Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.
40,407 vulnerabilities found (page 1385 of 1617)
| CVE ID | Plugin / Theme | Severity | CVSS | Description | Fixed In | Source |
|---|---|---|---|---|---|---|
| d4b6d2c6-d157-4c4c-b6e1-557b8353c742 | < 1.0.3 |
MEDIUM | 4.3 | The Auto Tag Creator plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability… | — | wordfence |
| d4a15720-2535-4258-8d58-20818cdbd413 | MEDIUM | 4.3 | The Title Experiments Free plugin for WordPress is vulnerable to unauthorized access due to a missing capability check o… | — | wordfence | |
| d49cdae7-4a95-494d-81da-a93e3c764ee7 | MEDIUM | 4.3 | The Lazy content Slider plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and includin… | — | wordfence | |
| d49b8c44-4dad-4990-a8a8-116b424a7dfa | < 1.2.2 |
MEDIUM | 4.3 | The Post Meta Data Manager plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and i… | — | wordfence |
| d49b404f-4683-410b-884e-2c11218a3204 | < 2.5.0 |
MEDIUM | 4.3 | The GutenKit β Page Builder Blocks, Patterns, and Templates for Gutenberg Block Editor plugin for WordPress is vulnera… | — | wordfence |
| d49a85d9-dea4-4632-adf7-c29b71b12c50 | MEDIUM | 4.3 | The Build App Online plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and includi… | — | wordfence | |
| d48f98cb-18d5-4b15-96cb-94a4c86148e4 | < 1.1.1 |
MEDIUM | 4.3 | The RealPress β Real Estate Plugin plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to,… | — | wordfence |
| d484500f-c8c1-4278-8a38-82a7fd5674f9 | < 1.0.35 |
MEDIUM | 4.3 | The ProjectHuddle Client Site plugin for WordPress is vulnerable to unauthorized modification of data due to a missing c… | — | wordfence |
| d4828a91-fd56-4c38-8666-d296721120e9 | MEDIUM | 4.3 | The Smart WeTransfer plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a fu… | — | wordfence | |
| d47f7d6f-7535-4117-b0da-b27811f733e6 | MEDIUM | 4.3 | The sevenstars theme for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.4… | — | wordfence | |
| d472011d-1623-4791-9d56-715d90fe0469 | < 3.0.3 |
MEDIUM | 4.3 | The Location Weather plugin for WordPress is vulnerable to unauthorized modification of data due to missing capability c… | — | wordfence |
| d46f7a3e-b444-42ce-bf5d-e93a83167181 | MEDIUM | 4.3 | The Fiorello theme for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including,… | — | wordfence | |
| d4655236-7dfe-40ae-9d0c-6eacc59af13d | < 1.3.1 |
MEDIUM | 4.3 | The Hide Dashboard Notifications plugin for WordPress is vulnerable to unauthorized modification of data due to a missin… | — | wordfence |
| d44a45fb-3bff-4a1f-8319-a58a47a9d76b | < 2.8.6 |
MEDIUM | 4.3 | The Social Media Share Buttons & Social Sharing Icons plugin for WordPress is vulnerable to Cross-Site Request Forgery i… | — | wordfence |
| d440b7fc-e094-49b7-91d0-8f0d54e6ce83 | MEDIUM | 4.3 | The Grand Blog theme for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 3.1. Th… | — | wordfence | |
| d433a5b3-4661-4246-ae60-8a99633372ad | < 1.1.4 |
MEDIUM | 4.3 | The Redirect Redirection plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and includi… | — | wordfence |
| d4271fde-ce9e-416e-8f7d-661a3e777a5d | MEDIUM | 4.3 | The Meks Quick Plugin Disabler plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and i… | — | wordfence | |
| d411982d-4ed3-4dd5-9a18-111c15aa641b | MEDIUM | 4.3 | The Multilanguage by BestWebSoft plugin for WordPress is vulnerable to unauthorized access due to a missing capability c… | — | wordfence | |
| d40e9d1c-8693-467f-a0e3-1000c6635a25 | < 1.3.10 |
MEDIUM | 4.3 | The WordPress Header Builder Plugin β Pearl plugin for WordPress is vulnerable to unauthorized access due to a missing… | — | wordfence |
| d3efaa0d-8af6-4cdf-9225-8bbcfdbb73d3 | < 3.3.50 |
MEDIUM | 4.3 | The Download Manager plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check… | — | wordfence |
| d3ee118c-b8cd-4bac-97bd-508efdfa1a1e | < 1.0.3 |
MEDIUM | 4.3 | The Disable Elementor Editor Translation plugin for WordPress is vulnerable to unauthorized access due to a missing capa… | — | wordfence |
| d3e6185e-b07c-4ce3-a2b4-971c88e10bc0 | MEDIUM | 4.3 | The Stratus theme for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in … | — | wordfence | |
| d3cd468e-424c-48bb-bc1f-cb8f8c3ccb20 | < 5.8.5 |
MEDIUM | 4.3 | The wp-google-map-gold plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a … | — | wordfence |
| d3ca4c3c-2b20-42d4-8dcf-77f4d52c25a3 | < 2.0.1 |
MEDIUM | 4.3 | The Square theme for WordPress is vulnerable to unauthorized plugin activation due to a missing capability check on the … | — | wordfence |
| d3c6fb8b-9df8-4cf5-b9e6-702852bb1977 | < 0.7.1 |
MEDIUM | 4.3 | The PixFields plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 0.7.0. … | — | wordfence |
EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.
Scan My Website →