Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.
40,407 vulnerabilities found (page 1423 of 1617)
| CVE ID | Plugin / Theme | Severity | CVSS | Description | Fixed In | Source |
|---|---|---|---|---|---|---|
| ab6dd645-8831-49bc-b6b1-bb153ef79204 | < 5.2.0 |
MEDIUM | 4.3 | The Food Menu β Restaurant Menu & Online Ordering for WooCommerce plugin for WordPress is vulnerable to unauthorized a… | — | wordfence |
| ab68a08d-a6d4-4424-a7bf-219951f752fa | MEDIUM | 4.3 | The Comparison Slider plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capabilit… | — | wordfence | |
| ab60edf0-0912-48d5-ae02-18b366c1d72b | MEDIUM | 4.3 | The LMSACE Connect β WooCommerce Moodleβ’ LMS Integration plugin for WordPress is vulnerable to unauthorized access d… | — | wordfence | |
| ab5d87d2-f3cb-4926-9cbf-acdbe9169f64 | < 5.8.6 |
MEDIUM | 4.3 | The Abandoned Cart Lite for WooCommerce plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up … | — | wordfence |
| ab57f010-4fd2-40c2-950f-c03888521c8f | < 3.1.1 |
MEDIUM | 4.3 | The Coupon Creator plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 3.… | — | wordfence |
| ab382c09-667b-42b9-b373-834a5f5ae9e2 | < 1.2.5 |
MEDIUM | 4.3 | The Lawyer Landing Page theme for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including… | — | wordfence |
| ab2b2a9d-fadd-4056-bb66-f1a070eb0361 | < 6.3.3 |
MEDIUM | 4.3 | The ThumbPress β Compress Images, Manage Thumbnails, Detect Image Issues, WebP/AVIF, Lazy Loading, Hotlinking & More p… | — | wordfence |
| ab2a4903-2c69-48da-bd4a-79b39b78806c | < 2.4.0 |
MEDIUM | 4.3 | The Custom Order Status for WooCommerce plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions… | — | wordfence |
| ab1bd64b-8575-4ab4-bca5-8d5ce6f476d1 | < 1.4.16 |
MEDIUM | 4.3 | The Category Slider for WooCommerce plugin for WordPress is vulnerable to unauthorized modification of data due to missi… | — | wordfence |
| ab1053e4-5135-49cc-a81b-9cf66e93bfef | MEDIUM | 4.3 | The WP Quick Contact Us plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and incl… | — | wordfence | |
| ab0a61e7-6814-4773-af44-e42cffb1f480 | < 1.9.29 |
MEDIUM | 4.3 | The Google Adsense & Banner Ads by AdsforWP plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions… | — | wordfence |
| ab015cb4-0b1e-40ff-ab9b-6c03eed3142f | < 20.2 |
MEDIUM | 4.3 | The Taboola plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.0.1. Th… | — | wordfence |
| aaf62045-b9ce-40d7-92b3-7ab683e5a08c | < 6.5.5 |
MEDIUM | 4.3 | The Easy Social Feed β Social Photos Gallery β Post Feed β Like Box plugin for WordPress is vulnerable to Cross-Si… | — | wordfence |
| aae70da2-fcd8-4e33-8f38-5e19e0c14733 | < 5.2.4 |
MEDIUM | 4.3 | The All-in-one Google Analytics, Pixels and Product Feed Manager for WooCommerce plugin for WordPress is vulnerable to C… | — | wordfence |
| aad57a68-c385-491f-a5a2-32906df4b52b | < 2.11.1 |
MEDIUM | 4.3 | The Ultimate Member plugin for WordPress is vulnerable to Profile Privacy Setting Bypass in all versions up to, and incl… | — | wordfence |
| aacfbc61-83a0-4876-80da-3b78e0ac6f31 | < 4.1.3 |
MEDIUM | 4.3 | The Generate PDF using Contact Form 7 plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to… | — | wordfence |
| aac9db5d-24fe-4136-b73d-8098c3dd4965 | < 3.19.0 |
MEDIUM | 4.3 | The Stackable plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function … | — | wordfence |
| aa9efe66-43e3-4711-bbe6-2a7bb383983e | < 2.1.8 |
MEDIUM | 4.3 | The Content Pilot β Autoblogging & Affiliate Marketing Suite plugin for WordPress is vulnerable to unauthorized access… | — | wordfence |
| aa93cf13-0578-447e-8b03-24f5f48fc782 | < 1.2.8 |
MEDIUM | 4.3 | The Activity Log for WordPress plugin for WordPress is vulnerable to unauthorized access due to a missing capability che… | — | wordfence |
| aa8d5feb-2ae9-44b8-90b5-9fc67226855a | < 23.5 |
MEDIUM | 4.3 | The Frontend File Manager Plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, … | — | wordfence |
| aa830c67-2860-489f-aa67-c7cc74437709 | < 2.4.7 |
MEDIUM | 4.3 | The wpForo Forum plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and inclu… | — | wordfence |
| aa7fe608-55cf-4299-993e-cb262dd74880 | < 2.4.19 |
MEDIUM | 4.3 | The Rife Free theme for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.4.18. … | — | wordfence |
| aa7c3513-cef2-4f8d-b3e2-1bb8e52e76df | MEDIUM | 4.3 | The PawFriends - Pet Shop and Veterinary WordPress Theme theme for WordPress is vulnerable to Insecure Direct Object Ref… | — | wordfence | |
| aa7276bb-6a9b-4cbd-8333-14c4dfac4108 | < 1.11 |
MEDIUM | 4.3 | The Debug plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.10. This … | — | wordfence |
| aa657530-7c85-4399-94bb-feaa7d21a47a | < 26.6.3 |
MEDIUM | 4.3 | The Betheme theme for WordPress is vulnerable to authorization bypass in versions up to, and including, 26.6.2. This is … | — | wordfence |
EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.
Scan My Website →