Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.
40,407 vulnerabilities found (page 1408 of 1617)
| CVE ID | Plugin / Theme | Severity | CVSS | Description | Fixed In | Source |
|---|---|---|---|---|---|---|
| bbc8e925-878a-42e2-ae78-35ec95e07526 | < 3.4.5 |
MEDIUM | 4.3 | Cross-Site Request Forgery (CSRF) vulnerability leading to plugin Settings Update discovered in WP Content Copy Protecti… | — | wordfence |
| bbc60271-5f22-48fe-8f56-a66549daf638 | < 1.18.9 |
MEDIUM | 4.3 | The Pochipp plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in… | — | wordfence |
| bbc41888-35e5-483b-b048-7a504d2e5566 | < 5.6.3 |
MEDIUM | 4.3 | The LatePoint plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 5.6.2. … | — | wordfence |
| bbb40038-75ea-4f09-b852-d90b087f1802 | MEDIUM | 4.3 | The sourceplay-navermap plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a… | — | wordfence | |
| bbb19be3-8783-4474-a258-285e3b90f1e0 | < 1.0.13 |
MEDIUM | 4.3 | The Meks Video Importer plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a… | — | wordfence |
| bba5f363-8d75-4c73-b8ae-eccf06dd1979 | < 1.5 |
MEDIUM | 4.3 | The PDF Thumbnail Generator plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and … | — | wordfence |
| bb995311-8837-4db5-a25d-37e41d932774 | < 5.25 |
MEDIUM | 4.3 | The WP Tools Repair, Javascript errors, Jquery errors, Increase Maximum Limits, File Permissions, Transients, Error Log … | — | wordfence |
| bb8aca3a-e4f7-41d6-9ea9-d189817c2c04 | < 2.3.5 |
MEDIUM | 4.3 | The Visibility Logic for Elementor plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, a… | — | wordfence |
| bb81b2ce-583b-411c-b0f5-a233e0d1986b | < 1.2.2 |
MEDIUM | 4.3 | The Hash Form β Drag & Drop Form Builder plugin for WordPress is vulnerable to unauthorized access due to a missing ca… | — | wordfence |
| bb7d99a7-1e7d-43e1-839c-286b454c8276 | MEDIUM | 4.3 | The SendGrid for WordPress plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability c… | — | wordfence | |
| bb70ad52-b964-4c56-98a2-06be375a79af | MEDIUM | 4.3 | The AdminQuickbar plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including,… | — | wordfence | |
| bb671c8f-9e14-4f79-adfa-72f48ec02449 | < 3.0.12 |
MEDIUM | 4.3 | The Post Duplicator plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 3.0… | — | wordfence |
| bb53b541-1c7a-4265-ba7a-18be976a01d7 | < 1.3.58 |
MEDIUM | 4.3 | The Findgo - Directory Listing WordPress Theme theme for WordPress is vulnerable to Cross-Site Request Forgery in all ve… | — | wordfence |
| bb280004-e0ba-44c8-a205-8fec30900d86 | < 8.0.1398 |
MEDIUM | 4.3 | The Bread & Butter: Gate content + Capture leads + Collect first-party data + Nurture with Ai agents plugin for WordPres… | — | wordfence |
| bb1fe70b-80f8-408f-8f4b-4eca57c6ade8 | < 1.7.1 |
MEDIUM | 4.3 | The WP Sync for Notion β Notion to WordPress plugin for WordPress is vulnerable to unauthorized access due to a missin… | — | wordfence |
| bb175149-05b5-4e8e-8437-9a07762c7269 | < 3.12.28 |
MEDIUM | 4.3 | The Easy Appointments plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions up to, and excl… | — | wordfence |
| bb15316c-2414-40c0-97e7-0b4d1b8293a4 | MEDIUM | 4.3 | The gap-hub-user-role plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including,… | — | wordfence | |
| bb0f8a0c-d02f-46e2-8808-3ffada105d13 | < 3.5.1.1 |
MEDIUM | 4.3 | The Tickera plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 3.5.1.0. … | — | wordfence |
| baf2af6b-277e-4613-b066-1f2acda56602 | < 5.0.1 |
MEDIUM | 4.3 | The Classified Listing β Classified ads & Business Directory Plugin plugin for WordPress is vulnerable to Content Inje… | — | wordfence |
| baee1bba-c531-4a6a-8e4d-5c44e3d7e84f | < 5.2.6 |
MEDIUM | 4.3 | The Ninja Tables β Easy Data Table Builder plugin for WordPress is vulnerable to Sensitive Information Exposure in all… | — | wordfence |
| bae67a68-4bd1-4b52-b3dd-af0eef014028 | < 1.1.3 |
MEDIUM | 4.3 | The WP Fastest Cache plugin for WordPress is vulnerable to unauthorized data deletion due to a missing capability check … | — | wordfence |
| bae36712-f400-4965-9885-de9f7fbfd9b1 | MEDIUM | 4.3 | The Just TinyMCE Custom Styles plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and i… | — | wordfence | |
| bad0bd6b-9c88-4d31-90b5-92d3ceb8c0af | < 0.9.95 |
MEDIUM | 4.3 | The WPvivid plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the r… | — | wordfence |
| bab68830-5ac5-4aa3-929a-ba2bca03b1ca | MEDIUM | 4.3 | The WP Prayer plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.0… | — | wordfence | |
| baa8e48f-769a-4f48-bc47-d55c179d1ca1 | < 3.1.15 |
MEDIUM | 4.3 | The Post to Google My Business plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and i… | — | wordfence |
EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.
Scan My Website →