Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.
40,434 vulnerabilities found (page 1538 of 1618)
| CVE ID | Plugin / Theme | Severity | CVSS | Description | Fixed In | Source |
|---|---|---|---|---|---|---|
| 302b872f-b25c-4964-993f-93596d12842d | < 8.5.6 |
MEDIUM | 4.3 | The WP VR plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on t… | — | wordfence |
| 302b004c-0443-4f47-8493-8bc7c5a25788 | < 2.2.0.6 |
MEDIUM | 4.3 | The WP Popups plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function … | — | wordfence |
| 300da4da-a3d4-4a64-80c2-4bb37ea64f5e | < 1.2.149 |
MEDIUM | 4.3 | The WooCommerce PDF Invoice Builder plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, … | — | wordfence |
| 3000b140-2e38-463d-9128-b486293e3cf6 | < 3.1.19 |
MEDIUM | 4.3 | The Icegram plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 3.1.18. T… | — | wordfence |
| 2fefcc8c-3864-4764-86e7-678d8604fd67 | < 1.0.16 |
MEDIUM | 4.3 | The Ricerca smart and advanced search plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to… | — | wordfence |
| 2fdd3061-b490-4be2-bc7e-82ca124ee8a3 | < 2.3.7 |
MEDIUM | 4.3 | The Listamester plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.3.6… | — | wordfence |
| 2fdc57ee-7923-4eae-a69d-2a8a53b5f841 | < 1.5.8 |
MEDIUM | 4.3 | The WordPress Contact Forms by Cimatti plugin for WordPress is vulnerable to unauthorized access due to a missing capabi… | — | wordfence |
| 2f9853a2-c378-42bf-a12b-392823750942 | < 4.1.11 |
MEDIUM | 4.3 | The Popup Builder plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 4.1… | — | wordfence |
| 2f8dcbd2-af51-4cc9-9962-53fe644985e1 | < 2.0.11 |
MEDIUM | 4.3 | The Constant Contact Forms by MailMunch plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up … | — | wordfence |
| 2f881298-23f3-471c-b6f1-ebaf72d7180e | < 3.15.0 |
MEDIUM | 4.3 | The Avada (Fusion) Builder plugin for WordPress is vulnerable to unauthorized access due to a missing capability check o… | — | wordfence |
| 2f72e5bb-e076-4379-8699-e399761c043f | < 2.0.8.5 |
MEDIUM | 4.3 | The WP Simple Booking Calendar plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, a… | — | wordfence |
| 2f6d43ad-d1b9-4f66-ba08-d0ffc235f7c8 | MEDIUM | 4.3 | The Nokaut Offers Box plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and includ… | — | wordfence | |
| 2f67da8c-da60-4c77-a8b8-7dfc027662e9 | < 4.9.3 |
MEDIUM | 4.3 | The Schedule Post Changes With PublishPress Future: Unpublish, Delete, Change Status, Trash, Change Categories plugin fo… | — | wordfence |
| 2f557c6e-2fbd-478d-8dc3-cdc550e523b7 | < 1.9 |
MEDIUM | 4.3 | The Mega Addons For Elementor plugin for WordPress is vulnerable to unauthorized access due to a missing capability chec… | — | wordfence |
| 2f526f3c-4e9b-4440-b3c3-8541c1be0ba0 | < 3.4.25 |
MEDIUM | 4.3 | The BuddyPress WooCommerce My Account Integration. Create WooCommerce Member Pages plugin for WordPress is vulnerable to… | — | wordfence |
| 2f2fb51b-984c-4b82-98d4-9a681a1855a7 | MEDIUM | 4.3 | The DX-auto-save-images plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and includin… | — | wordfence | |
| 2f2c6349-9444-4cea-90ae-f396ae92f85a | MEDIUM | 4.3 | The Chatter plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in… | — | wordfence | |
| 2f1b0b50-663f-40ff-803e-a20d7c7ea980 | MEDIUM | 4.3 | The Mobile Address Bar Changer plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and i… | — | wordfence | |
| 2ef43041-9c24-4ca2-bc01-c4ff5ba12e63 | < 1.1.0 |
MEDIUM | 4.3 | The WP Post Hide plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, … | — | wordfence |
| 2ef15cb1-b320-42d9-a2fd-afff2ec8a93b | < 1.23.3 |
MEDIUM | 4.3 | The Forminator plugin for WordPress is vulnerable to missing authorization due to a missing capability check on the 'loa… | — | wordfence |
| 2eddfe94-7232-4d3d-9f3a-f53fc476a012 | < 5.12.8 |
MEDIUM | 4.3 | The Shortcodes Ultimate plugin for WordPress is vulnerable to unauthorized access of data due to missing authorization c… | — | wordfence |
| 2edd9774-753b-49a4-9f7b-281829a1030e | < 2.2 |
MEDIUM | 4.3 | The MainWP Child Reports plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and inc… | — | wordfence |
| 2ed28379-1fc0-4cf4-a507-7d0bdc9f7f4a | < 2.3.0 |
MEDIUM | 4.3 | The Visual Link Preview plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a… | — | wordfence |
| 2ed1f200-5a27-4905-ac88-394b214bb430 | < 3.5.10 |
MEDIUM | 4.3 | The WooCommerce plugin for WordPress is vulnerable to authorization bypass due to a missing capability check and nonce c… | — | wordfence |
| 2ec9de0f-5af7-4664-b8ef-72a51b1661d7 | < 2.6.12 |
MEDIUM | 4.3 | The Otter Blocks PRO β Gutenberg Blocks, Page Builder for Gutenberg Editor & FSE plugin for WordPress is vulnerable to… | — | wordfence |
EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.
Scan My Website →