Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.
40,434 vulnerabilities found (page 1500 of 1618)
| CVE ID | Plugin / Theme | Severity | CVSS | Description | Fixed In | Source |
|---|---|---|---|---|---|---|
| 597fe53e-769e-4edd-b0b9-2bd2cff50da6 | MEDIUM | 4.3 | The Video Contest WordPress Plugin plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, a… | — | wordfence | |
| 597d6d6b-80d5-45d8-b013-2804fce12c85 | MEDIUM | 4.3 | The spam-byebye plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2… | — | wordfence | |
| 5974443a-48aa-4d5e-958a-40b99f68a1ae | < 1.2.0 |
MEDIUM | 4.3 | The Vandana Lite theme for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1… | — | wordfence |
| 5973afaa-5a64-4db1-8e32-3b39d1367eb8 | MEDIUM | 4.3 | The SIS Handball plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.0.… | — | wordfence | |
| 5971447d-0634-49a5-91d0-c4f0c0825a86 | < 4.0 |
MEDIUM | 4.3 | The Staff Directory Plugin plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and inclu… | — | wordfence |
| 595d0401-55b9-418e-8b99-48b23e9a2662 | MEDIUM | 4.3 | The Rucy plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 0.4.4. This … | — | wordfence | |
| 595a6ab3-0731-4ef4-a385-5dfebbd917f4 | < 4.25.3 |
MEDIUM | 4.3 | The WordPress File Upload plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and in… | — | wordfence |
| 59592b27-d431-499a-b3c3-3d43a5513c36 | < 6.5.2 |
MEDIUM | 4.3 | The FileBird β WordPress Media Library Folders & File Manager plugin for WordPress is vulnerable to missing authorizat… | — | wordfence |
| 5954c35a-7d0a-4bc5-9cad-3223e7be56eb | < 0.1.0.9 |
MEDIUM | 4.3 | The InstaWP Connect β 1-click WP Staging & Migration plugin for WordPress is vulnerable to Cross-Site Request Forgery … | — | wordfence |
| 592d42eb-4025-44af-a519-672656ad8b0e | < 5.2.7 |
MEDIUM | 4.3 | The Ninja Tables β Easy Data Table Builder plugin for WordPress is vulnerable to unauthorized database table creation … | — | wordfence |
| 58f048e5-f4be-4452-8fed-16871f4020b6 | MEDIUM | 4.3 | The WPDash Notes plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on … | — | wordfence | |
| 58d25eeb-b12c-4850-8308-eaa30982b5a8 | < 1.1.4 |
MEDIUM | 4.3 | The BEAR for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.1.3.3. This is du… | — | wordfence |
| 58cfb328-40d0-4bea-a707-d5d6c1ce364a | MEDIUM | 4.3 | The Sticky Social Media Icons plugin for WordPress is vulnerable to unauthorized settings update due to a missing capabi… | — | wordfence | |
| 58c35a21-1416-4926-a4ea-9c4fa3363114 | < 2.9.2 |
MEDIUM | 4.3 | The Page View Count plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a fun… | — | wordfence |
| 58b48d86-9b88-468b-878d-1fabd3c3d778 | < 0.5.4 |
MEDIUM | 4.3 | The Specific Content For Mobile β Customize the mobile version without redirections plugin for WordPress is vulnerable… | — | wordfence |
| 58b29729-e9c3-4d57-affd-6142dfa8cc6f | < 1.0.7.5 |
MEDIUM | 4.3 | The Categorify plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.… | — | wordfence |
| 5890360b-e0ef-4ec2-8117-1b4004573e93 | MEDIUM | 4.3 | The Popup for CF7 with Sweet Alert plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, a… | — | wordfence | |
| 58898db3-e3fb-4903-8121-3a438a09122a | MEDIUM | 4.3 | The Di Themes Demo Site Importer plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and… | — | wordfence | |
| 5881a375-39a1-4911-812e-1f968ad427f9 | < 2.2.7 |
MEDIUM | 4.3 | The WP Docs plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in… | — | wordfence |
| 58804f7a-51af-4199-85c9-b75b91b5c59b | < 2.9.72 |
MEDIUM | 4.3 | The Netgsm plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in … | — | wordfence |
| 587b53aa-2369-4433-b0f1-7f054f5a0653 | < 2.7 |
MEDIUM | 4.3 | The Pays β WooCommerce Payment Gateway plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up… | — | wordfence |
| 58756479-72f0-4c5e-8ed5-dfdbffed6026 | < 4.6.6.1 |
MEDIUM | 4.3 | The MobiLoud β WordPress Mobile Apps β Convert your WordPress Website to Native Mobile Apps plugin for WordPress is … | — | wordfence |
| 585a9eb4-f394-4cb2-9050-659171a994d9 | < 6.1.2 |
MEDIUM | 4.3 | The Popup Box plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 6.1… | — | wordfence |
| 5849a9f6-715e-4ac8-a0f7-1cd0814fff58 | < 3.9.5 |
MEDIUM | 4.3 | The Tutor LMS β eLearning and online course solution plugin for WordPress is vulnerable to Insecure Direct Object Refe… | — | wordfence |
| 58386353-93f5-4b87-8c72-c1b1341b884c | MEDIUM | 4.3 | The Simple Google Sitemap plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and in… | — | wordfence |
EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.
Scan My Website →