Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.
39,942 vulnerabilities found (page 758 of 1598)
| CVE ID | Plugin / Theme | Severity | CVSS | Description | Fixed In | Source |
|---|---|---|---|---|---|---|
| f2e36b11-db93-4bac-a9bd-16d2e22efe4d | MEDIUM | 6.3 | The WP-MUI β Mass User Input β Add and Export WP Users Quickly plugin for WordPress is vulnerable to authorization b… | — | wordfence | |
| f167c3c5-df35-456c-a5f1-139cc3c02ffb | < 2.4.49.1 |
MEDIUM | 6.3 | The CSS JS Manager plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.… | — | wordfence |
| f0c7324f-4c22-44e0-8d2a-9b95fd89467d | MEDIUM | 6.3 | The vSlider Multi Image Slider plugin for WordPress is vulnerable to unauthorized access of data, modification of data, … | — | wordfence | |
| efbecb4b-fc41-4719-be5e-af11b47ff683 | < 1.1.14 |
MEDIUM | 6.3 | The LoginPress plugin before 1.1.4 for WordPress has no capability check for updates to settings. | — | wordfence |
| ee0eead2-3eab-4a2a-bfe4-c0d8f91dc0a5 | < 4.0.52 |
MEDIUM | 6.3 | The The ARMember β Membership Plugin, Content Restriction, Member Levels, User Profile & User signup plugin for WordPr… | — | wordfence |
| ed6e2b9e-3d70-4c07-a779-45164816b89c | < 5.1.2 |
MEDIUM | 6.3 | The UserPro plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 5.1.1. Th… | — | wordfence |
| ec5e4e3f-df8f-4e07-a6e0-72247b2dd7a7 | < 21.7 |
MEDIUM | 6.3 | The WooCommerce Multiple Customer Addresses & Shipping plugin for WordPress is vulnerable to Missing Authorization in ve… | — | wordfence |
| ec0fff2a-602d-441b-89d1-64d609a4abc0 | < 3.72 |
MEDIUM | 6.3 | The Popup Builder plugin for WordPress is vulnerable to authorization bypass in versions up to, and including 3.71 due t… | — | wordfence |
| ec03840e-807b-4a9c-87e7-a1560b8b7f5c | < 7.3.0 |
MEDIUM | 6.3 | The Directorist β WordPress Business Directory Plugin with Classified Ads Listings plugin for WordPress is vulnerable … | — | wordfence |
| eb99c1a0-a0c3-4a6e-84b1-4ced45015db4 | < 2.10.5 |
MEDIUM | 6.3 | The Really Simple Facebook Twitter Share Buttons plugin for WordPress is vulnerable to Cross-Site Request Forgery in ver… | — | wordfence |
| e9e256b0-e4e3-4f41-842c-80aa2b80af72 | < 3.5.5 |
MEDIUM | 6.3 | The affiliate-toolkit β WordPress Affiliate Plugin plugin for WordPress is vulnerable to unauthorized access due to a … | — | wordfence |
| e999f4c0-03dd-4ea3-9245-b12ffd8da3e2 | < 1.7.4 |
MEDIUM | 6.3 | The Contact Form & Lead Form Elementor Builder plugin for WordPress is vulnerable to Arbitrary Settings Change in versio… | — | wordfence |
| e93ad115-1a0b-4d33-b89f-13e39508c9b0 | < 7.1.0 |
MEDIUM | 6.3 | The Careerfy theme for WordPress is vulnerable to authorization bypass & Cross-Site Request Forgery in versions up to, a… | — | wordfence |
| e92ce899-556f-4a17-8902-1919d485ee15 | < 2.0.7 |
MEDIUM | 6.3 | Vulnerable versions of the JupiterX Core plugin register an AJAX action jupiterx_conditional_manager which can be used t… | — | wordfence |
| e8d75eb6-2a9f-4c33-9e15-db7db037b67e | < 1.6.0 |
MEDIUM | 6.3 | The Health Check & Troubleshooting plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, a… | — | wordfence |
| e702675c-b3ec-458b-a382-cba5c03879c2 | MEDIUM | 6.3 | The OnePress Opt-In Panda plugin for WordPress is vulnerable to unauthorized modification of settings and retrieval of p… | — | wordfence | |
| e64e41a1-ea8e-41b4-911c-672caf0d2df1 | MEDIUM | 6.3 | The UserPlus plugin for WordPress is vulnerable to unauthorized access, modification, and loss of data due to a missing … | — | wordfence | |
| e35be8ee-81a3-42ce-8304-992bc75663fd | < 2.0.6 |
MEDIUM | 6.3 | The wpForo Forum plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions up to, and including… | — | wordfence |
| e093a923-4b9b-4def-a81b-78584aead5c1 | < 1.7.8 |
MEDIUM | 6.3 | The WordPress plugin Custom Product Tabs for WooCommerce is vulnerable to unauthenticated options update due to lack of … | — | wordfence |
| db8bebe2-c50c-4148-b232-04bcd808745e | < 1.2.7 |
MEDIUM | 6.3 | The Shapely Companion plugin for WordPress is vulnerable to arbitrary content import due to missing authorization checks… | — | wordfence |
| da0950ad-4d6c-46fe-83c9-c14653fe9f1f | MEDIUM | 6.3 | The Backup Scheduler plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on sev… | — | wordfence | |
| d946d4b5-bed7-4808-b133-783b2dcd7992 | < 6.6.1 |
MEDIUM | 6.3 | The WCFM Frontend Manager plugin for WordPress is vulnerable to unauthorized modification and access of data in versions… | — | wordfence |
| d937cacb-eb80-4c7c-9105-4ac4bd5c48cd | < 1.0.2 |
MEDIUM | 6.3 | The Category Icon plugin for WordPress is vulnerable to XML External Entity Injection (XXE) in versions up to, and inclu… | — | wordfence |
| d7d94443-3ab2-4d89-a580-2e9697d28cd7 | < 3.5.2 |
MEDIUM | 6.3 | WordPress before 3.5.2 does not properly check the capabilities of roles, which allows remote authenticated users to byp… | — | wordfence |
| d7b33199-d254-4d0c-88d0-ad2f7515d747 | MEDIUM | 6.3 | The Kingkong Board plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on one of… | — | wordfence |
EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.
Scan My Website →