Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.
40,407 vulnerabilities found (page 1448 of 1617)
| CVE ID | Plugin / Theme | Severity | CVSS | Description | Fixed In | Source |
|---|---|---|---|---|---|---|
| 90867c8b-a025-4c46-986f-9e83866033b5 | < 8.0.0 |
MEDIUM | 4.3 | The Element Pack Pro - Addon for Elementor Page Builder WordPress Plugin plugin for WordPress is vulnerable to unauthori… | — | wordfence |
| 90863334-9464-466b-bb32-870c78095ca4 | < 1.0.117 |
MEDIUM | 4.3 | The Royal Elementor Kit theme for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and inclu… | — | wordfence |
| 9075a705-e72f-4331-ab8f-bb06e1a58225 | MEDIUM | 4.3 | The Relocate Upload plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and includin… | — | wordfence | |
| 90752d8a-2e0c-4d46-8a49-778fe06361bd | < 9.0 |
MEDIUM | 4.3 | The Emergency Password Reset plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and inc… | — | wordfence |
| 904e9ac2-1f28-43ba-914c-3b4fd5a0bb22 | MEDIUM | 4.3 | The Customize Login Page plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and inc… | — | wordfence | |
| 9049ac31-b79a-4872-a522-2930fb1dfea6 | < 4.1.4 |
MEDIUM | 4.3 | The WC Marketplace plugin for WordPress is vulnerable to unauthorized access due to a missing capability check in versio… | — | wordfence |
| 9046f2cd-f046-46ce-b91c-db9d036ab1fb | MEDIUM | 4.3 | The Navayan Subscribe plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and includ… | — | wordfence | |
| 9020faf4-0577-41d9-b005-4d4ffc99ba30 | MEDIUM | 4.3 | The Admin Menu Manager plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and inclu… | — | wordfence | |
| 901d4e10-06e9-4acd-ba4a-85a537fa10bc | MEDIUM | 4.3 | The T1 Theme for WordPress is vulnerable to Open Redirect in versions up to, and including, 19.0. This is due to insuffi… | — | wordfence | |
| 901cc40d-fa20-4a1f-b01a-e3295891ebda | < 2.3.4 |
MEDIUM | 4.3 | The All-in-one Sticky Floating Contact Form, Call, Click to Chat, and 50+ Social Icon Tabs β My Sticky Elements plugi… | — | wordfence |
| 901baf71-03b5-4493-9318-ba28dcb97dbe | < 2.6.7 |
MEDIUM | 4.3 | The Spectra β WordPress Gutenberg Blocks plugin for WordPress is vulnerable to unauthorized access due to a missing ca… | — | wordfence |
| 900e6528-f350-4e1b-80a5-aa01248323a8 | < 1.12.0 |
MEDIUM | 4.3 | The Gallery Plugin for WordPress β Envira Photo Gallery plugin for WordPress is vulnerable to unauthorized modificatio… | — | wordfence |
| 9009deff-bf5a-4434-8f73-1485f733d599 | < 1.10.0.3 |
MEDIUM | 4.3 | The Contact Form by WPForms plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and incl… | — | wordfence |
| 900339ef-7481-4c55-ab1d-df2617987520 | < 2.5.9 |
MEDIUM | 4.3 | The CMSMasters Content Composer plugin for WordPress is vulnerable to unauthorized access due to a missing capability ch… | — | wordfence |
| 900294ef-dedb-49d3-b544-eae64399ea03 | < 20251128 |
MEDIUM | 4.3 | The Private Google Calendars plugin for WordPress is vulnerable to unauthorized modification of data due to a missing ca… | — | wordfence |
| 8ff9d034-3c6e-4f8f-a53e-86ad85cc10e6 | MEDIUM | 4.3 | The Restore Permanently delete Post or Page Data plugin for WordPress is vulnerable to Cross-Site Request Forgery in all… | — | wordfence | |
| 8ff3b35c-f7e3-4cae-b7f1-1a0930173ac5 | < 26.6.3 |
MEDIUM | 4.3 | The Betheme theme for WordPress is vulnerable to authorization bypass in versions up to, and including, 26.6.2. This is … | — | wordfence |
| 8ff2a842-2e46-4267-bbf1-e7d9d4a7e277 | < 3.2.9 |
MEDIUM | 4.3 | The Sunshine Photo Cart plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on t… | — | wordfence |
| 8ff16906-2516-4b3c-8217-e3fb24924e27 | < 3.1.14 |
MEDIUM | 4.3 | The ImageRecycle pdf & image compression plugin for WordPress is vulnerable to unauthorized modification of data due to … | — | wordfence |
| 8ff05617-61b1-4d1f-9230-c771f23d3283 | MEDIUM | 4.3 | The Custom Post Type Page Template plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, a… | — | wordfence | |
| 8fe7dc0e-3b8c-409d-a66a-2f67b88d0d32 | < 3.0.5 |
MEDIUM | 4.3 | The Graphina plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on several func… | — | wordfence |
| 8fe7b884-c245-4412-b43d-38d0565fccbd | < 3.6.5 |
MEDIUM | 4.3 | The Textmetrics plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a functio… | — | wordfence |
| 8fe0cb36-7b61-412f-ad2a-d31b18417ce8 | < 2.0.74 |
MEDIUM | 4.3 | The Radio Player plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a functi… | — | wordfence |
| 8fd845f2-9943-462a-afab-bd19b8064a88 | MEDIUM | 4.3 | The Frontend File Manager Plugin plugin for WordPress is vulnerable to unauthorized access due to a missing capability c… | — | wordfence | |
| 8fc88821-b2be-49a5-a2cf-53e87d0349a2 | MEDIUM | 4.3 | The WP Shamsi plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the '… | — | wordfence |
EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.
Scan My Website →