Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.
39,891 vulnerabilities found (page 448 of 1596)
| CVE ID | Plugin / Theme | Severity | CVSS | Description | Fixed In | Source |
|---|---|---|---|---|---|---|
| a7f0afe8-234a-4c3f-87c8-f3f23ac94fe3 | < 3.0.3 |
MEDIUM | 6.5 | The Cliengo β Chatbot plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capabil… | — | wordfence |
| a7e3818c-883f-4633-a460-a8c0446edffc | < 1.1.3.2 |
MEDIUM | 6.5 | The BEAR plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.1.3.1. Thi… | — | wordfence |
| a7af6721-4886-4bec-8931-992881310f26 | < 1.8.4 |
MEDIUM | 6.5 | The Maps Plugin using Google Maps for WordPress plugin before 1.8.4 does not have CSRF checks in most of its AJAX action… | — | wordfence |
| a7856d0f-bc7d-436c-968c-631fd6a686ab | < 3.4.5 |
MEDIUM | 6.5 | The SupportCandy β Helpdesk & Customer Support Ticket System plugin for WordPress is vulnerable to SQL Injection via t… | — | wordfence |
| a7764ea4-6c4b-47cf-a711-b92e56e03d3a | < 2.1.2 |
MEDIUM | 6.5 | The Amelia plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 2.1.1 due to insufficie… | — | wordfence |
| a6bb97fa-c8cd-44bc-90ba-dd3b6a3a78da | MEDIUM | 6.5 | The L Squared Hub WP plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 1.0 due to in… | — | wordfence | |
| a697aef0-5236-464f-aea3-40d93efaba82 | < 4.5 |
MEDIUM | 6.5 | The Content Views plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 4.4 due to insuf… | — | wordfence |
| a692d9c4-66e0-4461-ad13-65e1446106c5 | MEDIUM | 6.5 | The Hero Slider - WordPress Slider Plugin plugin for WordPress is vulnerable to SQL Injection via several parameters in … | — | wordfence | |
| a65e820d-afb7-4e1c-b690-5948447af59a | < 4.5.0 |
MEDIUM | 6.5 | The Nelio AB Testing plugin for WordPress is vulnerable to Directory Traversal in versions up to, and including, 4.4.4 v… | — | wordfence |
| a65a1f25-04e5-4ca3-9b2d-1b78254a8871 | < 1.5.9 |
MEDIUM | 6.5 | The WordPress CTA plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability ch… | — | wordfence |
| a63a41d1-b9b0-43a9-a6e0-761f3b8d9d4a | < 2.9.5 |
MEDIUM | 6.5 | The Customer Email Verification for WooCommerce plugin for WordPress is vulnerable to Sensitive Information Exposure in … | — | wordfence |
| a616cee1-2aee-40bb-ab79-3bebb3438582 | < 1.20.5 |
MEDIUM | 6.5 | The FooEvents for WooCommerce plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 1.20… | — | wordfence |
| a6072f47-91b3-4c5d-b16e-61bcd7760604 | < 1.7.7 |
MEDIUM | 6.5 | The tutor_place_rating AJAX action from the Tutor LMS β eLearning and online course solution WordPress plugin before 1… | — | wordfence |
| a601d0de-2f09-4f5c-8937-dfa20f1c64ec | < 2.2.57 |
MEDIUM | 6.5 | The B1.lt plugin for WordPress is vulnerable to SQL Injection via the 'id' parameter in all versions up to, and includin… | — | wordfence |
| a5f3fbd2-6152-4a89-8fe9-982120d1a640 | < 1.6.9.6 |
MEDIUM | 6.5 | The Appointment Booking Calendar β Simply Schedule Appointments Booking Plugin plugin for WordPress is vulnerable to S… | — | wordfence |
| a5c8d361-698b-4abd-bcdd-0361d3fd10c5 | < 2.8.10 |
MEDIUM | 6.5 | The BuddyForms plugin for WordPress is vulnerable to Email Verification Bypass in all versions up to, and including, 2.8… | — | wordfence |
| a5a8e4ca-c16b-4e9d-8ad2-5a671fdbc49a | < 6.3.7 |
MEDIUM | 6.5 | The Awesome Support - WordPress HelpDesk & Support Plugin for WordPress is vulnerable to authorization bypass due to mis… | — | wordfence |
| a57426d2-0ca4-405b-bfbf-0685e2c744a0 | < 4.7.20 |
MEDIUM | 6.5 | Wordpress is an open source CMS. One of the blocks in the WordPress editor can be exploited in a way that exposes passwo… | — | wordfence |
| a55cfeb3-7632-4a88-ac71-8e119b060721 | < 5.7.3 |
MEDIUM | 6.5 | The Element Pack Elementor Addons (Header Footer, Template Library, Dynamic Grid & Carousel, Remote Arrows) plugin for W… | — | wordfence |
| a4806327-46f9-4e84-8886-c9065e1a0ceb | MEDIUM | 6.5 | The WP Sitemap plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 1.0 due to insuffic… | — | wordfence | |
| a4647620-e06a-49d5-8f9d-a59cb5a999b1 | < 1.1.31 |
MEDIUM | 6.5 | The CubeWP Framework plugin for WordPress is vulnerable to SQL Injection in all versions up to and including 1.1.30. Thi… | — | wordfence |
| a46364f4-9258-4f5e-9d53-dcbaf726f2f0 | < 4.6.4 |
MEDIUM | 6.5 | The WP RSS Aggregator β News Feeds, Autoblogging, Youtube Video Feeds and More plugin for WordPress is vulnerable to a… | — | wordfence |
| a45a6b3d-49e1-4e25-aa66-15b396da8986 | < 5.1.3 |
MEDIUM | 6.5 | The WooCommerce Subscriptions plugin for WordPress is vulnerable to unauthorized modification of data due to a missing c… | — | wordfence |
| a3f791dd-7c24-45e3-b4f6-b8d7e594c568 | < 1.69.1 |
MEDIUM | 6.5 | The WP-DownloadManager plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 1.69 v… | — | wordfence |
| a3d14d8f-61f4-4942-9eff-42264bb036bb | < 1.1.3 |
MEDIUM | 6.5 | The WP Mail Log plugin for WordPress is vulnerable to Arbitrary File Read in all versions up to, and including, 1.1.2 vi… | — | wordfence |
EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.
Scan My Website →