Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.
40,407 vulnerabilities found (page 1358 of 1617)
| CVE ID | Plugin / Theme | Severity | CVSS | Description | Fixed In | Source |
|---|---|---|---|---|---|---|
| f22bb2ec-9d8d-45f6-9a86-cb5099fa301c | < 1.13.4 |
MEDIUM | 4.3 | The WP ERP | Complete HR solution with recruitment & job listings | WooCommerce CRM & Accounting plugin for WordPress is… | — | wordfence |
| f2262c0f-6839-43aa-9e19-9ccee6341ad7 | MEDIUM | 4.3 | The Simple Giveaways β Grow your business, email lists and traffic with contests plugin for WordPress is vulnerable to… | — | wordfence | |
| f21c9730-0834-4126-bc0d-c5f84b46dce9 | < 6.8.1 |
MEDIUM | 4.3 | The Abandoned Cart Lite for WooCommerce plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up … | — | wordfence |
| f212550c-1c93-4c3b-9eb2-b61cbe1eebb1 | MEDIUM | 4.3 | The Simple Price Calculator plugin for WordPress is vulnerable to unauthorized access due to a missing capability check … | — | wordfence | |
| f20d9160-bddf-4fdb-a5a6-cc792bb1c1ee | < 5.1.2 |
MEDIUM | 4.3 | The Event Booking Manager for WooCommerce plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versio… | — | wordfence |
| f1f69f93-80e3-434d-98a6-fc8757b4e6d1 | < 3.15.2 |
MEDIUM | 4.3 | The Avada (Fusion) Builder plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, a… | — | wordfence |
| f1f06f3d-ca03-470a-b63c-9ad7426472b7 | MEDIUM | 4.3 | The Authors List plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, … | — | wordfence | |
| f1eb9ec6-897a-4c38-a85c-033d7050dcfa | < 6.12.28 |
MEDIUM | 4.3 | The Ecwid by Lightspeed Ecommerce Shopping Cart plugin for WordPress is vulnerable to Cross-Site Request Forgery in all … | — | wordfence |
| f1e50d8c-e61c-4e94-b5e8-b24832dc24b6 | < 5.0.13 |
MEDIUM | 4.3 | The Download Monitor plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability… | — | wordfence |
| f1d3b954-2a3f-4be9-ad0a-dfc0774d8d91 | < 2.9.1 |
MEDIUM | 4.3 | The HT Mega β Absolute Addons For Elementor plugin for WordPress is vulnerable to unauthorized access due to a missing… | — | wordfence |
| f1bd7a28-cc48-4d99-8c4c-84cb810193ca | < 1.5.3 |
MEDIUM | 4.3 | The File Manager for Google Drive β Integrate Google Drive with WordPress plugin for WordPress is vulnerable to Cross-… | — | wordfence |
| f1b6f041-5ea6-48ca-9ca7-4ce96cbfa275 | < 1.10.0 |
MEDIUM | 4.3 | The WP Migration Plugin DB & Files β WP Synchro plugin for WordPress is vulnerable to Cross-Site Request Forgery in ve… | — | wordfence |
| f1aa6c8b-8231-49f1-a30a-fc1a03813221 | < 3.0.0 |
MEDIUM | 4.3 | The ProductX β Gutenberg WooCommerce Blocks plugin for WordPress is vulnerable to unauthorized modification of data du… | — | wordfence |
| f1a2a09d-b50e-499d-8cfd-6e2884e66127 | < 2.4.0 |
MEDIUM | 4.3 | The EazyDocs plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check o… | — | wordfence |
| f19a9bbb-9c7b-490f-b016-2e72ab2b35a5 | MEDIUM | 4.3 | The KiotViet Sync plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a funct… | — | wordfence | |
| f1946a48-c1d6-4ca9-909f-0d4b78c25c36 | MEDIUM | 4.3 | The delete-post-revisions-on-single-click theme for WordPress is vulnerable to Cross-Site Request Forgery in all version… | — | wordfence | |
| f18c1d00-ed8a-4b55-88d5-42d534ede493 | MEDIUM | 4.3 | The Team Builder plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a functi… | — | wordfence | |
| f18b1276-3f43-447d-8251-095c2dd57938 | MEDIUM | 4.3 | The Copymatic β AI Content Writer & Generator plugin for WordPress is vulnerable to Cross-Site Request Forgery in all … | — | wordfence | |
| f170379e-e833-42e0-96fd-1e1722a8331c | < 2.8.8 |
MEDIUM | 4.3 | The System Dashboard plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check… | — | wordfence |
| f16b11b0-11df-4fb7-a6af-123f6c09d791 | < 2.1.9 |
MEDIUM | 4.3 | The Kognetiks Chatbot for WordPress plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up … | — | wordfence |
| f15b4596-8e00-4e66-8b51-f49ede1ff307 | MEDIUM | 4.3 | The Refund Request for WooCommerce plugin for WordPress is vulnerable to unauthorized modification of data due to a miss… | — | wordfence | |
| f132b264-6e32-49d1-9733-f4a7c35dcdec | < 2.0.7 |
MEDIUM | 4.3 | The WP Table Builder β WordPress Table Plugin plugin for WordPress is vulnerable to Cross-Site Request Forgery in all … | — | wordfence |
| f131ea1e-d652-4854-abea-6a307ca8118f | < 1.6.3 |
MEDIUM | 4.3 | The EmailKit β Email Customizer for WooCommerce & WP plugin for WordPress is vulnerable to unauthorized data modificat… | — | wordfence |
| f12abcb2-37c1-4e2a-b947-74c50f49c6a4 | MEDIUM | 4.3 | The FormFacade plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.4.1.… | — | wordfence | |
| f10f6b12-5bf0-475a-ad9e-084ce5801b84 | < 7.11.28 |
MEDIUM | 4.3 | The WP Google Maps plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 7.… | — | wordfence |
EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.
Scan My Website →