Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.
40,549 vulnerabilities found (page 1586 of 1622)
| CVE ID | Plugin / Theme | Severity | CVSS | Description | Fixed In | Source |
|---|---|---|---|---|---|---|
| 003686a7-929b-4c17-bb4b-2a330506819c | < 4.1.19 |
MEDIUM | 4.3 | The Event SOlution plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and including… | — | wordfence |
| 00274313-9079-4877-b72e-310e312aa814 | < 1.3.0 |
MEDIUM | 4.3 | The Backup Migration plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, … | — | wordfence |
| 0007d830-2e68-4c2f-8fac-f4363bc2d73d | < 4.3.6 |
MEDIUM | 4.3 | The Gift Cards (Gift Vouchers and Packages) plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions… | — | wordfence |
| e3048c4c-77b1-4778-a5d0-b532df777d06 | MEDIUM | 4.2 | The Buddypress Force Password Change plugin for WordPress is vulnerable to authenticated account takeover due to the plu… | — | wordfence | |
| dcbfcaeb-2635-4b11-b426-ee04345d5f36 | < 1.8.8 |
MEDIUM | 4.2 | The Download Plugins and Themes in ZIP from Dashboard plugin for WordPress is vulnerable to Cross-Site Request Forgery i… | — | wordfence |
| c2081e4a-c6b7-4730-be59-bc728b90ecaa | < 1.67 |
MEDIUM | 4.2 | The WP Force SSL & HTTPS SSL Redirect plugin for WordPress is vulnerable to unauthorized modification of data due to a m… | — | wordfence |
| 8242e0f0-b9c5-46fe-b691-3275cd0f9a43 | < 5.1.19 |
MEDIUM | 4.2 | The Contact Form Plugin by Fluent Forms for Quiz, Survey, and Drag & Drop WP Form Builder plugin for WordPress is vulner… | — | wordfence |
| 63374c5c-0b0a-4091-9aee-2e6c1d17a1b2 | MEDIUM | 4.2 | The Lock User Account plugin for WordPress is vulnerable to user lock bypass in all versions up to, and including, 1.0.5… | — | wordfence | |
| f5b8d39c-d307-42c9-a972-29b5521a82a4 | < 6.9.12 |
MEDIUM | 4.1 | The Blog2Social plugin for WordPress is vulnerable to authorization bypass due to missing capability checks in versions… | — | wordfence |
| ee11d9e5-64d5-49b4-b5f5-b76605250028 | < 2.2.20 |
MEDIUM | 4.1 | The GeoDirectory plugin for WordPress is vulnerable to CSV Injection in versions up to, and including, 2.2.19. This allo… | — | wordfence |
| e9c9214d-45d4-4477-8244-7802a4901114 | < 7.0.6 |
MEDIUM | 4.1 | The Media Cleaner: Clean your WordPress! plugin for WordPress is vulnerable to Server-Side Request Forgery in all versio… | — | wordfence |
| dc24d2de-352c-4215-a4db-2966aa6467c7 | < 2.9 |
MEDIUM | 4.1 | The Real3D Flipbook plugin for WordPress is vulnerable to Directory Traversal via uploads in versions up to, and includi… | — | wordfence |
| d2e040bd-df5f-4b40-bc7b-9521f224c297 | < 1.3.43 |
MEDIUM | 4.1 | The Photo Gallery by 10Web plugin for WordPress is vulnerable to Path Traversal in versions up to, and including, 1.3.42… | — | wordfence |
| cd96beee-afcb-4439-ad9b-f24e8afeac3c | < 1.3.1 |
MEDIUM | 4.1 | The Broken Link Notifier plugin for WordPress is vulnerable to CSV Injection in all versions up to, and including, 1.3.0… | — | wordfence |
| bda0d24c-b1c9-4ae4-93b3-46568982d718 | < 1.5.5 |
MEDIUM | 4.1 | Multiple Authenticated Persistent Cross-Site Scripting (XSS) vulnerabilities in Simple Event Planner WordPress plugin <=… | — | wordfence |
| a3a5c4f2-22f6-45df-bf76-9dfa1d2f5f41 | < 3.2.4 |
MEDIUM | 4.1 | The Booking calendar, Appointment Booking System plugin for WordPress is vulnerable to unauthorized access due to a miss… | — | wordfence |
| 8436ba39-b236-4d76-95b6-d2bed3728d8a | < 2.0.0 |
MEDIUM | 4.1 | The Wholesale Market for WooCommerce plugin for WordPress is vulnerable to Arbitrary Log File Download in versions below… | — | wordfence |
| 7d65a987-e8a6-4615-b681-9f48b7caed4f | < 4.3.3 |
MEDIUM | 4.1 | The Iptanus WordPress File Upload plugin before 4.3.3 for WordPress mishandles shortcode attributes. | — | wordfence |
| 66bd5065-aa4c-4b5b-a312-2f7bd1643d35 | MEDIUM | 4.1 | Authenticated (contributor or higher user role) Stored Cross-Site Scripting (XSS) vulnerability in Opal Hotel Room Booki… | — | wordfence | |
| 5177bde6-4922-48ee-9155-577c392809a0 | < 3.3.1 |
MEDIUM | 4.1 | The Head, Footer and Post Injections plugin for WordPress is vulnerable to PHP Code Injection in all versions up to, and… | — | wordfence |
| 4fd929e7-8f28-43de-92ce-4f52ece24f7c | < 2.9.2 |
MEDIUM | 4.1 | The Export All Posts, Products, Orders, Refunds & Users plugin for WordPress is vulnerable to Remote Code Execution in a… | — | wordfence |
| 4a748589-51e5-4e3c-930c-d073d5cc94bf | < 1.1.83 |
MEDIUM | 4.1 | The WP Time Slots Booking Form plugin for WordPress is vulnerable to authorization bypass due to improper capability che… | — | wordfence |
| 3b1bfe88-2513-4acc-91e2-50a3bc9d7183 | < 3.5.8.4 |
MEDIUM | 4.1 | … | — | wordfence |
| 2677cea6-d60d-4e10-afd7-e088a5592b19 | < 2.9.7 |
MEDIUM | 4.1 | The Welcart e-Commerce plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 2… | — | wordfence |
| 258177c4-d3d4-4465-8b73-0af1b02485b0 | < 6.5.3 |
MEDIUM | 4.1 | The Import Export All WordPress Images, Users & Post Types WordPress plugin before 6.5.3 does not fully validate the fil… | — | wordfence |
EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.
Scan My Website →