Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.
39,836 vulnerabilities found (page 430 of 1594)
| CVE ID | Plugin / Theme | Severity | CVSS | Description | Fixed In | Source |
|---|---|---|---|---|---|---|
| f8befbf2-0d9d-4d0e-87de-0f1b26c0acd0 | MEDIUM | 6.5 | The Sales Report Email for WooCommerce plugin for WordPress is missing a capability and nonce check in several functions… | — | wordfence | |
| f89737cf-90f0-4d85-a7b3-f633047eb93c | < 10.2.5 |
MEDIUM | 6.5 | The Quiz And Survey Master plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 10.2.4 … | — | wordfence |
| f8945eed-eee4-4043-b6ab-d1ea553a4a23 | MEDIUM | 6.5 | The WP-Addpub plugin for WordPress is vulnerable to SQL Injection via the 'wp-addpub' shortcode in all versions up to, a… | — | wordfence | |
| f883823f-c225-4cd2-a0f6-39013476ed83 | < 9.7.3.1 |
MEDIUM | 6.5 | The Booking Calendar plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the booking form fields in ve… | — | wordfence |
| f88286b9-16b2-42a9-b8c6-0a6fe6c136ef | < 1.6 |
MEDIUM | 6.5 | The "Forminator Contact Form, Poll & Quiz Builder" plugin before 1.6 for WordPress has SQL Injection via the wp-admin/ad… | — | wordfence |
| f87df7cc-54bb-454c-94be-c8c4768cbe44 | < 2.8.5 |
MEDIUM | 6.5 | The Welcart e-Commerce plugin for WordPress is vulnerable to arbitrary file read due to missing restrictions to proper f… | — | wordfence |
| f8544784-1994-47e2-be39-568d0ab9ee00 | < 0.9.2.4 |
MEDIUM | 6.5 | The The Advanced Custom Fields: Extended plugin for WordPress is vulnerable to arbitrary shortcode execution in all vers… | — | wordfence |
| f7e2246d-704c-40df-ab82-ffdb85e78cd3 | MEDIUM | 6.5 | The Ray Enterprise Translation plugin for WordPress is vulnerable to unauthorized access due to a missing capability che… | — | wordfence | |
| f7d2a830-4b66-4875-98b1-4730c3b6ae4b | MEDIUM | 6.5 | The Duplicate Title Checker plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 1.2 du… | — | wordfence | |
| f7c39d66-f1e1-4d41-a9e4-984aec3f37dc | < 1.22.27 |
MEDIUM | 6.5 | The Backup and Staging by WP Time Capsule plugin for WordPress is vulnerable to Sensitive Information Exposure in all ve… | — | wordfence |
| f77e2d1e-7925-4343-9c22-5b77ea0d439b | < 3.4.8 |
MEDIUM | 6.5 | The Multiple Page Generator Plugin β MPG plugin for WordPress is vulnerable to SQL Injection in versions up to, and in… | — | wordfence |
| f76a757b-8eac-4e54-ae0e-3f0a491ff582 | < 3.4.3 |
MEDIUM | 6.5 | The Vitepos β Point of Sale (POS) for WooCommerce plugin for WordPress is vulnerable to SQL Injection in versions up t… | — | wordfence |
| f72ad187-9745-4d0b-8cb0-5bf07ab1e2ac | MEDIUM | 6.5 | The Distance Rate Shipping For WooCommerce plugin for WordPress is vulnerable to SQL Injection in all versions up to, an… | — | wordfence | |
| f719d624-d6f9-4095-abaf-f2ba9e448710 | MEDIUM | 6.5 | The Workreap (theme's plugin) plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 3.3.… | — | wordfence | |
| f68ac2b8-33dc-4cc2-b0f3-8777450e39f9 | < 2.0.0 |
MEDIUM | 6.5 | The Pro Mime Types plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.… | — | wordfence |
| f673e463-5ef0-4704-91a1-76e375df9d1c | < 2.9.9.5.2 |
MEDIUM | 6.5 | The Pinpoint Booking System plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 2.9.9.… | — | wordfence |
| f6043cff-f2b7-46bb-b00d-96bfcd69e54e | < 4.9.1.1 |
MEDIUM | 6.5 | The All In One SEO Pack plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 4.9.1 due … | — | wordfence |
| f5e92e16-606e-4540-9116-26fe77fe4142 | MEDIUM | 6.5 | The Review Stars Count For WooCommerce plugin for WordPress is vulnerable to SQL Injection in versions up to, and includ… | — | wordfence | |
| f5da4cdd-15c7-41a6-be2f-e31bd407ae05 | < 3.0.5 |
MEDIUM | 6.5 | The Classified Listing β Classified ads & Business Directory Plugin plugin for WordPress is vulnerable to unauthorized… | — | wordfence |
| f53d9579-56e9-41aa-b6b7-2472734ee719 | < 21.0.10 |
MEDIUM | 6.5 | The Shield Security plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and includin… | — | wordfence |
| f5266ae5-1e38-4f76-9137-1fcf94ed59b8 | MEDIUM | 6.5 | The Simple Personal Message plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 1.0.3 … | — | wordfence | |
| f4fcc6e5-1f90-41e7-8d5a-2bfe8cbf46fa | MEDIUM | 6.5 | The Flashcard plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 0.9 via the 'so… | — | wordfence | |
| f47d50dc-ec14-40c8-95a2-f393986ed71b | < 2.6 |
MEDIUM | 6.5 | There is CSRF in the CopySafe Web Protection plugin before 2.6 for WordPress, allowing attackers to change plugin settin… | — | wordfence |
| f46b01e4-1022-45aa-8511-6d2519e4e562 | < 1.0.8.2 |
MEDIUM | 6.5 | The WP Setup Wizard plugin for WordPress is vulnerable to unauthorized access of datadue to a missing capability check i… | — | wordfence |
| f4618bfd-77d9-4396-b041-d7ba0f6ec75a | < 3.6.3 |
MEDIUM | 6.5 | The Perfect Brands for WooCommerce plugin for WordPress is vulnerable to time-based SQL Injection via the `brands` attri… | — | wordfence |
EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.
Scan My Website →