Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.
40,407 vulnerabilities found (page 1390 of 1617)
| CVE ID | Plugin / Theme | Severity | CVSS | Description | Fixed In | Source |
|---|---|---|---|---|---|---|
| CVE-2026-2518 | MEDIUM | 4.3 | The FastX theme for WordPress is vulnerable to unauthorized limited plugin installation and activation due to missing ca… | — | nvd | |
| CVE-2026-2301 | MEDIUM | 4.3 | The Post Duplicator plugin for WordPress is vulnerable to unauthorized arbitrary protected post meta insertion in all ve… | — | nvd | |
| CVE-2026-2230 | MEDIUM | 4.3 | The Booking Calendar plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and i… | — | nvd | |
| CVE-2026-2112 | MEDIUM | 4.3 | The Dam Spam plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0.… | — | nvd | |
| CVE-2026-2023 | MEDIUM | 4.3 | The WP Plugin Info Card plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and incl… | — | nvd | |
| CVE-2026-1860 | MEDIUM | 4.3 | The Kali Forms plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and includi… | — | nvd | |
| CVE-2026-1857 | MEDIUM | 4.3 | The Gutenberg Blocks with AI by Kadence WP plugin for WordPress is vulnerable to Server-Side Request Forgery in all vers… | — | nvd | |
| CVE-2026-1655 | MEDIUM | 4.3 | The EventPrime plugin for WordPress is vulnerable to unauthorized post modification due to missing authorization checks … | — | nvd | |
| CVE-2026-1455 | MEDIUM | 4.3 | The Whatsiplus Scheduled Notification for Woocommerce plugin for WordPress is vulnerable to Cross-Site Request Forgery i… | — | nvd | |
| CVE-2025-14864 | MEDIUM | 4.3 | The Virusdie - One-click website security plugin for WordPress is vulnerable to Sensitive Information Exposure in all ve… | — | nvd | |
| CVE-2025-14742 | MEDIUM | 4.3 | The WP Recipe Maker plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check … | — | nvd | |
| CVE-2025-14342 | MEDIUM | 4.3 | The SEO Plugin by Squirrly SEO plugin for WordPress is vulnerable to unauthorized modification of data due to a missing … | — | nvd | |
| CVE-2025-14167 | MEDIUM | 4.3 | The Remove Post Type Slug plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and in… | — | nvd | |
| CVE-2025-13413 | MEDIUM | 4.3 | The Country Blocker for AdSense plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, … | — | nvd | |
| CVE-2025-13091 | MEDIUM | 4.3 | The Shopire theme for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on … | — | nvd | |
| CVE-2025-12172 | MEDIUM | 4.3 | The Mailchimp List Subscribe Form plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to… | — | nvd | |
| CVE-2025-12081 | MEDIUM | 4.3 | The ACF Photo Gallery Field plugin for WordPress is vulnerable to unauthorized modification of data due to a missing cap… | — | nvd | |
| CVE-2025-12075 | MEDIUM | 4.3 | The Order Splitter for WooCommerce plugin for WordPress is vulnerable to unauthorized access of data due to a missing ca… | — | nvd | |
| CVE-2025-12071 | MEDIUM | 4.3 | The Frontend User Notes plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, an… | — | nvd | |
| CVE-2025-12027 | MEDIUM | 4.3 | The Mesmerize Companion plugin for WordPress is vulnerable to unauthorized access and modification of data due to a miss… | — | nvd | |
| cffb3b61-fefc-4bf8-9904-55a7143aeef1 | < 5.3.0.1 |
MEDIUM | 4.3 | The Uncanny Automator Pro plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to 5.3.0.1. Th… | — | wordfence |
| cfd69b54-3056-4909-b3e8-ef2387ea9ea8 | < 1.4.2.1 |
MEDIUM | 4.3 | The WOOCS β WooCommerce Currency Switcher plugin for WordPress is vulnerable to unauthorized modification of data due … | — | wordfence |
| cfb87c87-f9dc-4f26-93f5-10d6bf6c822b | < 2.5.2 |
MEDIUM | 4.3 | The WP Discourse plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a functi… | — | wordfence |
| cfb45af3-c22a-4045-b564-22f7081868d7 | < 2.1.7 |
MEDIUM | 4.3 | The WP Mail Catcher plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2… | — | wordfence |
| cfaea9dd-98bf-4835-9c9f-362bf01e4639 | MEDIUM | 4.3 | The Infusionsoft Analytics plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and inclu… | — | wordfence |
EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.
Scan My Website →