Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.
40,407 vulnerabilities found (page 1422 of 1617)
| CVE ID | Plugin / Theme | Severity | CVSS | Description | Fixed In | Source |
|---|---|---|---|---|---|---|
| ac47ccff-6e36-4bc2-b7f3-70deb3d8b3b7 | < 2.5.1 |
MEDIUM | 4.3 | The Credova Financial plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and includ… | — | wordfence |
| ac34e369-de9e-4b13-8858-0b4300aef5f8 | < 1.0.3 |
MEDIUM | 4.3 | The WP2HTML plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0.2… | — | wordfence |
| ac2b2862-a56c-456e-a621-8b10b30235be | < 2.3.4 |
MEDIUM | 4.3 | The WPC Admin Columns plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and includ… | — | wordfence |
| ac245316-228e-4508-b3fe-f7071fb1bc8e | < 2.0.1 |
MEDIUM | 4.3 | The B Slider- Gutenberg Slider Block for WP plugin for WordPress is vulnerable to Server-Side Request Forgery in version… | — | wordfence |
| ac23bca5-38dd-4460-83ce-5f7fc8a1f6a0 | MEDIUM | 4.3 | The cForms β Light speed fast Form Builder plugin for WordPress is vulnerable to Cross-Site Request Forgery in all ver… | — | wordfence | |
| ac20b454-a5e5-4ff6-a5bf-9c3c339321d8 | < 2.10.3 |
MEDIUM | 4.3 | The Mediavine Control Panel plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and incl… | — | wordfence |
| ac200da9-6a02-416a-aeb2-344eba4fcc3e | MEDIUM | 4.3 | The BERTHA AI. Your AI co-pilot for WordPress and Chrome plugin for WordPress is vulnerable to unauthorized access due t… | — | wordfence | |
| ac176fdf-3ebc-47b3-8404-c2423d141029 | MEDIUM | 4.3 | The CubePoints plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.… | — | wordfence | |
| ac13f402-8a36-448f-87d4-48179a9699c6 | < 1.27 |
MEDIUM | 4.3 | The Schema & Structured Data for WP & AMP plugin for WordPress is vulnerable to unauthorized modification of data due to… | — | wordfence |
| ac111175-2059-41dc-afa2-a659da3adaca | < 2.2.3 |
MEDIUM | 4.3 | The Ocean Extra plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2… | — | wordfence |
| ac07cc53-311d-465e-a00f-8aa37fec2ad9 | < 7.6.3 |
MEDIUM | 4.3 | The admin-site-enhancements-pro plugin for WordPress is vulnerable to unauthorized access due to a missing capability ch… | — | wordfence |
| ac05441d-137e-433a-86bd-a702ec664db0 | < 2.3.2 |
MEDIUM | 4.3 | The Autopost for X (formerly Autoshare for Twitter) plugin for WordPress is vulnerable to unauthorized access due to a m… | — | wordfence |
| abf1ace3-e066-4f28-9f37-3e9fa79aef7d | < 9.6.6 |
MEDIUM | 4.3 | The Salon booking system plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and inc… | — | wordfence |
| abee822e-b929-435a-86c2-57901424f1a0 | < 4.0.4 |
MEDIUM | 4.3 | The Wow Skype Buttons plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and includ… | — | wordfence |
| abebfbc4-37ed-44d5-a35d-d6ad87346f3a | < 5.3.5 |
MEDIUM | 4.3 | The Classified Listing β AI-Powered Classified ads & Business Directory Plugin plugin for WordPress is vulnerable to S… | — | wordfence |
| abdd2653-d50c-4eee-9cab-36519fd2b209 | < 1.2.1 |
MEDIUM | 4.3 | The The Conference theme for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.2… | — | wordfence |
| abcb2e9f-a6f1-40c3-b419-e2f65ec5dd41 | MEDIUM | 4.3 | The AGP Font Awesome Collection plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and … | — | wordfence | |
| abaebd3b-69ab-4e9b-a528-c9d846e62238 | < 3.3.2 |
MEDIUM | 4.3 | The Notification for Telegram plugin for WordPress is vulnerable to unauthorized test message sending due to a missing c… | — | wordfence |
| ab8f8370-50bd-48c8-89e1-8b19b51f78b5 | < 2.3.4 |
MEDIUM | 4.3 | In the Redirection for Contact Form 7 WordPress plugin before 2.3.4, any authenticated user, such as a subscriber, could… | — | wordfence |
| ab88f0cf-971f-43e1-b6b7-4eb55188ecc8 | < 2.5.3 |
MEDIUM | 4.3 | The SurveyJS: Drag & Drop WordPress Form Builder to create, style and embed multiple forms of any complexity plugin for … | — | wordfence |
| ab8659e1-5880-4738-99ed-e671449c6878 | < 3.5.8 |
MEDIUM | 4.3 | The Sina Extension for Elementor plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up… | — | wordfence |
| ab844a05-80e0-42c7-981c-dea3a18cf4d5 | < 6.15.10 |
MEDIUM | 4.3 | The The Events Calendar plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on t… | — | wordfence |
| ab7c8926-c762-49b1-bc97-4b7a2f4f97fc | < 3.2.4 |
MEDIUM | 4.3 | Several plugins for WordPress by Inisev are vulnerable to Cross-Site Request Forgery to unauthorized installation of plu… | — | wordfence |
| ab795923-2ec0-49eb-a911-56a74d90ca3f | < 1.6.1 |
MEDIUM | 4.3 | The Contact Forms by Cimatti plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and inc… | — | wordfence |
| ab78f245-ab2d-4e9a-bd43-caa3afd1366b | < 3.4.135 |
MEDIUM | 4.3 | The Church Admin plugin for WordPress is vulnerable to Unauthenticated Backup Disclosure in versions up to, and includin… | — | wordfence |
EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.
Scan My Website →