Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.
40,407 vulnerabilities found (page 1352 of 1617)
| CVE ID | Plugin / Theme | Severity | CVSS | Description | Fixed In | Source |
|---|---|---|---|---|---|---|
| f80a1f13-c1b9-4259-8d96-71a3cbcaf4ca | < 1.5.8 |
MEDIUM | 4.3 | The WordPress Contact Forms by Cimatti plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up t… | — | wordfence |
| f8068fb3-5a19-4b17-848b-32cebfff2537 | < 26.6.3 |
MEDIUM | 4.3 | The Betheme theme for WordPress is vulnerable to authorization bypass in versions up to, and including, 26.6.2. This is … | — | wordfence |
| f7f9b1ef-2efc-4d88-bff8-e0dd711b85ab | < 1.7.1002 |
MEDIUM | 4.3 | The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to unauthorized access due to a missing capa… | — | wordfence |
| f7f77ca2-c69e-4f59-ad7b-a244863de424 | < 3.2.8 |
MEDIUM | 4.3 | The WP2LEADS plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on several func… | — | wordfence |
| f7ed8472-1e42-4abd-9978-8f5080ec2ee1 | < 1.2.1 |
MEDIUM | 4.3 | The OwnerRez plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.2.… | — | wordfence |
| f7ed53bd-08de-4ec9-a8dd-eef72b788359 | < 2.16.0 |
MEDIUM | 4.3 | The OptinMonster plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, … | — | wordfence |
| f7ce1d19-25fa-434d-943b-d10c5cb2ec51 | < 6.0.4 |
MEDIUM | 4.3 | The The Plus Addons for Elementor β Elementor Addons, Page Templates, Widgets, Mega Menu, WooCommerce plugin for WordP… | — | wordfence |
| f7cd392e-f223-4c39-bdf7-f0584c5b5bd8 | MEDIUM | 4.3 | The Publitio plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, … | — | wordfence | |
| f7be0fe9-3b6a-47e7-8a18-856b0e164f09 | < 1.3.0 |
MEDIUM | 4.3 | The Business One Page theme for WordPress is vulnerable to unauthorized modification of data due to a missing capability… | — | wordfence |
| f7b45b1d-7ed6-4382-b69c-45ea45e4d0db | < 3.9.12 |
MEDIUM | 4.3 | The FormCraft plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check in for… | — | wordfence |
| f7b239b1-c234-40d0-a4bc-f2db54937494 | < 8.2.0 |
MEDIUM | 4.3 | The ExactMetrics β Google Analytics Dashboard for WordPress (Website Stats Plugin) plugin for WordPress is vulnerable … | — | wordfence |
| f7afbe2b-72a8-40da-bc94-ff2a1b9569b4 | < 3.8.2.3 |
MEDIUM | 4.3 | The Brands for WooCommerce plugin for WordPress is vulnerable to Missing Authorization in versions up to, and including,… | — | wordfence |
| f7afae24-a905-473f-8015-c93b60189eb5 | MEDIUM | 4.3 | The Testimonial Slider plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a … | — | wordfence | |
| f7a2c607-a18b-49b5-ac72-892c570a5b8d | < 11.0.0 |
MEDIUM | 4.3 | The AcyMailing β An Ultimate Newsletter Plugin and Marketing Automation Solution for WordPress plugin for WordPress is… | — | wordfence |
| f79f9385-f8d1-44a0-9e53-7576a9453163 | < 1.8.4 |
MEDIUM | 4.3 | The Customize My Account for WooCommerce plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up… | — | wordfence |
| f79d3938-bf85-4e0d-80a3-2ff365482d36 | < 37 |
MEDIUM | 4.3 | The DH β Anti AdBlocker plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and includ… | — | wordfence |
| f785edc7-b5c1-4c39-bc66-d9d1404a2048 | < 8.5.6 |
MEDIUM | 4.3 | The WP eStore plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 8.5… | — | wordfence |
| f779443a-e5b9-45d6-bfd3-d22243d34917 | < 1.6.6 |
MEDIUM | 4.3 | The Simple calendar for Elementor plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, an… | — | wordfence |
| f7663085-970e-4d11-b63e-8363a51e3acd | < 1.3 |
MEDIUM | 4.3 | The Product Quantity Dropdown For Woocommerce plugin for WordPress is vulnerable to Cross-Site Request Forgery in versio… | — | wordfence |
| f765e21e-938a-4110-8fdf-12315e2a79cc | < 1.8.3 |
MEDIUM | 4.3 | The Futurio Extra plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.8… | — | wordfence |
| f76411f1-98ea-4d75-9ddd-e41a5d08c698 | < 1.1.1 |
MEDIUM | 4.3 | The SRS Simple Hits Counter plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and incl… | — | wordfence |
| f75c3ed0-3b05-4132-b102-ba64fb8c338d | < 5.4.5 |
MEDIUM | 4.3 | The Bus Ticket Booking with Seat Reservation plugin for WordPress is vulnerable to Cross-Site Request Forgery in version… | — | wordfence |
| f7551d48-0858-4d82-aaca-3b04741938fd | MEDIUM | 4.3 | The Portfolio Gallery plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a f… | — | wordfence | |
| f7474e9c-8db2-44ac-80d6-c8b105786af6 | < 1.2.0 |
MEDIUM | 4.3 | The SureDash plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, … | — | wordfence |
| f738ecf3-5f10-43ab-b8ce-34ac41229e9b | < 6.3.0.1 |
MEDIUM | 4.3 | The Auto Affiliate Links plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and includi… | — | wordfence |
EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.
Scan My Website →