Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.
40,434 vulnerabilities found (page 1498 of 1618)
| CVE ID | Plugin / Theme | Severity | CVSS | Description | Fixed In | Source |
|---|---|---|---|---|---|---|
| 5ba0ecd6-de5a-441c-a4f6-cdfa0ae0edee | MEDIUM | 4.3 | The HidePost plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.3.… | — | wordfence | |
| 5b9919d4-a947-4494-a316-5e2655a4a16f | < 3.3.1 |
MEDIUM | 4.3 | The Conditional Payments for WooCommerce plugin for WordPress is vulnerable to Cross-Site Request Forgery in all version… | — | wordfence |
| 5b962739-8308-4cbd-b14b-1aae440a677b | MEDIUM | 4.3 | The Responsive Flipbooks plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on … | — | wordfence | |
| 5b82994c-c0bd-4e44-95a7-7480ffbb1aad | < 3.19.10 |
MEDIUM | 4.3 | The 12 Step Meeting List plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on … | — | wordfence |
| 5b823a9d-40b2-4308-b732-4a02a06e03e9 | < 6.2.3 |
MEDIUM | 4.3 | The Hotel Booking Lite plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions up to, and inc… | — | wordfence |
| 5b6349c5-a5da-4b8b-b60a-c1176a06e645 | < 6.8.1 |
MEDIUM | 4.3 | The Coupon Affiliates plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capabilit… | — | wordfence |
| 5b62219a-c054-4ae6-ad00-b411995c2b9a | < 1.4 |
MEDIUM | 4.3 | The WP Podcasts Manager plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and incl… | — | wordfence |
| 5b559a48-3c8b-4f8a-9627-c4f838d20af3 | < 3.4.4 |
MEDIUM | 4.3 | The Interactive World Map plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and includ… | — | wordfence |
| 5b4e8413-2df6-432c-89b4-d675206e2afb | < 1.0.4 |
MEDIUM | 4.3 | The WeDesignTech Ultimate Booking Addon plugin for WordPress is vulnerable to unauthorized access due to a missing capab… | — | wordfence |
| 5b39933a-d38e-421b-9fe4-70350e2f3da8 | < 1.0.1 |
MEDIUM | 4.3 | The Instant Breaking News plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and in… | — | wordfence |
| 5b315119-8fd8-4709-8907-b584877c0cfe | MEDIUM | 4.3 | The Admin debug wordpress β enable debug plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions … | — | wordfence | |
| 5b2c6eb3-6042-402d-88e1-8d9fc2291a81 | MEDIUM | 4.3 | The Page Manager for Elementor plugin for WordPress is vulnerable to unauthorized access due to a missing capability che… | — | wordfence | |
| 5b1e6e52-6d4f-4901-859d-05cdec9beb52 | < 1.12.11 |
MEDIUM | 4.3 | The BERTHA AI. Your AI co-pilot for WordPress and Chrome plugin for WordPress is vulnerable to unauthorized access due t… | — | wordfence |
| 5b127a47-d22f-47b5-92a8-440a5892a181 | < 2.3.8 |
MEDIUM | 4.3 | The HT Politic plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.3.7.… | — | wordfence |
| 5b09bfff-4d6e-4de0-b6ab-6ac27c4f2be6 | < 1.8.7 |
MEDIUM | 4.3 | The File Manager Pro β Filester plugin for WordPress is vulnerable to unauthorized modification of data due to a missi… | — | wordfence |
| 5af799a4-0aee-4601-943e-82cbc860ede5 | < 3.1.2 |
MEDIUM | 4.3 | The Advanced Database Cleaner plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and in… | — | wordfence |
| 5af1063c-615e-4196-9fa6-960c008544c4 | < 4.2.5 |
MEDIUM | 4.3 | The MultiVendorX β The Ultimate WooCommerce Multivendor Marketplace Solution plugin for WordPress is vulnerable to una… | — | wordfence |
| 5aef5113-6b80-4fe8-ac98-59c1a10a146f | < 2.6.0 |
MEDIUM | 4.3 | The Buddyboss Platform plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and… | — | wordfence |
| 5ae4d19a-26f1-491e-b0ac-0bb2c6cdd318 | MEDIUM | 4.3 | The Create Posts & Terms plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and includi… | — | wordfence | |
| 5ae2d931-e188-4ab1-8e15-47fdee09e997 | MEDIUM | 4.3 | The Contact Form Widget plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and includin… | — | wordfence | |
| 5ae08e0b-ea17-46c1-aad3-4ecea69c1bdc | < 1.1.2502030 |
MEDIUM | 4.3 | The ECPay Ecommerce for WooCommerce plugin for WordPress is vulnerable to unauthorized loss of data due to a missing cap… | — | wordfence |
| 5ac7408d-8ec7-415b-bf52-024182888cb4 | < 2.4.6 |
MEDIUM | 4.3 | The W4 Post List plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and including, … | — | wordfence |
| 5abc627d-2d8e-44e6-8e8e-ad9f55cbb0d8 | < 5.0 |
MEDIUM | 4.3 | The WP Bing Map Pro plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to 4.1.4. This is du… | — | wordfence |
| 5abc282d-68c9-423c-a15c-d4d3f7035661 | < 4.3.1 |
MEDIUM | 4.3 | The WooCommerce PDF Invoices, Packing Slips, Delivery Notes and Shipping Labels plugin for WordPress is vulnerable to un… | — | wordfence |
| 5abc0853-5888-4538-a6f3-78acef88ff63 | < 1.23.00 |
MEDIUM | 4.3 | The E2Pdf β Export To Pdf Tool for WordPress plugin for WordPress is vulnerable to unauthorized access due to a missin… | — | wordfence |
EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.
Scan My Website →