Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.
40,407 vulnerabilities found (page 1405 of 1617)
| CVE ID | Plugin / Theme | Severity | CVSS | Description | Fixed In | Source |
|---|---|---|---|---|---|---|
| bfa7ae6c-6bc8-4787-b95b-c12243d0a45c | < 1.4.26 |
MEDIUM | 4.3 | The Royal MCP β Secure AI Connector for Claude, ChatGPT & Gemini plugin for WordPress is vulnerable to unauthorized ac… | — | wordfence |
| bf801042-5cd5-424f-a25a-858302285170 | < 1.24.2 |
MEDIUM | 4.3 | The Post and Page Builder by BoldGrid β Visual Drag and Drop Editor plugin for WordPress is vulnerable to Cross-Site R… | — | wordfence |
| bf798142-4daf-41f5-8416-701d03476520 | < 2.0.12 |
MEDIUM | 4.3 | The WooCommerce Conversion Tracking plugin for WordPress is vulnerable to unauthorized access due to a missing capabilit… | — | wordfence |
| bf77908d-2469-449b-abab-f8411ee42f65 | < 4.6.0 |
MEDIUM | 4.3 | The Online Booking & Scheduling Calendar for WordPress by vcita plugin for WordPress is vulnerable to unauthorized acces… | — | wordfence |
| bf539c01-596a-44dd-9587-6be6978ab0fa | < 2.28.15 |
MEDIUM | 4.3 | The Seraphinite Accelerator plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, … | — | wordfence |
| bf51e9ef-7a4b-4f5b-82ae-0de6bcd90758 | < 2.0.23 |
MEDIUM | 4.3 | The Market Exporter plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and includin… | — | wordfence |
| bf2ddc42-9910-40e5-9546-89f229b852da | MEDIUM | 4.3 | The Category Meta plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.2… | — | wordfence | |
| bf1f402d-98d7-42d7-8d8d-ff74a65e5293 | MEDIUM | 4.3 | The Permalinks Customizer plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and includ… | — | wordfence | |
| bf0ad697-159f-4466-aa7e-d7c60b737cd8 | < 0.6 |
MEDIUM | 4.3 | The HD Quiz β Save Results Light plugin for WordPress is vulnerable to unauthorized modification of data due to a miss… | — | wordfence |
| bf0871e7-7dc4-4acb-868f-7dc32016582e | MEDIUM | 4.3 | The Goldstar plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function i… | — | wordfence | |
| bf05a79a-0375-4c9d-bbf0-a87484327b87 | < 3.4.8 |
MEDIUM | 4.3 | The WP-Members Membership plugin for WordPress is vulnerable to unauthorized plugin settings update due to a missing cap… | — | wordfence |
| becbf49b-0384-4c78-a983-2effbfac8dd1 | MEDIUM | 4.3 | The WP Optimizer plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, … | — | wordfence | |
| bec89b35-8cf2-4afa-8f3e-92ee6420ae28 | < 1.2.21 |
MEDIUM | 4.3 | The Elastic Email Sender plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on … | — | wordfence |
| bec19d80-ba51-4ff8-a111-c2e45928fb51 | < 2.0.12 |
MEDIUM | 4.3 | The Fluent Boards Pro plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and … | — | wordfence |
| beadd35b-2bce-431e-8347-2d1a87d02f01 | MEDIUM | 4.3 | The Users To CSV plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.4.… | — | wordfence | |
| bea4b2c6-f078-4b47-b4d3-16216a54c0ab | < 1.9.3 |
MEDIUM | 4.3 | The Sync Post With Other Site plugin for WordPress is vulnerable to unauthorized access due to a missing capability chec… | — | wordfence |
| be9811b8-602f-4525-bc15-75e5efe794f6 | < 2.3.2 |
MEDIUM | 4.3 | The Fluent Support Pro plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and inclu… | — | wordfence |
| be964722-2080-4289-a960-a460a8d09c9e | < 1.4.3 |
MEDIUM | 4.3 | The News Kit Addons For Elementor plugin for WordPress is vulnerable to unauthorized access due to a missing capability … | — | wordfence |
| be8ec147-1469-449b-b51b-f1c328b1922f | MEDIUM | 4.3 | The User Activity Log Pro plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capab… | — | wordfence | |
| be8dcff9-1626-4919-b297-c423891f3d02 | MEDIUM | 4.3 | The Simple Mobile URL Redirect plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and i… | — | wordfence | |
| be86c751-499b-4772-a457-14427fa56c39 | MEDIUM | 4.3 | The Ray Enterprise Translation plugin for WordPress is vulnerable to unauthorized access due to a missing capability che… | — | wordfence | |
| be837a77-9b25-43af-aaba-94a8aa59e7e3 | < 4.6.15 |
MEDIUM | 4.3 | The rtMedia for WordPress, BuddyPress and bbPress plugin for WordPress is vulnerable to unauthorized access of data due … | — | wordfence |
| be73e45a-ce00-4a1f-b722-32a94c5beadc | < 1.2.11 |
MEDIUM | 4.3 | The FormCraft plugin for WordPress is vulnerable to unauthorized access of data due to missing capability checks on the … | — | wordfence |
| be436047-6bea-465b-8de1-b0a081a85ed6 | MEDIUM | 4.3 | The Booked - Appointment Booking for WordPress plugin for WordPress is vulnerable to Cross-Site Request Forgery in versi… | — | wordfence | |
| be3869a9-f72d-4bbb-ba51-d2761ca761f2 | < 1.1.0 |
MEDIUM | 4.3 | The Easy Mega Menu Plugin for WordPress β ThemeHunk plugin for WordPress is vulnerable to unauthorized access due to a… | — | wordfence |
EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.
Scan My Website →