Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.
40,407 vulnerabilities found (page 1353 of 1617)
| CVE ID | Plugin / Theme | Severity | CVSS | Description | Fixed In | Source |
|---|---|---|---|---|---|---|
| f72ba0e2-a9c4-43b0-a01f-185554090162 | < 6.1.0 |
MEDIUM | 4.3 | The WooCommerce CVR Payment Gateway plugin for WordPress is vulnerable to unauthorized modification of data due to a mis… | — | wordfence |
| f72820ec-5638-4c65-a0bd-355b8ca2435c | MEDIUM | 4.3 | The Page Manager for Elementor plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up t… | — | wordfence | |
| f713f2f8-545a-4f54-a028-8422c0942a63 | < 2.1.6 |
MEDIUM | 4.3 | The Wholesale Suite plugin for WordPress is vulnerable to unauthorized data modification due to a missing capability che… | — | wordfence |
| f711c9d0-aa56-4e4c-bbcf-afa9598c3518 | < 2.27.22 |
MEDIUM | 4.3 | The Seraphinite Accelerator plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and … | — | wordfence |
| f709fca2-b7b6-4567-8055-1156f510d1ca | < 1.8.4 |
MEDIUM | 4.3 | The Envo Extra plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.8.3.… | — | wordfence |
| f6f91816-a263-4938-bac1-eeb3bb2fc120 | MEDIUM | 4.3 | The Novo-Map : your WP posts on custom google maps plugin for WordPress is vulnerable to Cross-Site Request Forgery in v… | — | wordfence | |
| f6f12812-3c14-41c1-b14b-af84f835a773 | MEDIUM | 4.3 | The AP Background plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including,… | — | wordfence | |
| f6ef2976-0fae-4b8f-b63a-7de7390cbd00 | < 3.0.9 |
MEDIUM | 4.3 | The Quiz Cat β WordPress Quiz Plugin plugin for WordPress is vulnerable to unauthorized access due to a missing capabi… | — | wordfence |
| f6d90ca3-dc24-4634-9f98-83a909e3e093 | MEDIUM | 4.3 | The Automate Hub Free by Sperse.IO plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up t… | — | wordfence | |
| f6d44749-8b1a-4d22-9917-fee134737063 | MEDIUM | 4.3 | The Just Custom Fields plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capabili… | — | wordfence | |
| f6cf31f0-b560-40c5-b6e4-4fc444e6d23b | MEDIUM | 4.3 | The Super Static Cache plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and inclu… | — | wordfence | |
| f6ca7fc4-a5fb-4f8a-b49e-413956b8ac96 | MEDIUM | 4.3 | The Institutions Directory plugin for WordPress is vulnerable to unauthorized access due to a missing capability check o… | — | wordfence | |
| f6c8bd7c-0d9e-444d-9e0f-ccdd84b9b6dd | < 1.0.6 |
MEDIUM | 4.3 | The Writesonic plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.… | — | wordfence |
| f6c5e3f8-ebbd-4cc3-b9b1-3f1704e3c07a | < 2.12.9 |
MEDIUM | 4.3 | The Paid Memberships Pro β Content Restriction, User Registration, & Paid Subscriptions plugin for WordPress is vulner… | — | wordfence |
| f6bdd745-066d-4b8e-a66c-6d3fb9a9ef12 | < 9.1.4 |
MEDIUM | 4.3 | The NEX-Forms β Ultimate Forms Plugin for WordPress plugin for WordPress is vulnerable to Cross-Site Request Forgery i… | — | wordfence |
| f6b9e63f-0492-4d51-a8ae-0874ef57e852 | < 8.2.7 |
MEDIUM | 4.3 | The WordPress Tooltips plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including… | — | wordfence |
| f6b87ed9-84c9-497e-a8dc-96dfa9b940b7 | MEDIUM | 4.3 | The Grand Magazine theme for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 3.5… | — | wordfence | |
| f6a0d6df-60a6-42e3-9e9b-6171bb589f4e | < 2.9.0 |
MEDIUM | 4.3 | The CM Download Manager plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to 2.9.0. This i… | — | wordfence |
| f69dfe83-03cb-47e1-b462-7ba4998e9cd3 | MEDIUM | 4.3 | The Actionwear products sync plugin for WordPress is vulnerable to unauthorized access due to a missing capability check… | — | wordfence | |
| f6914ae1-6e31-4a5b-8dac-4d2ee96a6bd9 | MEDIUM | 4.3 | The Attractive Donations System - Easy Stripe & Paypal donations plugin for WordPress is vulnerable to Cross-Site Reques… | — | wordfence | |
| f68e6fed-1986-4172-8270-0460450d6a02 | < 3.8.7 |
MEDIUM | 4.3 | The Newspack plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function i… | — | wordfence |
| f6893498-5cd0-4649-893c-a204508cfd04 | < 5.1.7 |
MEDIUM | 4.3 | The No External Links plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including,… | — | wordfence |
| f670b93e-da2e-43e7-a28a-6cacba4df3a1 | < 2.51 |
MEDIUM | 4.3 | The Simple Author Box plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including,… | — | wordfence |
| f6658edb-11dc-4594-8936-95d60d581f49 | < 6.24.2 |
MEDIUM | 4.3 | The OAuth Single Sign On β SSO (OAuth Client) plugin for WordPress is vulnerable to Cross-Site Request Forgery in vers… | — | wordfence |
| f65ee908-004f-4526-aeca-41b36522bb30 | < 4.0 |
MEDIUM | 4.3 | The GoHero Store Customizer for WooCommerce plugin for WordPress is vulnerable to unauthorized modification of data due … | — | wordfence |
EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.
Scan My Website →