Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.
40,407 vulnerabilities found (page 1345 of 1617)
| CVE ID | Plugin / Theme | Severity | CVSS | Description | Fixed In | Source |
|---|---|---|---|---|---|---|
| 01bd8a24-5580-4b16-94b3-c231d5fe7a01 | < 2.3.0 |
MEDIUM | 4.4 | The WooDiscuz β WooCommerce Comments plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin setti… | — | wordfence |
| 01a70f60-9207-48a9-9ba2-7a29813fa934 | MEDIUM | 4.4 | The Lenix scss compiler plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and includi… | — | wordfence | |
| 014ccad9-a836-4a40-92d3-8c3320fbead8 | < 2.0.0 |
MEDIUM | 4.4 | The PDQ CSV plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin settings in versions up to,… | — | wordfence |
| 00dc3911-c29e-4f4f-973c-8e4da5dd0e35 | < 3.8.18 |
MEDIUM | 4.4 | The Ninja Forms β The Contact Form Builder That Grows With You plugin for WordPress is vulnerable to Stored Cross-Site… | — | wordfence |
| 00bb89b7-e8f3-4ffc-8086-34f70a66e641 | MEDIUM | 4.4 | The Login-Logout plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 3.8… | — | wordfence | |
| 0092f02d-ec3a-4a11-bad9-67714d3d976e | < 2.9.1 |
MEDIUM | 4.4 | The Social Media Share Buttons & Social Sharing Icons plugin for WordPress is vulnerable to Stored Cross-Site Scripting … | — | wordfence |
| 007d8935-974f-4bc4-833e-25ca50a50a29 | < 4.7.2 |
MEDIUM | 4.4 | The Button contact VR plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versio… | — | wordfence |
| 005032e2-b5aa-44d8-855f-2aceee9e740f | < 20240516 |
MEDIUM | 4.4 | The User Submitted Posts β Enable Users to Submit Posts from the Front End plugin for WordPress is vulnerable to Store… | — | wordfence |
| 001f25c8-d9b5-4b24-9cd1-be726916079c | < 3.59.3 |
MEDIUM | 4.4 | The Photo Gallery, Sliders, Proofing and Themes β NextGEN Gallery plugin for WordPress is vulnerable to Stored Cross-S… | — | wordfence |
| 0008b460-0c28-4e72-9c87-eda91989e39a | < 0.3 |
MEDIUM | 4.4 | The Site Favicon plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up… | — | wordfence |
| fffa6c31-8da0-48d7-b603-64f50950787b | MEDIUM | 4.3 | The Peer Publish plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, … | — | wordfence | |
| ffee6564-2718-4461-b481-cbf0e204a04d | < 3.8.8 |
MEDIUM | 4.3 | The Ultimate Dashboard β Custom WordPress Dashboard plugin for WordPress is vulnerable to unauthorized modification of… | — | wordfence |
| ffdf34bb-a887-444c-8a76-12901fed6662 | < 4.3.3 |
MEDIUM | 4.3 | The User Frontend: AI Powered Frontend Posting, User Directory, Profile, Membership & User Registration plugin for WordP… | — | wordfence |
| ffc5408c-ca31-4cb6-8cb5-063acbbad01e | < 1.2.2 |
MEDIUM | 4.3 | The News Kit Elementor Addons plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to… | — | wordfence |
| ffb8a285-43c6-4956-ad37-484269463b2d | < 6.1.7 |
MEDIUM | 4.3 | The Awesome Support β WordPress HelpDesk & Support Plugin plugin for WordPress is vulnerable to unauthorized modificat… | — | wordfence |
| ffa54d4e-a633-48a4-83c0-33b7cbd2229a | < 3.3.25 |
MEDIUM | 4.3 | The Download Manager plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, … | — | wordfence |
| ffa3b053-07cd-4c5f-b9d1-016cbca4b171 | < 2.0.7 |
MEDIUM | 4.3 | The Siteimprove plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.0.6… | — | wordfence |
| ff8e8889-ec02-4b8d-9509-2c6335fdd9a4 | < 2.2.0 |
MEDIUM | 4.3 | The Enter Addons β Ultimate Template Builder for Elementor plugin for WordPress is vulnerable to Information Exposure … | — | wordfence |
| ff850f88-6e89-48dd-ad70-dda4018c22fc | < 2.8.4 |
MEDIUM | 4.3 | The WooCommerce Canada Post Shipping plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to,… | — | wordfence |
| ff79e4b4-f3f1-4a7f-97f5-09bb3fc9c0c0 | < 1.1.0 |
MEDIUM | 4.3 | The YITH Slider for page builders plugin for WordPress is vulnerable to unauthorized access due to a missing capability … | — | wordfence |
| ff77ffea-6b43-4875-965a-a72d761e93f7 | < 3.21.1 |
MEDIUM | 4.3 | The Order Delivery Date for WooCommerce plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up … | — | wordfence |
| ff6c0ce5-b98e-4005-b8ea-7328119aec97 | < 3.7.31 |
MEDIUM | 4.3 | The MasterStudy LMS WordPress Plugin β for Online Courses and Education plugin for WordPress is vulnerable to unauthor… | — | wordfence |
| ff5d0ffb-c703-4bd1-83a0-c02e3744dd03 | < 5.2 |
MEDIUM | 4.3 | The Taxonomy/Term and Role based Discounts for WooCommerce plugin for WordPress is vulnerable to Cross-Site Request Forg… | — | wordfence |
| ff4b757a-9ede-496b-b559-cf952d39fe70 | < 2.5.7 |
MEDIUM | 4.3 | The GamiPress plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.5.6. … | — | wordfence |
| ff4895bb-b353-423c-a135-bf504ad77e53 | < 3.8.4.5 |
MEDIUM | 4.3 | The AI WP Writer plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 3.8.… | — | wordfence |
EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.
Scan My Website →