Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.
39,652 vulnerabilities found (page 333 of 1587)
| CVE ID | Plugin / Theme | Severity | CVSS | Description | Fixed In | Source |
|---|---|---|---|---|---|---|
| 06187bf0-7e3b-49c0-9f34-3d717e8d8ece | < 0.6.1 |
HIGH | 7.4 | The Lazy Load plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘content’ parameter in versi… | — | wordfence |
| 04802c63-4a5d-4948-9ef1-cf89c4cc757e | < 4.3.2 |
HIGH | 7.4 | The Popup Builder plugin for WordPress is vulnerable to unauthorized modification of data and loss of data due to a miss… | — | wordfence |
| 01ef62c8-e862-422c-948d-6d376d021c82 | < 8.3.10 |
HIGH | 7.4 | The File Manager Pro plugin for WordPress is vulnerable to Limited JavaScript File Upload in all versions up to, and inc… | — | wordfence |
| 0114f098-713d-4eef-8643-901f607375de | < 4.1.34 |
HIGH | 7.4 | WordPress is a free and open-source content management system written in PHP and paired with a MariaDB database. Due to … | — | wordfence |
| fc62adbf-1f04-46b2-9ae9-aac3dbce8759 | HIGH | 7.3 | The WP SEO TDK plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the seo-u… | — | wordfence | |
| fc3fcb8f-f130-4008-8f11-d98efa30f1a8 | HIGH | 7.3 | The LayoutBoxx plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including,… | — | wordfence | |
| fb165cba-34a9-42d9-bfd5-31a290d02311 | < 2.0.2 |
HIGH | 7.3 | The The AADMY – Add Auto Date Month Year Into Posts plugin for WordPress is vulnerable to arbitrary shortcode executio… | — | wordfence |
| facb9fd5-86e7-4dc1-affc-eae7aeae5631 | < 6.30.31 |
HIGH | 7.3 | The WP Compress – Instant Performance & Speed Optimization plugin for WordPress is vulnerable to broken authentication… | — | wordfence |
| f8a653ab-7703-4e73-8089-a15ba6cf9718 | < 1.2.5 |
HIGH | 7.3 | The WordPress Stop User Enumeration Plugin for WordPress is vulnerable to Security Bypass in versions up to, and includi… | — | wordfence |
| f8812cfe-4bbe-44ba-9513-7f81bad68d11 | < 2.2.5 |
HIGH | 7.3 | The Sharkdropship for AliExpress Dropship and Affiliate plugin for WordPress is vulnerable to unauthorized access and mo… | — | wordfence |
| f86a69ab-2fc5-4c84-872b-929dbec429cd | < 3.2.3 |
HIGH | 7.3 | The New User Approve plugin for WordPress is vulnerable to unauthorized access of data and modification of data due to a… | — | wordfence |
| f771cf62-3aa9-472e-beb5-011a4f28e335 | < 1.2.2 |
HIGH | 7.3 | The Social Media Share Buttons & Social Sharing Icons plugin for WordPress patched unspecified vulnerabilities in versio… | — | wordfence |
| f75f83bf-3c86-44e9-b535-cd721061ee93 | < 3.6.3 |
HIGH | 7.3 | The DirectoryPress plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on severa… | — | wordfence |
| f53e5192-e809-400c-aed9-36b5d6415a9d | < 2.6.4 |
HIGH | 7.3 | The Orbit Fox by ThemeIsle plugin for WordPress is vulnerable to authorization bypass due to missing capability checks o… | — | wordfence |
| f1ac2544-f96b-4859-96de-795753a94264 | HIGH | 7.3 | The The Enable Shortcodes inside Widgets,Comments and Experts plugin for WordPress is vulnerable to arbitrary shortcode … | — | wordfence | |
| f189f606-ec30-4f5d-81c9-d526ba7141f0 | < 1.6.6 |
HIGH | 7.3 | The The Uix Slideshow plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and inc… | — | wordfence |
| eebfa8de-8a20-4fac-b43a-f7ae674d9184 | < 0.2.9.25 |
HIGH | 7.3 | The WP-Filebase plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the 'del… | — | wordfence |
| ecf803cf-1b9c-4d2e-863f-d1f51b08f833 | < 1.0.6.6 |
HIGH | 7.3 | The The Active Products Tables for WooCommerce. Use constructor to create tables plugin for WordPress is vulnerable to a… | — | wordfence |
| ec425326-2729-4142-b5f4-460dfd3ed773 | < 3.3.3 |
HIGH | 7.3 | The WooCommerce Food - Restaurant Menu & Food ordering plugin for WordPress is vulnerable to arbitrary shortcode executi… | — | wordfence |
| eb81f83f-a0e7-46d9-b106-fe31f8ad3eb9 | < 21.8.0.100 |
HIGH | 7.3 | The Quiz Maker Business, Developer, and Agency plugins for WordPress is vulnerable to arbitrary shortcode execution in a… | — | wordfence |
| eaf19371-7b06-45c6-bf16-6ef7dfffb175 | < 2.13.1 |
HIGH | 7.3 | The The Paid Membership Subscriptions – Effortless Memberships, Recurring Payments & Content Restriction plugin for Wo… | — | wordfence |
| ea136a60-aa42-4577-88b6-a49c79098954 | < 4.2.3.1 |
HIGH | 7.3 | The LearnPress plugin for WordPress is vulnerable to unauthorized access of functionality due to a missing capability ch… | — | wordfence |
| e9303719-3d48-4a55-ac19-0c603801d458 | HIGH | 7.3 | The Dropshipping and affiliates for Amazon and woocommerce plugin for WordPress is vulnerable to authorization bypass du… | — | wordfence | |
| e796b203-31b4-47c6-9018-190389ce4df7 | < 1.3.1 |
HIGH | 7.3 | The Portable phpMyAdmin plugin before 1.3.0 for WordPress allows remote attackers to bypass authentication and obtain ph… | — | wordfence |
| e45afda4-447a-4d95-90cb-9731b398a009 | HIGH | 7.3 | The The Create custom forms for WordPress with a smart form plugin for smart businesses plugin for WordPress is vulnerab… | — | wordfence |
EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.
Scan My Website →