Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.
40,407 vulnerabilities found (page 1360 of 1617)
| CVE ID | Plugin / Theme | Severity | CVSS | Description | Fixed In | Source |
|---|---|---|---|---|---|---|
| efaef405-9721-4fb6-bcb4-4bd4f78742fd | MEDIUM | 4.3 | The WP Tiles plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and including, 1.1.… | — | wordfence | |
| efadd529-f369-4c7a-ab71-170e72c997f1 | < 3.2 |
MEDIUM | 4.3 | The WP Custom Cursors plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to 3.2. This is du… | — | wordfence |
| efa9b44d-8b6c-4a11-82af-cecc2c202024 | MEDIUM | 4.3 | The Simple Theme Changer plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and includi… | — | wordfence | |
| efa646ee-ebee-4528-a421-09ee3dc8275a | < 2.8.0 |
MEDIUM | 4.3 | The bitformpro plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including… | — | wordfence |
| efa4b67c-1bb8-413a-8cb8-039168b0b586 | < 1.0.6 |
MEDIUM | 4.3 | The Chankhe theme for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on … | — | wordfence |
| ef926bc7-b50f-40ac-9ace-7e01b26f34e1 | < 2.1.0 |
MEDIUM | 4.3 | The Page Builder: Pagelayer β Drag and Drop website builder plugin for WordPress is vulnerable to Incorrect Authorizat… | — | wordfence |
| ef8c41c6-3065-4650-81e9-bdba0e38f2bd | < 5.6.8 |
MEDIUM | 4.3 | The AutomatorWP β Automator plugin for no-code automations, webhooks & custom integrations in WordPress plugin for Wor… | — | wordfence |
| ef7ec175-cee5-4559-909d-ee689158d67c | < 1.14 |
MEDIUM | 4.3 | The League Table plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.13… | — | wordfence |
| ef7cf633-e907-4da1-bd96-0013e88defbb | < 2.1.8 |
MEDIUM | 4.3 | The Minify HTML plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.1.7… | — | wordfence |
| ef5f99ca-8a0d-4ec4-8b59-c0c4637dfbc3 | < 1.1.4 |
MEDIUM | 4.3 | The Redirect Redirection plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capabi… | — | wordfence |
| ef528553-4037-43e0-af2d-8324412147f3 | < 12.7 |
MEDIUM | 4.3 | The MihanPanel plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to 12.7. This is due to m… | — | wordfence |
| ef480fce-d0e3-47af-92ea-2c84c3f8e2f7 | < 2.2.7 |
MEDIUM | 4.3 | The Popup Box β new WordPress popup plugin plugin for WordPress is vulnerable to Cross-Site Request Forgery in all ver… | — | wordfence |
| ef47feb7-76fd-470d-ba48-55ba3c323c6d | < 1.9.3 |
MEDIUM | 4.3 | The Gutenberg Blocks and Page Layouts β Attire Blocks plugin for WordPress is vulnerable to unauthorized modification … | — | wordfence |
| ef176a6c-33d1-45d6-8a1d-3df1e8eb2170 | MEDIUM | 4.3 | The Bulk SEO Image plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to and including 1.1.… | — | wordfence | |
| ef1362b5-576d-4d22-ad5d-89f38e8e3743 | MEDIUM | 4.3 | The Business Card plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including,… | — | wordfence | |
| ef014597-dd85-4ac0-a08d-de60b34ab4c9 | MEDIUM | 4.3 | The Bulk Content Creator plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and includi… | — | wordfence | |
| eef7f964-8330-4c57-a5f4-0280853dcf76 | < 2.24.4 |
MEDIUM | 4.3 | The Internal Link Juicer: SEO Auto Linker for WordPress plugin for WordPress is vulnerable to Cross-Site Request Forgery… | — | wordfence |
| eef0796f-f56d-4be3-8fbd-010ac0fb3448 | < 1.5.2 |
MEDIUM | 4.3 | The Xpro Addons plugin for WordPress is vulnerable to unauthorized creation of data due to a missing capability check on… | — | wordfence |
| eec9ae40-3a76-4208-8348-4a9ef72fc918 | < 16.9 |
MEDIUM | 4.3 | The Malcure Malware Scanner β #1 Toolset for Malware Removal plugin for WordPress is vulnerable to unauthorized access… | — | wordfence |
| eeacc903-9be2-4333-9528-d98707d1df55 | < 1.5.4 |
MEDIUM | 4.3 | The Accelerate theme for WordPress is vulnerable to unauthorized modification of data due to a missing capability check … | — | wordfence |
| eea33d0b-2547-4c51-8c4c-d178d6c8502d | < 3.12.28 |
MEDIUM | 4.3 | The Easy Appointments plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 3… | — | wordfence |
| ee7c679e-392c-40cd-b768-d78fae6065bb | MEDIUM | 4.3 | The WP Sliding Login/Dashboard Panel plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up… | — | wordfence | |
| ee73937c-8a97-4afd-a0f6-d5e9caddc82c | MEDIUM | 4.3 | The Enable Latex plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, … | — | wordfence | |
| ee6ffb62-0dfd-40c1-8fde-8705d99d4144 | < 2.2.6 |
MEDIUM | 4.3 | The UpsellWP plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function i… | — | wordfence |
| ee5ad5d6-f38c-481a-ba0e-38481804739f | MEDIUM | 4.3 | The More Fields plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.1. … | — | wordfence |
EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.
Scan My Website →