Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.
40,549 vulnerabilities found (page 1564 of 1622)
| CVE ID | Plugin / Theme | Severity | CVSS | Description | Fixed In | Source |
|---|---|---|---|---|---|---|
| 187b072d-6314-4ac1-a924-b14324b2fd8d | < 2.2.2 |
MEDIUM | 4.3 | The Responsive Blocks β Page Builder for Blocks & Patterns plugin for WordPress is vulnerable to unauthorized access i… | — | wordfence |
| 1878f096-942f-4bc1-ba5f-419ff7ca535c | < 4.5.9 |
MEDIUM | 4.3 | The Usercentrics Cookiebot β Automatic Cookie Banner for GDPR/CCPA & Google Consent Mode plugin for WordPress is vulne… | — | wordfence |
| 186e4147-4cb4-4337-9c3c-d47589b06b20 | < 1.3 |
MEDIUM | 4.3 | The Hide Dashboard Notifications plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to,… | — | wordfence |
| 186b9f06-e637-4f04-a3c3-13ec8496402c | MEDIUM | 4.3 | The Mediavine Control Panel plugin for WordPress is vulnerable to unauthorized access due to a missing capability check … | — | wordfence | |
| 18530601-a294-448c-a1b2-c3995f9042ac | < 2.0.12 |
MEDIUM | 4.3 | The Draw Attention plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability c… | — | wordfence |
| 184885b0-66cd-433d-bfea-d7e8bbb02731 | < 3.9.6 |
MEDIUM | 4.3 | The Simple Download Monitor WordPress plugin before 3.9.6 allows users with a role as low as Contributor to remove thumb… | — | wordfence |
| 18464483-1d2f-4a4e-a1cc-6c1ddcc2dcf5 | MEDIUM | 4.3 | The 5280 Bootstrap Modal Contact Form plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions u… | — | wordfence | |
| 1842ffa7-a9e9-4b35-bec2-e3f9e8622c1c | < 1.3.19 |
MEDIUM | 4.3 | The JetBlocks for Elementor plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, … | — | wordfence |
| 180f6542-5f48-4d3c-87f7-1bfcb2d8a0c5 | MEDIUM | 4.3 | The Gmaper for Elementor plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on … | — | wordfence | |
| 180ab1ce-3f5c-4768-9f94-23ed4bc59a4b | < 2.14.2 |
MEDIUM | 4.3 | The Zoho Flow plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.14.1.… | — | wordfence |
| 18086779-a7db-4550-b44f-c10a5bf974cf | MEDIUM | 4.3 | The Auction Feed plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.1.… | — | wordfence | |
| 17f7c974-492d-4775-b602-bbec36d3bd8f | MEDIUM | 4.3 | The Custom Post Type Images plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and incl… | — | wordfence | |
| 17f2b07d-82de-4e25-9b17-ef4a1132e6c0 | < 3.8.4 |
MEDIUM | 4.3 | The Podlove Podcast Publisher plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and in… | — | wordfence |
| 17e8a743-7985-4b28-b854-ac052a834f3a | < 1.1.23 |
MEDIUM | 4.3 | The Wishlist and Save for later for Woocommerce plugin for WordPress is vulnerable to Insecure Direct Object Reference i… | — | wordfence |
| 17c7c61d-c110-448e-ad8a-bc1c00393524 | < 1.1.3 |
MEDIUM | 4.3 | The WP Fastest Cache plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, … | — | wordfence |
| 17bc3a9f-2bf9-44e3-81ef-bfa932085da9 | < 2.8.8 |
MEDIUM | 4.3 | The System Dashboard plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check… | — | wordfence |
| 17b20df5-4adf-47ce-bddf-2ec0b9499de8 | < 4.9.3 |
MEDIUM | 4.3 | The EAN for WooCommerce plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, an… | — | wordfence |
| 17ab4800-0afd-4c39-970a-bd8dcc6a8b93 | < 6.4.8 |
MEDIUM | 4.3 | The Complianz plugin for WordPress is vulnerable to Cross-Site Request Forgery to Stored Cross-Site Scripting in version… | — | wordfence |
| 179751c8-a634-4a2e-be29-46be0aad79c8 | < 3.4.0 |
MEDIUM | 4.3 | Plugin Settings Update vulnerability in ShortPixel's ShortPixel Adaptive Images plugin <= 3.3.1 at WordPress allows an a… | — | wordfence |
| 17792afd-c40c-44cb-844e-86020adfc9eb | < 3.1.4 |
MEDIUM | 4.3 | The Vitepos β Point of sale (POS) plugin for WooCommerce plugin for WordPress is vulnerable to unauthorized access due… | — | wordfence |
| 1777d037-d72d-44a6-946a-a97e20bd2839 | < 3.7.42 |
MEDIUM | 4.3 | The MasterStudy LMS WordPress Plugin β for Online Courses and Education plugin for WordPress is vulnerable to Insecure… | — | wordfence |
| 17621978-cff5-4e63-bf6e-f1349da74730 | < 6.2.1 |
MEDIUM | 4.3 | The Fluent Forms plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions up to, and including… | — | wordfence |
| 175e08ce-aec2-427a-90e0-f955711d58b2 | < 3.9.13 |
MEDIUM | 4.3 | The EmbedPress β Embed PDF, Google Docs, Vimeo, Wistia, Embed YouTube Videos, Audios, Maps & Embed Any Documents in Gu… | — | wordfence |
| 175dd04d-ce06-45a0-8cfe-14498e2f9198 | < 3.1.14 |
MEDIUM | 4.3 | The ImageRecycle pdf & image compression plugin for WordPress is vulnerable to unauthorized modification of data due to … | — | wordfence |
| 175cb977-dcba-429f-814c-6de078e23472 | < 4.10.32 |
MEDIUM | 4.3 | The Premium Addons for Elementor plugin for WordPress is vulnerable to unauthorized access of data due to a missing capa… | — | wordfence |
EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.
Scan My Website →