Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.
40,549 vulnerabilities found (page 1589 of 1622)
| CVE ID | Plugin / Theme | Severity | CVSS | Description | Fixed In | Source |
|---|---|---|---|---|---|---|
| 72abfbcf-4be4-4e0a-89a7-94caa01c22a6 | < 4.0.1 |
LOW | 3.7 | The LearnPress – Sepay Payment plugin for WordPress is vulnerable to unauthorized access due to a missing capability c… | — | wordfence |
| 68533b4c-1bdf-4104-a263-757b018af129 | < 4.7.4 |
LOW | 3.7 | The rtMedia for WordPress, BuddyPress and bbPress plugin for WordPress is vulnerable to to Information Disclosure due to… | — | wordfence |
| 4f29d476-0730-437c-8065-309523278efa | < 2.1.6 |
LOW | 3.7 | The Soumettre.fr plugin for WordPress is vulnerable to unauthorized access and modification of data due to a improper au… | — | wordfence |
| 4edbfeee-b668-4a85-a030-c15d6583dc82 | < 5.16.1 |
LOW | 3.7 | The Abandoned Cart Lite for WooCommerce plugin for WordPress is vulnerable to unauthorized access of data due to a missi… | — | wordfence |
| 438e36ba-fd0e-4c98-814b-95f3d5f60d2f | < 2.10.14 |
LOW | 3.7 | The DOOFINDER Search and Discovery for WP & WooCommerce plugin for WordPress is vulnerable to Sensitive Information Expo… | — | wordfence |
| 3bb93138-f2f9-4a3f-a0a2-d79a315c44f3 | < 2.4.4 |
LOW | 3.7 | The package loader-utils before 1.4.2, from 2.0.0 and before 2.0.4 as well as versions from 3.0.0 but below 3.2.1 are vu… | — | wordfence |
| 3a3fa988-6f0b-48d3-a946-0fc587858c9c | < 1.4.1 |
LOW | 3.7 | The WPSyncSheets Lite For Elementor – Elementor Pro Form Google Spreadsheet Addon plugin for WordPress was running sev… | — | wordfence |
| 334be95c-438a-4e03-9ee4-9a6d2c2fa5f7 | < 3.4.3 |
LOW | 3.7 | The WP Job Openings plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and includin… | — | wordfence |
| 30b4371d-54a2-4111-ad2c-b38b6b31884d | < 2.7.12 |
LOW | 3.7 | The Password Protected plugin for WordPress is vulnerable to authorization bypass via IP address spoofing in all version… | — | wordfence |
| 2f0d4f48-a315-4308-a5b6-7d3f045b292f | < 3.7.40 |
LOW | 3.7 | WordPress Core is vulnerable to information disclosure via a REST-API endpoint in versions up to 6.0.3. The endpoint for… | — | wordfence |
| 2d89a534-978e-4fd8-be3a-5137bdc22dc9 | < 2.7.6 |
LOW | 3.7 | The W3 Total Cache plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and including… | — | wordfence |
| 2954a007-37ac-4811-a258-b3fdd738043f | < 2.4.4 |
LOW | 3.7 | The package loader-utils before 1.4.2, from 2.0.0 and before 2.0.4 as well as versions from 3.0.0 but below 3.2.1 are v… | — | wordfence |
| 1d3771ee-b664-4416-93b7-96ab1e3510cc | < 7.3.12 |
LOW | 3.7 | Sensitive information disclosure discovered in wpDiscuz WordPress plugin (versions <= 7.3.11). | — | wordfence |
| 1a182243-b24a-4c46-8b65-6b38d8509a51 | < 1.3.9.3 |
LOW | 3.7 | The Drag and Drop Multiple File Upload for Contact Form 7 plugin for WordPress is vulnerable to unauthorized modificatio… | — | wordfence |
| 0fcdfba2-aa19-4d0c-8880-5ee2c0680555 | < 3.7.40 |
LOW | 3.7 | WordPress Core in versions up to 6.0.3 had a weakness in how Share User Instances were handled. This fix appears to have… | — | wordfence |
| 0c4eb735-46bc-4eed-9d9a-b3bd42d18eed | < 1.9.4.1 |
LOW | 3.7 | The Freesoul Deactivate Plugins plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to, … | — | wordfence |
| e86152a6-cd8d-4466-bcc5-830413500e12 | < 4.2.1 |
LOW | 3.5 | The Feed Them Social – Page, Post, Video, and Photo Galleries plugin for WordPress is vulnerable to Cross-Site Request… | — | wordfence |
| b9e64c54-a78f-454a-a9ee-02f64b6ae83d | < 1.7.5 |
LOW | 3.5 | The WP Fastest Cache Premium plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, an… | — | wordfence |
| 8746bd3a-6e2b-4ed2-9b21-4ed5a0e58de8 | < 3.7.34 |
LOW | 3.5 | In affected versions of WordPress, misuse of the `set-screen-option` filter's return value allows arbitrary user meta fi… | — | wordfence |
| 77930416-d79b-42bc-8a84-f7f140679a8a | < 2.7.21 |
LOW | 3.5 | The SportsPress – Sports Club & League Manager plugin for WordPress is vulnerable to unauthorized modification of data… | — | wordfence |
| 76af4656-547b-4daf-9078-8ed2b425d1ca | < 3.7.22 |
LOW | 3.5 | Before version 4.8.2, WordPress was susceptible to an open redirect attack in wp-admin/edit-tag-form.php and wp-admin/us… | — | wordfence |
| 5178f7ee-d7e3-4cd1-8cc2-121d217e66fa | < 5.1.3 |
LOW | 3.5 | Cross-site scripting (XSS) vulnerability in the Google Analytics by Yoast (google-analytics-for-wordpress) plugin before… | — | wordfence |
| a832cd41-c7be-43b5-bee3-4489170cad79 | < 1.6.1 |
LOW | 3.4 | Multiple Stored Authenticated Cross-Site Scripting (XSS) vulnerabilities were discovered in tarteaucitron.js – Cookies… | — | wordfence |
| a4e542e0-98cc-46af-bedf-a33b133b6de1 | < 3.15.8 |
LOW | 3.4 | The Flexmls® IDX Plugin plugin for WordPress is vulnerable to Open Redirect in all versions up to, and including, 3.15.… | — | wordfence |
| 06b332de-4f94-47dc-a573-53514adaf5c0 | < 3.4.0 |
LOW | 3.4 | The affiliate-toolkit – WordPress Affiliate Plugin is vulnerable to Open Redirect in versions up to, and including, 3.… | — | wordfence |
EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.
Scan My Website →