Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.
40,549 vulnerabilities found (page 1569 of 1622)
| CVE ID | Plugin / Theme | Severity | CVSS | Description | Fixed In | Source |
|---|---|---|---|---|---|---|
| 12a94f5b-bc30-4a65-b397-54488c836ec3 | < 1.57.0.10 |
MEDIUM | 4.3 | The VK Blocks plugin for WordPress is vulnerable to improper authorization via the REST 'update_vk_blocks_options' funct… | — | wordfence |
| 12a195a0-f992-462d-9b4e-69e8a2975635 | < 5.0 |
MEDIUM | 4.3 | The Appointment & Event Booking Calendar Plugin β Webba Booking plugin for WordPress is vulnerable to Cross-Site Reque… | — | wordfence |
| 12959cc5-d088-4e2c-8658-e54900839aa6 | < 1.91.3 |
MEDIUM | 4.3 | The FluentBoards β Project Management, Task Management, Goal Tracking, Kanban Board, and, Team Collaboration plugin fo… | — | wordfence |
| 12913ac3-82a7-42e9-ba44-8e6577e0fbc7 | MEDIUM | 4.3 | The DB Backup plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function … | — | wordfence | |
| 128bc7ee-9763-415f-b726-0e63d4b62271 | < 4.1.4 |
MEDIUM | 4.3 | The WP Table Manager plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on thew… | — | wordfence |
| 127b20c4-cd7c-4d04-b32f-bcc26beb2c35 | < 4.1.5 |
MEDIUM | 4.3 | The Snippet Shortcodes plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and inclu… | — | wordfence |
| 127691c4-dc63-44e0-b591-b342a3809888 | < 3.2.43 |
MEDIUM | 4.3 | The Cost Calculator Builder plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and … | — | wordfence |
| 12735e6b-9ed5-4bf6-ab72-36a5218fa43c | MEDIUM | 4.3 | The Bknewsticker plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, … | — | wordfence | |
| 126e2b92-322e-440c-a924-1b604330f164 | < 4.5.6 |
MEDIUM | 4.3 | The Return Refund and Exchange For WooCommerce plugin for WordPress is vulnerable to Insecure Direct Object Reference in… | — | wordfence |
| 126c77fa-11c5-431f-8fc9-0375ed6c8a91 | < 4.23.13 |
MEDIUM | 4.3 | The RSS Aggregator β RSS Import, News Feeds, Feed to Post, and Autoblogging plugin for WordPress is vulnerable to unau… | — | wordfence |
| 1268604c-08eb-4d86-8e97-9cdaa3e19c1f | < 5.4.9 |
MEDIUM | 4.3 | The WP EasyCart plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 5.4.8… | — | wordfence |
| 125eb557-0566-48e2-a966-f9255e877e0f | < 8.2.5 |
MEDIUM | 4.3 | The WP Customer Area plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and includi… | — | wordfence |
| 123c0279-a7f6-4a4b-a5e1-79702e295303 | < 2.5 |
MEDIUM | 4.3 | The User Registration Using Contact Form 7 plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versi… | — | wordfence |
| 1237f0b3-540a-4734-8966-4798799fef65 | < 2.7.0 |
MEDIUM | 4.3 | The Slugs Manager plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.6… | — | wordfence |
| 121cad41-d3cd-4042-b568-3d91909a38d3 | < 3.7.4 |
MEDIUM | 4.3 | The Import any XML or CSV File to WordPress plugin for WordPress is vulnerable to Cross-Site Request Forgery in all vers… | — | wordfence |
| 1218ed3b-badc-464e-adbc-76fb4f6af008 | < 3.2.6 |
MEDIUM | 4.3 | The Google Calendar Events plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and inclu… | — | wordfence |
| 1213a21f-a9c1-4da3-99b5-4a5a0673073f | < 6.3.0 |
MEDIUM | 4.3 | The WP Plugin Info Card plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and incl… | — | wordfence |
| 120a75c5-4fff-4a77-b376-d6968853b40e | MEDIUM | 4.3 | The WP Social Bookmark Menu plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and … | — | wordfence | |
| 11fc48b0-cee2-4392-866b-5c0f366e5d98 | MEDIUM | 4.3 | The Language plugin for WordPress is vulnerable to unauthorized access due to a missing capability check in versions up … | — | wordfence | |
| 11f74b86-a050-4247-b310-045bf48fd4bd | < 1.7.2 |
MEDIUM | 4.3 | The RapidLoad Power-Up for Autoptimize plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up t… | — | wordfence |
| 11ea3e40-8802-43ea-9816-973a15d7904d | < 2.2.2 |
MEDIUM | 4.3 | The WP OnlineSupport, Essential Plugin Popup Anything plugin for WordPress is vulnerable to Cross-Site Request Forgery i… | — | wordfence |
| 11e31621-295a-4d34-8f11-65408bc75260 | < 3.1.83 |
MEDIUM | 4.3 | The Newsletter, SMTP, Email marketing and Subscribe forms by Sendinblue plugin for WordPress is vulnerable to Cross-Site… | — | wordfence |
| 11cc8c6e-b60e-46b3-966e-07b1fb2bf8e9 | < 1.2.7 |
MEDIUM | 4.3 | The WP Affiliate Disclosure plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and … | — | wordfence |
| 11c4b855-8589-4ad2-b414-566ac8eb4632 | < 5.2.0 |
MEDIUM | 4.3 | The Quick Page/Post Redirect Plugin for WordPress is vulnerable to authorization bypass due to missing capability checks… | — | wordfence |
| 11bdcf58-be0c-4fdb-ac15-ee4c3afe7275 | < 1.7.6 |
MEDIUM | 4.3 | The Loginizer plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.7.5. … | — | wordfence |
EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.
Scan My Website →