MEDIUM | 5.3 | The WP Social Ninja β Embed Social Feeds, User Reviews & Chat Widgets plugin for WordPress is vulnerable to Sensitive … | — | wordfence |
| 21c09207-38a1-47ae-ae1e-52f8eea4785d | < 2.5.8 |
MEDIUM | 5.2 | The AWeber Forms by Optin Cat plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add… | — | wordfence |
EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.
Scan My Website →