Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.
40,549 vulnerabilities found (page 1584 of 1622)
| CVE ID | Plugin / Theme | Severity | CVSS | Description | Fixed In | Source |
|---|---|---|---|---|---|---|
| 02a9a673-4e6b-4c06-b752-88b4ecf55d70 | < 3.12.5 |
MEDIUM | 4.3 | The Email Marketing Plugin – WP Email Capture plugin for WordPress is vulnerable to unauthorized access due to a missi… | — | wordfence |
| 02822b64-7cfb-4cd1-a727-10f61603ece4 | < 3.5.7.2 |
MEDIUM | 4.3 | The Sunshine Photo Cart: Free Client Photo Galleries for Photographers plugin for WordPress is vulnerable to unauthorize… | — | wordfence |
| 025d576b-7342-4863-ac30-f1ff0205d638 | < 3.1.2 |
MEDIUM | 4.3 | The TS Webfonts for ã•ãらã®ãƒ¬ãƒ³ã‚¿ãƒ«ã‚µãƒ¼ãƒ plugin for WordPress is vulnerable to Cross-Site Request Forgery i… | — | wordfence |
| 025a06c7-6573-4074-af4c-7b5836081943 | < 6.2.5 |
MEDIUM | 4.3 | The Fluent Forms plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions up to, and including… | — | wordfence |
| 0253e3fa-c0ee-4c76-bd92-a450771cae0c | < 2.3.3 |
MEDIUM | 4.3 | The Fraud Prevention For WooCommerce and EDD plugin for WordPress is vulnerable to Sensitive Information Exposure in all… | — | wordfence |
| 024fa9ff-d1ba-4c1f-aa51-1dbf5a5713d8 | < 5.6.4 |
MEDIUM | 4.3 | The ShortPixel Image Optimizer plugin for WordPress is vulnerable to unauthorized access due to a missing capability che… | — | wordfence |
| 024f4058-065b-48b4-a08a-d9732d4375cd | < 1.1.3 |
MEDIUM | 4.3 | The WP Fastest Cache plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, … | — | wordfence |
| 02490a4b-b2c0-4921-bbf2-678c44c96a5b | < 1.2.26 |
MEDIUM | 4.3 | The Fastly plugin for WordPress is vulnerable to unauthorized access to functionality due to a missing capability check … | — | wordfence |
| 02409698-5421-4760-afcd-e53939082bfc | < 3.0.2 |
MEDIUM | 4.3 | The Bubble Menu – circle floating menu plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up… | — | wordfence |
| 0219851f-7fce-42e0-ba82-77af84b17d9f | < 4.4.10.6 |
MEDIUM | 4.3 | The WpStream – Live Streaming, Video on Demand, Pay Per View plugin for WordPress is vulnerable to Cross-Site Request … | — | wordfence |
| 0210637e-360b-422f-be96-43e6ac48fe64 | MEDIUM | 4.3 | The Clever Mega Menu for Visual Composer plugin for WordPress is vulnerable to unauthorized access due to a missing capa… | — | wordfence | |
| 020df8cb-a9ce-4f04-b88f-ceb988beeb75 | < 0.9.5.9 |
MEDIUM | 4.3 | The WPCal.io – Easy Meeting Scheduler plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions… | — | wordfence |
| 0206aead-d146-453d-99ed-3870f7dfdae9 | < 0.7.9 |
MEDIUM | 4.3 | The Maspik plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 0.7.8. Th… | — | wordfence |
| 01ec3ba3-4627-4072-b15d-44e98c652836 | < 4.9.11 |
MEDIUM | 4.3 | The Slim SEO plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions up to, and including, 4.… | — | wordfence |
| 01eaa600-6ddf-492b-b2cf-ca560ce71db5 | MEDIUM | 4.3 | The SpicePress theme for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.3.2.5… | — | wordfence | |
| 01e1b22f-9622-433f-bada-23d118dc3800 | < 2.0.2 |
MEDIUM | 4.3 | The Simple Admin Language Change plugin for WordPress is vulnerable to authorization bypass due to a missing capability … | — | wordfence |
| 01d115b7-38a7-4dfd-ac81-4d7ce71969b2 | < 3.2 |
MEDIUM | 4.3 | The Interact: Embed A Quiz On Your Site plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up … | — | wordfence |
| 01cc3955-ef2f-4e2b-8dc6-b26f5a3d2f89 | < 1.3.14 |
MEDIUM | 4.3 | The Dynamics 365 Integration plugin for WordPress is vulnerable to unauthorized modification of data due to a missing ca… | — | wordfence |
| 01c8d909-ecfd-4443-9bef-e1b541e74c2b | < 1.1.0 |
MEDIUM | 4.3 | The Integration for Google Sheets and Contact Form 7, WPForms, Elementor, Ninja Forms plugin for WordPress is vulnerable… | — | wordfence |
| 01bacc7f-9b17-4889-88f2-fcf55f3e61d5 | MEDIUM | 4.3 | The Co-marquage service-public.fr plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, an… | — | wordfence | |
| 01b90498-0ddb-4eb3-b76d-de30ed03d7d0 | < 1.6.4 |
MEDIUM | 4.3 | The WP ERP | Complete HR solution with recruitment & job listings | WooCommerce CRM & Accounting plugin for WordPress is… | — | wordfence |
| 01abc69a-65c3-4acc-b190-efd8da2ec76f | MEDIUM | 4.3 | The Payment Forms for Paystack plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to, a… | — | wordfence | |
| 01a6a5bf-636b-416c-86fa-43f639624e80 | < 2.9 |
MEDIUM | 4.3 | The LWSCache plugin for WordPress is vulnerable to unauthorized modification of data due to improper authorization on th… | — | wordfence |
| 01a3b9ba-b18a-48d9-8365-d10f79fc6a6b | < 2.6.2 |
MEDIUM | 4.3 | The User Profile Picture plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, a… | — | wordfence |
| 01996a4c-0ad8-4da8-bfa7-3442c5a67679 | MEDIUM | 4.3 | The WidgetPack Comment System plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, an… | — | wordfence |
EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.
Scan My Website →