Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.
40,407 vulnerabilities found (page 1409 of 1617)
| CVE ID | Plugin / Theme | Severity | CVSS | Description | Fixed In | Source |
|---|---|---|---|---|---|---|
| ba998993-4e89-45f8-9598-fc1f8b88d147 | < 1.4.4 |
MEDIUM | 4.3 | The Insert PHP Code Snippet plugin for WordPress is vulnerable to unauthorized access due to a missing capability check … | — | wordfence |
| ba8de7af-6167-4aa8-8222-481b04e6fcb2 | < 3.14.4 |
MEDIUM | 4.3 | The SmartCrawl SEO checker, analyzer & optimizer plugin for WordPress is vulnerable to unauthorized access due to a miss… | — | wordfence |
| ba86268a-7bd6-40ed-9af6-29409245675d | < 19.10.0 |
MEDIUM | 4.3 | The Poll, Survey & Quiz Maker Plugin by Opinion Stage plugin for WordPress is vulnerable to unauthorized modification of… | — | wordfence |
| ba619587-21d2-48b2-984a-210b43b0d87b | MEDIUM | 4.3 | The Simple Trackback Disabler plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, an… | — | wordfence | |
| ba5cca24-514b-4f8b-911f-8d138287fce2 | < 3.2.12 |
MEDIUM | 4.3 | The Robo Gallery Plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 3.2.… | — | wordfence |
| ba3d59a1-d0f6-4fe8-bf79-35b35b2a2fee | < 1.1.5 |
MEDIUM | 4.3 | The ShipTime: Discount Shipping plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up … | — | wordfence |
| ba351515-d984-42da-9530-5e7afad3df29 | MEDIUM | 4.3 | The Fast User Switching plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and includin… | — | wordfence | |
| ba2ff1ab-f981-417d-b400-13750c9320ad | < 1.7.4 |
MEDIUM | 4.3 | The WP Social Comments plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capabili… | — | wordfence |
| ba27d52e-e43a-4f03-ad99-632c18279413 | < 1.90 |
MEDIUM | 4.3 | The WP-PostRatings plugin for WordPress is vulnerable to Race Condition in versions up to, and including, 1.89. This can… | — | wordfence |
| ba22205d-5c09-4901-ba8b-0ffe2f4a09e0 | < 4.8.7.2 |
MEDIUM | 4.3 | The All in One SEO β Powerful SEO Plugin to Boost SEO Rankings & Increase Traffic plugin for WordPress is vulnerable t… | — | wordfence |
| ba20a30c-7dd2-4cb7-b055-9a105461f7d1 | < 2.4.4 |
MEDIUM | 4.3 | The User Meta WordPress plugin before 2.4.4 does not validate the filepath parameter of its um_show_uploaded_file AJAX a… | — | wordfence |
| ba111255-3b91-4ef6-8d57-10ff08363c48 | < 5.1.10 |
MEDIUM | 4.3 | The Download Monitor plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 5.1… | — | wordfence |
| b9edcbdc-5b01-4880-95ec-57d87ccbb472 | < 2.0.1 |
MEDIUM | 4.3 | The VG WORT METIS plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability ch… | — | wordfence |
| b9e25fd7-848d-4d33-9c49-72f4698856e2 | MEDIUM | 4.3 | The Ave Core plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function i… | — | wordfence | |
| b9d63462-04ec-4b46-91cf-25b7dd098fc7 | < 2.1.6 |
MEDIUM | 4.3 | The Comment Link Remove and Other Comment Tools WordPress plugin before 2.1.6 does not have CSRF check in its 'Delete co… | — | wordfence |
| b9d161a3-eb9f-447f-b2d2-b8b193678d20 | < 1.22 |
MEDIUM | 4.3 | The First Order Discount Woocommerce plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to,… | — | wordfence |
| b9b92a1f-19d5-4aaa-b196-043f26e4614f | < 1.1.4 |
MEDIUM | 4.3 | The Acknowledgify plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a funct… | — | wordfence |
| b9b18739-67ed-4cb0-9577-eb60bc84bbeb | < 2.5.7 |
MEDIUM | 4.3 | The Maspik β Ultimate Spam Protection plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions… | — | wordfence |
| b9a4e0c1-7bbb-4ab0-948c-3d172717e5fe | MEDIUM | 4.3 | The Chat by Chatwee plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and includin… | — | wordfence | |
| b99ba627-1d24-4be1-a4db-ff39354526f2 | MEDIUM | 4.3 | The W3SC Elementor to Zoho CRM plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, a… | — | wordfence | |
| b9982ccd-e9b3-46e3-90ed-1ae6ff59bb62 | MEDIUM | 4.3 | The Safe Ai Malware Protection for WP plugin for WordPress is vulnerable to unauthorized access due to a missing capabil… | — | wordfence | |
| b98c5623-15fe-4937-9a0e-770aa0ab06f3 | < 2.3.3 |
MEDIUM | 4.3 | The Hide admin notices β Admin Notification Center plugin for WordPress is vulnerable to Cross-Site Request Forgery in… | — | wordfence |
| b9842421-93da-4535-9d48-fd591cd5e80f | < 1.2.151 |
MEDIUM | 4.3 | The PDF Builder for WooCommerce. Create invoices,packing slips and more plugin for WordPress is vulnerable to unauthoriz… | — | wordfence |
| b9815a47-dc71-4dd0-8645-f52408ecb20f | < 3.6.0 |
MEDIUM | 4.3 | The DoFollow Case by Case plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and in… | — | wordfence |
| b97b84a8-cf4e-4648-8d58-b81a71b7988c | < 0.6.2.5 |
MEDIUM | 4.3 | The WP Accessibility Helper (WAH) plugin for WordPress is vulnerable to unauthorized use of AJAX actions due to a missin… | — | wordfence |
EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.
Scan My Website →