Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.
40,407 vulnerabilities found (page 1407 of 1617)
| CVE ID | Plugin / Theme | Severity | CVSS | Description | Fixed In | Source |
|---|---|---|---|---|---|---|
| bcde21fd-8a2b-482d-91a0-7c8578055b61 | < 2.4.6 |
MEDIUM | 4.3 | The Animation Addons for Elementor β GSAP Powered Elementor Addons & Website Templates plugin for WordPress is vulnera… | — | wordfence |
| bcdc73d4-f47d-4bbf-a47c-1028021fb5a4 | < 1.8.5 |
MEDIUM | 4.3 | The CM Pop-Up β Create engaging popups to capture attention and boost interaction plugin for WordPress is vulnerable t… | — | wordfence |
| bcd6a860-3f60-474c-a5bf-e0ed4ca574be | MEDIUM | 4.3 | The Base64 Encoder/Decoder plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and i… | — | wordfence | |
| bcd5b83a-7d51-455b-bb31-dd776264fc6b | MEDIUM | 4.3 | The Skysa Text Ticker App plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and in… | — | wordfence | |
| bcc7f142-b330-492f-9855-10b443a98b63 | < 3.24.1 |
MEDIUM | 4.3 | The FlexTable β Data Table Sync with Google Sheets plugin for WordPress is vulnerable to unauthorized access due to a … | — | wordfence |
| bca37dc1-64a7-4265-bd38-d58844140336 | < 4.6.0 |
MEDIUM | 4.3 | The Online Booking & Scheduling Calendar for WordPress by vcita plugin for WordPress is vulnerable to Sensitive Informat… | — | wordfence |
| bc9a2639-cec8-408e-9ba2-ffb6c8c7da21 | < 1.0.44 |
MEDIUM | 4.3 | The Google Maps CP plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability c… | — | wordfence |
| bc96bbc5-b4ad-4076-a0dd-13e3407b9d76 | < 7.7.4 |
MEDIUM | 4.3 | The ChatBot plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in… | — | wordfence |
| bc883e7e-af82-47e1-a0c0-122e6abd6b52 | < 2.1.7 |
MEDIUM | 4.3 | The WP Hotel Booking plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check… | — | wordfence |
| bc6cfad1-d23a-4a96-9d6c-841b6d795a01 | < 7.13.55 |
MEDIUM | 4.3 | The Super Socializer plugin for WordPress is vulnerable to Cross-Site Request Forgery due to missing nonce checks on sev… | — | wordfence |
| bc5ef2cf-8b97-4aca-8e90-bb0a19788e4e | < 1.9.2 |
MEDIUM | 4.3 | The Stripe Payments For WooCommerce by Checkout plugin for WordPress is vulnerable to Cross-Site Request Forgery in vers… | — | wordfence |
| bc5da189-838d-4c0b-a734-283c4da36473 | < 3.1.2 |
MEDIUM | 4.3 | The Advanced Classifieds & Directory Pro plugin for WordPress is vulnerable to unauthorized loss of data due to a missin… | — | wordfence |
| bc59b997-a8e2-4c75-aa5f-36cc5a66326e | MEDIUM | 4.3 | The Plainview Protect Passwords plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and … | — | wordfence | |
| bc44c95e-9ca0-46d0-8315-72612ef3f855 | < 1.2.0 |
MEDIUM | 4.3 | The WPCS β WordPress Currency Switcher Professional plugin for WordPress is vulnerable to unauthorized modification of… | — | wordfence |
| bc3f1d4e-84f7-4878-8b06-10444caa7dcf | MEDIUM | 4.3 | The WP iCal Availability plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and includi… | — | wordfence | |
| bc2cbf43-3e8a-4364-9355-6d6587204c1c | < 1.1.8 |
MEDIUM | 4.3 | The MSHOP MY SITE plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability ch… | — | wordfence |
| bc2af96c-09c5-4ddf-a910-04291aeeef49 | < 2.0.4 |
MEDIUM | 4.3 | The Ultimate Member plugin for WordPress is vulnerable to unrestricted file uploads in versions prior to version 2.0.4. … | — | wordfence |
| bc20f303-cac3-4517-9c45-153c410a13af | < 1.1.4 |
MEDIUM | 4.3 | The BEAR for WordPress is vulnerable to Missing Authorization in versions up to, and including, 1.1.3.3. This is due to … | — | wordfence |
| bc200f72-072d-407d-9114-201241c244f2 | MEDIUM | 4.3 | The Questionar for Elementor plugin for WordPress is vulnerable to unauthorized access due to a missing capability check… | — | wordfence | |
| bc1dfd50-aeac-465a-a402-ba85c50fdfc5 | < 7.0.1 |
MEDIUM | 4.3 | The PlatiOnline Payments plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on … | — | wordfence |
| bc1abdd7-d563-44af-86d3-58005706d624 | < 4.4.3 |
MEDIUM | 4.3 | The WPC Grouped Product for WooCommerce plugin for WordPress is vulnerable to unauthorized access due to a missing capab… | — | wordfence |
| bbe973a3-a8bf-4037-9067-7cc0987291fe | < 3.0.2 |
MEDIUM | 4.3 | The qTranslate X Cleanup and WPML Import plugin for WordPress is vulnerable to unauthorized modification of data due to … | — | wordfence |
| bbdeaa77-72c9-4afc-8913-7a1e44cdeb82 | MEDIUM | 4.3 | The Bulk Edit Post Titles plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on… | — | wordfence | |
| bbd0fb22-a39c-43f5-a93c-976b7e49967b | < 1.34.0 |
MEDIUM | 4.3 | The YITH WooCommerce Account Funds Premium plugin for WordPress is vulnerable to unauthorized access due to a missing ca… | — | wordfence |
| bbcdb70f-77db-48ab-ae23-c46caecdd3be | < 3.8.15 |
MEDIUM | 4.3 | The Ultimate Dashboard plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and inclu… | — | wordfence |
EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.
Scan My Website →