Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.
39,590 vulnerabilities found (page 188 of 1584)
| CVE ID | Plugin / Theme | Severity | CVSS | Description | Fixed In | Source |
|---|---|---|---|---|---|---|
| 3d2236cd-dfed-42d0-a77f-4573e74a4781 | < 0.0.9 |
HIGH | 8.8 | The Contact Form 7 Captcha WordPress plugin before 0.0.9 does not have any CSRF check in place when saving its settings,… | — | wordfence |
| 3d0a709e-1514-43dd-8719-e9bdfdc610d2 | HIGH | 8.8 | The NMI Gateway For WooCommerce plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and … | — | wordfence | |
| 3d015c7d-bace-4d00-8ba5-1c85acb08d57 | < 1.1.1 |
HIGH | 8.8 | The Elegant Themes Bloom plugin before 1.1.1 for WordPress has privilege escalation. | — | wordfence |
| 3cfec2b8-1df0-4f3f-b6cc-ed0adecaeb16 | HIGH | 8.8 | The Cimy Header Image Rotator WordPress plugin through 6.1.1 does not have CSRF check in place when updating its setting… | — | wordfence | |
| 3ce0fece-a7e5-4d27-a70a-37ab0973c15f | < 3.3.1 |
HIGH | 8.8 | The Throws SPAM Away WordPress plugin before 3.3.1 does not have CSRF checks in place when deleting comments (either all… | — | wordfence |
| 3cc4a11a-7562-44e7-ac8e-770c4e39e2c7 | < 3.5.2 |
HIGH | 8.8 | The Academy LMS Pro plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in … | — | wordfence |
| 3c8ba503-db7e-4ac1-898f-a301854db60f | < 1.5.5 |
HIGH | 8.8 | The Barcode Scanner and Inventory manager. POS (Point of Sale) – scan barcodes & create orders with barcode reader. pl… | — | wordfence |
| 3c833223-c8c9-413f-9d72-6fb13101459b | < 2.4.14 |
HIGH | 8.8 | The wpForo Forum plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 2.4.13… | — | wordfence |
| 3c730a69-015a-4b36-aa16-eff6916a302f | < 1.2.4 |
HIGH | 8.8 | The Shop as a Customer for WooCommerce plugin for WordPress is vulnerable to privilege escalation in versions up to, and… | — | wordfence |
| 3c192623-eb46-4f1d-b897-433ac80608cb | < 1.5.0 |
HIGH | 8.8 | The Alt Text AI – Automatically generate image alt text for SEO and accessibility plugin for WordPress is vulnerable t… | — | wordfence |
| 3c021686-3c9d-4382-be5c-9d4bf989cdcd | < 1.6.9 |
HIGH | 8.8 | Insecure Direct Object Reference in edit function of Advanced Forms (Free & Pro) before 1.6.9 allows authenticated remot… | — | wordfence |
| 3bf59f44-356c-4d84-add3-72e8905a80f9 | < 1.0.9 |
HIGH | 8.8 | Cross-site request forgery (CSRF) vulnerability in Zoho SalesIQ 1.0.8 and earlier allows remote attackers to hijack the … | — | wordfence |
| 3bee82d8-d019-450b-b532-5b3e2e3aff6f | < 1.7.0 |
HIGH | 8.8 | The wpForo plugin 1.6.5 for WordPress allows wp-admin/admin.php?page=wpforo-usergroups CSRF. | — | wordfence |
| 3bed2531-1a7d-49d9-91c9-d9e7357e5613 | < 3.5 |
HIGH | 8.8 | The Erident Custom Login & Dashboard plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to,… | — | wordfence |
| 3be36cd6-27a3-4b15-9e43-b1f6c25efae6 | < 12.0.8 |
HIGH | 8.8 | The wp-statistics plugin before 12.0.8 for WordPress has SQL injection. | — | wordfence |
| 3bdb73f9-d091-4de7-975c-10090ee1f749 | < 3.7.4 |
HIGH | 8.8 | wp-includes/pluggable.php in WordPress before 3.9.2 rejects invalid CSRF nonces with a different timing depending on whi… | — | wordfence |
| 3bc19aca-15df-40c8-a7c4-10ae7faf0308 | < 2.0 |
HIGH | 8.8 | The Booking for Appointments and Events Calendar – Amelia plugin for WordPress is vulnerable to Privilege Escalation i… | — | wordfence |
| 3ba8a9f5-0633-4cf0-af27-5466d93e9020 | < 3.17 |
HIGH | 8.8 | The Media Library Assistant plugin for WordPress is vulnerable to time-based SQL Injection via the ‘order’ parameter… | — | wordfence |
| 3ba33a18-429f-4a3e-b018-bdfbbe6e8482 | HIGH | 8.8 | The WP Human Resource Management plugin for WordPress is vulnerable to Privilege Escalation due to missing authorization… | — | wordfence | |
| 3b89319c-53ed-4130-8c67-420a7efef13b | HIGH | 8.8 | The Make Email Customizer for WooCommerce plugin for WordPress is vulnerable to unauthorized modification of data that c… | — | wordfence | |
| 3b7f8739-7f40-40a7-952e-002ea3b82ac7 | < 3.1 |
HIGH | 8.8 | The Jquery news ticker plugin for WordPress is vulnerable to SQL Injection via the plugin's shortcode in versions up to,… | — | wordfence |
| 3b71805c-15bb-4cde-b91f-4f3e9b7ab520 | < 2.8.4 |
HIGH | 8.8 | The Welcart e-Commerce plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including… | — | wordfence |
| 3b6c114b-00e0-4d3d-ba8b-dc9b294112db | < 2.2.2 |
HIGH | 8.8 | The EKC Tournament Manager plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and inclu… | — | wordfence |
| 3b6ae26e-9262-4241-81d1-d5522bd35345 | HIGH | 8.8 | The Ultimate Product Catalog plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type valid… | — | wordfence | |
| 3b345dfe-3945-405a-9825-c88816b2adee | < 3.24.0 |
HIGH | 8.8 | The Thrive Themes Builder theme for WordPress is vulnerable to privilege escalation in all versions prior to 3.24.0. Thi… | — | wordfence |
EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.
Scan My Website →