Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.
39,891 vulnerabilities found (page 467 of 1596)
| CVE ID | Plugin / Theme | Severity | CVSS | Description | Fixed In | Source |
|---|---|---|---|---|---|---|
| 4bc10693-6d7c-4293-8848-02181ceb0d25 | < 1.6.1 |
MEDIUM | 6.5 | The Gutena Forms – Contact Form, Survey Form, Feedback Form, Booking Form, and Custom Form Builder plugin for WordPres… | — | wordfence |
| 4bbff678-db55-4058-9f54-9220321616b0 | < 1.2.3 |
MEDIUM | 6.5 | The Fonto – Custom Web Fonts Manager plugin for WordPress is vulnerable to Path Traversal in all versions up to, and i… | — | wordfence |
| 4b796697-5f4b-435f-a63f-1f20afc4182b | < 1.1.3 |
MEDIUM | 6.5 | The Hive Support – WordPress Help Desk plugin for WordPress is vulnerable to SQL Injection in versions up to, and incl… | — | wordfence |
| 4b68e8d4-58d4-4753-bda3-60c0d874f822 | < 2.2.1 |
MEDIUM | 6.5 | The YaySMTP WordPress plugin before 2.2.1 does not have capability check before displaying the Mailer Credentials in JS … | — | wordfence |
| 4a86d15a-0abf-464c-a998-c1fc96edc964 | MEDIUM | 6.5 | The Gboy Custom Google Map plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 1.2 due… | — | wordfence | |
| 4a82c911-71aa-4f6c-8088-7b839e027a6a | < 1.8.42 |
MEDIUM | 6.5 | The Photo Gallery by 10Web – Mobile-Friendly Image Gallery plugin for WordPress is vulnerable to SQL Injection in vers… | — | wordfence |
| 4a7c9797-918b-4cde-9815-9d796fb09d45 | MEDIUM | 6.5 | The Quran Shortcode plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 1.5 due to ins… | — | wordfence | |
| 4a7a15ab-4f13-4eb1-aeb5-143230308871 | < 1.3.7 |
MEDIUM | 6.5 | The All Bootstrap Blocks plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and includi… | — | wordfence |
| 4a0c04fe-7a9f-4a3f-ba2c-3bdcb5dec060 | < 4.5.6 |
MEDIUM | 6.5 | The Groundhogg — CRM, Newsletters, and Marketing Automation plugin for WordPress is vulnerable to generic SQL Injectio… | — | wordfence |
| 49f5bb21-d18f-453b-bef4-e3b234d162c8 | < 1.4.3 |
MEDIUM | 6.5 | The Simple Downloads List plugin for WordPress is vulnerable to SQL Injection via the 'category' attribute of the 'neofi… | — | wordfence |
| 497b51f5-fb0a-4fd4-a545-cece9ec80a94 | MEDIUM | 6.5 | The Pakke Envíos plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 1.0.2 due to ins… | — | wordfence | |
| 495183b6-dc7c-4ff7-bc99-fc05a10d1269 | < 1.3.53 |
MEDIUM | 6.5 | The CP Contact Form with PayPal plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, … | — | wordfence |
| 490061dc-11f7-48f2-bc9a-974bedf16621 | < 2.3.3 |
MEDIUM | 6.5 | The Stamped.io Product Reviews & UGC for WooCommerce plugin for WordPress is vulnerable to unauthorized access and modif… | — | wordfence |
| 48d6cd72-6a38-403b-9a8f-960e99d8801f | < 1.6.13 |
MEDIUM | 6.5 | The Fullscreen Galleria plugin for WordPress is vulnerable to generic SQL Injection via 'href' Attribute in Post Content… | — | wordfence |
| 48ba0558-41ad-46f5-971d-3da9311b262b | < 1.8.2 |
MEDIUM | 6.5 | The Rankie - Wordpress Rank Tracker Plugin plugin for WordPress is vulnerable to SQL Injection in all versions up to 1.8… | — | wordfence |
| 48a59d72-16f2-498e-b042-ce79b55605dc | < 0.3.5 |
MEDIUM | 6.5 | The Cecabank WooCommerce Plugin plugin for WordPress is vulnerable to unauthorized access due to a missing capability ch… | — | wordfence |
| 487d94e8-e4f1-4da8-914c-96157f8ae14d | < 5.7 |
MEDIUM | 6.5 | The MouseWheel Smooth Scroll WordPress plugin before 5.7 does not have CSRF check in place on its settings page, which c… | — | wordfence |
| 48784892-443f-452c-9fe9-12e73af1cf7f | < 5.6.1 |
MEDIUM | 6.5 | The Booster for WooCommerce plugin for WordPress is vulnerable to order modification due to a missing capability/authori… | — | wordfence |
| 4838c2ad-87e0-4140-81bb-7d39d7a704dc | < 6.2.9 |
MEDIUM | 6.5 | The eshop plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘eshoptemplate’ GET parameter… | — | wordfence |
| 4822f1c7-3f83-416c-8957-17e4b53d7e69 | < 2.1 |
MEDIUM | 6.5 | The The Album and Image Gallery plus Lightbox plugin for WordPress is vulnerable to arbitrary shortcode execution in all… | — | wordfence |
| 4783eff5-b7cf-4342-b762-85f745c38ec8 | < 4.0.0-rc17 |
MEDIUM | 6.5 | The Font Awesome plugin for WordPress versions 4.0.0-rc15 and 4.0.0-rc16 are vulnerable to API Token Exposure. The vulne… | — | wordfence |
| 4772b482-f5e5-4707-b012-aca70fc89e49 | MEDIUM | 6.5 | The Breaking News WP plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1.… | — | wordfence | |
| 475ca301-32f2-4913-925c-369a9a4c83c1 | MEDIUM | 6.5 | The Table Generator plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the … | — | wordfence | |
| 47243ee1-42da-480c-94b8-bdebd8f9eac6 | < 3.0.7 |
MEDIUM | 6.5 | The Taskbuilder plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 3.0.6 due to insuf… | — | wordfence |
| 46c61f38-553e-43b2-a666-b160db40e66d | < 3.4.9 |
MEDIUM | 6.5 | The WP-Members Membership Plugin plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up… | — | wordfence |
EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.
Scan My Website →