Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.
39,590 vulnerabilities found (page 192 of 1584)
| CVE ID | Plugin / Theme | Severity | CVSS | Description | Fixed In | Source |
|---|---|---|---|---|---|---|
| 341cbd60-33b9-49f8-b8f3-3c44664ce463 | HIGH | 8.8 | The Hover Image plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.4.1… | — | wordfence | |
| 34110479-2581-4710-82ff-1d53535d83e1 | < 4.2.0 |
HIGH | 8.8 | The LearnPress plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 4.1.7.3.2 due to in… | — | wordfence |
| 340d6e92-81a0-4659-b60b-922f63476a33 | < 1.47 |
HIGH | 8.8 | The SrbTransLatin plugin 1.46 for WordPress has CSRF via an srbtranslatoptions action to wp-admin/options-general.php. | — | wordfence |
| 33f07db9-ff4f-4f81-bf32-18b04d19624d | < 2.6.6 |
HIGH | 8.8 | The Affiliates Manager plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions before 2.6.6. This m… | — | wordfence |
| 33aed550-5a2d-4a0a-8199-f2dfd212be92 | HIGH | 8.8 | The Mega Addons For WPBakery Page Builder plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions u… | — | wordfence | |
| 338a4238-900c-4f3e-a724-52c4b3603af2 | < 2.9.3 |
HIGH | 8.8 | The Yogi theme for WordPress is vulnerable to PHP Object Injection in versions up to, and excluding, 2.9.3 via deseriali… | — | wordfence |
| 3368e4b4-9876-447b-acb4-3648e83ed997 | < 4.0.5 |
HIGH | 8.8 | The Acunetix WP Security plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and includi… | — | wordfence |
| 33517dba-78ac-4391-a55e-d1f13801b212 | < 3.7.7 |
HIGH | 8.8 | The SMS Alert Order Notifications β WooCommerce plugin for WordPress is vulnerable to unauthorized modification of dat… | — | wordfence |
| 332f8a7e-2342-4b77-a7d6-17137e432b5b | < 1.2.1 |
HIGH | 8.8 | The Counter Box WordPress plugin before 1.2.1 is lacking CSRF check when activating and deactivating counters, which cou… | — | wordfence |
| 33129b72-0976-4c09-9cea-b5ba321ae46f | < 3.3.7 |
HIGH | 8.8 | The Import feature in the wp-advanced-search plugin 3.3.6 for WordPress is vulnerable to authenticated SQL injection via… | — | wordfence |
| 33086968-359f-46d7-825e-29c4e4449899 | < 2.12 |
HIGH | 8.8 | Low privileged users can use the AJAX action 'cp_plugins_do_button_job_later_callback' in the Visitor Traffic Real Time … | — | wordfence |
| 32d80824-c420-40e8-8c07-fb17b1b50644 | < 1.3 |
HIGH | 8.8 | Cross-site request forgery (CSRF) vulnerability in the FourSquare Checkins plugin before 1.3 for WordPress allows remote… | — | wordfence |
| 32b6938a-0566-46c8-8761-0403b3a0e3e9 | < 4.6.19 |
HIGH | 8.8 | The rtMedia for WordPress, BuddyPress and bbPress plugin for WordPress is vulnerable to blind SQL Injection via the rtme… | — | wordfence |
| 32b3ad84-6adb-44c1-942a-51f27638c8c9 | < 1.3.7 |
HIGH | 8.8 | The Multiple Roles plugin for WordPress is vulnerable to privilege escalation in versions before 1.3.7. This could allow… | — | wordfence |
| 329f6e9b-f2f4-4c4e-9512-fcf504c2c0ed | < 1.3.3 |
HIGH | 8.8 | Multiple cross-site request forgery (CSRF) vulnerabilities in the Simple Sticky Footer plugin before 1.3.3 for WordPress… | — | wordfence |
| 327f645b-4990-4b5e-b39c-6c55ac4e66f0 | < 2.7.1 |
HIGH | 8.8 | The WP Easy Gallery for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.7. Thi… | — | wordfence |
| 327f5628-20f8-4e37-9c54-d37d61e939b3 | < 1.4.5 |
HIGH | 8.8 | The EmpikPlace for Woocommerce plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and includi… | — | wordfence |
| 327e706d-2d6c-4204-a531-281f2e2dbcf0 | < 2.5 |
HIGH | 8.8 | The Horizontal scrolling announcements plugin for WordPress is vulnerable to SQL Injection via the plugin's 'hsas-shortc… | — | wordfence |
| 327a155c-7a7d-494d-94d1-f7e7ee8927f0 | < 2.0.6 |
HIGH | 8.8 | The Wholesale for WooCommerce plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and incl… | — | wordfence |
| 32725074-5c62-49e0-83f9-c6cb77fb77a4 | < 2025.03.27 |
HIGH | 8.8 | The Administrator Z plugin for WordPress is vulnerable to unauthorized modification of data that can lead to privilege e… | — | wordfence |
| 32419c04-bd10-431a-b87c-1975dacc2e01 | HIGH | 8.8 | The PDF24 Article To PDF WordPress plugin through 4.2.2 does not have CSRF check in place when updating its settings, wh… | — | wordfence | |
| 320c0c1d-9d1b-43d7-aca5-2104b2a63e8f | < 2.6.6 |
HIGH | 8.8 | The Kraken.io Image Optimizer plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and in… | — | wordfence |
| 31de3c9b-068d-47d8-9811-feae07f2e9d0 | < 3.6.6 |
HIGH | 8.8 | The WP User Frontend β Registration, User Profile, Membership, Content Restriction, User Directory, and Frontend Post … | — | wordfence |
| 31c10c95-fe6a-4e2d-a472-b6e8b8bc7fe7 | HIGH | 8.8 | The Insertify plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.1.4. … | — | wordfence | |
| 31b67763-0542-4c50-9713-434d15c18cb7 | HIGH | 8.8 | The Bstone Demo Importer plugin for WordPress is vulnerable to privilege escalation due to a missing capability check on… | — | wordfence |
EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.
Scan My Website →