Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.
40,549 vulnerabilities found (page 1568 of 1622)
| CVE ID | Plugin / Theme | Severity | CVSS | Description | Fixed In | Source |
|---|---|---|---|---|---|---|
| 13ba9474-b1ca-4ba4-ad94-88f7795a4c3c | MEDIUM | 4.3 | The CM On Demand Search And Replace plugin for WordPress is vulnerable to unauthorized access due to a missing capabilit… | — | wordfence | |
| 13b63844-0ff8-47d3-beef-990a835fdb1c | < 1.2.64 |
MEDIUM | 4.3 | The ApusListing theme for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.2.63… | — | wordfence |
| 13aa1288-257a-417e-aad8-86075c9b9abe | < 1.79.262 |
MEDIUM | 4.3 | The WP Fast Total Search β The Power of Indexed Search plugin for WordPress is vulnerable to unauthorized access due t… | — | wordfence |
| 13a0dd72-1124-4b5d-9bad-fe4fea8e3e68 | < 8.2.8 |
MEDIUM | 4.3 | The WP VR plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 8.2.7. This… | — | wordfence |
| 13981d82-5e27-4cde-8bb7-2ab6155741e3 | < 1.2.7 |
MEDIUM | 4.3 | The Printus β Automatic Printing Plugin for WooCommerce β Print WooCommerce Orders, PDF Invoices, Packaging Slips & … | — | wordfence |
| 138c636b-27fb-4d76-b01c-60a10749913d | MEDIUM | 4.3 | The Smart Maintenance Mode plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and i… | — | wordfence | |
| 137ca3b1-703f-4032-8574-02401f4d2e22 | < 5.1.18 |
MEDIUM | 4.3 | The Projectopia β WordPress Project Management plugin for WordPress is vulnerable to unauthorized access due to a miss… | — | wordfence |
| 13791cb9-280e-4a48-aa52-85127d6ac0a1 | MEDIUM | 4.3 | The Flatsome theme for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in… | — | wordfence | |
| 137623ec-1e40-4b66-a273-706b630580fe | < 1.5.5 |
MEDIUM | 4.3 | The Directory Kit plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and including,… | — | wordfence |
| 137327c8-01cb-4074-9424-89d826a9586e | < 10.0.5 |
MEDIUM | 4.3 | The WooCommerce plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and includin… | — | wordfence |
| 13648a6d-481d-4eb4-82c8-30476454793e | < 5.4.4 |
MEDIUM | 4.3 | The Classified Listing plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a … | — | wordfence |
| 1359945a-cf4e-4883-830b-53a3fcd40e56 | < 5.0.5 |
MEDIUM | 4.3 | The Dokan: AI Powered WooCommerce Multivendor Marketplace Solution β Build Your Own Amazon, eBay, Etsy plugin for Word… | — | wordfence |
| 1355bc94-7110-4d61-855e-78889e58dcad | MEDIUM | 4.3 | The WordPress Photo Gallery β Image Gallery plugin for WordPress is vulnerable to Cross-Site Request Forgery in versio… | — | wordfence | |
| 134a3615-a9fa-48b5-8cd1-4c3fb24a777a | < 5.7.9 |
MEDIUM | 4.3 | The ProfileGrid plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 5.7.… | — | wordfence |
| 134130a9-4750-4a63-88a0-60d4285acb77 | MEDIUM | 4.3 | The Country Blocker for AdSense plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, … | — | wordfence | |
| 130637ce-d70a-4831-8b88-a2a6e8a95c42 | < 1.0.263 |
MEDIUM | 4.3 | The Colibri Page Builder plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capabi… | — | wordfence |
| 13046019-f390-48ae-bf08-53293c41f178 | MEDIUM | 4.3 | The NOO Timetable plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.1… | — | wordfence | |
| 13033a3c-f020-4821-a7ad-bfcfca407df0 | < 2.0.4 |
MEDIUM | 4.3 | The Ultimate Member plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions prior to version … | — | wordfence |
| 12ecf3d5-1457-405a-8856-517c7d2f2db1 | < 3.0.18 |
MEDIUM | 4.3 | The eCommerce Product Catalog Plugin for WordPress plugin for WordPress is vulnerable to Cross-Site Request Forgery in v… | — | wordfence |
| 12e64de4-d50f-44df-b150-d23ec9f3a0d5 | < 2.6.5 |
MEDIUM | 4.3 | The Namaste! LMS plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, … | — | wordfence |
| 12c7661c-0700-4370-9272-d8a19b17006e | < 3.4 |
MEDIUM | 4.3 | The Catch Themes Demo Import plugin for WordPress is vulnerable to Missing Authorization in versions up to, and includin… | — | wordfence |
| 12c56bf6-ce9b-4c4b-ad7d-0fa54ad221f2 | < 1.2.4 |
MEDIUM | 4.3 | The SmartFix theme for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in… | — | wordfence |
| 12bcc338-9e16-410f-bf3b-3756bc9b7024 | MEDIUM | 4.3 | The Comment Info Detector plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and in… | — | wordfence | |
| 12b81441-d22c-4211-a8da-811182de622d | < 1.1.1 |
MEDIUM | 4.3 | The Laposta Signup Embed plugin for WordPress is vulnerable to Missing Authorization in versions up to, and including, 1… | — | wordfence |
| 12b808a9-93d8-4fd4-b194-044f3a5376b8 | < 5.1.4 |
MEDIUM | 4.3 | The Bold Page Builder plugin for WordPress is vulnerable to unauthorized use of functionality due to a missing capabilit… | — | wordfence |
EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.
Scan My Website →