Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.
40,434 vulnerabilities found (page 1511 of 1618)
| CVE ID | Plugin / Theme | Severity | CVSS | Description | Fixed In | Source |
|---|---|---|---|---|---|---|
| 4d64a157-8d9c-4c57-b7e2-2d253319da57 | < 2.0 |
MEDIUM | 4.3 | The Copymatic β AI Content Writer & Generator plugin for WordPress is vulnerable to unauthorized modification of data … | — | wordfence |
| 4d5b1a3d-ce7f-4d5d-b72b-61024d5c5378 | < 1.17.1 |
MEDIUM | 4.3 | The Thrive Automator plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, … | — | wordfence |
| 4d4d0176-3b7d-4de5-95ec-365873e6f13b | < 3.5.5 |
MEDIUM | 4.3 | The affiliate-toolkit β WordPress Affiliate Plugin plugin for WordPress is vulnerable to unauthorized access due to a … | — | wordfence |
| 4d3858f5-3f13-400c-acf4-eb3dc3a43308 | < 1.1.3 |
MEDIUM | 4.3 | The WP Fastest Cache plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, … | — | wordfence |
| 4d246a99-fd92-4132-9576-efa065a58f59 | < 3.1.5 |
MEDIUM | 4.3 | The WP Meteor Page Speed Optimization Topping plugin for WordPress is vulnerable to Cross-Site Request Forgery in versio… | — | wordfence |
| 4d23132e-b82e-4129-ab4a-8f0f3721d270 | MEDIUM | 4.3 | The Live Sports Streamthunder plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, an… | — | wordfence | |
| 4d1ef6e3-c502-4099-9099-55058b6ba430 | < 1.6.0 |
MEDIUM | 4.3 | The Music Player for WooCommerce plugin for WordPress is vulnerable to unauthorized access due to a missing capability c… | — | wordfence |
| 4d114ce7-30af-49a3-a6f7-8445c15a2820 | MEDIUM | 4.3 | The WP Add Active Class To Menu Item plugin for WordPress is vulnerable to Cross-Site Request Forgery in version * -<=1.… | — | wordfence | |
| 4cfdbf80-3733-4d5c-9bc6-01e543ee08b1 | < 8.1.19 |
MEDIUM | 4.3 | The Quiz And Survey Master plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and inclu… | — | wordfence |
| 4ced42ce-2009-45f6-81c0-ad9e5a05b381 | MEDIUM | 4.3 | The Aspose.Words β Import and Export word documents plugin for WordPress is vulnerable to unauthorized access due to a… | — | wordfence | |
| 4ce32dcb-3b7b-433e-9add-512dc2f9f2d8 | < 1.3.2 |
MEDIUM | 4.3 | The Integration for Contact Form 7 HubSpot plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions … | — | wordfence |
| 4cdd4bae-b9ee-4d87-acca-38886f499dcf | < 3.7 |
MEDIUM | 4.3 | The Smartsupp β live chat, chatbots, AI and lead generation plugin for WordPress is vulnerable to Cross-Site Request F… | — | wordfence |
| 4cce2842-bd8e-4a83-b83c-66aefe4df4b8 | < 3.4.1 |
MEDIUM | 4.3 | The Memberships and User Profiles for WooCommerce β ProfileGrid WooCommerce Integration plugin for WordPress is vulner… | — | wordfence |
| 4cc29d32-2727-42df-bd42-2caf0f182c0e | < 4.16.13 |
MEDIUM | 4.3 | The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content β ProfilePr… | — | wordfence |
| 4cc27a99-747f-4a80-85f5-b26b6a57d9db | < 0.0.10 |
MEDIUM | 4.3 | The Cookie Consent β GDPR & CCPA Cookie Banner & Consent Manager plugin for WordPress is vulnerable to unauthorized ac… | — | wordfence |
| 4cb5d487-0f22-4a34-8558-fe06c19a375b | < 1.0.6 |
MEDIUM | 4.3 | The PZ Frontend Manager plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and incl… | — | wordfence |
| 4cb4b5ca-0abc-4b41-bc48-de9740bb13ff | < 1.9 |
MEDIUM | 4.3 | The Export Order, Product, Customer & Coupon for WooCommerce to Google Sheets plugin for WordPress is vulnerable to unau… | — | wordfence |
| 4ca43066-fcfb-4e6d-83c4-b6f0108d26ec | < 1.5.5 |
MEDIUM | 4.3 | The PDF Generator for WordPress plugin for WordPress is vulnerable to unauthorized access due to a missing capability ch… | — | wordfence |
| 4c953a46-d2ae-41f7-a940-d23b011d9eca | < 1.1.4 |
MEDIUM | 4.3 | The Redirect Redirection plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capabi… | — | wordfence |
| 4c8f1c29-b99d-4af0-9cc4-5d6179529ab4 | < 4.7.5 |
MEDIUM | 4.3 | The AI Infographic Maker plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capabi… | — | wordfence |
| 4c836671-f488-40d9-81b6-e4cd32d0606c | MEDIUM | 4.3 | The Laybuy Payment Extension for WooCommerce plugin for WordPress is vulnerable to unauthorized access due to a missing … | — | wordfence | |
| 4c7fe6e7-f776-4fd5-8341-b95237a63d4e | < 1.5.0 |
MEDIUM | 4.3 | The Travel Agency plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including,… | — | wordfence |
| 4c6e6335-7f18-425a-bb86-7e4fc09dae86 | < 1.2.8 |
MEDIUM | 4.3 | The Spa and Salon theme for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.2.… | — | wordfence |
| 4c659f6d-e02b-42ab-ba02-eb9b00602ad4 | < 4.5.2 |
MEDIUM | 4.3 | The WP Activity Log Premium plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and incl… | — | wordfence |
| 4c635405-997e-44ea-8851-7d09051307ad | MEDIUM | 4.3 | The Company Posts for LinkedIn plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and in… | — | wordfence |
EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.
Scan My Website →