Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.
40,434 vulnerabilities found (page 1487 of 1618)
| CVE ID | Plugin / Theme | Severity | CVSS | Description | Fixed In | Source |
|---|---|---|---|---|---|---|
| 66bc83f5-0f6c-425f-a560-e79e777b76ca | MEDIUM | 4.3 | The WooCommerce Order Status Change Notifier plugin for WordPress is vulnerable to unauthorized modification of data due… | — | wordfence | |
| 66b59837-b0e6-4bab-b7b6-7c3510164f04 | < 2.1.60 |
MEDIUM | 4.3 | The Job Board Manager plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including,… | — | wordfence |
| 66b5662a-0be7-43f5-b055-02b3cd3a44d1 | < 3.29.11 |
MEDIUM | 4.3 | The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to unauthorized access due to a missing capability c… | — | wordfence |
| 66ac51f9-3571-4e07-a110-afec43abab37 | < 2.0.6 |
MEDIUM | 4.3 | The Password Policy Manager | Password Manager plugin for WordPress is vulnerable to unauthorized modification of data d… | — | wordfence |
| 66a5a011-4c2f-4da9-9b17-96af830ba880 | MEDIUM | 4.3 | The Nictitate theme for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.1.4. T… | — | wordfence | |
| 669f5363-22af-4526-b375-3cca2b1db0ec | MEDIUM | 4.3 | The Jazz Popups plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.8.7… | — | wordfence | |
| 669b0f30-8958-420c-93c5-0103b71967dd | < 6.18.16 |
MEDIUM | 4.3 | The Website Builder by SeedProd β Theme Builder, Landing Page Builder, Coming Soon Page, Maintenance Mode plugin for W… | — | wordfence |
| 66988357-af1a-4763-b814-9092b86e51ef | < 2.4.1 |
MEDIUM | 4.3 | The PDF Poster plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function… | — | wordfence |
| 669833b3-1689-4051-8990-c6eddae4858f | < 3.1.1 |
MEDIUM | 4.3 | The Wp Social Login and Register Social Counter plugin for WordPress is vulnerable to Cross-Site Request Forgery in all … | — | wordfence |
| 66889a85-07d9-4d0f-ac16-31bb9d2d974a | MEDIUM | 4.3 | The Constructo theme for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 4.3.9. … | — | wordfence | |
| 6677813d-1441-41c7-bd2d-859b79260c87 | MEDIUM | 4.3 | The Popping Sidebars and Widgets Light plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions … | — | wordfence | |
| 6670b07e-c9ff-468c-8bfe-603d21bb9afb | < 1.1.6 |
MEDIUM | 4.3 | The Coachify theme for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.1.5… | — | wordfence |
| 6669d04c-9f97-43a5-a312-1cb3d67d21fa | < 3.4.2 |
MEDIUM | 4.3 | The Rate my Post - WP Rating System plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions u… | — | wordfence |
| 66585943-cb70-4296-af66-5b786d1bafb9 | < 1.23 |
MEDIUM | 4.3 | The reCAPTCHA for all plugin for WordPress is vulnerable to unauthorized plugin settings update due to a missing capabil… | — | wordfence |
| 663d7ec3-5e95-41c9-aced-18756907f2db | < 2.7.4 |
MEDIUM | 4.3 | The GDPR CCPA Compliance & Cookie Consent Banner plugin for WordPress is vulnerable to unauthorized access due to a miss… | — | wordfence |
| 66377ee2-cc87-4cfe-a4e4-cef4459bf2ec | < 1.4 |
MEDIUM | 4.3 | The Seraphinite Alternative Slugs Manager plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions u… | — | wordfence |
| 66363035-c09f-4b41-b9fe-2e2bdd851f41 | < 1.9.2.2 |
MEDIUM | 4.3 | The If-So Dynamic Content Personalization plugin for WordPress is vulnerable to Information Exposure in all versions up … | — | wordfence |
| 662f6ae2-2047-4bbf-b4a6-2d536051e389 | < 1.6.44 |
MEDIUM | 4.3 | The Elementor Header & Footer Builder plugin for WordPress is vulnerable to Information Disclosure in all versions up to… | — | wordfence |
| 66294c25-d715-42f2-b249-5ef68ae92cca | < 5.04 |
MEDIUM | 4.3 | The Dynamic Post plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a functi… | — | wordfence |
| 6625dcea-13cc-4c08-9361-946638bf6678 | < 3.9.8 |
MEDIUM | 4.3 | The Tutor LMS plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function … | — | wordfence |
| 660d4214-999f-4a4f-9a7e-332163b9867b | MEDIUM | 4.3 | The Pro Bulk Watermark Plugin for WordPress plugin for WordPress is vulnerable to Path Traversal in all versions up to, … | — | wordfence | |
| 66095908-875f-486d-ae77-6015671872de | < 5.0.3 |
MEDIUM | 4.3 | The Taskbuilder β WordPress Project Management & Task Management plugin for WordPress is vulnerable to authorization b… | — | wordfence |
| 66019297-a8a8-4bbc-99db-4b47066f3e50 | < 1.2.1 |
MEDIUM | 4.3 | The Comments Like Dislike plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capab… | — | wordfence |
| 65f521f4-1968-4c43-a3f0-b0f81632d7aa | MEDIUM | 4.3 | The The Code Snippets CPT plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and… | — | wordfence | |
| 65f4978f-23c3-460d-958e-5aed66b071b4 | < 1.0.0 |
MEDIUM | 4.3 | The Slick Google Map plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, … | — | wordfence |
EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.
Scan My Website →