Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.
40,434 vulnerabilities found (page 1520 of 1618)
| CVE ID | Plugin / Theme | Severity | CVSS | Description | Fixed In | Source |
|---|---|---|---|---|---|---|
| 43d24ac2-c3b9-4e5e-9b58-c99bacc56495 | < 2.2.5 |
MEDIUM | 4.3 | The Premmerce Product Search for WooCommerce plugin for WordPress is vulnerable to Cross-Site Request Forgery in version… | — | wordfence |
| 43d01824-507d-4d26-af88-9ea5b4c1b108 | < 9.0.41 |
MEDIUM | 4.3 | The WP Go Maps plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 9.0.40… | — | wordfence |
| 43c4ca71-0bf0-4529-97d9-2349f96bbb9e | < 2.6.4 |
MEDIUM | 4.3 | The Mollie Forms plugin for WordPress is vulnerable to unauthorized post or page duplication due to a missing capability… | — | wordfence |
| 43b05697-bc36-4f32-86b4-2feef892fe42 | < 2.9.7.2 |
MEDIUM | 4.3 | The myCred β Points Management System For Gamification, Ranks, Badges, and Loyalty Program plugin for WordPress is vul… | — | wordfence |
| 43af2d38-72e8-405f-a910-500fb782ded2 | MEDIUM | 4.3 | The Google Plus One Bottom plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and i… | — | wordfence | |
| 43a237fd-5d3a-47fb-bacf-ceb5eeaa8bbb | MEDIUM | 4.3 | The Quantic Social Image Hover plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, a… | — | wordfence | |
| 439e7c0d-e45a-44f2-9ecb-3092843f63e0 | < 2.4.0 |
MEDIUM | 4.3 | The Visual Link Preview plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and … | — | wordfence |
| 439809ad-21ea-4a0b-b1fd-5de9f8f5ee7a | < 4.2.1 |
MEDIUM | 4.3 | The Photo Gallery, Sliders, Proofing and Themes β NextGEN Gallery plugin for WordPress is vulnerable to Insecure Direc… | — | wordfence |
| 4394f96a-ceb5-463f-b454-a6fa4a59fc45 | < 3.7.40 |
MEDIUM | 4.3 | WordPress Core is vulnerable to information disclosure via the REST-API in versions up to 6.0.3. The REST API endpoint f… | — | wordfence |
| 4381d22f-5607-4b54-9762-33ac6611a658 | < 4.4 |
MEDIUM | 4.3 | The WP Maintenance Mode & Site Under Construction plugin for WordPress is vulnerable to Cross-Site Request Forgery in al… | — | wordfence |
| 43790bc7-23ff-48b1-bf49-bf13cf184bd1 | MEDIUM | 4.3 | The Backup Bolt plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1… | — | wordfence | |
| 434b140a-43b7-41bc-8cc2-ed82787b90c3 | < 6.1.10 |
MEDIUM | 4.3 | The Essential Addons for Elementor β Popular Elementor Addon With Ready Templates, Advanced Widgets, Kits & WooCommerc… | — | wordfence |
| 4340ef32-82d4-4523-ae63-36f0ef853f76 | < 3.5.7 |
MEDIUM | 4.3 | The YayPricing plugin for WordPress is vulnerable to unauthorized access in versions up to, and including, 3.5.6. This i… | — | wordfence |
| 433a03c2-09fd-4ce6-843b-55ad09f4b4f7 | < 2.9.35 |
MEDIUM | 4.3 | The Affiliates Manager plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and inclu… | — | wordfence |
| 432b11be-174d-45d6-aa3b-2fbfa85ec17a | < 4.3.12 |
MEDIUM | 4.3 | The BetterDocs plugin for WordPress is vulnerable to Missing Authorization in versions up to and including 4.3.11. This … | — | wordfence |
| 42fff63c-62ec-466e-9a05-60d76f80039e | < 1.0.9 |
MEDIUM | 4.3 | The Easy Hide Login plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1… | — | wordfence |
| 42f8f378-0f84-49ad-b95e-6abb3a94df7e | < 4.5.3 |
MEDIUM | 4.3 | The Podlove Podcast Publisher plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to 4.5.3. … | — | wordfence |
| 42e63318-661e-465d-919f-df0635ea1a6d | < 1.4.4 |
MEDIUM | 4.3 | The Qi Blocks plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 1.4.3. T… | — | wordfence |
| 42b77d66-8519-4e7e-b253-fefac581df4b | < 10.2.3 |
MEDIUM | 4.3 | The Quiz and Survey Master (QSM) β Easy Quiz and Survey Maker plugin for WordPress is vulnerable to Cross-Site Request… | — | wordfence |
| 42b2d840-4e8b-4027-ab3b-78b17c9ed9aa | < 1.2.2 |
MEDIUM | 4.3 | The Floating Action Button plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and i… | — | wordfence |
| 42ac91dc-bcde-4804-bac7-b96597627a27 | < 4.0.4 |
MEDIUM | 4.3 | The Cookie Banner, Cookie Consent, Consent Log, Cookie Scanner, Script Blocker (for GDPR, CCPA & ePrivacy) : WP Cookie C… | — | wordfence |
| 42a14820-710d-4149-9a8d-aa84479f0980 | < 6.4.9 |
MEDIUM | 4.3 | The Photo Gallery by Ays plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and inc… | — | wordfence |
| 4280f2db-cabe-4955-af68-d03e299bfcf4 | < 0.99 |
MEDIUM | 4.3 | The Simple Maps plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 0… | — | wordfence |
| 4276e68b-4d0d-4a16-a32c-51b4f6e3c570 | MEDIUM | 4.3 | The CBX Restaurant Booking plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and i… | — | wordfence | |
| 42711f2d-99e4-45cf-bd57-a3e228f3bf25 | MEDIUM | 4.3 | The Easy Child Theme Creator plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and… | — | wordfence |
EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.
Scan My Website →