Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.
40,407 vulnerabilities found (page 1411 of 1617)
| CVE ID | Plugin / Theme | Severity | CVSS | Description | Fixed In | Source |
|---|---|---|---|---|---|---|
| b81b06b4-559f-4b69-9fdd-e09e66525867 | < 2.5.10 |
MEDIUM | 4.3 | The Wallet System for WooCommerce plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, an… | — | wordfence |
| b80c8888-e8d6-4458-ae93-8e4182060590 | < 4.53 |
MEDIUM | 4.3 | The Disable Json API, Login Lockdown, XMLRPC, Pingback, Stop User Enumeration Anti Hacker Scan plugin for WordPress is v… | — | wordfence |
| b80b7152-be95-4737-b324-be0a3ff7c354 | < 2.8.168 |
MEDIUM | 4.3 | The GeoDirectory plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and including, … | — | wordfence |
| b7fb851b-dcf0-4074-82f3-dd2e57429a70 | MEDIUM | 4.3 | The Freshchat plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.3.4. … | — | wordfence | |
| b7e417c2-bf9c-4c88-be2b-9c2324897b07 | < 1.4.2 |
MEDIUM | 4.3 | The Laposta Signup Basic plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capabi… | — | wordfence |
| b7db3d45-2b96-4ba4-b258-08ee5e0b947b | < 2.0.0 |
MEDIUM | 4.3 | The Pro Mime Types plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.… | — | wordfence |
| b7c54b5d-ad73-44f1-afdb-01136ec0b9ae | < 1.0.1 |
MEDIUM | 4.3 | The Web to SugarCRM Lead plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and inc… | — | wordfence |
| b7c39952-d179-4b40-9762-7815e881a560 | < 5.7 |
MEDIUM | 4.3 | The Dynamic Word Spinner: CSS3 Animated Rotation plugin for WordPress is vulnerable to Cross-Site Request Forgery in all… | — | wordfence |
| b79e0723-9e6f-44e9-ba85-393cea134f94 | MEDIUM | 4.3 | The Ð¯Ð½Ð´ÐµÐºÑ Ð”Ð¾Ñтавка (Boxberry) plugin for WordPress is vulnerable to unauthorized access due to a missing … | — | wordfence | |
| b798cd27-03c3-495e-aa94-743d80a493e0 | < 3.5.6.3 |
MEDIUM | 4.3 | The Tickera – Sell Tickets & Manage Events plugin for WordPress is vulnerable to unauthorized access due to a missing … | — | wordfence |
| b797e141-a9d2-48c4-a44e-a59a80a90a5b | < 2.9.4.1 |
MEDIUM | 4.3 | The Beaver Builder – WordPress Page Builder plugin for WordPress is vulnerable to Missing Authorization in all version… | — | wordfence |
| b796b514-b6ca-4a22-9340-df02fec97075 | MEDIUM | 4.3 | The WP Custom Post Template plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and incl… | — | wordfence | |
| b793a4cb-3130-428e-9b61-8ce29fcdaf70 | < 1.1.3 |
MEDIUM | 4.3 | The WP Fastest Cache plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, … | — | wordfence |
| b77b0802-2efe-45d1-b338-d6d020f2bb05 | MEDIUM | 4.3 | The WP-PManager plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1… | — | wordfence | |
| b764f232-6638-4866-b48c-1f89efac76c6 | MEDIUM | 4.3 | The Login Alert plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 0… | — | wordfence | |
| b758c8a7-6220-4b54-af88-7933a530b5ba | < 1.3.0 |
MEDIUM | 4.3 | The ARI Stream Quiz – WordPress Quizzes Builder plugin for WordPress is vulnerable to Cross-Site Request Forgery in al… | — | wordfence |
| b75789ff-6050-4044-a3ff-d071591b4ec6 | < 4.0.0 |
MEDIUM | 4.3 | The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to unauthorized access due to … | — | wordfence |
| b75696a4-fc07-4ab4-b108-6425c050de50 | MEDIUM | 4.3 | The Interactive UK Regional Map plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, … | — | wordfence | |
| b74c99e7-e7e4-4bb6-a1e5-3ff7047400cd | MEDIUM | 4.3 | The WP Wand – Unlimited Content Generation using AI – for OpenAI, Claude, Openrouter and Deepseek plugin for WordPre… | — | wordfence | |
| b74a5a4c-250a-46bc-bf08-2dd720de41ae | < 1.2.3 |
MEDIUM | 4.3 | The Contact Form 7 Connector plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and inc… | — | wordfence |
| b73ca36d-c6cc-482d-a9b8-dd76327aef08 | < 1.9.2 |
MEDIUM | 4.3 | The WP Delicious – Recipe Plugin for Food Bloggers (formerly Delicious Recipes) plugin for WordPress is vulnerable to … | — | wordfence |
| b738a4fe-6724-4216-be77-ea67843f89d1 | < 5.3.7 |
MEDIUM | 4.3 | The Event Booking Manager for WooCommerce – Sell Tickets, Event Registration, RSVP & Event Calendar plugin for WordPre… | — | wordfence |
| b73467de-fb0c-45e3-b3ae-5158b261907b | < 2.3.9 |
MEDIUM | 4.3 | The Button Generator – easily Button Builder plugin for WordPress is vulnerable to Cross-Site Request Forgery in versi… | — | wordfence |
| b71958cc-6438-4a0c-af49-f1fd4932ad24 | < 4.4.0 |
MEDIUM | 4.3 | The Eazy Plugin Manager – Powerful Plugin Management Solution for WordPress plugin for WordPress is vulnerable to unau… | — | wordfence |
| b712250f-4315-4188-bbe1-c2991a10ad3f | < 3.0.1 |
MEDIUM | 4.3 | The Easy Upload Files During Checkout plugin for WordPress is vulnerable to unauthorized access due to a missing capabil… | — | wordfence |
EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.
Scan My Website →