Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.
40,402 vulnerabilities found (page 1241 of 1617)
| CVE ID | Plugin / Theme | Severity | CVSS | Description | Fixed In | Source |
|---|---|---|---|---|---|---|
| afcbad6d-90ca-42cb-a69c-4e0bcc4606e0 | < 6.3.6.3 |
MEDIUM | 5.1 | The Advanced Custom Fields (ACF) plugin for WordPress is vulnerable to limited arbitrary function calls via the 'registe… | — | wordfence |
| 219614b7-2394-490c-baf4-14a12249c4b5 | MEDIUM | 5.1 | The Simple CSV/XLS Exporter plugin for WordPress is vulnerable to CSV injection in versions up to, and including, 1.5.8.… | — | wordfence | |
| f330bf36-0a39-40d6-a075-c87fdb9dc2da | < 3.1.15 |
MEDIUM | 5.0 | The ImageRecycle pdf & image compression plugin for WordPress is vulnerable to unauthorized modification of data due to … | — | wordfence |
| ed507ac7-6732-4315-99dd-0a8636cc9cc3 | < 3.0.0 |
MEDIUM | 5.0 | The Yumpu ePaper publishing plugin for WordPress is vulnerable to unauthorized modification of data due to a missing cap… | — | wordfence |
| ea26eb81-e6d1-4c6d-95f4-fd1b2d919632 | < 4.5 |
MEDIUM | 5.0 | WordPress before 4.5 does not consider octal and hexadecimal IP address formats when determining an intranet address, wh… | — | wordfence |
| e5b7b20d-d701-4146-b982-23d6be7a7ea0 | < 2.6.45 |
MEDIUM | 5.0 | The Like Button Rating WordPress plugin before 2.6.45 allows any logged-in user, such as subscriber, to send arbitrary e… | — | wordfence |
| cb5c5e82-d6e5-4237-958f-12fc4698e77e | MEDIUM | 5.0 | The Resoto theme for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on t… | — | wordfence | |
| c33ec58f-3e83-425a-9f0f-5e529be15e05 | < 5.1.1 |
MEDIUM | 5.0 | The RSS Aggregator by Feedzy β Feed to Post, Autoblogging, News & YouTube Video Feeds Aggregator plugin for WordPress … | — | wordfence |
| c16e16dc-8888-4222-862f-a57a9f14e7f4 | < 5.1 |
MEDIUM | 5.0 | The iframe plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in all versio… | — | wordfence |
| b9c501a3-e092-453a-900f-60967b12c928 | < 1.8.0 |
MEDIUM | 5.0 | The Cooked β Recipe Management plugin for WordPress is vulnerable to HTML Injection in all versions up to, and includi… | — | wordfence |
| b062f72a-542c-4212-af83-4faefbf69bd7 | < 2.3.1 |
MEDIUM | 5.0 | The DK PDF β WordPress PDF Generator plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions… | — | wordfence |
| aa2035ef-5251-49cc-a480-b6c167b5ef8c | < 3.5.4.3 |
MEDIUM | 5.0 | The The WP-Members Membership Plugin plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions… | — | wordfence |
| 9cd2b3fd-1bca-4611-9753-ccb57b0e36a4 | < 1.2.59 |
MEDIUM | 5.0 | The UsersWP β Front-end login form, User Registration, User Profile & Members Directory plugin for WP plugin for WordP… | — | wordfence |
| 97c100c3-8a96-4198-b38a-206268ff20ec | < 8.2.6 |
MEDIUM | 5.0 | The Element Pack Addons for Elementor plugin for WordPress is vulnerable to Blind Server-Side Request Forgery in all ver… | — | wordfence |
| 92a3e622-b3b2-450e-82a7-0a942711e8c0 | < 12.7 |
MEDIUM | 5.0 | The Jetpack β WP Security, Backup, Speed, & Growth plugin for WordPress is vulnerable to Clickjacking via iframe injec… | — | wordfence |
| 8f24f7e2-2516-4f4d-955f-f3f6001cbce7 | < 2.0.0 |
MEDIUM | 5.0 | The PhonePe Payment Solutions plugin for WordPress is vulnerable to Server-Side Request Forgery in versions up to, and i… | — | wordfence |
| 848f36de-c62a-45ee-b259-46dab73e4439 | < 1.1.7 |
MEDIUM | 5.0 | The ArtiBot Free Chat Bot for WordPress WebSites plugin for WordPress is vulnerable to unauthorized modification of data… | — | wordfence |
| 7e0ef4a5-42d7-4cea-b19f-51917e3ee55f | < 5.3.6 |
MEDIUM | 5.0 | The AI ChatBot plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check… | — | wordfence |
| 689eb95b-2f72-4aa4-9f21-6ae186346061 | < 1.6.27 |
MEDIUM | 5.0 | The Elementor Header & Footer Builder for WordPress is vulnerable to HTML Injection in all versions up to, and including… | — | wordfence |
| 66f392d0-d5fb-4a8c-b972-becfac6cf6e7 | < 4.9 |
MEDIUM | 5.0 | The iFrame plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the srcdoc parameter in versions up to,… | — | wordfence |
| 58a4cb88-033e-48f4-b6fa-2a9754ab6a7f | < 4.10.0 |
MEDIUM | 5.0 | Directory traversal vulnerability in Shortcodes Ultimate prior to version 4.10.0 allows remote attackers to read arbitra… | — | wordfence |
| 55ba8d6a-df38-4e24-afa4-6f82cb318c6b | MEDIUM | 5.0 | The Shortcodify plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'name' Shortcode Attribute in all … | — | wordfence | |
| 44276b28-9509-4f59-936c-fff2ae404076 | < 2.7.2 |
MEDIUM | 5.0 | The Responsive Lightbox & Gallery plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up t… | — | wordfence |
| 42106dad-c568-4a79-af56-2d714dd8f487 | < 20.8.2 |
MEDIUM | 5.0 | The Client Invoicing by Sprout Invoices β Easy Estimates and Invoices for WordPress plugin for WordPress is vulnerable… | — | wordfence |
| 3709465d-6d67-45bd-abb9-4875065b8129 | < 4.3.18 |
MEDIUM | 5.0 | The NextScripts: Social Networks Auto-Poster plugin for WordPress is vulnerable to authorization bypass due to missing c… | — | wordfence |
EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.
Scan My Website →