Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.
39,891 vulnerabilities found (page 443 of 1596)
| CVE ID | Plugin / Theme | Severity | CVSS | Description | Fixed In | Source |
|---|---|---|---|---|---|---|
| bd53bc57-b10e-47a7-8c10-96bf1f1e82a5 | MEDIUM | 6.5 | The All in One B2B for WooCommerce plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, a… | — | wordfence | |
| bd46a2c3-f24d-4dff-b899-a95acb6310f7 | < 2.1.13 |
MEDIUM | 6.5 | The Ultimate Member plugin before 2.1.13 for WordPress mishandles hidden name="timestamp" fields in forms. | — | wordfence |
| bd31e8b0-6089-4521-a80f-e65e61ad062f | MEDIUM | 6.5 | The Word Replacer Pro plugin for WordPress is vulnerable to unauthorized access due to a missing capability check in ver… | — | wordfence | |
| bcca7ade-8b35-4ba1-a8b4-b1e815b025e3 | < 5.4.9 |
MEDIUM | 6.5 | The WP EasyCart plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 5.4.8… | — | wordfence |
| bcaa5d0e-b764-4566-bd46-2d41dc391c36 | < 2.4.2 |
MEDIUM | 6.5 | The WooCommerce Dynamic Pricing and Discounts plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versi… | — | wordfence |
| bca9d9a2-6c96-4653-9408-2e20f4a9d5f4 | MEDIUM | 6.5 | The The Armania - Fashion, Furniture, Organic, Food Multipurpose Elementor WooCommerce Theme (RTL Supported) theme for W… | — | wordfence | |
| bc5e3932-809c-46d7-bb8d-1dffac9877a4 | < 2.53.9 |
MEDIUM | 6.5 | The mappress-google-maps-for-wordpress plugin before 2.53.9 for WordPress does not correctly implement AJAX functions wi… | — | wordfence |
| bc53ad70-d630-4d4a-bcca-79732134e6a6 | < 2.76.0 |
MEDIUM | 6.5 | The WP-Polls plugin for WordPress is vulnerable to IP Validation Bypass in versions up to, and including, 2.75.6. This i… | — | wordfence |
| bc3b5faa-1a29-4fa7-9146-d782adce0b1f | < 1.1.6 |
MEDIUM | 6.5 | The BEAR β Bulk Editor and Products Manager Professional for WooCommerce by Pluginus.Net plugin for WordPress is vulne… | — | wordfence |
| bc2e883b-fb91-425c-a779-89a34eed2ba8 | < 1.3.56 |
MEDIUM | 6.5 | The Royal Elementor Addons plugin for WordPress is vulnerable to authorization bypass due to a missing capability check … | — | wordfence |
| bc045440-a8ca-40d3-b198-421b197e6928 | < 2.0.3 |
MEDIUM | 6.5 | Plugin Settings Change leading to Cross-Site Scripting (XSS) vulnerability in Cloudways Breeze plugin <= 2.0.2 on WordPr… | — | wordfence |
| bbedad66-a5a6-4fb5-b03e-0ecf9fbef19a | < 3.9.1 |
MEDIUM | 6.5 | The Profile Builder β User Profile & User Registration Forms plugin for WordPress is vulnerable to sensitive informati… | — | wordfence |
| bb5178f4-356b-4352-96ca-500e49006f8a | < 2.1.5 |
MEDIUM | 6.5 | The following plugins and themes for WordPress are vulnerable to arbitrary option deletion and user data manipulation: T… | — | wordfence |
| bb0625ec-5ac9-4896-ac11-87fc9287f68a | < 2.1.10 |
MEDIUM | 6.5 | The IDonate β Blood Donation, Request And Donor Management System plugin for WordPress is vulnerable to Insecure Direc… | — | wordfence |
| bb036338-abd7-4061-835d-038b765c68a6 | < 6.1.18 |
MEDIUM | 6.5 | The Fluent Forms Pro Add On Pack plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and … | — | wordfence |
| baff5795-f164-489e-8f57-536174867ec5 | < 1.4.17 |
MEDIUM | 6.5 | The Open User Map plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 1.4.16. Thi… | — | wordfence |
| bafadafe-4aa5-4349-8a9c-89b21ada47ba | MEDIUM | 6.5 | The WP Bannerize WordPress plugin is vulnerable to authenticated SQL injection via the id parameter found in the ~/Class… | — | wordfence | |
| ba98a282-39ee-4a84-b988-ecfc0c4cd297 | < 1.0.114 |
MEDIUM | 6.5 | The Brizy - Page Builder plugin for WordPress is vulnerable to authorization bypass due to a missing capability check an… | — | wordfence |
| b9ed7e26-34f0-4e5d-b560-03b1de9c5c95 | < 1.2.0 |
MEDIUM | 6.5 | The PS PHPCaptcha pluginfor WordPress is vulnerable to Denial of Service in versions up to, and including, 1.1.0. This i… | — | wordfence |
| b9cc0348-396e-4be1-92f5-851d20804ef5 | < 4.16.3 |
MEDIUM | 6.5 | The WordPress File Upload Free and Pro WordPress plugins before 4.16.3 allow users with a role as low as Contributor to … | — | wordfence |
| b9c273a3-c8b5-4f00-8daa-76fa486df0f2 | < 3.4.3 |
MEDIUM | 6.5 | The affiliate-toolkit β WordPress Affiliate Plugin plugin for WordPress is vulnerable to Server-Side Request Forgery i… | — | wordfence |
| b99e9fc4-a028-4616-9f6d-aad1972151b0 | MEDIUM | 6.5 | The Private Content plugin for WordPress is vulnerable to SQL Injection in all versions up to, and including, 8.11.5 due… | — | wordfence | |
| b9860e0e-e330-42fc-8a74-336ceb787f39 | < 4.13.2 |
MEDIUM | 6.5 | The The GiveWP β Donation Plugin and Fundraising Platform plugin for WordPress is vulnerable to arbitrary shortcode ex… | — | wordfence |
| b9502669-ddbb-40c3-9d98-95c862f47a9a | < 2.0 |
MEDIUM | 6.5 | The Multiple Shipping Address Woocommerce WordPress plugin before 2.0 does not properly sanitise and escape numerous par… | — | wordfence |
| b937940c-a3e0-49d3-b066-550b78351b54 | < 1.1.5 |
MEDIUM | 6.5 | The WP Fastest Cache plugin for WordPress is vulnerable to Server-Side Request Forgery in versions up to, and including,… | — | wordfence |
EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.
Scan My Website →