Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.
40,407 vulnerabilities found (page 1447 of 1617)
| CVE ID | Plugin / Theme | Severity | CVSS | Description | Fixed In | Source |
|---|---|---|---|---|---|---|
| 91a83f52-069e-4611-9b46-4a1913e23f42 | < 6.0.7.2 |
MEDIUM | 4.3 | The RegistrationMagic plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a f… | — | wordfence |
| 91a2fa6e-f434-4b56-af68-71e1ee565cc8 | < 10.17 |
MEDIUM | 4.3 | The Salon Booking System, Appointment Scheduling for Salons, Spas & Small Businesses plugin for WordPress is vulnerable … | — | wordfence |
| 91a20180-871b-4208-b11e-d3ff2a7e8d23 | < 3.2.7 |
MEDIUM | 4.3 | The CM Answers β Powerful WordPress Forum Plugin plugin for WordPress is vulnerable to unauthorized access due to a mi… | — | wordfence |
| 91a1278a-0308-4fe0-a46e-172ca1735c53 | MEDIUM | 4.3 | The Mavis HTTPS to HTTP Redirection plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, … | — | wordfence | |
| 919dd168-1b4c-4e3a-977e-051cb48eaded | < 3.0.3 |
MEDIUM | 4.3 | The Order Limit for WooCommerce plugin for WordPress is vulnerable to unauthorized access due to a missing capability ch… | — | wordfence |
| 917a6b76-0bb4-4320-9ab9-bc433b6dfbe8 | < 1.0.2 |
MEDIUM | 4.3 | The HomeLancer theme for WordPress is vulnerable to unauthorized access due to a missing capability check on a function … | — | wordfence |
| 916c2984-292c-458b-b3be-c187e7c4d30a | < 1.6.2 |
MEDIUM | 4.3 | The Document & Data Automation plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and i… | — | wordfence |
| 915f81ec-8b48-4036-90c6-9a1c31febfdd | < 1.1.35.2 |
MEDIUM | 4.3 | The Tablesome Table β Contact Form DB β WPForms, CF7, Gravity, Forminator, Fluent plugin for WordPress is vulnerable… | — | wordfence |
| 91531e13-5344-442c-99d3-8ccfd61b715d | < 2.0.5 |
MEDIUM | 4.3 | wp-admin/user-edit.php in WordPress before 2.0.5 allows remote authenticated users to read the metadata of an arbitrary … | — | wordfence |
| 9148268a-1179-4bc5-b388-309cf08510d7 | < 1.6.1 |
MEDIUM | 4.3 | The KB Support plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on th… | — | wordfence |
| 91427e3e-fedb-407e-8af6-8f4411a4166a | < 13.5.6 |
MEDIUM | 4.3 | The WPBot Pro Wordpress Chatbot plugin for WordPress is vulnerable to unauthorized modification of data due to a missing… | — | wordfence |
| 913a94ad-f425-4d24-9e23-7074ecfed8ad | < 2.6.0 |
MEDIUM | 4.3 | The Modular DS: Monitor, update, and backup multiple websites plugin for WordPress is vulnerable to Cross-Site Request F… | — | wordfence |
| 91272920-fec6-4c75-b7d9-a97a23a54742 | < 1.2.1 |
MEDIUM | 4.3 | The Print PDF Generator and Publisher plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to… | — | wordfence |
| 912488f1-c06c-4504-a3d8-a3730c4253b0 | < 1.1.13 |
MEDIUM | 4.3 | The Order Cancellation & Returns for WooCommerce plugin for WordPress is vulnerable to Insecure Direct Object Reference … | — | wordfence |
| 9122068b-567f-462e-86b8-0419804bd46c | < 4.0.0 |
MEDIUM | 4.3 | The AWCA β The Great Analytics Insights for Your eStore plugin for WordPress is vulnerable to unauthorized access due … | — | wordfence |
| 911d083a-57d2-4574-a5b3-b299c368400c | < 5.20.0 |
MEDIUM | 4.3 | The Citadela Listing plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and excluding, … | — | wordfence |
| 9114018f-0678-4973-bb1e-932f0d93f963 | < 1.8.2 |
MEDIUM | 4.3 | The JobSearch WP Job Board plugin for WordPress is vulnerable to authorization bypass due to a missing capability check … | — | wordfence |
| 91062d2c-f2a6-4a92-b684-e133391afe60 | < 1.2.7 |
MEDIUM | 4.3 | The WP Education plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.2.… | — | wordfence |
| 90e69e43-597c-4c18-b581-d99dacefb9b8 | MEDIUM | 4.3 | The ShortCodes UI plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.9… | — | wordfence | |
| 90c774a5-e315-4671-a21b-ccfd1b1346ac | < 1.11.8 |
MEDIUM | 4.3 | The WS Form LITE plugin for WordPress is vulnerable to unauthorized access in versions up to, and including, 1.11.7. Thi… | — | wordfence |
| 90c71b01-f82e-4f06-b1c9-6a2a5618a744 | MEDIUM | 4.3 | The Login Logger plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, … | — | wordfence | |
| 90b7fa47-ca32-41a6-ae9c-e15f361c6398 | < 3.9.1 |
MEDIUM | 4.3 | The SMS Alert Order Notifications plugin for WordPress is vulnerable to unauthorized access due to a missing capability … | — | wordfence |
| 90ab885e-b4df-4774-96e0-53cff569713a | < 1.7.2 |
MEDIUM | 4.3 | The Image Optimizer by Elementor plugin for WordPress is vulnerable to unauthorized access due to a missing capability c… | — | wordfence |
| 909d9b9b-78da-41c0-87bc-54730f452bff | MEDIUM | 4.3 | The Epicwin Plugin plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including… | — | wordfence | |
| 908ef8e1-d4dc-4348-90b8-d8f38666d9ed | < 5.3.10 |
MEDIUM | 4.3 | The Modal Window β create popup modal window plugin for WordPress is vulnerable to Cross-Site Request Forgery in all v… | — | wordfence |
EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.
Scan My Website →