Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.
39,891 vulnerabilities found (page 471 of 1596)
| CVE ID | Plugin / Theme | Severity | CVSS | Description | Fixed In | Source |
|---|---|---|---|---|---|---|
| 39192c3f-0021-4094-81c7-e74de1900d4f | MEDIUM | 6.5 | The Error Log Viewer plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 1.0.5 due to … | — | wordfence | |
| 39005c38-f60d-44fa-9121-a77039dc34de | < 1.0.99 |
MEDIUM | 6.5 | The Booking for Appointments and Events Calendar β Amelia plugin for WordPress is vulnerable to unauthorized access du… | — | wordfence |
| 38f84f31-5aeb-4f6f-9e10-33e365f6f2c8 | < 8.3.8 |
MEDIUM | 6.5 | The The Woodmart theme for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including… | — | wordfence |
| 37f6993a-2812-4007-b649-833a32163c75 | MEDIUM | 6.5 | The imEvent theme for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in … | — | wordfence | |
| 37a9b2d0-e27d-4a2c-945a-a06a9b9bd2ea | < 6.9.1 |
MEDIUM | 6.5 | The Stylish Price List WordPress plugin before 6.9.1 does not perform capability checks in its spl_upload_ser_img AJAX a… | — | wordfence |
| 379aa658-ebc4-4000-913e-5f95a4783233 | < 3.0.8 |
MEDIUM | 6.5 | The Rearrange Woocommerce Products WordPress plugin before 3.0.8 does not have proper access controls in the save_all_or… | — | wordfence |
| 377b8532-61b8-45be-ad7c-c9ff60a7100a | < 1.4.0 |
MEDIUM | 6.5 | The Caldera Forms β More Than Contact Forms plugin for WordPress is vulnerable to Sensitive Information Disclosure due… | — | wordfence |
| 36d92fc7-8383-4dca-b672-db3b1916c07d | MEDIUM | 6.5 | The Corpkit - Business Consulting WordPress Theme theme for WordPress is vulnerable to Sensitive Information Exposure in… | — | wordfence | |
| 368bc607-42b4-49fc-90b1-0ca427cdda4a | MEDIUM | 6.5 | The WooCommerce Point Of Sale (POS) plugin for WordPress is vulnerable to SQL Injection in versions up to, and including… | — | wordfence | |
| 365fce53-223b-48d3-bfb6-151b74218875 | MEDIUM | 6.5 | The Doctor Appointment Booking plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 1.0… | — | wordfence | |
| 3610644e-3481-4fed-a83c-cd9ce09775d2 | MEDIUM | 6.5 | The Traffic Manager plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on an u… | — | wordfence | |
| 36051ae9-80ae-4abe-8bc7-9a9ec78ee7aa | < 2.6 |
MEDIUM | 6.5 | The UberSlider plugin for WordPress is vulnerable to SQL Injection in versions up to, and excluding, 2.6 due to insuffic… | — | wordfence |
| 35eebcc8-a6bf-4cbb-9cc6-f49bd1625d6b | < 2.15.4 |
MEDIUM | 6.5 | The Tourfic β Ultimate Hotel Booking, Travel Booking & Apartment Booking WordPress Plugin | WooCommerce Booking plugin… | — | wordfence |
| 35be104a-15bc-489b-9806-9abe4ea2388a | MEDIUM | 6.5 | The Rename wp-login.php plugin for WordPress is vulnerable to Cross-Site Request Forgery as well as an authorization byp… | — | wordfence | |
| 351926d4-a9be-4fbd-bdf2-8bbff41d97ef | < 3.4.3 |
MEDIUM | 6.5 | The EventPrime β Events Calendar, Bookings and Tickets plugin for WordPress is vulnerable to unauthorized modification… | — | wordfence |
| 3511e110-d091-447d-87c0-25d33900bc30 | < 2.20 |
MEDIUM | 6.5 | The Export All Posts, Products, Orders, Refunds & Users plugin for WordPress is vulnerable to Cross-Site Request Forgery… | — | wordfence |
| 34e89c4d-de55-40bd-8b78-c2ec544c2f60 | < 4.9.5 |
MEDIUM | 6.5 | The WooCommerce - PDF Vouchers plugin for WordPress is vulnerable to unauthorized access due to a missing capability che… | — | wordfence |
| 34e7688d-af94-4ba4-96a5-8b1ebbde8214 | < 3.1.0 |
MEDIUM | 6.5 | The wpForo Forum plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 3.0.9 due to insu… | — | wordfence |
| 34d5dbd4-5546-439e-a47a-4f9385116adc | < 1.53 |
MEDIUM | 6.5 | The BBE theme before 1.53 for WordPress allows a direct launch of an HTML editor. | — | wordfence |
| 34a6d349-dfdc-4301-9380-7fc64c25f043 | < 2.6.71 |
MEDIUM | 6.5 | The Smart Forms WordPress plugin before 2.6.71 does not have authorisation in its rednao_smart_forms_entries_list AJAX a… | — | wordfence |
| 3486f114-5625-4751-a25e-2c5ab7b15b38 | < 28.4.1 |
MEDIUM | 6.5 | The Betheme theme for WordPress is vulnerable to Arbitrary File Deletion in versions up to, and including, 28.4. This is… | — | wordfence |
| 34817e32-d5a3-403a-85f0-1d60af8945de | < 1.2.4 |
MEDIUM | 6.5 | The YourChannel plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check when … | — | wordfence |
| 340e98bf-6484-4634-b2f8-e02f14de67de | < 1.2.3 |
MEDIUM | 6.5 | The Predictive Search plugin for WordPress is vulnerable to unauthorized modification and disclosure of data due to miss… | — | wordfence |
| 33cdd58b-9e5e-492e-a211-78de592f0663 | < 2.4.7 |
MEDIUM | 6.5 | The easy.jobs- Best Recruitment Plugin for Job Board Listing, Manager, Career Page for Elementor & Gutenberg plugin for … | — | wordfence |
| 33823749-e977-4c91-b8c4-d9774ba46dd9 | < 6.3.14 |
MEDIUM | 6.5 | The eshop plugin through 6.3.13 for WordPress has CSRF with resultant XSS via the wp-admin/admin.php?page=eshop-download… | — | wordfence |
EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.
Scan My Website →