Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.
39,836 vulnerabilities found (page 431 of 1594)
| CVE ID | Plugin / Theme | Severity | CVSS | Description | Fixed In | Source |
|---|---|---|---|---|---|---|
| f4425296-5519-4c90-9bdd-00be5811b3dd | MEDIUM | 6.5 | The School Management plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 92.0.0 due t… | — | wordfence | |
| f440a5c5-2a48-4beb-849f-3f7cde5a8653 | < 2.0.0 |
MEDIUM | 6.5 | The Gerencianet Oficial plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on … | — | wordfence |
| f431ce10-dfb2-4dc5-9865-3f29cdcba156 | MEDIUM | 6.5 | The AmaDiscount plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 1.0 due to insuffi… | — | wordfence | |
| f426c32e-a376-4447-b83f-409a8eb0c499 | MEDIUM | 6.5 | The IMPress Listings plugin for WordPress is vulnerable to unauthorized access due to a missing capability check in vers… | — | wordfence | |
| f40cc632-c6af-4c8b-a455-76319f7fe151 | < 3.41.0 |
MEDIUM | 6.5 | The Tag, Category, and Taxonomy Manager β AI Autotagger with OpenAI plugin for WordPress is vulnerable to time-based b… | — | wordfence |
| f3bbc23b-94af-4f4f-8b5f-6af41108fd93 | < 0.48 |
MEDIUM | 6.5 | The Google Authenticator plugin for WordPress is vulnerable to authentication bypass due to a missing capability check o… | — | wordfence |
| f38c28f4-e73a-4eb2-8bbd-73c849385c4e | < 2.2.17 |
MEDIUM | 6.5 | The School Management System β WPSchoolPress plugin for WordPress is vulnerable to SQL Injection via the 'cid' paramet… | — | wordfence |
| f35b6b83-93e7-464e-baaf-4be12e694510 | < 2.4.2 |
MEDIUM | 6.5 | The ClickWhale β Link Manager, Link Shortener and Click Tracker for Affiliate Links & Link Pages plugin for WordPress … | — | wordfence |
| f2ba40d9-2d37-453a-a731-078f1de1fc69 | < 4.5.5 |
MEDIUM | 6.5 | The Groundhogg β CRM, Newsletters, and Marketing Automation plugin for WordPress is vulnerable to generic SQL Injectio… | — | wordfence |
| f2b7258e-c594-415a-a872-d5b28397e40d | < 1.6.19 |
MEDIUM | 6.5 | The weForms plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the '… | — | wordfence |
| f29f9290-1f98-4019-997b-e33f2c151a5d | < 3.3.3 |
MEDIUM | 6.5 | Cross-site scripting (XSS) vulnerability in wp-includes/default-filters.php in WordPress before 3.3.3 allows remote atta… | — | wordfence |
| f29e5b19-2505-4b02-92c7-071833de6bc2 | < 3.3.1 |
MEDIUM | 6.5 | The Brevo - Email, SMS, Web Push, Chat, and more. plugin for WordPress is vulnerable to authorization bypass due to type… | — | wordfence |
| f24749a8-e01d-436a-9ec8-3745a6b5eecf | < 4.8.21 |
MEDIUM | 6.5 | The MasterStudy LMS Pro Plus plugin for WordPress is vulnerable to generic SQL Injection via the 'columns' parameter in … | — | wordfence |
| f24003da-2d30-427c-b3f7-bbce4649c34d | < 3.6.21 |
MEDIUM | 6.5 | The My auctions allegro plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 3.6.20 due… | — | wordfence |
| f23dd2d7-3b21-47d6-b6da-24c20c36ee7c | MEDIUM | 6.5 | The The TechOne - Electronics Multipurpose WooCommerce Theme ( RTL Supported ) theme for WordPress is vulnerable to arbi… | — | wordfence | |
| f234d676-86ac-47ab-b8b3-b0459cbb4538 | < 1.3.4 |
MEDIUM | 6.5 | The Youzify β BuddyPress Community, User Profile, Social Network & Membership Plugin for WordPress plugin for WordPres… | — | wordfence |
| f21e48b7-7dc7-4fd2-802c-da3c01cd5268 | < 3.15.1 |
MEDIUM | 6.5 | The AppMySite plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function … | — | wordfence |
| f1ed51a3-c049-4816-ada1-49f7edcb9a6f | < 6.3.8 |
MEDIUM | 6.5 | The Simple File List plugin for WordPress is vulnerable to unauthorized file operations due to a missing authorization c… | — | wordfence |
| f1eb0852-00ef-489a-aa39-7d8603249deb | < 5.11 |
MEDIUM | 6.5 | Advanced Custom Fields versions prior to 5.11 and Advanced Custom Fields Pro versions prior to 5.11 contain a missing au… | — | wordfence |
| f13a7eab-9c15-4829-9756-c5d4961a618c | MEDIUM | 6.5 | The include-file plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 1. This make… | — | wordfence | |
| f119c6c2-cd4e-415a-b717-2bfc90ed729e | < 1.0.30 |
MEDIUM | 6.5 | The Piotnet Forms plugin for WordPress is vulnerable to unauthorized access of data and modification of data due to a mi… | — | wordfence |
| f1152a9d-7bc4-4fc9-a25f-cd94496b2306 | MEDIUM | 6.5 | The The deepdigital theme for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and includ… | — | wordfence | |
| f10ae2b6-1580-418c-9cf7-e75ed71bb309 | < 2.1.2 |
MEDIUM | 6.5 | The Product Recommendation Quiz for eCommerce plugin for WordPress is vulnerable to unauthorized modification of data du… | — | wordfence |
| f105c62b-4b70-4514-a63d-6b6b78085c90 | < 1.10.0.1 |
MEDIUM | 6.5 | The If-So Dynamic Content β Elementor & All Page Builders Personalization plugin for WordPress is vulnerable to SQL In… | — | wordfence |
| f0c5d1f4-6c6d-413b-8f0d-a6d36556dc4a | < 4.7.9 |
MEDIUM | 6.5 | The Gallery by BestWebSoft β Customizable Image and Photo Galleries for WordPress plugin for WordPress is vulnerable t… | — | wordfence |
EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.
Scan My Website →