Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.
40,434 vulnerabilities found (page 1528 of 1618)
| CVE ID | Plugin / Theme | Severity | CVSS | Description | Fixed In | Source |
|---|---|---|---|---|---|---|
| 3aade1bd-b69d-4134-a4f7-78372a291557 | < 2.8.0 |
MEDIUM | 4.3 | The Download Manager and Payment Form WordPress Plugin β WP SmartPay plugin for WordPress is vulnerable to Insecure Di… | — | wordfence |
| 3aa6f3c2-0e45-4243-a26d-ba1c702fbe11 | < 2.16.3.4 |
MEDIUM | 4.3 | The Knowledge Base documentation & wiki plugin β BasePress Docs plugin for WordPress is vulnerable to unauthorized mod… | — | wordfence |
| 3a9feacb-ef9c-40d4-abdb-a3fcfd529901 | < 8.0.5 |
MEDIUM | 4.3 | The stops-core-theme-and-plugin-updates plugin before 8.0.5 for WordPress has insufficient restrictions on option change… | — | wordfence |
| 3a923f58-f6c7-47ee-87f6-27453b39d1cf | MEDIUM | 4.3 | The Mediabay plugin for WordPress is vulnerable to unauthorized use of functionality due to missing capability checks on… | — | wordfence | |
| 3a89d81b-7d4b-4afc-8131-0acdc5298544 | < 1.2.31 |
MEDIUM | 4.3 | The WP Time Slots Booking Form plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, a… | — | wordfence |
| 3a845632-fcd3-4663-959d-d786667d0499 | < 1.9.15 |
MEDIUM | 4.3 | The GPT3 AI Content Writer plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and inclu… | — | wordfence |
| 3a7f6fa5-ea69-4c58-994c-f9d3f3357a33 | < 1.8.22 |
MEDIUM | 4.3 | The Bulk Edit Products for WooCommerce β WP Sheet Editor plugin for WordPress is vulnerable to unauthorized access due… | — | wordfence |
| 3a75a005-cf56-4841-a11b-318011d80fe6 | < 3.4.5 |
MEDIUM | 4.3 | The WPKoi Templates for Elementor plugin for WordPress is vulnerable to unauthorized access due to a missing capability … | — | wordfence |
| 3a7440e2-637a-4f24-8452-e269e559aa17 | MEDIUM | 4.3 | The Hyyan WooCommerce Polylang Integration plugin for WordPress is vulnerable to unauthorized access due to a missing ca… | — | wordfence | |
| 3a5a421a-3c76-4ea0-aa8a-878bbb7671d7 | < 2.3.1 |
MEDIUM | 4.3 | The WP Hotel Booking plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a fu… | — | wordfence |
| 3a49f5f8-eec3-4b43-a007-329a7c1c6840 | < 2.7.6 |
MEDIUM | 4.3 | The Wallet System for WooCommerce β Digital Wallet, Buy Now Pay Later (BNPL), Instant Cashback, Referral program, Part… | — | wordfence |
| 3a38c10f-b150-417a-8a00-df33edd9a08a | MEDIUM | 4.3 | The Swiss Toolkit For WP plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on … | — | wordfence | |
| 3a34e4ad-cdd6-4663-881a-d6e29cd86043 | < 1.9.10 |
MEDIUM | 4.3 | The Envo Extra plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check… | — | wordfence |
| 3a0d9356-8083-4154-aa04-9008627dd3f5 | < 2.6.2 |
MEDIUM | 4.3 | The Sky Addons for Elementor plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to,… | — | wordfence |
| 3a0b8c4d-44b4-4e94-a983-4feb73883386 | < 4.7.0 |
MEDIUM | 4.3 | The Slim SEO β A Fast & Automated SEO Plugin For WordPress plugin for WordPress is vulnerable to unauthorized access d… | — | wordfence |
| 3a0a7a6d-7acd-4a70-b78d-da2ac697e374 | MEDIUM | 4.3 | The Simple COD Fees for WooCommerce plugin for WordPress is vulnerable to unauthorized access due to a missing capabilit… | — | wordfence | |
| 3a036855-35e0-4efd-aa27-16189b3538e9 | < 6.7.56 |
MEDIUM | 4.3 | The Slider Revolution plugin for WordPress in versions 6.0.0-6.7.55 and 7.0.0-7.0.14 is vulnerable to unauthorized modif… | — | wordfence |
| 39e9f38c-f06e-4b6a-9f09-a23c52b50026 | MEDIUM | 4.3 | The Smart Product Viewer plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on … | — | wordfence | |
| 39e35136-a096-40d5-8d6e-2667e7b83aaa | MEDIUM | 4.3 | The Easy Appointments plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a f… | — | wordfence | |
| 39da62be-e630-48cd-b732-80ed3d337638 | < 3.4.2 |
MEDIUM | 4.3 | The EventPrime β Events Calendar, Bookings and Tickets plugin for WordPress is vulnerable to unauthorized access of da… | — | wordfence |
| 39ca4256-09c5-4f80-a04c-9429c8fe6b8b | MEDIUM | 4.3 | The Slack Notifications by dorzki plugin for WordPress is vulnerable to unauthorized access due to a missing capability … | — | wordfence | |
| 39c9f055-2527-4678-bda1-27a29ab24acd | < 2.3.0 |
MEDIUM | 4.3 | The Products Quick View for WooCommerce plugin for WordPress is vulnerable to unauthorized access of data due to a missi… | — | wordfence |
| 39c53cd7-3ea3-4971-be51-9544ca9d488f | < 1.3.5 |
MEDIUM | 4.3 | The Integrate Google Drive plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and inclu… | — | wordfence |
| 39bb69e0-fb18-4737-9eb7-bda2b5bc16a2 | < 4.24.8 |
MEDIUM | 4.3 | The WordPress File Upload plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including… | — | wordfence |
| 39aed7e9-05c6-4251-b489-de7a33ed2c2e | < 4.6.5 |
MEDIUM | 4.3 | The YouTube Playlist Player plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and incl… | — | wordfence |
EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.
Scan My Website →