Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.
40,434 vulnerabilities found (page 1519 of 1618)
| CVE ID | Plugin / Theme | Severity | CVSS | Description | Fixed In | Source |
|---|---|---|---|---|---|---|
| 44c14dca-19df-4f83-80bf-6ea0ea261e28 | < 6.4.19 |
MEDIUM | 4.3 | The Business Directory plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capabili… | — | wordfence |
| 44bca8c2-1591-484c-ac40-8c968d5d1cad | MEDIUM | 4.3 | The CTL Arcade Lite plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and includin… | — | wordfence | |
| 44b62b99-99eb-424b-a04a-9bbacf5fbbaa | < 20240307 |
MEDIUM | 4.3 | The Gestpay for WooCommerce plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and … | — | wordfence |
| 44b02690-462a-458b-88c9-89acc9c209cb | < 3.0.2 |
MEDIUM | 4.3 | The Media Hygiene: Remove or Delete Unused Images and More! plugin for WordPress is vulnerable to unauthorized loss of d… | — | wordfence |
| 44ad056b-8995-4068-8b05-4fefb8d2ff0a | < 2.0.5 |
MEDIUM | 4.3 | The Buzz Club β Night Club, DJ and Music Festival Event WordPress Theme theme for WordPress is vulnerable to unauthori… | — | wordfence |
| 44a2e2f3-1902-43c5-8e3c-4174cb1ffa63 | MEDIUM | 4.3 | The WP Page Numbers plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 0… | — | wordfence | |
| 4490afba-1487-40a4-99c6-c753acb10df3 | < 2.13.4 |
MEDIUM | 4.3 | The Image Gallery β Photo Grid & Video Gallery plugin for WordPress is vulnerable to unauthorized modification of data… | — | wordfence |
| 448a9e55-e976-4988-a0df-57f1f06fe66d | MEDIUM | 4.3 | The Project Cost Calculator plugin for WordPress is vulnerable to unauthorized access due to a missing capability check … | — | wordfence | |
| 44895f32-d5be-4dc7-85d2-539ff1720b37 | < 1.0.25 |
MEDIUM | 4.3 | The Feeds for TikTok β Display Video Feeds in Grid Layouts plugin for WordPress is vulnerable to unauthorized access d… | — | wordfence |
| 4484fa86-5878-426d-92b9-8eb0751075e5 | < 6.10.13 |
MEDIUM | 4.3 | The Simple:Press Forum plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and inclu… | — | wordfence |
| 447cef6f-fa2e-4087-946d-6e0214830ea9 | < 4.0.3 |
MEDIUM | 4.3 | The Post Lockdown plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 4.0.2… | — | wordfence |
| 44777529-660f-4038-bbee-566ca3a8d24e | < 3.2.7 |
MEDIUM | 4.3 | The Easy Digital Downloads plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and inclu… | — | wordfence |
| 4473de39-a122-4c2e-9f64-50157b589a28 | < 2.8.8 |
MEDIUM | 4.3 | The WPeMatico RSS Feed Fetcher plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, a… | — | wordfence |
| 445cee5c-21d5-4597-9efc-84e094476c3e | < 2.0.2 |
MEDIUM | 4.3 | The WordPress Booking plugin for Appointment Calendar and Woocommcerce Booking β Bookingor plugin for WordPress is vul… | — | wordfence |
| 4454f002-0d31-4023-9a44-bb8f3050e233 | < 1.4.1 |
MEDIUM | 4.3 | The Disable Admin Notices individually plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up t… | — | wordfence |
| 444a25d7-6837-49a2-b21c-d6a00c0bc0bc | MEDIUM | 4.3 | The Busiprof theme for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.5.2. Th… | — | wordfence | |
| 443c59b9-275d-4d17-a870-9ae013c1a5c1 | < 1.5.3 |
MEDIUM | 4.3 | The Qode Essential Addons plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capab… | — | wordfence |
| 442a8f8e-319e-4ae5-8c7f-2bcdcf542158 | < 4.7.16 |
MEDIUM | 4.3 | The MasterStudy LMS Pro plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to 4.7.1… | — | wordfence |
| 4425f63e-2910-4d1c-9f99-0c24fb3350d2 | < 1.0.8 |
MEDIUM | 4.3 | The FoodBoxBooker plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions up to, and includin… | — | wordfence |
| 43fd1949-2682-469b-a129-223ebecc312e | < 7.6 |
MEDIUM | 4.3 | The Mark New Posts plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability c… | — | wordfence |
| 43fc71bb-87ba-4cf9-ae4d-1cba7bd84806 | < 1.2.3 |
MEDIUM | 4.3 | The WC Sales Notification plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and includ… | — | wordfence |
| 43e7b61e-f97a-4889-aae4-3d35ee0c5241 | < 1.6.0 |
MEDIUM | 4.3 | The Photo Block β A Modern Image Block With Lightbox and Caption Support plugin for WordPress is vulnerable to unautho… | — | wordfence |
| 43d8576b-e6ad-4e0a-b99f-948ba36f53ff | MEDIUM | 4.3 | The WP Landing Page plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and includin… | — | wordfence | |
| 43d534f8-fb1c-4170-a66e-2cef72cd40de | < 3.0.2 |
MEDIUM | 4.3 | The qTranslate X Cleanup and WPML Import plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up… | — | wordfence |
| 43d46ada-4cbf-40e4-a0e5-685d8bf1a8a5 | < 2.9.2 |
MEDIUM | 4.3 | WordPress 2.9 before 2.9.2 allows remote authenticated users to read trash posts from other authors via a direct request… | — | wordfence |
EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.
Scan My Website →