Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.
39,942 vulnerabilities found (page 760 of 1598)
| CVE ID | Plugin / Theme | Severity | CVSS | Description | Fixed In | Source |
|---|---|---|---|---|---|---|
| b6bfe229-88a9-45bf-8321-0afe52797c46 | < 1.8.12 |
MEDIUM | 6.3 | The TrustMate.io integration for WooCommerce plugin for WordPress is vulnerable to Arbitrary Settings Update via the 'sa… | — | wordfence |
| b3083afd-ca84-4088-8e72-95254d56a0c0 | < 2.4.2 |
MEDIUM | 6.3 | Cross-site request forgery (CSRF) vulnerability in the WordPress File Upload plugin (wp-file-upload) before 2.4.2 for Wo… | — | wordfence |
| b1c450d9-42d8-40f5-84fc-1bc0c8cfcf9b | < 4.1.7 |
MEDIUM | 6.3 | The Houzez theme for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 4.1.6 via des… | — | wordfence |
| affdaf63-2098-4ad6-b15b-990d1941fecb | < 2.39 |
MEDIUM | 6.3 | The Minimal Coming Soon β Coming Soon Page plugin for WordPress is vulnerable to unauthorized modification of data due… | — | wordfence |
| af420213-039b-41a4-b177-4035fc727867 | < 3.6.1 |
MEDIUM | 6.3 | wp-admin/includes/post.php in WordPress before 3.6.1 allows remote authenticated users to spoof the authorship of a post… | — | wordfence |
| ae98e3bd-f663-4609-92ed-ed0431047d85 | < 1.10.26 |
MEDIUM | 6.3 | The Data Tables Generator by Supsystic plugin for WordPress is vulnerable to unauthorized access, modification or loss o… | — | wordfence |
| ad3b9040-05ed-452d-9b3f-26d1a93c62ba | < 16.26.12 |
MEDIUM | 6.3 | The WP-Recall β Registration, Profile, Commerce & More plugin for WordPress is vulnerable to arbitrary shortcode execu… | — | wordfence |
| ac3a7732-c076-4418-b44a-748cc5668107 | < 2.2.1 |
MEDIUM | 6.3 | The Discount Rules for WooCommerce plugin for WordPress is vulnerable to missing authorization via several AJAX actions … | — | wordfence |
| ab693b1f-2842-4101-99f3-eaf5b7bf5d83 | < 2.2.4 |
MEDIUM | 6.3 | The Social Share Buttons by Supsystic plugin for WordPress is vulnerable to authorization bypass due to missing capabil… | — | wordfence |
| ab1cc1ef-d0e0-491d-91a8-eaa0605fc1da | < 8.6.1 |
MEDIUM | 6.3 | The Indeed Membership Pro plugin for WordPress is vulnerable to authorization bypass due to missing capability checks on… | — | wordfence |
| aaef8d31-52e5-4bda-b2d6-e8df31c2c16a | < 2.0.0 |
MEDIUM | 6.3 | The Elite Notification β Sales Popup, Social Proof, FOMO & WooCommerce Notification plugin for WordPress is vulnerable… | — | wordfence |
| aa6d82f7-cee4-4640-a736-26e3a35712e1 | < 1.11.19 |
MEDIUM | 6.3 | The Easy Google Maps plugin for WordPress is vulnerable to XML External Entity Injection in all versions up to, and incl… | — | wordfence |
| aa60ed7c-baf3-4308-b4bf-1baa928d8e37 | < 2.79 |
MEDIUM | 6.3 | Multiple cross-site request forgery (CSRF) vulnerabilities in the Disqus Comment System plugin before 2.79 for WordPress… | — | wordfence |
| aa3497ae-7f3a-4e67-ad7a-77b50dccaf3b | MEDIUM | 6.3 | The MagicForm plugin for WordPress is vulnerable to access and modification of data due to a missing capability check on… | — | wordfence | |
| a9ee709d-6590-4c07-9788-6150733c1691 | < 2.0.29 |
MEDIUM | 6.3 | The Booking Manager plugin for WordPress is vulnerable to Server-Side Request Forgery in versions up to, and including, … | — | wordfence |
| a9892dd1-3939-41a9-a828-fa1bf7d96eb8 | < 1.7.33 |
MEDIUM | 6.3 | The PWA for WP & AMP plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the… | — | wordfence |
| a8c8d839-d2a4-4b2a-ad61-a3cda7826636 | < 1.4.2 |
MEDIUM | 6.3 | The Duplicate Post plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.… | — | wordfence |
| a57675f0-d840-4954-b86e-a9fbc1483bc7 | < 1.25.5 |
MEDIUM | 6.3 | The Name Directory plugin for WordPress is vulnerable to unauthorized settings update due to insufficient permissions ch… | — | wordfence |
| a56df440-a1ed-4c5a-ac9c-5ddeffb28e60 | < 4.1.8 |
MEDIUM | 6.3 | The Responsive Menu plugin for WordPress is vulnerable to authorization bypass due to missing authorization checks on va… | — | wordfence |
| a4e26035-ce4e-4b4b-aa3c-cd86b29b199a | MEDIUM | 6.3 | The Page Builder by AZEXO plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and includ… | — | wordfence | |
| a3a715b9-85df-46dd-9207-2066b6da9c43 | < 3.64.1 |
MEDIUM | 6.3 | The Popup Builder plugin before 3.64.1 for WordPress allows information disclosure and settings modification, leading to… | — | wordfence |
| a39e9b54-6beb-4dbd-a4cf-ba05e73a58a0 | < 1.4.1 |
MEDIUM | 6.3 | The WP Sticky Button plugin for WordPress is vulnerable to unauthenticated plugin settings update in versions up to, and… | — | wordfence |
| a2c5e232-3561-43a1-bdfa-4a68f20b5889 | < 1.1.2 |
MEDIUM | 6.3 | The Frontend File Manager & Sharing β User Private Files plugin for WordPress is vulnerable to authorization bypass in… | — | wordfence |
| a09659bc-e42b-4f08-a1a1-23e226be1be9 | < 2.5.6 |
MEDIUM | 6.3 | The The Discussion Board β WordPress Forum Plugin plugin for WordPress is vulnerable to arbitrary shortcode execution … | — | wordfence |
| 9ff51513-309c-49d5-a03a-11224e404a94 | < 4.19 |
MEDIUM | 6.3 | The Accessibility Suite by Ability, Inc plugin for WordPress is vulnerable to unauthorized access due to a missing capab… | — | wordfence |
EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.
Scan My Website →