Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.
40,407 vulnerabilities found (page 1357 of 1617)
| CVE ID | Plugin / Theme | Severity | CVSS | Description | Fixed In | Source |
|---|---|---|---|---|---|---|
| f31b42c8-cf82-49cf-ac4c-d42a28252d66 | < 1.2.3.1 |
MEDIUM | 4.3 | The UsersWP WordPress plugin before 1.2.3.1 is missing access controls when updating a user avatar, and does not make su… | — | wordfence |
| f31a42c1-afb7-4a44-b4e8-f68c622bc43e | < 4.4 |
MEDIUM | 4.3 | The DSGVO All in one for WP plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and incl… | — | wordfence |
| f3108ef4-f889-4ae1-b86f-cedf46dcea19 | < 1.7.2 |
MEDIUM | 4.3 | The RapidLoad Power-Up for Autoptimize plugin for WordPress is vulnerable to unauthorized cache modification due to a mi… | — | wordfence |
| f30ae90a-54fb-4c55-a6ed-9c411a6997fb | < 1.12.2 |
MEDIUM | 4.3 | The SureForms β Drag and Drop Form Builder for WordPress plugin for WordPress is vulnerable to Sensitive Information D… | — | wordfence |
| f3063e92-e152-440d-bf02-b852ff87e319 | < 3.1.1.2 |
MEDIUM | 4.3 | The WP 2FA β Two-factor authentication for WordPress plugin for WordPress is vulnerable to accoutn takeover in all ver… | — | wordfence |
| f3045ebf-70af-4124-9116-42c07f64a3bf | < 2.6.7 |
MEDIUM | 4.3 | The Password Protected β Ultimate Plugin to Password Protect Your WordPress Content with Ease plugin for WordPress is … | — | wordfence |
| f2fc0457-ee9b-4571-b1ef-0649dde1badb | MEDIUM | 4.3 | The Easy Hotel Booking plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a … | — | wordfence | |
| f2fb18eb-a5ce-463f-aae2-55dc0bb3e9c7 | < 5.4.3 |
MEDIUM | 4.3 | The Classified Listing β AI-Powered Classified ads & Business Directory plugin for WordPress is vulnerable to unauthor… | — | wordfence |
| f2eccedd-c75e-41d8-b2de-9977b1143cc2 | < 4.6.1 |
MEDIUM | 4.3 | The JSM Show Post Metadata plugin for WordPress is vulnerable to unauthorized access due to a missing capability check o… | — | wordfence |
| f2cdd50d-6290-4cef-a72c-2e9d680d4f1f | < 3.3.33 |
MEDIUM | 4.3 | The Download Manager plugin for WordPress is vulnerable to unauthorized access of sensitive information in all versions … | — | wordfence |
| f2b31db1-c4f7-47c6-ad83-7ecd375e5f65 | MEDIUM | 4.3 | The Piotnet Addons For Elementor Pro plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to,… | — | wordfence | |
| f2b1e9a7-cbbd-4915-a1bb-e98bb70aa6a1 | MEDIUM | 4.3 | The Slider by 10Web β Responsive Image Slider plugin for WordPress is vulnerable to Cross-Site Request Forgery in all … | — | wordfence | |
| f2a79874-6dfe-41e7-a29b-2ee6b3753264 | < 4.0.7 |
MEDIUM | 4.3 | The Adminify plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function i… | — | wordfence |
| f29c44b4-903c-4165-9c2d-ede4e0086e85 | MEDIUM | 4.3 | The Pre-Publish Post Checklist plugin for WordPress is vulnerable to unauthorized access due to a missing capability che… | — | wordfence | |
| f29843c7-6249-4f6f-8238-f3b0d94ec10a | < 2.15 |
MEDIUM | 4.3 | The Merge + Minify + Refresh plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and… | — | wordfence |
| f29514d0-20a5-43f2-bf36-660579103220 | < 6.2.1 |
MEDIUM | 4.3 | The Dollie Hub β Build Your Own WordPress Cloud Platform plugin for WordPress is vulnerable to Information Exposure in… | — | wordfence |
| f2949ff1-5c69-4189-99a9-e50c65c78461 | < 2.1.4 |
MEDIUM | 4.3 | The Freesoul Deactivate Plugins β Plugin manager and cleanup plugin for WordPress is vulnerable to Cross-Site Request … | — | wordfence |
| f26a6ace-4623-4931-a4e4-8176d799d274 | < 1.3.7 |
MEDIUM | 4.3 | The WordPress Hosting Benchmark tool plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to,… | — | wordfence |
| f25de9b7-cd9d-4211-9201-816645b2caf9 | MEDIUM | 4.3 | The WP Subscription Forms PRO plugin for WordPress is vulnerable to unauthorized access due to a missing capability chec… | — | wordfence | |
| f256036d-11e8-4311-baa0-d15193c72da0 | < 3.3.53 |
MEDIUM | 4.3 | The Eventin plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the import_fi… | — | wordfence |
| f250793b-40c3-4362-bc0c-e3d65c922288 | < 2.2.1 |
MEDIUM | 4.3 | The WP Logger plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function … | — | wordfence |
| f24cfefe-f671-456d-a378-44a41fc81c0e | < 2.0.4 |
MEDIUM | 4.3 | Directory traversal vulnerability in the shortcodes function of Ultimate Member plugin prior to version 2.0.4 for WordPr… | — | wordfence |
| f23b144e-4380-4099-89b5-816c8c2f710f | < 5.0.12 |
MEDIUM | 4.3 | The WP Attachments plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including… | — | wordfence |
| f2358979-25b9-4c52-88dc-25390be6bd22 | < 5.10.3.1 |
MEDIUM | 4.3 | The TheGem theme for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on t… | — | wordfence |
| f231da1f-7eea-4fba-96b8-1f6e0c6ee3c2 | MEDIUM | 4.3 | The Custom Style plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.0.… | — | wordfence |
EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.
Scan My Website →