Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.
40,407 vulnerabilities found (page 1429 of 1617)
| CVE ID | Plugin / Theme | Severity | CVSS | Description | Fixed In | Source |
|---|---|---|---|---|---|---|
| a4ac5738-0ebe-480a-b2b7-f0568d668fa6 | < 1.7.9 |
MEDIUM | 4.3 | The Redirect 404 Error Page to Homepage or Custom Page with Logs WordPress plugin before 1.7.9 does not check for CSRF w… | — | wordfence |
| a4a67ec6-ee13-4532-8213-d17dbf5f2c55 | < 7.1.3 |
MEDIUM | 4.3 | The Sirv plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on th… | — | wordfence |
| a49d5e93-754d-4543-8066-911746fe6aee | < 4.3.0 |
MEDIUM | 4.3 | The Jobify - Job Board WordPress Theme theme for WordPress is vulnerable to Cross-Site Request Forgery in versions up to… | — | wordfence |
| a4997290-c7d5-48cb-92e1-b84b42bd213e | < 5.10.5.2 |
MEDIUM | 4.3 | The TheGem Demo Import (for WPBakery) plugin for WordPress is vulnerable to unauthorized access due to a missing capabil… | — | wordfence |
| a48dcada-aafe-4af0-9d27-8ae2e86232a8 | MEDIUM | 4.3 | The WP Social Bookmarking plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and in… | — | wordfence | |
| a4879ad0-8999-4856-bfbf-28c89092b4e2 | MEDIUM | 4.3 | The Block Slider plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a functi… | — | wordfence | |
| a48634d7-30c9-4124-87dd-93a303a969eb | < 2.5.0 |
MEDIUM | 4.3 | The Ultimate Store Kit Elementor Addons, Woocommerce Builder, EDD Builder, Elementor Store Builder, Product Grid, Produc… | — | wordfence |
| a467ad30-8271-421c-8af4-8165fd60c03e | < 2.18.3 |
MEDIUM | 4.3 | The Lazy Load for Videos plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and includi… | — | wordfence |
| a4647210-ba7e-4233-83d6-12572213f5fb | < 1.7.5 |
MEDIUM | 4.3 | The Premium version of the Checkout Field Editor plugin for WordPress is vulnerable to Cross-Site Request Forgery in ver… | — | wordfence |
| a462789a-d311-47d7-9f54-190eaf5da03f | < 4.3.0 |
MEDIUM | 4.3 | The Analytify plugin for WordPress is vulnerable to authorization bypass & Cross-Site Request Forgery in versions up to,… | — | wordfence |
| a443e857-a915-4aa4-9879-1465d50544cc | < 29.0.0 |
MEDIUM | 4.3 | The Contest Gallery β Upload & Vote Photos, Media, Sell with PayPal & Stripe plugin for WordPress is vulnerable to Sen… | — | wordfence |
| a4420935-4952-4460-afc2-1c6df6965b3d | < 3.35.8 |
MEDIUM | 4.3 | The Elementor Website Builder plugin for WordPress is vulnerable to Incorrect Authorization to Sensitive Information Exp… | — | wordfence |
| a420a8b5-e43e-4c0d-86f3-b35f11efdf46 | < 3.1.2 |
MEDIUM | 4.3 | The Jeg Kit for Elementor plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, an… | — | wordfence |
| a4178271-c09e-4094-a616-5a00d28f39a3 | < 1.3.88 |
MEDIUM | 4.3 | The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to Cross-Site Request Forgery in all version… | — | wordfence |
| a3fc4131-9cbe-4fb9-93bf-285701411aa7 | MEDIUM | 4.3 | The Global Translator plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and includ… | — | wordfence | |
| a3f1d836-da32-414f-9f2b-d485c44b2486 | < 4.2.0 |
MEDIUM | 4.3 | The Contact Form 7 β Dynamic Text Extension plugin for WordPress is vulnerable to Insecure Direct Object Reference in … | — | wordfence |
| a3f0e97c-f41f-47ed-93c7-cff5915e9d01 | < 4.3.1 |
MEDIUM | 4.3 | The SULly plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 4.3. Th… | — | wordfence |
| a3f0556e-a875-4f88-b96c-a924f8fe01da | < 7.9.9 |
MEDIUM | 4.3 | The WPBot β AI ChatBot for Live Support, Lead Generation, AI Services plugin for WordPress is vulnerable to unauthoriz… | — | wordfence |
| a39ca182-981b-4636-acd5-4c8a269858dd | < 1.0.7 |
MEDIUM | 4.3 | The WOLF plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.0.6. This … | — | wordfence |
| a397a7f0-2f6a-48aa-9646-ae2abd410c48 | < 1.00.04 |
MEDIUM | 4.3 | The Termin-Kalender plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability … | — | wordfence |
| a3936c4b-2326-41dc-b7d6-a8cf43752ddb | < 2.5.1 |
MEDIUM | 4.3 | The myCred plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.5. This … | — | wordfence |
| a38e649d-00ad-4198-a96a-e280bc810cff | < 2.2.12 |
MEDIUM | 4.3 | The Sign-up Sheets plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.… | — | wordfence |
| a3895b45-b103-4ba0-905c-611f5d1ba9a6 | MEDIUM | 4.3 | The Fix Rss Feeds plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including,… | — | wordfence | |
| a38386f1-5d5c-4ab4-b3b7-60bceb04730d | < 2.6.4 |
MEDIUM | 4.3 | The Feeds for YouTube (YouTube video, channel, and gallery plugin) plugin for WordPress is vulnerable to unauthorized ac… | — | wordfence |
| a36dedad-da5e-440e-b626-95df0d154870 | < 2.7.60 |
MEDIUM | 4.3 | The BuddyBoss Platform plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to 2.7.… | — | wordfence |
EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.
Scan My Website →