Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.
40,407 vulnerabilities found (page 1375 of 1617)
| CVE ID | Plugin / Theme | Severity | CVSS | Description | Fixed In | Source |
|---|---|---|---|---|---|---|
| dee18143-3b95-42fe-a69c-1862f3d30237 | < 1.3.9 |
MEDIUM | 4.3 | The CM WordPress Search And Replace Plugin plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versi… | — | wordfence |
| ded3a14d-f8ac-46f9-843b-591a6b558556 | < 1.3.2 |
MEDIUM | 4.3 | The Nanosoft theme for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in… | — | wordfence |
| decba9c0-36ee-4f97-9cc8-b56039233d10 | < 8.0.2 |
MEDIUM | 4.3 | Lack of CSRF checks in the ActiveCampaign WordPress plugin, versions before 8.0.2, on its Settings form, which could all… | — | wordfence |
| deb2544f-75ac-4d6c-bec7-9f35cfe0028d | < 1.2.2 |
MEDIUM | 4.3 | The HT Menu plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.2.1. Th… | — | wordfence |
| dea4a7f4-e075-45d9-bf71-f411f4ce30df | < 3.1.3 |
MEDIUM | 4.3 | The Prodigy Commerce plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a fu… | — | wordfence |
| de7b68e2-9cae-4e6f-a625-d8346836da39 | MEDIUM | 4.3 | The MF Gig Calendar plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and includin… | — | wordfence | |
| de69d597-b663-4c58-82e0-c90391fb8416 | < 1.1.4 |
MEDIUM | 4.3 | The Redirect Redirection plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability c… | — | wordfence |
| de62020b-5803-4ea7-89a1-24e5a512f2f3 | < 4.5.11 |
MEDIUM | 4.3 | The WPML plugin for WordPress is vulnerable to missing authorization checks in versions up to, and including, 4.5.10. Th… | — | wordfence |
| de6048e7-75c6-44b1-bc68-e36dce936c78 | MEDIUM | 4.3 | The Category SEO Meta Tags plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and inclu… | — | wordfence | |
| de53b1d8-e38f-42c5-adfc-2b0ce8d6945b | MEDIUM | 4.3 | The Typer Core plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 1.9.6 vi… | — | wordfence | |
| de495201-669c-4483-b30d-bb2abf6fe6c6 | < 5.7.7 |
MEDIUM | 4.3 | The ProfileGrid β User Profiles, Memberships, Groups and Communities plugin for WordPress is vulnerable to Insecure Di… | — | wordfence |
| de46743b-2cc6-4a29-bbc4-bc6cfb540e26 | < 4.1.6 |
MEDIUM | 4.3 | The Advanced Dynamic Pricing for WooCommerce plugin for WordPress is vulnerable to unauthorized modification of data due… | — | wordfence |
| de249879-00b8-49b3-8964-f7ab69ab292f | < 5.1.0 |
MEDIUM | 4.3 | The GDPR Cookie Compliance plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and inclu… | — | wordfence |
| de112e5a-4b92-4389-8c6e-b2bfeb6f6cd4 | MEDIUM | 4.3 | The Play.ht β Make Your Blog Posts Accessible With Text to Speech Audio plugin for WordPress is vulnerable to Cross-Si… | — | wordfence | |
| de00d13b-fab9-4284-9594-abd000fbb7ef | < 1.12.0 |
MEDIUM | 4.3 | The WP Mail Logging plugin for WordPress is vulnerable to unauthorized notice dismissal due to a missing capability chec… | — | wordfence |
| ddfc0150-d05c-4027-80d2-64c565fdd56d | < 4.1.1 |
MEDIUM | 4.3 | The Podlove Podcast Publisher plugin for WordPress is vulnerable to unauthorized access due to a missing capability chec… | — | wordfence |
| ddfba11c-eaa6-4c9e-9422-9390d433f24f | < 6.50.05 |
MEDIUM | 4.3 | The WP Compress for MainWP plugin for WordPress is vulnerable to unauthorized access due to a missing capability check o… | — | wordfence |
| ddee10e0-093c-47a3-8aa9-946d6d21e1b2 | < 4.3.7 |
MEDIUM | 4.3 | The GDPR Cookie Consent plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capabil… | — | wordfence |
| dde63254-058d-4151-b79e-33029c03decf | MEDIUM | 4.3 | The WP Accessibility Helper (WAH) plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, an… | — | wordfence | |
| dddecb2e-9ad6-4e44-afce-5eba7da6322d | < 7.7.12 |
MEDIUM | 4.3 | The The Post Grid β Shortcode, Gutenberg Blocks and Elementor Addon for Post Grid plugin for WordPress is vulnerable t… | — | wordfence |
| ddd85ff2-6607-4ac8-b91c-88f6f2fa6c56 | < 3.3.2 |
MEDIUM | 4.3 | The Metform Elementor Contact Form Builder for WordPress is vulnerable to Information Disclosure via the 'mf_payment_sta… | — | wordfence |
| ddc29341-a23e-4694-b852-90794c01473a | < 2.2.5 |
MEDIUM | 4.3 | The Clearfy Cache β WordPress optimization plugin, Minify HTML, CSS & JS, Defer plugin for WordPress is vulnerable to … | — | wordfence |
| ddacd612-0cd5-4b07-9184-bec6f1adbb4c | < 2.0.8 |
MEDIUM | 4.3 | The Simple 301 Redirects by BetterLinks plugin for WordPress is vulnerable to unauthorized enabling of plugin usage trac… | — | wordfence |
| dda9aa4a-bac7-4aa1-b0c3-c8e37b1fbe70 | < 3.4.1 |
MEDIUM | 4.3 | The WP HTML Mail plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 3.4.… | — | wordfence |
| dda43cdd-f0bb-4448-a067-1c9fb07b88ea | MEDIUM | 4.3 | The Event Rocket plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a functi… | — | wordfence |
EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.
Scan My Website →