Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.
40,407 vulnerabilities found (page 1428 of 1617)
| CVE ID | Plugin / Theme | Severity | CVSS | Description | Fixed In | Source |
|---|---|---|---|---|---|---|
| a590ed63-ccec-4f20-961d-62c1f08781b0 | MEDIUM | 4.3 | The Fast Custom Social Share by CodeBard plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up… | — | wordfence | |
| a57d6585-bffb-41c4-9301-5f9e2f16eb2c | MEDIUM | 4.3 | The WooCommerce Orders & Customers Exporter plugin for WordPress is vulnerable to unauthorized access due to a missing c… | — | wordfence | |
| a57509c5-6535-4a73-a138-a03805746754 | MEDIUM | 4.3 | The TinyNav plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.4. … | — | wordfence | |
| a554b365-b54b-4696-87f6-df5099e15708 | MEDIUM | 4.3 | The WPsoonOnlinePage plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, … | — | wordfence | |
| a54e9aa6-943d-4f76-81af-3424a23f9313 | < 5.9 |
MEDIUM | 4.3 | The MP3 Audio Player β Music Player, Podcast Player & Radio by Sonaar plugin for WordPress is vulnerable to unauthoriz… | — | wordfence |
| a548e71f-4f36-4a29-8293-474e119f09cc | < 1.7.1 |
MEDIUM | 4.3 | The Subscribers Text Counter plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and inc… | — | wordfence |
| a54841af-65ce-4434-a67e-79ea673ec8f9 | < 2.0.4 |
MEDIUM | 4.3 | The WooCommerce Bookings plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and includi… | — | wordfence |
| a533ddd4-cf89-4bf9-981e-2fdd4ff4d414 | < 1.0.22 |
MEDIUM | 4.3 | The EmpowerWP theme for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.0.21. … | — | wordfence |
| a531730a-8505-4461-aeff-94b04778c8b9 | MEDIUM | 4.3 | The Labinator Content Types Duplicator plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions … | — | wordfence | |
| a528a2b5-55e5-46e4-8f04-0d2b49f2f683 | < 3.8.17 |
MEDIUM | 4.3 | The Video Conferencing with Zoom WordPress plugin before 3.8.17 does not have authorisation in its vczapi_get_wp_users A… | — | wordfence |
| a5276227-9bd4-4ad8-a6b7-ac7d05e8b056 | < 2.2 |
MEDIUM | 4.3 | The Easy PayPal & Stripe Buy Now Button plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions… | — | wordfence |
| a52325f9-51b5-469c-865e-73a22002d46f | < 1.7.2 |
MEDIUM | 4.3 | The RapidLoad Power-Up for Autoptimize plugin for WordPress is vulnerable to unauthorized data loss due to a missing cap… | — | wordfence |
| a51d081b-344d-4a07-b069-473548b7edbb | < 6.7 |
MEDIUM | 4.3 | The Oneline Lite theme for WordPress is vulnerable to unauthorized access due to a missing capability check on a functio… | — | wordfence |
| a4ffb3ef-9d77-463f-92c4-4bc799ac16aa | < 6.5.2 |
MEDIUM | 4.3 | The Easy Social Feed plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability… | — | wordfence |
| a4fd7e76-4d8b-4e4d-9ae9-c7f9933f8324 | < 2.1.8 |
MEDIUM | 4.3 | The Kognetiks Chatbot for WordPress plugin for WordPress is vulnerable to unauthorized modification of data due to a mis… | — | wordfence |
| a4f7211b-0ff0-406e-9a0a-2dd7b1314d6d | < 7.0.18 |
MEDIUM | 4.3 | The WP Full Stripe Free plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and includin… | — | wordfence |
| a4ea53bd-2ce7-4dce-8c57-51ba81838f1a | < 2.2.0 |
MEDIUM | 4.3 | The CodeBard's Patron Button and Widgets for Patreon plugin for WordPress is vulnerable to Cross-Site Request Forgery in… | — | wordfence |
| a4e24622-5ff7-4261-a07b-4c096b77fb13 | < 2.8.3 |
MEDIUM | 4.3 | The WooCommerce - Social Login plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, a… | — | wordfence |
| a4d6dcb5-a97a-4e80-b0dc-5649c9867374 | < 5.0.31.decaf |
MEDIUM | 4.3 | The Event Espresso 4 Decaf plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and inclu… | — | wordfence |
| a4cd49b2-ff93-4582-906b-b690d8472c38 | < 7.1.1 |
MEDIUM | 4.3 | The Booster for WooCommerce for WordPress is vulnerable to Information Disclosure via the 'wcj_wp_option' shortcode in v… | — | wordfence |
| a4c8d390-145a-4926-99e9-b386dfe5e6ac | < 1.3.4 |
MEDIUM | 4.3 | The Integrate Google Drive plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capa… | — | wordfence |
| a4c6d924-c741-4044-b6e2-a95793c606e2 | MEDIUM | 4.3 | The Editor Custom Color Palette plugin for WordPress is vulnerable to unauthorized access due to a missing capability ch… | — | wordfence | |
| a4c32896-bd0d-4bdb-845d-ca5a9aa5d5c0 | MEDIUM | 4.3 | The Categorify β WordPress Media Library Category & File Manager plugin for WordPress is vulnerable to unauthorized ac… | — | wordfence | |
| a4b847b5-9deb-41c4-b976-725249e0098e | < 2.4.7 |
MEDIUM | 4.3 | The Ultimate Addons for Elementor (Formerly Elementor Header & Footer Builder) plugin for WordPress is vulnerable to una… | — | wordfence |
| a4aed6ba-23a2-46b6-b7e1-7b7e462b1f5b | < 1.0.44 |
MEDIUM | 4.3 | The Google Maps CP plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.… | — | wordfence |
EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.
Scan My Website →