Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.
40,434 vulnerabilities found (page 1523 of 1618)
| CVE ID | Plugin / Theme | Severity | CVSS | Description | Fixed In | Source |
|---|---|---|---|---|---|---|
| 402582a9-9bb9-499f-b149-e60a733ff866 | < 1.0.0 |
MEDIUM | 4.3 | The Newspack Content Converter plugin for WordPress is vulnerable to unauthorized modification of data due to an insuffi… | — | wordfence |
| 40244a11-e72b-4afe-8613-4c7874635765 | MEDIUM | 4.3 | The Sober theme for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in ve… | — | wordfence | |
| 401a08d8-500e-4d23-a02d-2eec09fc29d8 | MEDIUM | 4.3 | The Image Sizes Controller, Create Custom Image Sizes, Disable Image Sizes plugin for WordPress is vulnerable to unautho… | — | wordfence | |
| 3ff59aa5-a2f2-4fe1-a0b6-d9b07b0fdb1a | < 1.4.3 |
MEDIUM | 4.3 | The WP Testimonials plugin for WordPress is vulnerable to Cross-Site Request Forgery due to a missing nonce check in the… | — | wordfence |
| 3fd42c34-f6bb-46b9-9816-5bdfe673bae7 | < 2.4.26 |
MEDIUM | 4.3 | The Booqable Rental Plugin plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and i… | — | wordfence |
| 3fcb35f8-ed88-4440-8cdf-95c1f0028253 | < 4.7.5 |
MEDIUM | 4.3 | The WP ULike β The Ultimate Engagement Toolkit for Websites plugin for WordPress is vulnerable to Cross-Site Request F… | — | wordfence |
| 3fc94760-d64b-48e1-b2bd-40cedcf48340 | < 4.21.3 |
MEDIUM | 4.3 | The Leaky Paywall plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 4.2… | — | wordfence |
| 3fbdb0df-fc76-496f-aed5-38d4221c730c | MEDIUM | 4.3 | The Thim Core plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function … | — | wordfence | |
| 3fb35366-b09c-4667-8fb9-6f80ba6d09f0 | MEDIUM | 4.3 | The WPPerformanceTester plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and includin… | — | wordfence | |
| 3fa9e1cf-a7d5-4373-81ca-87e9275fe413 | MEDIUM | 4.3 | The SendGrid for WordPress plugin for WordPress is vulnerable to unauthorized access due to a missing capability check o… | — | wordfence | |
| 3fa88976-774a-4a85-869b-81d29442525f | < 2.0.5 |
MEDIUM | 4.3 | The Barcode Generator for WooCommerce β Show barcodes on products, orders, invoices and other pages plugin for WordPre… | — | wordfence |
| 3fa62b8f-1c2f-4bc9-9f2a-8b9765c2d30d | < 2.4 |
MEDIUM | 4.3 | The Login/Signup Popup plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including… | — | wordfence |
| 3f9acfe0-7a99-47ed-aceb-4cea6ce4f55e | MEDIUM | 4.3 | The W3SCloud Contact Form 7 to Zoho CRM plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up … | — | wordfence | |
| 3f904fd6-c937-4676-8e6e-6e94d3c42b0d | < 1.7.19 |
MEDIUM | 4.3 | The Multi Step Form plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and includin… | — | wordfence |
| 3f8f3f75-4c31-47df-826c-8fb26239add6 | < 2.1.1 |
MEDIUM | 4.3 | The Reoon Email Verifier plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on … | — | wordfence |
| 3f8c5c34-e7ea-4034-85d9-104f0e0815cf | < 1.5.1 |
MEDIUM | 4.3 | The I Order Terms plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including,… | — | wordfence |
| 3f873f1a-19e6-4490-9067-59ee67538ee1 | < 1.3.4 |
MEDIUM | 4.3 | The Url Rewrite Analyzer plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on … | — | wordfence |
| 3f81003b-8214-4fa3-960f-81b166623de9 | < 1.8.1 |
MEDIUM | 4.3 | The WordPress Pinterest Plugin β Make a Popup, User Profile, Masonry and Gallery Layout plugin for WordPress is vulner… | — | wordfence |
| 3f7e300f-06b5-4f59-9deb-9771bf86a204 | MEDIUM | 4.3 | The RRAddons for Elementor plugin for WordPress is vulnerable to Information Exposure in all versions up to, and includi… | — | wordfence | |
| 3f57fbbc-ed5a-4452-bd8a-6fc0a4536d76 | < 2.8.9 |
MEDIUM | 4.3 | The JS Help Desk β The Ultimate Help Desk & Support Plugin plugin for WordPress is vulnerable to Insecure Direct Objec… | — | wordfence |
| 3f37c650-af0d-4474-9c1b-7f8d361b4d81 | MEDIUM | 4.3 | The Speedup Optimization plugin for WordPress is vulnerable to Missing Authorization in all versions up to and including… | — | wordfence | |
| 3f18f658-abce-4e15-ae2f-4879716534af | < 1.1.3 |
MEDIUM | 4.3 | The Travel Monster theme for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.1… | — | wordfence |
| 3eff4992-dbd4-4b9b-872e-1670ce7dab9d | < 2.6.3 |
MEDIUM | 4.3 | The ApplyOnline β Application Form Builder and Manager plugin for WordPress is vulnerable to unauthorized access of da… | — | wordfence |
| 3efe1af6-16c8-4773-a11a-c09d6fc210f9 | MEDIUM | 4.3 | The Movies Bulk Importer plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and includi… | — | wordfence | |
| 3efd3105-675b-4e6b-bcd7-ca8d0e602cf9 | < 4.3.3 |
MEDIUM | 4.3 | The Estatik plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 4.3.2. Th… | — | wordfence |
EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.
Scan My Website →