Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.
40,407 vulnerabilities found (page 1414 of 1617)
| CVE ID | Plugin / Theme | Severity | CVSS | Description | Fixed In | Source |
|---|---|---|---|---|---|---|
| b4a44a8a-740b-45dd-962c-945238f6ddee | < 1.4.3 |
MEDIUM | 4.3 | The PayPal Brasil para WooCommerce Plugin is vulnerable to Cross-Site Request Forgery in versions up to, and including, … | — | wordfence |
| b49bb71b-1cdd-4341-9288-d33c74bc9426 | MEDIUM | 4.3 | The Free Woocommerce Product Table View β Woo Table Pro plugin for WordPress is vulnerable to unauthorized access due … | — | wordfence | |
| b492ccac-9cdc-42e1-9f0b-4612622d4266 | < 2.1.7 |
MEDIUM | 4.3 | The Goodlayers Core plugin for WordPress is vulnerable to Privilege Escalation in all versions up to 2.1.7 (exclusive). … | — | wordfence |
| b48bc632-c825-48e0-8766-3ac59e5b87c6 | < 3.2.71 |
MEDIUM | 4.3 | The Download Manager plugin for WordPress is vulnerable to information disclosure in versions up to, and including, 3.2.… | — | wordfence |
| b4862cb6-110b-48ec-80fb-c25ab080838c | < 1.1.9 |
MEDIUM | 4.3 | The Flexible Cookies plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and includi… | — | wordfence |
| b4772ab0-41cd-4b35-bda9-d72e0fd7b7a5 | < 2.2.6 |
MEDIUM | 4.3 | The WP Job Portal β A Complete Recruitment System for Company or Job Board website plugin for WordPress is vulnerable … | — | wordfence |
| b4595eed-ce5d-42f1-979e-cc37350d15d5 | MEDIUM | 4.3 | The Dating theme for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 11.2.0. Thi… | — | wordfence | |
| b452fcc8-1359-439c-a255-91054c83d6aa | < 5.5.0 |
MEDIUM | 4.3 | The Analytify β Google Analytics Dashboard For WordPress (GA4 analytics made easy) plugin for WordPress is vulnerable … | — | wordfence |
| b437020c-31a3-413e-a1da-b4781da34f10 | < 1.2.3 |
MEDIUM | 4.3 | The Contact Form 7 Connector plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and… | — | wordfence |
| b42178a9-2f73-48d2-a912-50efe0bec76e | < 6.4.6 |
MEDIUM | 4.3 | The FileBird β WordPress Media Library Folders & File Manager plugin for WordPress is vulnerable to Insecure Direct Ob… | — | wordfence |
| b411a97b-2f1c-4feb-b1c7-bc5a1aab7f33 | MEDIUM | 4.3 | The Admin side data storage for Contact Form 7 plugin for WordPress is vulnerable to Cross-Site Request Forgery in all v… | — | wordfence | |
| b40e70ed-cdcb-4999-92a9-45bbd2515a3d | < 4.0.15 |
MEDIUM | 4.3 | The Podlove Podcast Publisher plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, an… | — | wordfence |
| b3fef149-a087-4ce3-9802-cf0c12f13885 | < 1.3.2 |
MEDIUM | 4.3 | The Integration for WooCommerce and QuickBooks plugin for WordPress is vulnerable to Cross-Site Request Forgery in all v… | — | wordfence |
| b3f87bd6-b432-4bf8-9046-8d66b45f6a85 | < 1.3.8 |
MEDIUM | 4.3 | The Legal Pages plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability chec… | — | wordfence |
| b3e12653-ddfe-4e02-9d9e-0263b9f71def | < 1.3.60 |
MEDIUM | 4.3 | The Royal Elementor Addons plugin for WordPress is vulnerable to insufficient access control in the 'wpr_save_template_c… | — | wordfence |
| b3d9b755-1e6e-44ac-989a-201237f6dc9f | MEDIUM | 4.3 | The Buy one click WooCommerce plugin for WordPress is vulnerable to unauthorized modification of data due to a missing c… | — | wordfence | |
| b3d27929-1955-4700-95b3-a6d399bf7cee | < 1.0.6 |
MEDIUM | 4.3 | The Manage User Columns plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and includin… | — | wordfence |
| b3c96e57-0300-4ea7-a0c6-5d060b6e979d | MEDIUM | 4.3 | The DX Sources plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.… | — | wordfence | |
| b3c232b4-7c30-413b-83ff-49f47dc28117 | < 1.2.10 |
MEDIUM | 4.3 | The Xpro Theme Builder For Elementor β FREE plugin for WordPress is vulnerable to unauthorized access due to a missing… | — | wordfence |
| b3b23544-71de-4da8-9fd5-6d9ef995ad7b | < 2.1.1 |
MEDIUM | 4.3 | The Himer theme for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.1.0. T… | — | wordfence |
| b3ae17c3-9f65-4855-aed6-64d3ccb2ff0b | < 2.3.1 |
MEDIUM | 4.3 | The Fluent Support β Helpdesk & Customer Support Ticket System plugin for WordPress is vulnerable to Insecure Direct O… | — | wordfence |
| b39d66de-6d83-4fb5-a78c-c46e4540c48c | MEDIUM | 4.3 | The Woocommerce Customers Order History plugin for WordPress is vulnerable to unauthorized access due to a missing capab… | — | wordfence | |
| b3900e4f-4ae4-4026-89df-b63bd869a763 | < 3.1.14 |
MEDIUM | 4.3 | The ImageRecycle pdf & image compression plugin for WordPress is vulnerable to Cross-Site Request Forgery in all version… | — | wordfence |
| b37ee395-aad8-4908-b3f7-c9f68ed4a4e6 | < 3.9.13 |
MEDIUM | 4.3 | The Tutor LMS plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including,… | — | wordfence |
| b3533123-a141-4a15-b8cd-46a2870ecbd6 | < 2.4.6 |
MEDIUM | 4.3 | The Clone plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on t… | — | wordfence |
EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.
Scan My Website →