Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.
40,549 vulnerabilities found (page 1570 of 1622)
| CVE ID | Plugin / Theme | Severity | CVSS | Description | Fixed In | Source |
|---|---|---|---|---|---|---|
| 118eedee-3816-49e3-b924-f4ed67eede3e | MEDIUM | 4.3 | The WordPress Testimonials Slider plugin for WordPress is vulnerable to unauthorized access due to a missing capability … | — | wordfence | |
| 118e1a8c-a638-4571-9ce9-cf2cba4b9b06 | < 118 |
MEDIUM | 4.3 | The Simple URLs plugin for WordPress is vulnerable to unauthorized utilization of AJAX functionality due to a missing ca… | — | wordfence |
| 1171a510-ae5c-4f8e-99a2-aa98cf54d82e | < 5.1.1 |
MEDIUM | 4.3 | The ElasticPress plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, … | — | wordfence |
| 1165c68d-3da4-45f3-b054-4904e54d18ac | MEDIUM | 4.3 | The Google XML Sitemap for Images plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, an… | — | wordfence | |
| 1161af9d-89f7-429f-a481-5a3008f3be8a | < 1.9.6 |
MEDIUM | 4.3 | The Offload, AI & Optimize with Cloudflare Images plugin for WordPress is vulnerable to unauthorized access due to a mis… | — | wordfence |
| 114e8ba9-b6b0-4b54-982c-8e9efaa616c7 | < 4.9.11 |
MEDIUM | 4.3 | The Spiffy Calendar plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the a… | — | wordfence |
| 113f0cb7-a5eb-42d5-ad42-871c0381b617 | MEDIUM | 4.3 | The Keap Landing Pages plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including… | — | wordfence | |
| 113b3093-18fe-40ae-85af-aae1945201db | MEDIUM | 4.3 | The RD Contacto plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1… | — | wordfence | |
| 113aa171-c5b2-4cb0-808d-cd56594bacb1 | < 2.7.13 |
MEDIUM | 4.3 | The Brizy β Page Builder plugin for WordPress is vulnerable to unauthorized access due to a missing capability check o… | — | wordfence |
| 1127fe1e-4359-4dff-93a7-392a8bfded51 | < 3.2.4 |
MEDIUM | 4.3 | The WP Courses LMS β Online Courses Builder, eLearning Courses, Courses Solution, Education Courses plugin for WordPre… | — | wordfence |
| 110e5e67-b318-4ab2-9b4d-59aabcf7db7c | < 2.12.7 |
MEDIUM | 4.3 | The Spectra β WordPress Gutenberg Blocks plugin for WordPress is vulnerable to Path Traversal in versions up to, and i… | — | wordfence |
| 10ffe689-143a-4232-8094-45844dc5262b | MEDIUM | 4.3 | The FreshMail For WordPress plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and incl… | — | wordfence | |
| 10f00859-3adf-40ff-8f33-827bbb1f62df | < 2.11.2 |
MEDIUM | 4.3 | The Paid Membership Subscriptions β Effortless Memberships, Recurring Payments & Content Restriction plugin for WordPr… | — | wordfence |
| 10dbed32-1766-4746-b820-3f17d774ba04 | MEDIUM | 4.3 | The Shk Corporate theme for WordPress is vulnerable to unauthorized access due to a missing capability check on a functi… | — | wordfence | |
| 10dbaf83-03c4-409d-b31a-198eab101dd1 | < 1.52.2 |
MEDIUM | 4.3 | The Broadstreet plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a functio… | — | wordfence |
| 10cc54a9-4b3d-4584-a90e-7828cd9cdc26 | < 1.0.97 |
MEDIUM | 4.3 | The Corpiva theme for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.0.96. Th… | — | wordfence |
| 10c17e74-dced-483e-bcaf-00ff5b11059c | < 10.6.1 |
MEDIUM | 4.3 | The WP Recipe Maker plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check … | — | wordfence |
| 10a811f3-0c5b-4e06-a9bb-338d36d0b5eb | < 3.7.15 |
MEDIUM | 4.3 | WordPress before 4.5.3 allows remote attackers to obtain sensitive revision-history information by leveraging the abilit… | — | wordfence |
| 1090acfc-5b0c-478a-ac71-db54fdaefdf5 | < 1.3.6 |
MEDIUM | 4.3 | The Boostify Header Footer Builder for Elementor plugin for WordPress is vulnerable to unauthorized modification of data… | — | wordfence |
| 108fc77a-b260-4bbf-a551-7593bbecc6e0 | MEDIUM | 4.3 | The ListingPro theme for WordPress is vulnerable to unauthorized access due to a missing capability check on a function … | — | wordfence | |
| 108cd0dd-f5c9-4ca8-989e-0ae5384ff6c1 | MEDIUM | 4.3 | The FPW Category Thumbnails plugin for WordPress is vulnerable to unauthorized access due to a missing capability check … | — | wordfence | |
| 1089ab17-b780-4840-8dcd-c50258513634 | < 2.2.1 |
MEDIUM | 4.3 | The Schema App Structured Data plugin for WordPress is vulnerable to unauthorized modification of data due to a missing … | — | wordfence |
| 107cb15f-4b2e-4ed4-8e8a-4f716f4873db | < 1.6.5 |
MEDIUM | 4.3 | The Rate Star Review Vote - AJAX Reviews, Votes, Star Ratings plugin for WordPress is vulnerable to Missing Authorizatio… | — | wordfence |
| 10735038-69dd-4b74-9374-38379832cdcb | < 3.1.10 |
MEDIUM | 4.3 | The Gallery by FooGallery plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability … | — | wordfence |
| 10724b12-fbe4-4da1-b3f5-157b2702996d | MEDIUM | 4.3 | The Media Author plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a functi… | — | wordfence |
EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.
Scan My Website →