Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.
40,434 vulnerabilities found (page 1535 of 1618)
| CVE ID | Plugin / Theme | Severity | CVSS | Description | Fixed In | Source |
|---|---|---|---|---|---|---|
| 3386ea07-9c61-4b54-a451-1178ca6325cb | < 5.4.5 |
MEDIUM | 4.3 | The Meow Gallery plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability che… | — | wordfence |
| 3386e24f-5861-4115-96ea-a47cd65a560f | < 1.2.5 |
MEDIUM | 4.3 | The Element Invader β Template Kits for Elementor plugin for WordPress is vulnerable to unauthorized access due to a m… | — | wordfence |
| 338158b5-bbda-4cd8-b4ea-97a3926a0989 | < 4.3.5 |
MEDIUM | 4.3 | The Ninja Tables plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 4.3.… | — | wordfence |
| 33800fbb-7660-4704-a978-d5b64ff9f66e | < 2.7.4 |
MEDIUM | 4.3 | The Wallet System for WooCommerce β Digital Wallet, Buy Now Pay Later (BNPL), Instant Cashback, Referral program, Part… | — | wordfence |
| 337bb11f-dcab-4914-aeb4-68084504b8f9 | < 1.8.13 |
MEDIUM | 4.3 | The VikBooking Hotel Booking Engine & PMS plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions u… | — | wordfence |
| 33735219-3e12-4a8b-87af-99d7a836e9fa | MEDIUM | 4.3 | The Widgets Reset plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including,… | — | wordfence | |
| 3371df49-aecc-4442-9b8c-58e3c7e26752 | MEDIUM | 4.3 | The WebinarPress plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a functi… | — | wordfence | |
| 3354b925-2e4a-4ee5-b436-2c1a502b1725 | < 3.39 |
MEDIUM | 4.3 | The NextGEN Gallery plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 3… | — | wordfence |
| 335402dd-5c18-4927-aa59-9683003064ca | < 3.1.12 |
MEDIUM | 4.3 | The Page Builder Gutenberg Blocks β CoBlocks plugin for WordPress is vulnerable to Server-Side Request Forgery in all … | — | wordfence |
| 33275cdc-21d4-42b7-bd0e-f5154faf2d6c | < 1.2.3 |
MEDIUM | 4.3 | The Comments Like Dislike plugin for WordPress is vulnerable to IP Address Spoofing in all versions up to, and including… | — | wordfence |
| 331a893c-498d-4ae8-8a04-e7aa25640e80 | MEDIUM | 4.3 | The Theme Duplicator plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and includi… | — | wordfence | |
| 330e40d9-56b2-446a-8aa9-22a59e17c122 | < 1.4.6 |
MEDIUM | 4.3 | The Legal Pages β Privacy Policy, Terms & Conditions, GDPR, CCPA, and Cookie Notice Generator plugin for WordPress is … | — | wordfence |
| 330e236b-410e-43c3-8a9f-216e3f177789 | MEDIUM | 4.3 | The Contact Form, Drag and Drop Form Builder Plugin β Live Forms plugin for WordPress is vulnerable to unauthorized ac… | — | wordfence | |
| 3301899e-5c38-4ecd-b095-6e00b0f7582e | < 3.75 |
MEDIUM | 4.3 | The MyCurator Content Curation plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and i… | — | wordfence |
| 32fe8a09-b08f-42dc-b436-96a6ea50a439 | < 1.12.04 |
MEDIUM | 4.3 | The xili-tidy-tags plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.… | — | wordfence |
| 32ee3eb8-18b7-47da-b4f9-cb252ffabc71 | MEDIUM | 4.3 | The Quiz Expert β Easy Quiz Maker, Exam and Test Manager plugin for WordPress is vulnerable to Cross-Site Request Forg… | — | wordfence | |
| 32ec6291-cd65-4244-8990-c536e812673e | < 9.2.09.002 |
MEDIUM | 4.3 | The Photo Album Plus plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a fu… | — | wordfence |
| 32c7a2fb-8390-4ae0-9a12-113250b1969e | < 3.1.0 |
MEDIUM | 4.3 | The Gutenverse News β Advanced News Magazine Blog Gutenberg Blocks Addons plugin for WordPress is vulnerable to unauth… | — | wordfence |
| 32c2a25d-e660-4700-8df3-b043cf6aa78a | < 1.0.14 |
MEDIUM | 4.3 | The WordPress Live Chat Plugin for Elementor β LiveChat plugin for WordPress is vulnerable to Cross-Site Request Forge… | — | wordfence |
| 32ad6b52-1d59-4458-9661-3f1f126163ca | < 6.5.0 |
MEDIUM | 4.3 | The PDF for Elementor Forms + Drag And Drop Template Builder plugin for WordPress is vulnerable to unauthorized access d… | — | wordfence |
| 32a1d281-cc98-4e63-80f5-4f89104f9377 | < 1.36.0 |
MEDIUM | 4.3 | The Hubbub Lite β Fast, Reliable Social Sharing Buttons plugin for WordPress is vulnerable to Sensitive Information Ex… | — | wordfence |
| 329a7910-fc9e-4786-9f0e-84eeb6e48bf4 | < 3.4.2 |
MEDIUM | 4.3 | The Logo Carousel WordPress plugin before 3.4.2 allows users with a role as low as Contributor to duplicate and view arb… | — | wordfence |
| 328fc7a9-be41-4e30-bb8d-c12ac3fd63f5 | < 2.14.2 |
MEDIUM | 4.3 | The Zoho Flow plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.14.1.… | — | wordfence |
| 328d65f4-422c-4c96-ad5d-b02b596aa998 | < 2.3.0 |
MEDIUM | 4.3 | The Dynamic Pricing and Discount Rules plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions … | — | wordfence |
| 328ccf8f-797b-4b1a-b0f1-afd8e44f41e6 | < 1.53.2 |
MEDIUM | 4.3 | The Broadstreet plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and includ… | — | wordfence |
EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.
Scan My Website →