Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.
40,407 vulnerabilities found (page 1350 of 1617)
| CVE ID | Plugin / Theme | Severity | CVSS | Description | Fixed In | Source |
|---|---|---|---|---|---|---|
| fa085bc0-af0b-4797-a10f-4d41b4988c02 | < 1.4.6.3 |
MEDIUM | 4.3 | The 140+ Widgets | Xpro Addons For Elementor β FREE plugin for WordPress is vulnerable to Sensitive Information Exposu… | — | wordfence |
| f9f5be49-e099-4862-af9d-4ddbb6decfc5 | < 0.9.19 |
MEDIUM | 4.3 | The Contact Form 7 Extension For Mailchimp plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versi… | — | wordfence |
| f9f273ed-2ffd-4632-9886-244c0d55ede5 | < 3.6.1 |
MEDIUM | 4.3 | The WP Content Copy Protection & No Right Click plugin for WordPress is vulnerable to Cross-Site Request Forgery in vers… | — | wordfence |
| f9ebef5d-b651-4b09-b9af-97292a75f1c2 | MEDIUM | 4.3 | The FiveStar - Hotel Booking WordPress Theme theme for WordPress is vulnerable to Insecure Direct Object Reference in al… | — | wordfence | |
| f9eb1d99-76d9-4a6c-b1ce-618085c4f2aa | < 1.3.6 |
MEDIUM | 4.3 | The Ultimate WP Mail plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a fu… | — | wordfence |
| f9e7acc4-8b17-44a8-b20f-4c8f2a36180a | < 2.6.25 |
MEDIUM | 4.3 | The WP Project Manager β Task, team, and project management plugin featuring kanban board and gantt charts plugin for … | — | wordfence |
| f9d90717-fd48-493b-9293-32976bf2cada | < 5.7.35 |
MEDIUM | 4.3 | The Email Subscribers by Icegram Express β Email Marketing, Newsletters, Automation for WordPress & WooCommerce plugin… | — | wordfence |
| f9cf0430-8577-449a-aefe-d7bf606fe2de | < 3.9.8 |
MEDIUM | 4.3 | The Tutor LMS β eLearning and online course solution plugin for WordPress is vulnerable to Insecure Direct Object Refe… | — | wordfence |
| f9c6eccc-3f91-4923-b3d3-46070bb3662d | < 9.3.1 |
MEDIUM | 4.3 | The PixelYourSite plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 9.3… | — | wordfence |
| f9c0c44f-13bb-4e09-9edf-59be12d508a8 | < 3.6.8 |
MEDIUM | 4.3 | The Sunshine Photo Cart β Client Photo Gallery & Photo Proofing for Photographers plugin for WordPress is vulnerable t… | — | wordfence |
| f9b392cb-04f9-475e-bfe3-d6086f2b5885 | < 1.9.11 |
MEDIUM | 4.3 | The PPWP β Password Protect WordPress | #1 Most-Reviewed Password Plugin plugin for WordPress is vulnerable to Sensiti… | — | wordfence |
| f9ab2d12-5ed0-472a-be96-723577b011aa | < 1.1.4 |
MEDIUM | 4.3 | The Chic Lite theme for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.1.3. T… | — | wordfence |
| f9a3dc87-5309-41fe-bfc3-60b5878b6c57 | < 1.0.7.5 |
MEDIUM | 4.3 | The Categorify plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check… | — | wordfence |
| f98aad51-a08e-4eea-84f7-345f2442081a | < 1.1.5 |
MEDIUM | 4.3 | The F4 Media Taxonomies plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a… | — | wordfence |
| f98aab54-877b-47df-9c8a-5e70ea985c1c | < 3.3.0 |
MEDIUM | 4.3 | The Aeropage Sync for Airtable plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capabili… | — | wordfence |
| f9691ccf-269e-4154-b524-8587644fde24 | MEDIUM | 4.3 | The Salon Booking System β Free Version plugin for WordPress is vulnerable to Insecure Direct Object Reference in vers… | — | wordfence | |
| f962a3ef-205d-42e2-acf1-45eabfdba3ee | < 2.8.3 |
MEDIUM | 4.3 | The Local Development plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including,… | — | wordfence |
| f9624f16-5e18-4093-ba3a-bee228b2895d | < 1.0.8 |
MEDIUM | 4.3 | The Animated Text Block plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a… | — | wordfence |
| f9454765-f70b-4d8d-a5cc-28bc34375216 | < 8.4.6 |
MEDIUM | 4.3 | The Soledad theme for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 8.4.5. Thi… | — | wordfence |
| f9429c04-a1f8-42c4-bc43-df0a96aa5a6d | MEDIUM | 4.3 | The Sola Testimonials plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and includ… | — | wordfence | |
| f92f614b-162a-4ca5-bf7d-9d7088f59af9 | MEDIUM | 4.3 | The WP Site Protector plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including,… | — | wordfence | |
| f925833e-06d6-4175-8dca-5cb7baec9364 | < 2.5.1 |
MEDIUM | 4.3 | The EazyDocs β Most Powerful Knowledge base, wiki, Documentation Builder Plugin plugin for WordPress is vulnerable to … | — | wordfence |
| f923cf4a-a908-464b-b1c1-b0234fdc1d68 | < 4.49 |
MEDIUM | 4.3 | The Real Estate Property 2025 Create Your Own Fields and Search Bar plugin for WordPress is vulnerable to unauthorized a… | — | wordfence |
| f9190d35-c9e7-4190-8e66-f6066fe66af8 | < 3.8.1 |
MEDIUM | 4.3 | The Ally β Web Accessibility & Usability plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versi… | — | wordfence |
| f917802c-ea05-4e87-b0e5-00268c68f224 | < 2.1.8 |
MEDIUM | 4.3 | The WpTravelly plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function… | — | wordfence |
EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.
Scan My Website →