Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.
39,891 vulnerabilities found (page 481 of 1596)
| CVE ID | Plugin / Theme | Severity | CVSS | Description | Fixed In | Source |
|---|---|---|---|---|---|---|
| 0c410d91-08cc-496d-9c8e-c57f107399da | < 4.2.6.4 |
MEDIUM | 6.5 | The LearnPress β WordPress LMS Plugin plugin for WordPress is vulnerable to Insecure Direct Object Reference in all ve… | — | wordfence |
| 0b4cb873-77b7-44f9-820c-38e5d43393f3 | < 3.2.1 |
MEDIUM | 6.5 | The Library Management System β Manage e-Digital Books Library plugin for WordPress is vulnerable to SQL Injection via… | — | wordfence |
| 0b32c63d-ce6b-4fac-8198-3a598fc84f7a | < 6.7.7 |
MEDIUM | 6.5 | The WooCommerce Frontend Manager β Ultimate plugin for WordPress is vulnerable to SQL Injection in versions up to 6.7.… | — | wordfence |
| 0b301c6e-a3c5-4435-9bc9-fab18085fe2d | < 2.0.4 |
MEDIUM | 6.5 | The pCloud WP Backup plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and inc… | — | wordfence |
| 0b04ab77-880b-423a-bba6-59822f0463bc | < 2.18.0 |
MEDIUM | 6.5 | The NextMove Lite β Thank You Page for WooCommerce plugin for WordPress is vulnerable to unauthorized modification of … | — | wordfence |
| 0add0b7c-c47a-4ff0-b750-9b1433970d85 | < 1.23.3 |
MEDIUM | 6.5 | The Timber plugin for WordPress is utilizing a vulnerable version of Twig in all versions up to, and including, 1.23.1. … | — | wordfence |
| 0abd2533-5cb3-4568-8ad2-f2852ab3a8db | < 2.5.25 |
MEDIUM | 6.5 | The Html5 Video Player plugin for WordPress is vulnerable to SQL Injection via the 'idβ parameter in all versions up t… | — | wordfence |
| 0aa21fad-4dd0-4ccd-a325-de3532a6ffaf | < 5.0.0 |
MEDIUM | 6.5 | The The AI Infographic Maker plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, … | — | wordfence |
| 0a69e4e0-0872-4604-98ae-6a0502e7e965 | < 1.0.6 |
MEDIUM | 6.5 | The The TableOn β WordPress Posts Table Filterable plugin for WordPress is vulnerable to arbitrary shortcode execution… | — | wordfence |
| 0a4521af-692a-4a84-ba9b-1904a42786c1 | MEDIUM | 6.5 | The App Builder β Create Native Android & iOS Apps On The Flight plugin for WordPress is vulnerable to Privilege Escal… | — | wordfence | |
| 09bfe9c2-fea2-4876-8f7c-0bd14060e4ad | < 3.8.2 |
MEDIUM | 6.5 | The SALESmanago plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a functio… | — | wordfence |
| 09aa2a44-8665-4f70-97a5-2e869c4610a4 | < 1.9.7 |
MEDIUM | 6.5 | The ActiveCampaign plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the c… | — | wordfence |
| 09925777-5a25-4c7a-bc05-970512992943 | MEDIUM | 6.5 | The eRoom β Webinar & Meeting Plugin for Zoom, Google Meet, Microsoft Teams plugin for WordPress is vulnerable to SQL … | — | wordfence | |
| 09831b2f-8f79-4833-8fc6-f1af56c6abc8 | < 5.0.0 |
MEDIUM | 6.5 | The WP BASE Booking of Appointments, Services and Events plugin for WordPress is vulnerable to unauthorized access of da… | — | wordfence |
| 095a2262-1da2-4f79-896c-6d48eb079a7b | < 1.1.7 |
MEDIUM | 6.5 | The AffiEasy plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.1.… | — | wordfence |
| 093611bc-1b09-4654-a7f8-b4c6bd7c72c5 | MEDIUM | 6.5 | The Video List Manager plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 1.7 due to … | — | wordfence | |
| 08eb1d49-9928-43f8-97fc-14105e3a4a25 | < 1.2.2 |
MEDIUM | 6.5 | The CTHthemes CityBook before 2.3.4, TownHub before 1.0.6, and EasyBook before 1.2.2 themes for WordPress allow unspecif… | — | wordfence |
| 08bebfbd-08f4-45d9-9570-46f5c848afca | < 1.1.2 |
MEDIUM | 6.5 | The User Meta plugin for wordPress is vulnerable to Arbitrary File Uploads in versions up to, and including 1.1.1, due t… | — | wordfence |
| 08bd24ca-eec6-4b62-af49-192496e65a5b | < 1.2.6 |
MEDIUM | 6.5 | The Youzify β BuddyPress Community, User Profile, Social Network & Membership Plugin for WordPress plugin for WordPres… | — | wordfence |
| 08aabd8d-8add-423e-835f-dc4d8bbdb72c | < 8.6.10 |
MEDIUM | 6.5 | The The MapSVG β Vector maps, Image maps, Google Maps plugin for WordPress is vulnerable to arbitrary shortcode execut… | — | wordfence |
| 085d06e1-31d3-4c01-8d8e-588c04b79ae3 | < 9.7.0 |
MEDIUM | 6.5 | The WP Recipe Maker plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the βtooltipβ parameter in… | — | wordfence |
| 085a4fae-c3f4-45f9-ab30-846c6297d04e | < 3.1.3 |
MEDIUM | 6.5 | The Product Filter for WooCommerce by WBW plugin for WordPress is vulnerable to unauthorized data loss due to a missing … | — | wordfence |
| 0830d0c3-99c0-423e-99ab-f0c1cbec52d9 | < 3.9.4 |
MEDIUM | 6.5 | The Tutor LMS β eLearning and online course solution plugin for WordPress is vulnerable to unauthorized access of data… | — | wordfence |
| 07c79459-66b8-4c93-a1cd-6e3ede95643f | < 5.1.3 |
MEDIUM | 6.5 | The User Registration & Membership β Free & Paid Memberships, Subscriptions, Content Restriction, User Profile, Custom… | — | wordfence |
| 07c0b4c5-d76e-4bdc-87d1-3144a1466c77 | < 3.1.4 |
MEDIUM | 6.5 | The SupportCandy plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and including, … | — | wordfence |
EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.
Scan My Website →