Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.
40,407 vulnerabilities found (page 1431 of 1617)
| CVE ID | Plugin / Theme | Severity | CVSS | Description | Fixed In | Source |
|---|---|---|---|---|---|---|
| a298955e-c8e2-4732-a38e-4f7338a088bc | < 4.1.21 |
MEDIUM | 4.3 | The Eventin plugin for WordPress is vulnerable to unauthorized access in versions up to, and including, 4.1.20. This is … | — | wordfence |
| a2926c11-c6a2-4988-89ed-42d9e0791b95 | < 4.7.31 |
MEDIUM | 4.3 | WordPress Core is vulnerable to Sensitive Information Exposure in all versions up to, and including, 6.8.2. This makes i… | — | wordfence |
| a28e3f3b-6f8d-4745-bb56-a7c9e973a4ca | < 10.3.0 |
MEDIUM | 4.3 | The WP Recipe Maker plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a fun… | — | wordfence |
| a27eb4f9-3e8e-42bc-8808-fd47a17d5cd7 | < 1.12.2 |
MEDIUM | 4.3 | The SMTP2GO for WordPress β Email Made Easy plugin for WordPress is vulnerable to unauthorized access due to a missing… | — | wordfence |
| a26a6f28-4a7f-421d-a69e-2afbe1367106 | < 1.6.50 |
MEDIUM | 4.3 | The WooCommerce Brands plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including… | — | wordfence |
| a250f678-1ec7-48ea-8b81-e5ef89992155 | < 6.24.2 |
MEDIUM | 4.3 | The OAuth Single Sign On β SSO (OAuth Client) plugin for WordPress is vulnerable to Cross-Site Request Forgery in vers… | — | wordfence |
| a228e60c-c91b-4a82-8b05-a0ffaed82524 | < 3.5.14 |
MEDIUM | 4.3 | The Simple Sitemap β Create a Responsive HTML Sitemap plugin for WordPress is vulnerable to Cross-Site Request Forgery… | — | wordfence |
| a201aa76-8849-47a8-bc67-86a08a4159ea | MEDIUM | 4.3 | The Huger for Elementor plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a… | — | wordfence | |
| a1fc4ce9-ae96-4d8e-bf1c-941ed15d7d1a | < 2.5.2 |
MEDIUM | 4.3 | The Droip plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on a… | — | wordfence |
| a1fbb3a6-fcc2-47c5-a086-331e69292add | < 3.2.3 |
MEDIUM | 4.3 | The WP EasyPay β Square for WordPress plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up … | — | wordfence |
| a1e51a99-f5d4-47d4-bead-00ca1f5f72c2 | < 5.14.2 |
MEDIUM | 4.3 | The Abandoned Cart Lite for WooCommerce plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up … | — | wordfence |
| a1e34a47-b025-469e-83da-ec6e1ea40d4d | MEDIUM | 4.3 | The Flatsome theme for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in… | — | wordfence | |
| a1e02c2d-a38a-495c-9c37-098049297be2 | MEDIUM | 4.3 | The Anomify AI β Anomaly Detection and Alerting plugin for WordPress is vulnerable to Cross-Site Request Forgery (CSRF… | — | wordfence | |
| a1d8adf9-a529-45eb-9c59-8f43049de460 | MEDIUM | 4.3 | The DN Popup plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.2.… | — | wordfence | |
| a1bf7283-2ad7-4a4e-b5b7-7b944c5001a0 | MEDIUM | 4.3 | The Gmedia Photo Gallery plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and includi… | — | wordfence | |
| a1b99ea1-109e-4632-9439-3ffbb10f0839 | < 1.8.7 |
MEDIUM | 4.3 | The Signature Add-On for Gravity Forms plugin for WordPress is vulnerable to unauthorized access due to a missing capabi… | — | wordfence |
| a1b3bcad-4bee-4848-8d68-0aacaf199910 | < 2.5.8 |
MEDIUM | 4.3 | The HT Mega β Absolute Addons For Elementor plugin for WordPress is vulnerable to Directory Traversal in all versions … | — | wordfence |
| a1ad32fb-929e-4181-8789-df50a77a71ef | < 2.0.15 |
MEDIUM | 4.3 | The Advanced Ads β Ad Manager & AdSense plugin for WordPress is vulnerable to authorization bypass in versions up to, … | — | wordfence |
| a1a3c767-465b-4307-b114-7144ff9ef47b | < 2.0.8 |
MEDIUM | 4.3 | The Burst Statistics β Privacy-Friendly Analytics for WordPress plugin for WordPress is vulnerable to Cross-Site Reque… | — | wordfence |
| a199e16a-80a7-4471-afc6-4942c7de31bf | < 3.7.1 |
MEDIUM | 4.3 | The Logo Slider β Logo Showcase, Logo Carousel, Logo Gallery and Client Logo Presentation plugin for WordPress is vuln… | — | wordfence |
| a189e436-e8af-4379-aa6e-2d1a4a2d4bfa | MEDIUM | 4.3 | The Bulk images optimizer: Resize, optimize, convert to webp, rename β¦ plugin for WordPress is vulnerable to unauthori… | — | wordfence | |
| a1877e8a-0ae1-4277-93ac-7bc56fd8c3ce | MEDIUM | 4.3 | The Wishlist plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function i… | — | wordfence | |
| a1859dca-d771-470c-ae4a-48246977212c | < 1.9.4 |
MEDIUM | 4.3 | The Big Store plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.9.3. … | — | wordfence |
| a184090c-0281-4d8d-bd4d-256b4ed826dc | MEDIUM | 4.3 | The Smart YouTube PRO plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including,… | — | wordfence | |
| a1825e57-b59f-4c57-8008-640717e05eb3 | < 1.8.3 |
MEDIUM | 4.3 | The Frisbii Pay plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a functio… | — | wordfence |
EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.
Scan My Website →