Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.
40,434 vulnerabilities found (page 1552 of 1618)
| CVE ID | Plugin / Theme | Severity | CVSS | Description | Fixed In | Source |
|---|---|---|---|---|---|---|
| 2089b54c-9a34-4701-84bf-56b64e51982b | < 1.6.2 |
MEDIUM | 4.3 | The ValidateCertify Free plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and inc… | — | wordfence |
| 2077bd81-52bd-4aa7-85f6-9abb02aec65b | < 4.0.1 |
MEDIUM | 4.3 | The JCH Optimize plugin for WordPress is vulnerable to unauthorized modification of data due to missing capability check… | — | wordfence |
| 206c386c-15c2-4701-a011-e54d0cb3596c | MEDIUM | 4.3 | The Grand Portfolio theme for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 3.… | — | wordfence | |
| 2061a442-eccd-4a57-a5c5-a432fcea8394 | < 2022.9.29 |
MEDIUM | 4.3 | The Administrator Z plugin for WordPress uses Advanced Custom Fields which has a file upload vulnerability in versions u… | — | wordfence |
| 205a6972-b49f-4b6d-b0de-7a047d5ee496 | < 2.2.5 |
MEDIUM | 4.3 | The WP Upload Restriction plugin for WordPress is vulnerable to authorization bypass due to a missing capability check o… | — | wordfence |
| 204107bc-721c-46a9-a8c3-102240f66fc2 | < 2026.05.10 |
MEDIUM | 4.3 | The Administrator Z plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and excludin… | — | wordfence |
| 20151f80-c25f-482e-a2b0-34607dba9d1e | < 6.0.1 |
MEDIUM | 4.3 | The Floating Button plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 6… | — | wordfence |
| 200fbfc1-df21-43b0-8eb1-b2ba0cc0c0df | < 1.2.92 |
MEDIUM | 4.3 | The WooCommerce PDF Invoice Builder for WordPress is vulnerable to unauthorized access of data due to a missing capabili… | — | wordfence |
| 200b3446-6107-434b-b46d-2078461f3f94 | < 1.3.0 |
MEDIUM | 4.3 | The ImagePress – Image Gallery plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to,… | — | wordfence |
| 2009a0d7-ce42-46b5-986d-33e3d06a513d | < 1.127.0 |
MEDIUM | 4.3 | The AFI – The Easiest Integration Plugin plugin for WordPress is vulnerable to unauthorized access due to a missing ca… | — | wordfence |
| 2008df3e-29d2-4d64-b850-c83c2a6a9996 | < 2.2.5 |
MEDIUM | 4.3 | The Mark Posts plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function… | — | wordfence |
| 1ff5889e-b9fd-494f-b25d-78e85e94d34c | < 1.1.25.2 |
MEDIUM | 4.3 | The FuseWP plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.1.24… | — | wordfence |
| 1fe73b99-f113-4514-ae13-e22f897608b2 | < 3.2.4 |
MEDIUM | 4.3 | The New User Approve plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, … | — | wordfence |
| 1fe3e2bf-9fbd-4534-8389-8383cb2370a8 | < 1.2.3 |
MEDIUM | 4.3 | The Integration for Mailchimp and Contact Form 7, WPForms, Elementor, Ninja Forms plugin for WordPress is vulnerable to … | — | wordfence |
| 1fe2ea48-6764-4b1c-a811-423fac23f98a | < 2.9.6 |
MEDIUM | 4.3 | The Points and Rewards for WooCommerce – Create Loyalty Programs, Reward Customer Purchases, User Badges, Gamification… | — | wordfence |
| 1fd84e08-abc2-4655-999c-6dcdaa7f372c | MEDIUM | 4.3 | The Casengo Live Chat Support plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and in… | — | wordfence | |
| 1fcbe3d1-449c-4135-bbf5-9ea9236e5328 | < 2.8.7 |
MEDIUM | 4.3 | The Feed Them Social – Page, Post, Video, and Photo Galleries plugin for WordPress is vulnerable to Cross-Site Request… | — | wordfence |
| 1fc58078-7520-4ee7-b5a1-d6a362ac1860 | < 2.1.5 |
MEDIUM | 4.3 | The DeepL Pro API translation plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and in… | — | wordfence |
| 1fc0f287-8f39-4580-b58e-c308a603ba32 | < 1.2.6 |
MEDIUM | 4.3 | The WP Gravity Forms HubSpot plugin for WordPress is vulnerable to Open Redirect in all versions up to, and including, 1… | — | wordfence |
| 1fa45fa7-b1da-42f0-945b-2a6b0db5ba91 | MEDIUM | 4.3 | The Enable/Disable Auto Login when Register plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions… | — | wordfence | |
| 1f9d4d86-9d5f-4888-9cc4-d55c117ae4ea | < 2.4.0 |
MEDIUM | 4.3 | The Different Menu in Different Pages – Control Menu Visibility (All in One) plugin for WordPress is vulnerable to una… | — | wordfence |
| 1f96a0f3-8ebf-40b7-8498-157373e95b22 | < 7.1.0.38 |
MEDIUM | 4.3 | The Xagio SEO plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function … | — | wordfence |
| 1f7aa23c-ffa7-481b-8481-a36c7ed599d8 | < 5.2.6 |
MEDIUM | 4.3 | The LatePoint – Calendar Booking Plugin for Appointments and Events plugin for WordPress is vulnerable to Cross-Site R… | — | wordfence |
| 1f66cdcf-cbe5-43e0-ad18-c2b9c4491ed4 | < 2.4.2 |
MEDIUM | 4.3 | The Music Player for Elementor – Audio Player & Podcast Player plugin for WordPress is vulnerable to unauthorized modi… | — | wordfence |
| 1f533cf9-bec8-48a8-87e3-99117a9948f1 | MEDIUM | 4.3 | The افزونه حمل و نقل ووکامرس | پست پیشتاز، تیپاکس و پیک موتوری plugin for … | — | wordfence |
EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.
Scan My Website →