Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.
39,836 vulnerabilities found (page 432 of 1594)
| CVE ID | Plugin / Theme | Severity | CVSS | Description | Fixed In | Source |
|---|---|---|---|---|---|---|
| f07c1aac-28c1-47fc-a2e5-fbe48a90f051 | < 1.0.36 |
MEDIUM | 6.5 | The Sitemap by click5 WordPress plugin before 1.0.36 does not have authorisation and CSRF checks when updating options v… | — | wordfence |
| f00015e7-f669-451e-a614-17aa12843bf3 | < 4.0.2 |
MEDIUM | 6.5 | The Taskbuilder plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 4.0.1 due to insuf… | — | wordfence |
| ef9ee3e3-f6b7-400f-a977-2a3230c3b080 | MEDIUM | 6.5 | The Database Sync plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and includ… | — | wordfence | |
| ef9ad9c6-268c-4abc-8fa0-535b3612d259 | MEDIUM | 6.5 | The 5 Stars Rating Funnel plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 1.4.01 d… | — | wordfence | |
| ef60c109-30e2-48e9-8599-6f226e74b6bc | MEDIUM | 6.5 | The WP Limit Login Attempts plugin for WordPress is vulnerable to IP Address Spoofing in versions up to, and including, … | — | wordfence | |
| ef4c6f76-4d3e-4ab0-9e12-1df55a8edae5 | < 1.4 |
MEDIUM | 6.5 | The Browser Theme Color plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and includin… | — | wordfence |
| eecd1497-c94e-4f67-8cc5-72afffe9fae2 | < 1.3.0 |
MEDIUM | 6.5 | The Be POPIA Compliant plugin for WordPress is vulnerable to SQL Injection via the 'check_id' parameter in versions up t… | — | wordfence |
| eec9afef-2d71-4aa6-9b51-5be1ba51b8a5 | MEDIUM | 6.5 | The NC Wishlist for Woocommerce plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 1.… | — | wordfence | |
| ee5e1262-193c-480b-bc27-481c961c7c47 | < 2.8.2 |
MEDIUM | 6.5 | The Quick Adsense plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the se… | — | wordfence |
| ee5cddbc-9162-4397-8e7a-0ec5552cc367 | < 1.5.2 |
MEDIUM | 6.5 | The Xpro Elementor Addons plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 1.5.1 du… | — | wordfence |
| ee50731f-696f-4e9f-a930-05b2b23752de | < 2.8.7 |
MEDIUM | 6.5 | The Cost of Goods for WooCommerce plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, an… | — | wordfence |
| edc0d90f-41a7-430a-a994-57be7fba8753 | < 2.6.2 |
MEDIUM | 6.5 | The (1) rand and (2) mt_rand functions in PHP 5.2.6 do not produce cryptographically strong random numbers, which allows… | — | wordfence |
| ed99a056-42c6-4540-950e-12f8b547b64d | < 2.8.5 |
MEDIUM | 6.5 | The Doneren met Mollie plugin for WordPress is vulnerable to Sensitive Data Exposure in versions up to, and including, 2… | — | wordfence |
| ed2290ea-b567-487f-92b0-3a718e1ce496 | < 3.4.7 |
MEDIUM | 6.5 | The Views for WPForms – Display & Edit WPForms Entries on your site frontend plugin for WordPress is vulnerable to SQL… | — | wordfence |
| ecd9800e-ce0f-45f3-bb66-3690c51d885b | < 2.4.6 |
MEDIUM | 6.5 | The Newsletter - API v1 and v2 addon plugin for WordPress is vulnerable to unauthorized subscribers management due to PH… | — | wordfence |
| ecd383f1-0546-4ff2-9f93-ee9d48ac3053 | MEDIUM | 6.5 | The Robcore Netatmo plugin for WordPress is vulnerable to SQL Injection via the ‘module_id’ attribute of the robcore… | — | wordfence | |
| ecb40bc2-aff5-4ced-8ded-1505d7b9db45 | < 2.8.28 |
MEDIUM | 6.5 | Cross-site scripting (XSS) vulnerability in the Contact Form DB (aka CFDB and contact-form-7-to-database-extension) plug… | — | wordfence |
| ebcbf872-1420-4a57-a4b4-8a52ba74e0a1 | < 3.4 |
MEDIUM | 6.5 | The Funnelforms Free plugin for WordPress is vulnerable to Stored Cross-Site Scripting via form submission answers in ve… | — | wordfence |
| ebbc420d-43fd-48c4-8507-6d94b9fed565 | < 1.5.0 |
MEDIUM | 6.5 | The Media Sync plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 1.4.9 via the … | — | wordfence |
| ebb9e37c-9e8b-429b-b4ef-cd875351852c | MEDIUM | 6.5 | The BadgeOS plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions up to, and including, 3.7… | — | wordfence | |
| eb6b0c35-b478-4616-a708-1fd243c95c14 | < 3.6.8 |
MEDIUM | 6.5 | … | — | wordfence |
| ead76977-d0dc-4385-8666-c8a4694c3bbe | < 6.4.0 |
MEDIUM | 6.5 | The Site Reviews plugin for WordPress is vulnerable to CSV Injection in versions up to, and including, 6.2.0. This allow… | — | wordfence |
| eab85a0a-f328-4cb6-b01f-d7e57540969d | < 3.6.9 |
MEDIUM | 6.5 | The Import any XML or CSV File to WordPress plugin for WordPress is vulnerable to arbitrary file uploads due to improper… | — | wordfence |
| ea49df40-e58f-4e20-8e48-ed0f9a1b94ca | < 6.7.37 |
MEDIUM | 6.5 | The Slider Revolution plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 6.7.36 … | — | wordfence |
| ea2b5dca-42a5-49d4-800d-b268572968a9 | < 9.96.0.0 |
MEDIUM | 6.5 | The VK All in One Expansion Unit plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up… | — | wordfence |
EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.
Scan My Website →