Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.
40,407 vulnerabilities found (page 1455 of 1617)
| CVE ID | Plugin / Theme | Severity | CVSS | Description | Fixed In | Source |
|---|---|---|---|---|---|---|
| 89d3a9da-2496-4f75-ad8f-65629f198fe5 | < 4.10.12 |
MEDIUM | 4.3 | The Event Espresso 4 Decaf plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and inclu… | — | wordfence |
| 89cbe41d-3765-4061-8ef6-b63556a5677c | MEDIUM | 4.3 | The Site Notes plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.… | — | wordfence | |
| 89ca9214-145e-43c6-a642-7c371f635332 | MEDIUM | 4.3 | The JTRT Responsive Tables plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and inclu… | — | wordfence | |
| 89a05036-93f6-421f-ac64-a26622427ebb | < 15.0.9 |
MEDIUM | 4.3 | The Simple Link Directory Pro - AI Powered plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions … | — | wordfence |
| 897ee0c1-9f28-47b5-9b10-f6fd8c4c4f18 | < 4.2.4 |
MEDIUM | 4.3 | The PushEngage β Web Push Notifications, WooCommerce Automation & Chat Widget plugin for WordPress is vulnerable to Se… | — | wordfence |
| 896d69ff-ec05-4811-a959-84f632b4b915 | < 1.4.14 |
MEDIUM | 4.3 | The Call Now Button β The #1 Click to Call Button for WordPress plugin for WordPress is vulnerable to Cross-Site Reque… | — | wordfence |
| 89696d1c-8e6e-402a-9d7a-03fe0f364a72 | < 3.3.2 |
MEDIUM | 4.3 | The ELEX WordPress HelpDesk & Customer Ticketing System plugin for WordPress is vulnerable to unauthorized modification … | — | wordfence |
| 89635463-966d-4f7d-995d-ad83a502d95b | < 1.6 |
MEDIUM | 4.3 | The Remove Schema plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.5… | — | wordfence |
| 894c875a-078f-4c1f-83d2-4a6e4a309c3e | < 3.0.9 |
MEDIUM | 4.3 | The Dokan plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 3.0.8. This… | — | wordfence |
| 894ad797-5143-4493-a3d6-29b22cee1cc6 | < 11.0.0 |
MEDIUM | 4.3 | The AcyMailing SMTP Newsletter plugin for WordPress is vulnerable to unauthorized access due to a missing capability che… | — | wordfence |
| 8945bae7-2224-4d9f-b693-10c94c94dea0 | < 1.17.6 |
MEDIUM | 4.3 | The NitroPack plugin for WordPress is vulnerable to unauthorized arbitrary transient update due to a missing capability … | — | wordfence |
| 8939cad2-f9fc-45aa-97d1-9a1a2a59bf94 | < 6.3.8 |
MEDIUM | 4.3 | The Simple File List plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a fu… | — | wordfence |
| 8931a3ab-886c-4618-b413-c25884ef24bc | < 1.8.0 |
MEDIUM | 4.3 | The Behance Portfolio Manager plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and in… | — | wordfence |
| 89315bf7-19f2-4fec-b9f5-62aa2a928d7a | < 2.8.1 |
MEDIUM | 4.3 | The Brizy Pro plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function … | — | wordfence |
| 8925157c-8642-4cbc-89e3-fb2ac148eee6 | < 2.1.1 |
MEDIUM | 4.3 | The Himer theme for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.1.0. T… | — | wordfence |
| 892372c9-380c-43b2-b928-b5964574c414 | < 2.1.0 |
MEDIUM | 4.3 | The Wp Ultimate Review plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including… | — | wordfence |
| 891a625e-8248-4d21-a796-bf0cff6fc253 | MEDIUM | 4.3 | The ENL Newsletter plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including… | — | wordfence | |
| 8919ba4e-e217-4e1d-8bd6-4c2387f9680f | < 1.1.6 |
MEDIUM | 4.3 | The WP Insightly for Contact Form 7, WPForms, Elementor, Formidable and Ninja Forms plugin for WordPress is vulnerable t… | — | wordfence |
| 89100b33-0e27-4a04-9407-8505524e7e45 | < 3.3.0 |
MEDIUM | 4.3 | The Gutenverse β Ultimate WordPress FSE Blocks Addons & Ecosystem plugin for WordPress is vulnerable to unauthorized a… | — | wordfence |
| 890bcce2-18c2-4df8-a945-0c23437534fc | < 1.0.99 |
MEDIUM | 4.3 | The ColibriWP Theme framework used by multiple themes for WordPress is vulnerable to unauthorized modification of data d… | — | wordfence |
| 88fb7e43-26b1-44e4-864a-e6bd6f2c48fa | < 4.8.3 |
MEDIUM | 4.3 | The Featured Image from URL plugin for WordPress is vulnerable to unauthorized modification of data due to an insufficie… | — | wordfence |
| 88fa4a43-7126-42e6-9469-25ffbfd8ed17 | < 3.2.1 |
MEDIUM | 4.3 | The Powerlift - Fitness and Gym WordPress Theme theme for WordPress is vulnerable to unauthorized access due to a missin… | — | wordfence |
| 88f6a24f-f14a-4d0a-be5a-f8c84910b4fc | < 2.10.230 |
MEDIUM | 4.3 | The Orbit Fox by ThemeIsle plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and i… | — | wordfence |
| 88f51ef6-2207-4e91-9182-48c6babe178b | < 3.3.2 |
MEDIUM | 4.3 | The Gutenberg Blocks with AI by Kadence WP β Page Builder Features plugin for WordPress is vulnerable to unauthorized … | — | wordfence |
| 88dc4a77-0d81-4d90-9a43-cc4d3055e39c | < 8.0.8 |
MEDIUM | 4.3 | The Quiz And Survey Master plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and inclu… | — | wordfence |
EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.
Scan My Website →