Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.
40,434 vulnerabilities found (page 1521 of 1618)
| CVE ID | Plugin / Theme | Severity | CVSS | Description | Fixed In | Source |
|---|---|---|---|---|---|---|
| 426f0993-8b75-4bb1-9368-8927241d7cda | < 2.2.14 |
MEDIUM | 4.3 | The Breeze β WordPress Cache Plugin plugin for WordPress is vulnerable to unauthorized access due to a missing capabil… | — | wordfence |
| 4243bd6d-34f6-4d29-a333-4499a2e2d2e1 | < 2.2.5.2 |
MEDIUM | 4.3 | The SecuPress Free β WordPress Security plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versio… | — | wordfence |
| 4238ce95-ff9a-492f-b3ef-3b263efdda7b | < 3.8.5 |
MEDIUM | 4.3 | The WP-Lister Lite for eBay plugin for WordPress is vulnerable to unauthorized access due to a missing capability check … | — | wordfence |
| 42303b60-cbb5-4176-94f9-b2ed29f59cc8 | MEDIUM | 4.3 | The Bulk Comment Remove plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and includin… | — | wordfence | |
| 421fcee2-a05d-4486-837e-ddee3d73d737 | < 2.4.8 |
MEDIUM | 4.3 | The EventON Lite plugin for WordPress is vulnerable to Information Exposure in all versions less than, or equal to, 2.4.… | — | wordfence |
| 421ed38f-cf0b-437f-a477-5bae7963e9e6 | < 1.6.44 |
MEDIUM | 4.3 | The One Page Express Companion plugin for WordPress is vulnerable to unauthorized access due to a missing capability che… | — | wordfence |
| 420f56de-4c83-4c9f-933c-0422467bbc7a | < 4.0.9 |
MEDIUM | 4.3 | The User Activity Tracking and Log plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, a… | — | wordfence |
| 41fada19-c697-4078-825b-0bdf6a827b02 | < 1.6.0 |
MEDIUM | 4.3 | The PHP Compatibility Checker plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and in… | — | wordfence |
| 41ecc6fc-5178-40db-84da-665d60816345 | MEDIUM | 4.3 | The Social Profilr plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.… | — | wordfence | |
| 41d9786e-4ce3-42d6-a0d6-8eb863103d5c | < 5.5 |
MEDIUM | 4.3 | The Animated Rotating Words plugin for WordPress is vulnerable to unauthorized modification of data due to a missing cap… | — | wordfence |
| 41ce3250-17aa-41d6-835d-b37a498c9a29 | MEDIUM | 4.3 | The Image slider with description plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to… | — | wordfence | |
| 41b0b12f-ff52-4913-aa54-3fbaf0839959 | < 1.4.4 |
MEDIUM | 4.3 | The Qi Blocks plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the `resize… | — | wordfence |
| 41aeb465-48c2-48db-90ea-186ceeac6753 | < 1.2.5 |
MEDIUM | 4.3 | The Serious Slider plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including… | — | wordfence |
| 41ac45c7-6741-4b7c-ab74-fd2dfd3c31d1 | < 3.2.21 |
MEDIUM | 4.3 | The VPSUForm β No-Code Custom Form Builder β Contact Forms, Conversion Form & More plugin for WordPress is vulnerabl… | — | wordfence |
| 41a38bb5-a474-4a78-b28d-0d730097b4cb | MEDIUM | 4.3 | The Woo File Dropzone plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path valida… | — | wordfence | |
| 41960c28-80f9-4c50-8b4b-b1175695a6f4 | < 1.1.2 |
MEDIUM | 4.3 | The Advanced All in One Admin Search by WP Spotlight plugin for WordPress is vulnerable to Cross-Site Request Forgery in… | — | wordfence |
| 418b9138-9ae0-41f1-a75b-69cbcaffbb88 | < 7.33 |
MEDIUM | 4.3 | The WP Custom Admin Interface plugin for WordPress is vulnerable to unauthorized modification of data due to a missing c… | — | wordfence |
| 4181dcad-b5bd-46db-b47c-3cdee427123c | < 3.11.13 |
MEDIUM | 4.3 | The Avada (Fusion) Builder plugin for WordPress is vulnerable to Information Exposure in all versions up to, and includi… | — | wordfence |
| 417ae2f2-e245-49bb-8b77-0eabf6095459 | < 3.0.9 |
MEDIUM | 4.3 | The MasterStudy LMS plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability … | — | wordfence |
| 416da5d4-3d47-443b-a82c-c059c38f5218 | < 1.5.7.1 |
MEDIUM | 4.3 | The Duplicator plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.5.7.… | — | wordfence |
| 4169ad47-7b66-433e-8184-cef0d0fec476 | < 4.1.20 |
MEDIUM | 4.3 | The Eventin β Event Calendar, Tickets, Registration, Booking & WooCommerce plugin for WordPress is vulnerable to Sensi… | — | wordfence |
| 415d69d9-2afd-41f8-8339-ea32fac3aa48 | < 9.3.9 |
MEDIUM | 4.3 | The XStore theme for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in v… | — | wordfence |
| 4154aa02-7fa1-4858-bea7-092ec4a508ac | < 2.1.4 |
MEDIUM | 4.3 | The Social Media Feather plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on … | — | wordfence |
| 4147e973-5a17-41d8-b8d9-5e43a23c9bc9 | < 11.0 |
MEDIUM | 4.3 | The Sort SearchResult By Title plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and i… | — | wordfence |
| 414165a3-78f8-4254-ac24-2de177cad3dd | < 1.11.0 |
MEDIUM | 4.3 | The CLUEVO LMS, E-Learning Platform plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, … | — | wordfence |
EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.
Scan My Website →