Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.
40,434 vulnerabilities found (page 1496 of 1618)
| CVE ID | Plugin / Theme | Severity | CVSS | Description | Fixed In | Source |
|---|---|---|---|---|---|---|
| 5debe121-6373-4b56-8441-f0d4a5920089 | < 1.0.5 |
MEDIUM | 4.3 | The Shortcodes for Elementor plugin for WordPress is vulnerable to Information Exposure in all versions up to, and inclu… | — | wordfence |
| 5de953ee-8a01-4372-a376-74a4cff674ce | < 3.7.1 |
MEDIUM | 4.3 | The DecaLog plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 3.7.0. Th… | — | wordfence |
| 5de4f912-1dc2-48e8-a413-04b06a1b61f5 | < 3.5.1 |
MEDIUM | 4.3 | The WP2LEADS | WordPress und KlickTipp einfach verbinden β WooCommerce und KlickTipp einfach verbinden plugin for Wor… | — | wordfence |
| 5de212c9-5c2e-4713-b1ce-022dd84520c3 | < 3.9.4 |
MEDIUM | 4.3 | The Tutor LMS β eLearning and online course solution plugin for WordPress is vulnerable to unauthorized course enrollm… | — | wordfence |
| 5ddfea92-b790-4cf3-8b98-39c2374c7c31 | < 1.0.4 |
MEDIUM | 4.3 | The ContentLock plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1… | — | wordfence |
| 5dd2f81c-8e7c-47e6-93ff-8d6ae2f23304 | < 1.16 |
MEDIUM | 4.3 | The All in One Accessibility plugin for WordPress is vulnerable to unauthorized access due to a missing capability check… | — | wordfence |
| 5dd2a4cb-dd74-4b00-82f5-3bf1452e71a3 | MEDIUM | 4.3 | The 10WebAnalytics plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability c… | — | wordfence | |
| 5dbbd1a0-de05-4510-b06b-8bc396b65a97 | < 13.7.1 |
MEDIUM | 4.3 | The Quick Featured Images plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capab… | — | wordfence |
| 5db431b1-6601-490b-960f-4dda6c25c872 | MEDIUM | 4.3 | The Hotlink2Watermark plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and includ… | — | wordfence | |
| 5dae8e82-e252-48d9-ae1f-62acfcd17e2b | MEDIUM | 4.3 | The BadgeOS plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions up to, and including, 3.7… | — | wordfence | |
| 5da8a4d4-9c98-4ee1-affd-105c88528c56 | < 3.4.2 |
MEDIUM | 4.3 | The AI Engine (Pro) plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a fun… | — | wordfence |
| 5d9e20f7-813c-4691-bce4-d0ff4774ae48 | < 1.2.0 |
MEDIUM | 4.3 | The Reviews Feed β Add Testimonials and Customer Reviews From Google Reviews, Yelp, TripAdvisor, and More plugin for W… | — | wordfence |
| 5d96ea1b-1763-4a54-bd67-ac29175e9e01 | < 1.20.27 |
MEDIUM | 4.3 | The SurveyJS: Drag & Drop WordPress Form Builder plugin for WordPress is vulnerable to Cross-Site Request Forgery in all… | — | wordfence |
| 5d716a6c-72b7-439f-8a99-56cd588515e3 | < 3.4.5.1 |
MEDIUM | 4.3 | The Watu Quiz plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function … | — | wordfence |
| 5d6f38d7-a769-422d-ae3f-565cb1cc8a73 | < 2026.2 |
MEDIUM | 4.3 | The Stop Spammers Classic plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and in… | — | wordfence |
| 5d572cac-b8e3-4c52-9b35-80fe5ee9e900 | < 3.2.5 |
MEDIUM | 4.3 | The ClickCease Click Fraud Protection plugin for WordPress is vulnerable to unauthorized access of data due to an improp… | — | wordfence |
| 5d3fa174-93c6-4086-b247-099d448a494f | MEDIUM | 4.3 | The Elastic Email Subscribe Form plugin for WordPress is vulnerable to unauthorized access due to a missing capability c… | — | wordfence | |
| 5d386d25-d228-4491-b58d-6adbb3b863a5 | MEDIUM | 4.3 | The Vimeo plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and including, 1.2.2. … | — | wordfence | |
| 5d3251b8-4759-42c5-8fec-8b7f87e10b1a | < 20250820 |
MEDIUM | 4.3 | The Simple Statistics for Feeds plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, … | — | wordfence |
| 5d255ca7-37a5-4c1b-84be-356ae3900f7e | < 1.4.1 |
MEDIUM | 4.3 | The Block for Font Awesome plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and inclu… | — | wordfence |
| 5d1ff79e-5246-422a-ae75-20763e7acd17 | < 6.3.8 |
MEDIUM | 4.3 | The Poll Maker β Versus Polls, Anonymous Polls, Image Polls plugin for WordPress is vulnerable to Sensitive Informatio… | — | wordfence |
| 5d1dc9b4-9018-4e23-933b-5c03fa60d56a | MEDIUM | 4.3 | The FastBook β Responsive Appointment Booking and Scheduling System plugin for WordPress is vulnerable to Cross-Site R… | — | wordfence | |
| 5d1d012a-46cd-4c86-ac6f-993736a91acb | < 1.1.4 |
MEDIUM | 4.3 | The Redirect Redirection plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and includi… | — | wordfence |
| 5d18f911-a766-4b13-a00e-8cdeee788d7a | < 2.3.0 |
MEDIUM | 4.3 | The Gutenverse Form β Contact Form Builder, Booking, Reservation, Subscribe for Block Editor plugin for WordPress is v… | — | wordfence |
| 5d01548e-91bf-44db-83dc-10c7d5962f9b | < 5.1 |
MEDIUM | 4.3 | The Optimize Database after Deleting Revisions plugin for WordPress is vulnerable to Cross-Site Request Forgery in versi… | — | wordfence |
EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.
Scan My Website →