Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.
40,402 vulnerabilities found (page 1242 of 1617)
| CVE ID | Plugin / Theme | Severity | CVSS | Description | Fixed In | Source |
|---|---|---|---|---|---|---|
| 34b6475c-b5dd-42a1-98d1-9b5ae9ff4ad5 | < 5.3.6 |
MEDIUM | 5.0 | The AI ChatBot plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check… | — | wordfence |
| 288853b8-7523-472e-8406-257ffb3bd5ea | < 2.0.9 |
MEDIUM | 5.0 | The WP-FormAssembly plugin for WordPress is vulnerable to Server-Side Request Forgery in versions up to, and including, … | — | wordfence |
| 261aad1e-43fc-4927-a97d-85a001863023 | < 5.11 |
MEDIUM | 5.0 | The MP3 Audio Player β Music Player, Podcast Player & Radio by Sonaar plugin for WordPress is vulnerable to Server-Sid… | — | wordfence |
| 1c0572a5-6cc9-43ab-a4a3-c8d3b93c8fcf | < 5.3.6 |
MEDIUM | 5.0 | The AI ChatBot plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on th… | — | wordfence |
| 1173e2ad-c53d-4d37-9c77-4b63f04ff335 | < 2.5.3 |
MEDIUM | 5.0 | The Pz-LinkCard plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, … | — | wordfence |
| 0c2925c1-f5c6-45b9-bc61-96f325c0372f | < 1.7.60 |
MEDIUM | 5.0 | The Unite Gallery Lite plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.7.… | — | wordfence |
| ffcf8071-89be-484c-9b6a-8b08e12cf100 | < 7.3.2 |
MEDIUM | 4.9 | The SEO Booster plugin for WordPress is vulnerable to generic SQL Injection via the 'sort_field' parameter in all versio… | — | wordfence |
| ffc2fe31-9bc2-497a-a8f4-1bc4f93de5a2 | < 5.7.10 |
MEDIUM | 4.9 | The JoomSport β for Sports: Team & League, Football, Hockey & more plugin for WordPress is vulnerable to time-based SQ… | — | wordfence |
| fd7b0eef-3b8e-4272-bbd7-ad52088d0835 | < 1.1.43 |
MEDIUM | 4.9 | The RSFirewall! plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 1.1.42 via th… | — | wordfence |
| fd75e795-54b8-4b9a-9417-9f707215ebfa | < 1.24.3 |
MEDIUM | 4.9 | The Mail Mint β Email Marketing, Newsletter, Email Automation & WooCommerce Emails plugin for WordPress is vulnerable … | — | wordfence |
| fcbe5bfa-7680-452e-bb18-ea9fbbb07b8e | < 1.5.9 |
MEDIUM | 4.9 | The Product Labels For Woocommerce plugin for WordPress is vulnerable to SQL Injection in versions up to, and including,… | — | wordfence |
| fcbd718b-4d7d-48a4-9db2-dd938de7c7eb | < 0.8.5.8 |
MEDIUM | 4.9 | The WP Fastest Cache plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the… | — | wordfence |
| fc1f36b1-cf28-472c-8a7a-f091ecb48c2d | MEDIUM | 4.9 | The All push notification for WP plugin for WordPress is vulnerable to time-based SQL Injection via the 'delete_id' para… | — | wordfence | |
| fbe12337-52ca-41ca-a7bf-5dfca52a8018 | < 6.0.2 |
MEDIUM | 4.9 | The Popup Box β Create Countdown, Coupon, Video, Contact Form Popups plugin for WordPress is vulnerable to SQL Injecti… | — | wordfence |
| fad8ad54-56eb-40fa-a357-77b7d656d378 | MEDIUM | 4.9 | The Code Explorer plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 1.4.6 via t… | — | wordfence | |
| faa6ecad-1430-4300-b314-53619d69837b | < 2.9.10 |
MEDIUM | 4.9 | The Post SMTP plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 2.9.9 due to insuffi… | — | wordfence |
| fa795a7e-9a7a-4686-9f42-df87f49f6e0d | < 1.14.0 |
MEDIUM | 4.9 | The WPMasterToolKit (WPMTK) β All in one plugin plugin for WordPress is vulnerable to Directory Traversal in all versi… | — | wordfence |
| f9ff3058-a08c-40ed-b756-81e703b2277a | < 2.8.3 |
MEDIUM | 4.9 | The Loco Translate plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 2.8.2 via … | — | wordfence |
| f96d3773-29a1-44bd-904a-905aff2b345e | < 1.5.0 |
MEDIUM | 4.9 | The Accredible Certificates & Open Badges plugin for WordPress is vulnerable to time-based SQL Injection via the βorde… | — | wordfence |
| f928d3e0-b9ac-43bb-9e54-5a6bae2a3cb4 | < 1.9.1 |
MEDIUM | 4.9 | The SMTP for Amazon SES plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 1.9 due to… | — | wordfence |
| f790114b-d000-4dd3-828d-3d00ee9ab52b | MEDIUM | 4.9 | The Adicon Server plugin for WordPress is vulnerable to SQL Injection via the adStatus parameter in all versions up to, … | — | wordfence | |
| f7007230-f27e-447a-adc4-d835a0a3039b | < 1.13.10 |
MEDIUM | 4.9 | The InfiniteWP Client plugin for WordPress is vulnerable to SQL Injection in all versions up to, and including, 1.13.9. … | — | wordfence |
| f6c71e38-5ac3-46f1-8292-a49c6e44f1d8 | < 4.5.12 |
MEDIUM | 4.9 | The OMGF | Host Google Fonts Locally WordPress plugin before 4.5.12 does not validate the cache directory setting, allow… | — | wordfence |
| f62f756d-70f2-42fe-89d7-f9f50ddf466e | < 9.1.0 |
MEDIUM | 4.9 | The Newsletter plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 9.0.9 due to insuff… | — | wordfence |
| f6023483-3fa5-4b85-9422-7d395abcfbd8 | < 1.0.5 |
MEDIUM | 4.9 | The Thumbnail carousel slider plugin for WordPress is vulnerable to SQL Injection via the 'id' parameter in all versions… | — | wordfence |
EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.
Scan My Website →