Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.
40,407 vulnerabilities found (page 1359 of 1617)
| CVE ID | Plugin / Theme | Severity | CVSS | Description | Fixed In | Source |
|---|---|---|---|---|---|---|
| f105bee6-21b2-4014-bb0a-9e53c49e29b0 | < 4.4.6 |
MEDIUM | 4.3 | The Social Sharing Plugin β Social Warfare plugin for WordPress is vulnerable to Cross-Site Request Forgery in all ver… | — | wordfence |
| f0e8d029-af6b-43cb-aa90-f92777c5ac99 | MEDIUM | 4.3 | The Timthumb Vulnerability Scanner plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, a… | — | wordfence | |
| f0d584d0-1709-47dd-884b-ad21cac9d537 | < 4.1.20 |
MEDIUM | 4.3 | The Eventin β Event Calendar, Tickets, Registration, Booking & WooCommerce plugin for WordPress is vulnerable to Sensi… | — | wordfence |
| f0b25726-0b8e-4fce-a986-5f1e176da75a | < 4.1.6 |
MEDIUM | 4.3 | The Booking Calendar plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions before 4.1.6. This is … | — | wordfence |
| f0af86e4-c30b-49e2-ad6a-97a415a74d18 | < 2.9.5 |
MEDIUM | 4.3 | The Top 10 plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.10.4. Th… | — | wordfence |
| f08c63a0-2e8a-4ae9-abf6-5bd09c0a2073 | < 4.7.1 |
MEDIUM | 4.3 | The Print Anywhere & Create PDFs of Order Receipts, Invoices, Labels & More. plugin for WordPress is vulnerable to unaut… | — | wordfence |
| f079037c-cea6-4ba6-843f-99c5e5fe59a5 | < 1.0.105 |
MEDIUM | 4.3 | The Search in Place plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1… | — | wordfence |
| f0767c75-7571-46d9-b16a-2760be5a843b | MEDIUM | 4.3 | The 6Storage Rentals plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a fu… | — | wordfence | |
| f065648a-436a-459c-8ab1-c948c78b43c9 | < 4.4 |
MEDIUM | 4.3 | The Paytium: Mollie payment forms & donations plugin for WordPress is vulnerable to unauthorized access of data due to a… | — | wordfence |
| f0576cde-8d32-4f06-899a-a9ebff99d8ba | < 2.6.0 |
MEDIUM | 4.3 | The Post Expirator WordPress plugin before 2.6.0 does not have proper capability checks in place, which could allow user… | — | wordfence |
| f0543f32-54d4-4180-95c4-c9ddc0e08384 | < 0.9.6.1 |
MEDIUM | 4.3 | The Inline Google Spreadsheet Viewer plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to,… | — | wordfence |
| f0542cea-7550-4f51-a8b5-d313189b637a | MEDIUM | 4.3 | The flexo-social-gallery plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and inc… | — | wordfence | |
| f04ef770-73d9-4940-9736-c214bf5137ba | MEDIUM | 4.3 | The Course Redirects for Learndash plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up t… | — | wordfence | |
| f03deae6-24c6-49b4-b8cc-1d80275a2952 | < 1.2.8.5 |
MEDIUM | 4.3 | The Xpro Theme Builder For Elementor β FREE plugin for WordPress is vulnerable to unauthorized access due to a missing… | — | wordfence |
| f03dd6f4-44ca-4afe-b3fa-8770fca8a067 | < 4.5.5.3 |
MEDIUM | 4.3 | The Geo My WP plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions up to, and including, 4… | — | wordfence |
| f03cf84f-842f-4696-a152-d2fe0b23a5db | MEDIUM | 4.3 | The Developer plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.2.6. … | — | wordfence | |
| f0292877-33ca-425f-a95b-547b3bed2c10 | < 20.8.14 |
MEDIUM | 4.3 | The Sprout Invoices β Client Invoicing & Estimates plugin for WordPress is vulnerable to unauthorized access due to a … | — | wordfence |
| f01071a6-4188-4cb4-9aa5-731b32c6960e | MEDIUM | 4.3 | The Behance Portfolio Manager plugin for WordPress is vulnerable to unauthorized access due to a missing capability chec… | — | wordfence | |
| f00ca075-cbf0-428b-a53b-dc723889f69b | < 1.0.24 |
MEDIUM | 4.3 | The Email Address Encoder plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and includ… | — | wordfence |
| f00ac468-870a-4c43-af25-9febea5e4d67 | MEDIUM | 4.3 | The AI Post Generator | AutoWriter plugin for WordPress is vulnerable to unauthorized modification of data due to a miss… | — | wordfence | |
| f002d061-4e9d-49be-9d4c-c470ec97f653 | MEDIUM | 4.3 | Several YITHEMES plugins for WordPress are vulnerable to Cross-Site Request Forgery. This is due to missing or incorrect… | — | wordfence | |
| eff03dbc-1bb7-4a72-b57c-f1bde966c286 | < 1.8.7 |
MEDIUM | 4.3 | The Product Table by WBW plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and includi… | — | wordfence |
| efee685c-e2cd-471b-aea9-607124df6006 | < 1.2.59 |
MEDIUM | 4.3 | The UsersWP β Front-end login form, User Registration, User Profile & Members Directory plugin for WordPress is vulner… | — | wordfence |
| efe57241-2bb3-41d1-8638-b69ceaff0b4f | < 2.1.4 |
MEDIUM | 4.3 | The Alba Board plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 2.1.3. T… | — | wordfence |
| efcf88af-9c65-4825-a248-9c29eec7031b | < 2.8.3 |
MEDIUM | 4.3 | The Serial Codes Generator and Validator with WooCommerce Support plugin for WordPress is vulnerable to unauthorized acc… | — | wordfence |
EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.
Scan My Website →