Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.
40,407 vulnerabilities found (page 1415 of 1617)
| CVE ID | Plugin / Theme | Severity | CVSS | Description | Fixed In | Source |
|---|---|---|---|---|---|---|
| b352be87-ea61-4666-a4d0-cf93fef40e33 | < 5.0.5 |
MEDIUM | 4.3 | The The Post Grid β Shortcode, Gutenberg Blocks and Elementor Addon for Post Grid plugin for WordPress is vulnerable t… | — | wordfence |
| b350a20e-6f86-4760-9092-27a4b365b590 | < 3.6.0 |
MEDIUM | 4.3 | The All-in-One Video Gallery plugin for WordPress is vulnerable to unauthorized access due to a missing capability check… | — | wordfence |
| b34194de-6b6e-4aaa-908e-85c424207c51 | < 6.7.0.65 |
MEDIUM | 4.3 | The Quiz Maker plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 6.7.0.… | — | wordfence |
| b335bd15-7af7-4d8b-ad01-b1d9e76beb53 | < 4.17.6 |
MEDIUM | 4.3 | The MStore API β Create Native Android & iOS Apps On The Cloud plugin for WordPress is vulnerable to unauthorized modi… | — | wordfence |
| b331c32e-7341-458b-80be-574cfa915159 | < 1.9.8 |
MEDIUM | 4.3 | The Caddy plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.9.7. This… | — | wordfence |
| b319eab0-29af-45b9-a6fd-608bce552837 | < 3.5.6 |
MEDIUM | 4.3 | The Read More & Accordion plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on… | — | wordfence |
| b316094a-0d69-4712-a395-037ce6f2e59b | < 1.1.11 |
MEDIUM | 4.3 | The HelloAsso plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the ha_ajax… | — | wordfence |
| b3146b41-27d5-465d-a9ec-af4c50a0d612 | < 2.4.30 |
MEDIUM | 4.3 | The DearFlip β PDF Flipbook, 3D Flipbook, PDF embed, PDF viewer plugin for WordPress is vulnerable to unauthorized acc… | — | wordfence |
| b30c9414-0a9b-47b5-bc57-ec79f182fc9d | < 2.3.7 |
MEDIUM | 4.3 | The WP Meta and Date Remover plugin for WordPress is vulnerable to unauthorized access due to a missing capability check… | — | wordfence |
| b3011679-51e8-4a13-8364-1d0723656d08 | < 1.4.3 |
MEDIUM | 4.3 | The Disable Admin Notices β Hide Dashboard Notifications plugin for WordPress is vulnerable to Cross-Site Request Forg… | — | wordfence |
| b2ff2954-f494-4cd7-9f29-ee0e8551e339 | < 1.3.88 |
MEDIUM | 4.3 | The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to Cross-Site Request Forgery in all version… | — | wordfence |
| b2fad930-8dae-4feb-a9c7-a2fb801cef51 | < 2.0.23 |
MEDIUM | 4.3 | The Blocksy theme for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.0.22. Th… | — | wordfence |
| b2efcf06-14e7-48d2-aa5a-4b623b81c193 | MEDIUM | 4.3 | The Auto Post After Image Upload plugin for WordPress is vulnerable to unauthorized access due to a missing capability c… | — | wordfence | |
| b2ed8026-bcce-4f93-a721-e9af522f2c39 | MEDIUM | 4.3 | The Auto Last Youtube Video plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and … | — | wordfence | |
| b2ec7d77-fe50-4bb2-a57b-6ee4246805f9 | < 1.1.4 |
MEDIUM | 4.3 | The Redirect Redirection plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability c… | — | wordfence |
| b2ec4c4e-5252-4feb-88b5-c52ce3c2e057 | MEDIUM | 4.3 | The Listify theme for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 3.2.5. Thi… | — | wordfence | |
| b2e76535-b97e-4104-8e90-ac21348b34ef | MEDIUM | 4.3 | The User Meta Shortcodes WordPress plugin through 0.5 registers a shortcode that allows any user with a role as low as c… | — | wordfence | |
| b2dee8d2-e1ab-455c-b922-92881f62fc5c | < 1.2.4 |
MEDIUM | 4.3 | The Paid Memberships Pro - Courses for Membership Add On plugin for WordPress is vulnerable to unauthorized modification… | — | wordfence |
| b2d20052-184e-473d-8e5b-46b7dd270c52 | MEDIUM | 4.3 | The Responsive Slider β Sangar Slider plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions… | — | wordfence | |
| b2c702a5-8677-49f3-8824-1e8345ff54ed | < 0.6 |
MEDIUM | 4.3 | The Blogger Importer plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, … | — | wordfence |
| b2c44c95-6a00-4c56-967b-003ce307f90c | MEDIUM | 4.3 | The Woo Commerce Minimum Weight plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to a… | — | wordfence | |
| b2c2110d-e07c-4e1e-90e1-7272c7039170 | < 2.8.4 |
MEDIUM | 4.3 | The Falcon β WordPress Optimizations & Tweaks plugin for WordPress is vulnerable to unauthorized access of functionali… | — | wordfence |
| b2b0c5f9-b734-41e6-8ecb-4cf3d891ddb7 | MEDIUM | 4.3 | The Google XML Sitemap for Mobile plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, an… | — | wordfence | |
| b2a825e4-3ffc-4412-81f4-6992dbbe756b | < 4.0.2 |
MEDIUM | 4.3 | The Custom Content Shortcode WordPress plugin before 4.0.2 does not validate the data passed to its load shortcode, whic… | — | wordfence |
| b28a0818-4732-45e8-b47c-9f2ce1ef9ddc | < 2.14.1 |
MEDIUM | 4.3 | The WPMasterToolKit (WPMTK) β All in one plugin plugin for WordPress is vulnerable to unauthorized access due to a mis… | — | wordfence |
EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.
Scan My Website →