Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.
40,407 vulnerabilities found (page 1440 of 1617)
| CVE ID | Plugin / Theme | Severity | CVSS | Description | Fixed In | Source |
|---|---|---|---|---|---|---|
| 9921f4d0-0aa2-457e-afb2-7ecafb605948 | < 2.1.38 |
MEDIUM | 4.3 | The Blocksy Companion Pro plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and includi… | — | wordfence |
| 9916af89-4b12-47eb-adb2-56267f077d2f | < 2.2.2 |
MEDIUM | 4.3 | Multiple plugins for WordPress are vulnerable to Cross-Site Request Forgery in various versions. This is due to missing … | — | wordfence |
| 9915758a-47f0-4fa7-8885-311b2f75a7b6 | MEDIUM | 4.3 | The Holmes - Digital Agency WordPress Theme theme for WordPress is vulnerable to Insecure Direct Object Reference in all… | — | wordfence | |
| 98ebcc70-58c3-4c9d-a1cd-776c159647ed | MEDIUM | 4.3 | The WP Tabs Slides plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.… | — | wordfence | |
| 98e82ea8-3d92-4ce3-a280-2def3ab5430f | < 6.1.2 |
MEDIUM | 4.3 | The MainWP Dashboard: Self-hosted WordPress Management for Agencies plugin for WordPress is vulnerable to unauthorized a… | — | wordfence |
| 98e0d103-2369-4c6a-93ae-6be2a1770bae | < 1.3.13 |
MEDIUM | 4.3 | The Dynamics 365 Integration plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and inc… | — | wordfence |
| 98dffc17-ac45-4ccd-ae57-96b36bd02be3 | < 1.0.7.1 |
MEDIUM | 4.3 | The WOLF plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.0.7. This … | — | wordfence |
| 98bbec12-25f5-429c-a926-e8da34945962 | < 3.35.6 |
MEDIUM | 4.3 | The Elementor Website Builder plugin for WordPress is vulnerable to unauthorized access due to a missing capability chec… | — | wordfence |
| 98b38844-c6fe-4655-8bbe-7600203b567e | < 1.6.5 |
MEDIUM | 4.3 | The Wallet for WooCommerce plugin for WordPress is vulnerable to authorization bypass in all versions up to, and includi… | — | wordfence |
| 98ae3315-8361-43bb-be2c-1564f4df8d5b | < 3.98.8 |
MEDIUM | 4.3 | The Store Locator plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 3.9… | — | wordfence |
| 98a953b9-60e1-4445-a61e-88d5867895eb | < 1.27.10 |
MEDIUM | 4.3 | The Post and Page Builder by BoldGrid β Visual Drag and Drop Editor plugin for WordPress is vulnerable to unauthorized… | — | wordfence |
| 98a73a02-33fa-4dd4-9606-3d35d58c2398 | < 3.3.101 |
MEDIUM | 4.3 | The Zephyr Project Manager plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to,… | — | wordfence |
| 98a734d2-ea6f-4053-94b5-d20d6418b3ae | < 3.4.3 |
MEDIUM | 4.3 | The Groundhogg plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 3.4.2.… | — | wordfence |
| 98a2570c-c757-44ad-9981-af0bf2d3c341 | < 2.0.2 |
MEDIUM | 4.3 | The WP Job Portal plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.0… | — | wordfence |
| 989f312b-9c6c-44e1-9c4c-03917c8ec296 | < 2.3.2 |
MEDIUM | 4.3 | The Grid plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.3.1. This … | — | wordfence |
| 989836fc-a15d-4424-be0e-348e1acc7466 | < 1.7.0 |
MEDIUM | 4.3 | The WP Like Button plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.… | — | wordfence |
| 9891587b-2a63-41be-b79d-afe407dd57fa | < 1.3 |
MEDIUM | 4.3 | The Custom Field For WP Job Manager plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versio… | — | wordfence |
| 9879150f-ea35-4b05-af67-06f82714c430 | < 5.2.4 |
MEDIUM | 4.3 | The Analytify β Google Analytics Dashboard For WordPress (GA4 analytics made easy) plugin for WordPress is vulnerable … | — | wordfence |
| 98736b9d-3e0a-40c0-900a-fbbaaac07958 | MEDIUM | 4.3 | The TITLE ANIMATOR plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including… | — | wordfence | |
| 98730677-200b-4b1a-8568-7af8b2b0e94b | < 2.0.4 |
MEDIUM | 4.3 | The Welcome Bar for WordPress is vulnerable to unauthorized AJAX action access due to a missing capability check on the … | — | wordfence |
| 9870db7f-0c8e-44a4-aa0f-13709d773756 | < 2.10.1 |
MEDIUM | 4.3 | The SimpleShop plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.… | — | wordfence |
| 986835a7-2f73-4139-b080-ca1f7af077fb | MEDIUM | 4.3 | The Brilliant Web-to-Lead for Salesforce plugin for WordPress is vulnerable to Cross-Site Request Forgery in all version… | — | wordfence | |
| 985dfe25-4860-477a-bd85-5bf3375b86db | < 2.36 |
MEDIUM | 4.3 | The Post Duplicator plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a fun… | — | wordfence |
| 9854d09a-2fab-46e6-9fc1-ff6d68df2662 | < 2.3.11 |
MEDIUM | 4.3 | The Request a Quote plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2… | — | wordfence |
| 9852e499-f413-4218-9bac-6c2be62ecc32 | MEDIUM | 4.3 | The DW Question & Answer plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and includi… | — | wordfence |
EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.
Scan My Website →