Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.
39,891 vulnerabilities found (page 466 of 1596)
| CVE ID | Plugin / Theme | Severity | CVSS | Description | Fixed In | Source |
|---|---|---|---|---|---|---|
| 4fcaab95-7940-45f9-a3c2-c3b0dc540b61 | < 1.2.5 |
MEDIUM | 6.5 | The Database for CF7 plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check o… | — | wordfence |
| 4f96b87a-1405-4cf6-b903-ad0c7c8e2826 | < 4.27.2 |
MEDIUM | 6.5 | The plugin provides an Admin Search page that allows users with the `edit_posts` capability to run Relevanssi searches f… | — | wordfence |
| 4f6d0e20-9a30-4628-a090-feb1f0adc8af | MEDIUM | 6.5 | The New Simple Gallery plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 8.0 due to … | — | wordfence | |
| 4f5ff7bc-9443-4b34-abd3-dac800f162a1 | < 4.5.1 |
MEDIUM | 6.5 | The KiviCare β Clinic & Patient Management System (EHR) plugin for WordPress is vulnerable to generic SQL Injection vi… | — | wordfence |
| 4f57cac9-5610-454b-affb-86384ea00881 | < 7.0.11 |
MEDIUM | 6.5 | The Slider Revolution plugin for WordPress is vulnerable to Sensitive Information Disclosure in versions 7.0 to 7.0.10. … | — | wordfence |
| 4f2fd4a2-4a99-479e-aa9d-3d847ba8f00c | MEDIUM | 6.5 | The Menus Plus+ plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 1.9.6 due to insuf… | — | wordfence | |
| 4f1ed4a2-eb0d-42cd-9273-10d7d127cdf9 | MEDIUM | 6.5 | The lasTunes plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.6.… | — | wordfence | |
| 4f17976e-d6b9-40fb-b2fb-d60bcfd68d12 | < 0.9.69 |
MEDIUM | 6.5 | The Migration, Backup, Staging β WPvivid plugin for WordPress is vulnerable to unauthorized access due to a missing ca… | — | wordfence |
| 4f145c85-f3c6-46a7-b8ae-d486dd23087d | < 3.0.1 |
MEDIUM | 6.5 | The Wp Social Login and Register Social Counter plugin for WordPress is vulnerable to unauthorized modification of data … | — | wordfence |
| 4ed81348-7604-4858-bc8e-b4504d77ee45 | < 3.1.2 |
MEDIUM | 6.5 | The User Meta β User Profile Builder and User management plugin plugin for WordPress is vulnerable to Insecure Direct … | — | wordfence |
| 4e5d7d04-f73a-48ea-81e3-36a514c76cc6 | < 1.3 |
MEDIUM | 6.5 | The RapidResult plugin for WordPress is vulnerable to SQL Injection via the 's' parameter in all versions up to, and inc… | — | wordfence |
| 4e4f0275-7689-4b72-9761-45534f9c706d | MEDIUM | 6.5 | The Printcart Web to Print Product Designer for WooCommerce plugin for WordPress is vulnerable to unauthorized access du… | — | wordfence | |
| 4e4df9a6-8f7d-428b-a596-0751ca047169 | < 4.7.1 |
MEDIUM | 6.5 | The Simple Membership plugin for WordPress is vulnerable to Improper Handling of Missing Values in all versions up to, a… | — | wordfence |
| 4e41a12d-44a6-4851-b72a-ffa65bbbeb0b | < 1.2.8 |
MEDIUM | 6.5 | The WIP Custom Login plugin for WordPress is vulnerable to authorization bypass due to a missing capability and nonce ch… | — | wordfence |
| 4e3a6fe2-6292-44ff-8925-a4aeb77c2a7f | < 5.9.7 |
MEDIUM | 6.5 | WordPress Core processes shortcodes in user-generated content on block themes in versions up to, and including, 6.2.1. T… | — | wordfence |
| 4e0f38db-84bb-4ba9-9068-40937e78010d | < 10.0.1 |
MEDIUM | 6.5 | The WP Travel β Ultimate Travel Booking System, Tour Management Engine plugin for WordPress is vulnerable to SQL Injec… | — | wordfence |
| 4dfc28ec-1411-43c3-833e-a6c85a3ed767 | < 3.1.3 |
MEDIUM | 6.5 | The ShopLentor β WooCommerce Builder for Elementor & Gutenberg +20 Modules β All in One Solution (formerly WooLentor… | — | wordfence |
| 4df46cb5-11a9-4c44-8329-4fc8086bc367 | MEDIUM | 6.5 | The WooCommerce Orders & Customers Exporter plugin for WordPress is vulnerable to SQL Injection in versions up to, and i… | — | wordfence | |
| 4dd63ea6-7821-42b8-9b52-e721a8b2382d | MEDIUM | 6.5 | The Quicksand Post Filter jQuery Plugin plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up … | — | wordfence | |
| 4db55163-3037-4a3a-97a0-2a3109a8245d | < 1.0.42 |
MEDIUM | 6.5 | The Wishlist plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 1.0.41 due to insuffi… | — | wordfence |
| 4d9ef3ab-fdba-4f9c-9323-0731a8d9db54 | < 2.1.30 |
MEDIUM | 6.5 | The The Cozy Blocks β All-in-One Page Builder Blocks for Gutenberg and Full Site Editing (FSE) plugin for WordPress is… | — | wordfence |
| 4d59eedb-550f-44c1-a0cd-609c5661134d | < 2.11.22 |
MEDIUM | 6.5 | The Welcart e-Commerce plugin for WordPress is vulnerable to SQL Injection via the cookie in all versions up to, and inc… | — | wordfence |
| 4cf89f94-587a-4fed-a6e4-3876b7dbc9ba | < 5.0.20 |
MEDIUM | 6.5 | The Hide My WP Ghost β Security Plugin plugin for WordPress is vulnerable to IP Address Spoofing in versions up to, an… | — | wordfence |
| 4c956651-4f5e-4e2d-a0f2-b02d4f25bd68 | < 1.2.5 |
MEDIUM | 6.5 | The Accordion and Accordion Slider plugin for WordPress is vulnerable to unauthorized access of data and modification of… | — | wordfence |
| 4c1d49d0-c9aa-401c-80b9-d4df7fe97691 | < 1.4.1.9 |
MEDIUM | 6.5 | The FOX β Currency Switcher Professional for WooCommerce plugin is vulnerable to Unauthenticated Arbitrary Shortcode E… | — | wordfence |
EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.
Scan My Website →