Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.
40,407 vulnerabilities found (page 1410 of 1617)
| CVE ID | Plugin / Theme | Severity | CVSS | Description | Fixed In | Source |
|---|---|---|---|---|---|---|
| b96273e8-29a8-4802-8c83-1ce5ab9600b6 | < 5.5.7 |
MEDIUM | 4.3 | The JoomSport plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check … | — | wordfence |
| b949d563-3d1d-469d-9793-c2613efbfaa8 | MEDIUM | 4.3 | The WordPress Admin Bar Improved plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to,… | — | wordfence | |
| b93e9e84-1675-4128-a018-03833ff75943 | < 6.3.0 |
MEDIUM | 4.3 | The Advanced Custom Fields (ACF) plugin for WordPress is vulnerable to arbitrary custom field access in all versions up … | — | wordfence |
| b92deadd-a50c-406d-afdf-301453967880 | < 1.0.35 |
MEDIUM | 4.3 | The NewsMash theme for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.0.34. T… | — | wordfence |
| b9216875-8cb6-45a7-b23b-19d13f8b49dc | MEDIUM | 4.3 | The MP Customize Login Page plugin for WordPress is vulnerable to Cross-Site Request Forgery (CSRF) in all versions up t… | — | wordfence | |
| b90f76d9-3eb3-4ffe-aac7-95953de9972d | < 1.1.1 |
MEDIUM | 4.3 | The Freetobook Responsive Widget plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to,… | — | wordfence |
| b90b7f6c-df7f-48a5-b283-cf5facbd71e5 | < 1.58.0.0 |
MEDIUM | 4.3 | The VK Blocks plugin for WordPress is vulnerable to improper authorization via the REST 'update_options' function in ver… | — | wordfence |
| b8fe4fe5-2b13-4001-a177-0d182aa2af30 | < 2.0.10 |
MEDIUM | 4.3 | The PropertyHive plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability che… | — | wordfence |
| b8faa34a-17fd-4a2e-b8bf-ed40fc7a88d9 | < 2.4.0 |
MEDIUM | 4.3 | The Stock Sync for WooCommerce plugin for WordPress is vulnerable to unauthorized use of AJAX actions due to a missing c… | — | wordfence |
| b8f31f8e-03a0-436c-bfa3-bc41d70e8e2a | MEDIUM | 4.3 | The Blog Designer For Elementor – Post Slider, Post Carousel, Post Grid plugin for WordPress is vulnerable to Cross-Si… | — | wordfence | |
| b8d88cc2-91e4-4e53-8c46-93d6ce8bc320 | < 1.0.14 |
MEDIUM | 4.3 | The Generate Security.txt plugin for WordPress is vulnerable to authorization bypass in all versions up to, and includin… | — | wordfence |
| b8d73c3d-e8b1-400d-8fed-d26a045026c2 | MEDIUM | 4.3 | The Table of content plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and includi… | — | wordfence | |
| b8d5fa2d-07ee-46ef-bbcf-e7e45a4bbf69 | < 2.3.8 |
MEDIUM | 4.3 | The Easy Elementor Addons – Addons Pack for Elementor Page Builder plugin for WordPress is vulnerable to Cross-Site Re… | — | wordfence |
| b8d0638e-06c5-4884-a14d-4b28ae3ef3f3 | MEDIUM | 4.3 | The Cache Sniper for Nginx plugin for WordPress is vulnerable to unauthorized access due to a missing capability check o… | — | wordfence | |
| b8add6b9-8d53-4239-bbbc-d32a562fd9b9 | < 2.18.2 |
MEDIUM | 4.3 | The NextMove Lite plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.1… | — | wordfence |
| b8a82989-e7e7-484a-b619-3897d88872b9 | MEDIUM | 4.3 | The Professional Contact Form plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, an… | — | wordfence | |
| b8a4ec9b-218a-4811-ad8b-236fc8e960fa | MEDIUM | 4.3 | The occupancyplan plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.0… | — | wordfence | |
| b8a26695-4793-418b-9a23-6709fe79ea4f | < 2.0.3 |
MEDIUM | 4.3 | The Constant Contact Forms plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capa… | — | wordfence |
| b89cf8ef-9fa0-4ede-8ec9-c166d0db74fe | MEDIUM | 4.3 | The wpMandrill plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on th… | — | wordfence | |
| b8954061-cb8f-49fc-84d9-50851f7f48a2 | < 1.8.7 |
MEDIUM | 4.3 | The WP Blast | SEO & Performance Booster plugin for WordPress is vulnerable to Cross-Site Request Forgery in all version… | — | wordfence |
| b889440b-33f9-410b-b3d5-f41e08bcee82 | MEDIUM | 4.3 | The Easy WP Optimizer – Optimize DB & WordPress plugin for WordPress is vulnerable to unauthorized access due to a mis… | — | wordfence | |
| b871ac5e-a62a-499e-9ef2-a38d105ed020 | < 2.4.0 |
MEDIUM | 4.3 | The JobWP – Job Board, Job Listing, Career Page and Recruitment Plugin plugin for WordPress is vulnerable to Cross-Sit… | — | wordfence |
| b854d8ba-2dc4-45f7-8128-8d2737fbb7d4 | MEDIUM | 4.3 | The Ahmeti Wp Güzel Sözler plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and… | — | wordfence | |
| b843e8f7-e854-4572-9b1f-b1b27f752f07 | < 6.0.8 |
MEDIUM | 4.3 | The Popup Box – Create Countdown, Coupon, Video, Contact Form Popups plugin for WordPress is vulnerable to Cross-Site … | — | wordfence |
| b83abce2-077e-4892-908b-8de88cd0a298 | MEDIUM | 4.3 | The HL Twitter plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 20… | — | wordfence |
EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.
Scan My Website →