Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.
39,891 vulnerabilities found (page 469 of 1596)
| CVE ID | Plugin / Theme | Severity | CVSS | Description | Fixed In | Source |
|---|---|---|---|---|---|---|
| 425b4f6d-9f13-4aa7-bc97-d6c221d234ca | < 2.29.0 |
MEDIUM | 6.5 | The Relevanssi Premium plugin for WordPress is vulnerable to SQL Injection in all versions up to 4.26.0 (Free) & 2.29.0 … | — | wordfence |
| 4235f279-0975-4814-b156-b45b011e3ce6 | < 2.1 |
MEDIUM | 6.5 | The Prevent Landscape Rotation plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and i… | — | wordfence |
| 422bb9a5-c848-4492-add7-bc65b1111565 | MEDIUM | 6.5 | The Booking Calendar and Notification plugin for WordPress is vulnerable to unauthorized access, modification, and loss … | — | wordfence | |
| 420bcda3-e275-4811-ae37-df69d4d60cee | < 3.6.9 |
MEDIUM | 6.5 | The Import any XML or CSV File to WordPress plugin for WordPress is vulnerable to arbitrary file uploads due to missing … | — | wordfence |
| 418e1f3b-ca99-4576-add9-d6134ba3869d | < 4.3.25 |
MEDIUM | 6.5 | The NextScripts: Social Networks Auto-Poster WordPress plugin before 4.3.25 does not have CSRF check in place when delet… | — | wordfence |
| 4165cff7-457d-4790-8678-84c4365a191a | < 1.4.9.1 |
MEDIUM | 6.5 | The Beaver Themer plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and includ… | — | wordfence |
| 4120c8e6-e162-4adf-890c-8070e5009748 | MEDIUM | 6.5 | The Duplicate Page and Post plugin for WordPress is vulnerable to time-based SQL Injection via the βmeta_keyβ parame… | — | wordfence | |
| 4101c35e-5af9-4372-9ed1-fb6a15d8500f | < 3.2.1 |
MEDIUM | 6.5 | The KiviCare β Clinic & Patient Management System (EHR) plugin for WordPress is vulnerable to Cross-Site Request Forge… | — | wordfence |
| 408312d3-9a9e-4b6b-9991-aee6b77745b2 | < 2.7.12 |
MEDIUM | 6.5 | The Jobs for WordPress plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 2… | — | wordfence |
| 407a5c69-cce0-4868-aef0-ffc88981e256 | < 7.6.1 |
MEDIUM | 6.5 | The Link Library plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'll_reciprocal' parameter in … | — | wordfence |
| 4072ba5f-6385-4fa3-85b6-89dac7b60a92 | < 5.1.2 |
MEDIUM | 6.5 | The UserPro plugin for WordPress is vulnerable to sensitive information disclosure via the 'userpro' shortcode in versio… | — | wordfence |
| 40595943-121d-4492-a0ed-f2de1bd99fda | < 3.22.1 |
MEDIUM | 6.5 | The GiveWP β Donation Plugin and Fundraising Platform plugin for WordPress is vulnerable to unauthorized access of dat… | — | wordfence |
| 402f32fa-466b-4d9e-948f-3b7dc4507105 | < 3.2.1 |
MEDIUM | 6.5 | The Bit Form β Contact Form, Payment Forms, Multi Step Forms, Calculator & Custom Form Builder plugin for WordPress is… | — | wordfence |
| 400fe58b-8203-4fd5-a3d3-d30eb1b8cd85 | < 3.4.2 |
MEDIUM | 6.5 | The Funnelforms Free plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability… | — | wordfence |
| 3fb59a19-3d04-4605-a98a-bcff51359708 | < 1.3.62 |
MEDIUM | 6.5 | The CP Contact Form with Paypal plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 1.… | — | wordfence |
| 3fb25dd5-4191-46ec-8b36-5bb389a7ebfc | < 1.5.5 |
MEDIUM | 6.5 | The Directory Kit plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 1.5.4 due to ins… | — | wordfence |
| 3f8f8319-d75f-4e71-90d4-1c60b5a8df90 | < 2.11.14 |
MEDIUM | 6.5 | The Welcart e-Commerce plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path valid… | — | wordfence |
| 3f8f083e-0de2-42a5-b289-101ec53aa44c | < 4.16.12 |
MEDIUM | 6.5 | The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content β ProfilePr… | — | wordfence |
| 3f7f7cb3-e153-4315-991c-80e8c9be7764 | < 11.11 |
MEDIUM | 6.5 | The Visitor Traffic Real Time Statistics pro plugin for WordPress is vulnerable to SQL Injection in versions up to, and … | — | wordfence |
| 3f753961-3eeb-402d-876f-4a4dea41a96a | < 1.1.4 |
MEDIUM | 6.5 | The Duplicator plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.1.3.… | — | wordfence |
| 3f596af2-ff83-4c67-a8f0-e4df4a0adbd2 | < 1.1 |
MEDIUM | 6.5 | An issue was discovered in the MULTIDOTS Add Social Share Messenger Buttons Whatsapp and Viber plugin 1.0.8 for WordPres… | — | wordfence |
| 3f58ed72-5a0b-4b43-ad76-7730c79741da | < 5.9.8.5 |
MEDIUM | 6.5 | The ProfileGrid β User Profiles, Groups and Communities plugin for WordPress is vulnerable to blind SQL Injection via … | — | wordfence |
| 3f159aac-092b-4655-9d97-a496ac01738c | MEDIUM | 6.5 | The WP Blockade plugin for WordPress is vulnerable to Missing Authorization in all versions up to and including 0.9.14. … | — | wordfence | |
| 3f070125-faee-46fe-aa6e-a51772868192 | < 5.0.53.decaf |
MEDIUM | 6.5 | The Event Espresso β Event Registration & Ticketing Sales plugin for WordPress is vulnerable to unauthorized access du… | — | wordfence |
| 3ec00aaa-a236-4b99-8104-5062ed440920 | MEDIUM | 6.5 | The Apollo plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 3.6.3 due to insufficie… | — | wordfence |
EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.
Scan My Website →