Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.
39,891 vulnerabilities found (page 461 of 1596)
| CVE ID | Plugin / Theme | Severity | CVSS | Description | Fixed In | Source |
|---|---|---|---|---|---|---|
| 66b669ce-142a-48b8-9adf-620657c2db74 | < 5.16.7.2 |
MEDIUM | 6.5 | The The Coupon Affiliates – Affiliate Plugin for WooCommerce plugin for WordPress is vulnerable to arbitrary shortcode… | — | wordfence |
| 668a77e4-9d0a-4835-be5c-4c1acfe7ba43 | < 3.43 |
MEDIUM | 6.5 | The WP Tools plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the wptools… | — | wordfence |
| 667547a9-0dc5-4810-aba9-025f0c222d24 | MEDIUM | 6.5 | The Account Manager for WooCommerce plugin for WordPress is vulnerable to authorization bypass due to a missing capabili… | — | wordfence | |
| 65b54e53-ec14-4dae-bcc1-1ca9b4128324 | < 4.0.2 |
MEDIUM | 6.5 | The Visualizer – Tables & Charts Manager with Built-in AI Generator plugin for WordPress is vulnerable to SQL Injectio… | — | wordfence |
| 65b48fc0-27fd-4a37-afb8-2213ca0d4746 | < 8.4.5 |
MEDIUM | 6.5 | The Blog2Social: Social Media Auto Post & Scheduler plugin for WordPress is vulnerable to SQL Injection via the ‘prgSo… | — | wordfence |
| 65a9e877-e870-4e36-985d-c0629abe3f78 | < 9.660 |
MEDIUM | 6.5 | The WP Cost Estimation plugin for WordPress is vulnerable to Upload Directory Traversal in versions before 9.660 via the… | — | wordfence |
| 658ff7da-6496-4cca-8b1c-76b794c20aad | < 1.2.0 |
MEDIUM | 6.5 | The Quantity Plus Minus Button for WooCommerce by CodeAstrology plugin for WordPress is vulnerable to Cross-Site Request… | — | wordfence |
| 657e2a4d-7e10-495d-8352-1adc0cb89e83 | < 1.0.32 |
MEDIUM | 6.5 | The Simple Page Access Restriction plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up t… | — | wordfence |
| 655e3795-44c8-498c-a8cd-9985abc9664c | < 5.9.5.1 |
MEDIUM | 6.5 | The ProfileGrid plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 5.9.5.0 due to in… | — | wordfence |
| 65585b03-5a53-454a-b6f9-1d124a622f5e | MEDIUM | 6.5 | The Docxpresso plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 2.6. This… | — | wordfence | |
| 6535f932-3aa4-4686-adf6-4e7a1f494e02 | < 2.5.0 |
MEDIUM | 6.5 | The REST API endpoint get_users in the User Profile Picture WordPress plugin before 2.5.0 returned more information than… | — | wordfence |
| 64f43aee-01ee-4fbb-a174-966ed3c06b21 | < 1.1.25 |
MEDIUM | 6.5 | The RSFirewall! plugin for WordPress is vulnerable to IP Address Spoofing in versions less than and equal to 1.1.24 due … | — | wordfence |
| 64e4d51a-7b65-4fba-9742-bc7d23f46f8d | < 2.4.6 |
MEDIUM | 6.5 | The MotoPress Appointment Booking plugin for WordPress is vulnerable to generic SQL Injection via the 's' parameter in a… | — | wordfence |
| 64ce00e9-1ef6-4155-9d0d-69a130bddba6 | < 1.8.0 |
MEDIUM | 6.5 | The Behance Portfolio Manager plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 1.7.… | — | wordfence |
| 647b0d58-1397-47ad-b001-6d5085fb4c4f | < 7.4.1 |
MEDIUM | 6.5 | The Events Manager plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 7.4.0 due to in… | — | wordfence |
| 64599caf-d79f-425a-b0b0-b97665130144 | < 3.11.2.2 |
MEDIUM | 6.5 | The The Eventer - WordPress Event & Booking Manager Plugin plugin for WordPress is vulnerable to arbitrary shortcode exe… | — | wordfence |
| 641e52d1-d046-4c15-9624-3b1919cd674f | < 1.3.4 |
MEDIUM | 6.5 | The Accept Donations with PayPal WordPress plugin before 1.3.4 does not have CSRF check in place and does not ensure tha… | — | wordfence |
| 63fec549-09e0-4d4e-ae41-128ce0669501 | < 11.2.1 |
MEDIUM | 6.5 | The Quiz Master Next plugin for WordPress is vulnerable to SQL Injection via stored quiz page data in versions up to, an… | — | wordfence |
| 63dc0acf-cec6-402b-aad3-21135354e488 | MEDIUM | 6.5 | The Attention Bar plugin for WordPress is vulnerable to SQL Injection via the 'id' parameter in all versions up to, and … | — | wordfence | |
| 63567094-9fb1-44b2-a3e6-99194389c4b6 | < 1.80 |
MEDIUM | 6.5 | The 1003 Mortgage Application plugin for WordPress is vulnerable to CSV Injection in versions up to, and including, 1.75… | — | wordfence |
| 634bec5f-e511-4047-9a46-09147ccc3a25 | < 2.0.0 |
MEDIUM | 6.5 | The Download Plugin plugin for WordPress is vulnerable to Missing Authorization in versions up to, and including, 1.6.2 … | — | wordfence |
| 6335cc7b-7282-4f54-9d8e-09a98ac3c3e5 | MEDIUM | 6.5 | The iFrame Images Gallery plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 9.0 due … | — | wordfence | |
| 630cc68e-102e-4e05-98ff-94de434a10ae | < 3.2.1 |
MEDIUM | 6.5 | The Registrations For The Events Calendar plugin for WordPress is vulnerable to SQL Injection via JSON keys in the 'stan… | — | wordfence |
| 6300c8c2-f539-46b2-9ee0-80bebbe4cad3 | < 5.9.6 |
MEDIUM | 6.5 | WordPress Core processes shortcodes in user-generated content on block themes in versions up to, and including, 6.2. Thi… | — | wordfence |
| 62e75bb6-83d9-43db-8c89-0995698ca0ca | < 27.1.2 |
MEDIUM | 6.5 | The Betheme theme for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the '_to… | — | wordfence |
EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.
Scan My Website →