Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.
39,836 vulnerabilities found (page 429 of 1594)
| CVE ID | Plugin / Theme | Severity | CVSS | Description | Fixed In | Source |
|---|---|---|---|---|---|---|
| fd8f3eb7-ac60-46c4-b41f-5d89e3133042 | < 1.5.7 |
MEDIUM | 6.5 | The Wallet for WooCommerce plugin for WordPress is vulnerable to incorrect conversion between numeric types in all versi… | — | wordfence |
| fd80133d-03c7-4ecb-ad2c-98950f788ca6 | < 7.38 |
MEDIUM | 6.5 | The WP Import β Ultimate CSV XML Importer for WordPress plugin for WordPress is vulnerable to SQL Injection in all ver… | — | wordfence |
| fd7916f3-7844-4f3f-87ae-a8a66a9f3dec | < 3.1.7 |
MEDIUM | 6.5 | The awesome-support plugin before 3.1.7 for WordPress has a security issue in which shortcodes are allowed in replies. | — | wordfence |
| fd28c405-ed2f-435a-806c-1fc43cac0f80 | < 4.0.2 |
MEDIUM | 6.5 | The Sreamit theme for WordPress is vulnerable to arbitrary file downloads in all versions up to, and including, 4.0.1. T… | — | wordfence |
| fd063077-7fda-4c64-abc8-c7456c3dc2b8 | < 2.6.9 |
MEDIUM | 6.5 | The WC Vendors β WooCommerce Multivendor, WooCommerce Marketplace, Product Vendors plugin for WordPress is vulnerable … | — | wordfence |
| fc56aeb0-eba1-4196-aac9-e5723674cd1a | < 3.2.8 |
MEDIUM | 6.5 | The Traveler theme for WordPress is vulnerable to SQL Injection in versions up to 3.2.8 due to insufficient escaping on … | — | wordfence |
| fc48f75d-a2e8-49ea-9bfa-a27a61ff8a84 | < 1.6.3 |
MEDIUM | 6.5 | The Blocks for ACF Fields plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability … | — | wordfence |
| fba36ebc-a396-4eb8-8cb6-afc50b9c974e | MEDIUM | 6.5 | The Bucketlister plugin for WordPress is vulnerable to SQL Injection via the plugin's shortcode `category` and `id` attr… | — | wordfence | |
| fb7fd98d-de1d-4b06-b769-92df40bc1873 | < 4.5.9 |
MEDIUM | 6.5 | The Groundhogg β CRM, Newsletters, and Marketing Automation plugin for WordPress is vulnerable to generic SQL Injectio… | — | wordfence |
| fb77413e-3e7a-4315-8dde-59ac4e2534ae | < 2.4.11 |
MEDIUM | 6.5 | The Restaurant Menu and Food Ordering plugin for WordPress is vulnerable to SQL Injection in versions up to, and includi… | — | wordfence |
| fb291c79-8b8e-476b-b6e4-e8428bf60d6e | MEDIUM | 6.5 | The Filter Portfolio Gallery WordPress plugin through 1.5 is lacking Cross-Site Request Forgery (CSRF) check when deleti… | — | wordfence | |
| faffd8e3-b110-4ba3-98c1-22aee7f19586 | MEDIUM | 6.5 | The Commenter Emails plugin for WordPress is vulnerable to CSV Injection in versions up to, and including, 2.6.1. This a… | — | wordfence | |
| fab4db72-e8d6-4417-ba40-a55f395beb35 | < 1.0.2 |
MEDIUM | 6.5 | The Category Icon plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 1.0.1. This… | — | wordfence |
| fa48aeb9-5d20-43c4-8177-30730852eeb0 | MEDIUM | 6.5 | The WooMS plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in v… | — | wordfence | |
| fa2bb0c0-e412-4e78-a7b5-4517f1c15481 | < 1.0.1 |
MEDIUM | 6.5 | The Mail Subscribe List plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'bwsmn_form_email' par… | — | wordfence |
| fa15939c-44eb-45e5-95d7-49307912f21c | < 2.0.0 |
MEDIUM | 6.5 | The Backup and Restore WordPress β Backup Plugin plugin for WordPress is vulnerable to Cross-Site Request Forgery in a… | — | wordfence |
| f9fcd12b-bcc8-48cb-a077-ccf1bc4ff276 | < 3.1.3 |
MEDIUM | 6.5 | The mtouch-quiz plugin before 3.1.3 for WordPress has wp-admin/options-general.php CSRF. | — | wordfence |
| f9989f22-d5a0-453a-86e8-dc45c7cdd5dd | < 1.1.5 |
MEDIUM | 6.5 | The TH Advance Product Search plugin for WordPress is vulnerable to authorization bypass due to a missing capability che… | — | wordfence |
| f99192a3-7ca1-4a19-aa9c-f2fc04fd2d1f | MEDIUM | 6.5 | The AI Quiz plugin for WordPress is vulnerable to unauthorized access of functionality due to a missing capability check… | — | wordfence | |
| f98acfe6-b012-47c6-b47e-66a4304d3501 | < 1.5.6 |
MEDIUM | 6.5 | The Directory Kit plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 1.5.5 due to ins… | — | wordfence |
| f979e58a-9520-4b6b-82ee-421380552593 | MEDIUM | 6.5 | The LambertGroup - AllInOne - Content Slider plugin for WordPress is vulnerable to SQL Injection in versions up to, and … | — | wordfence | |
| f9661fa8-1c69-433b-8e18-039000e7d6e7 | < 6.5.0 |
MEDIUM | 6.5 | The Uncanny Automator β Easy Automation, Integration, Webhooks & Workflow Builder Plugin plugin for WordPress is vulne… | — | wordfence |
| f94eabc5-6e3b-46df-9e36-d7d0fad833de | < 2.7.0 |
MEDIUM | 6.5 | The Kraken.io Image Optimizer plugin for WordPress is vulnerable to authorization bypass due to a missing capability che… | — | wordfence |
| f8ed68ab-1f25-4683-b4a3-60de785681b1 | MEDIUM | 6.5 | The AI Hub - Startup & Technology WordPress Theme theme for WordPress is vulnerable to Path Traversal in all versions up… | — | wordfence | |
| f8d4029e-07b0-4ceb-ae6e-11a3f7416ebc | < 2.7.0 |
MEDIUM | 6.5 | The Tutor LMS β eLearning and online course solution plugin for WordPress is vulnerable to unauthorized modification o… | — | wordfence |
EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.
Scan My Website →