Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.
39,942 vulnerabilities found (page 762 of 1598)
| CVE ID | Plugin / Theme | Severity | CVSS | Description | Fixed In | Source |
|---|---|---|---|---|---|---|
| 74d222b9-22e9-485d-8111-d3bee505b200 | < 2.7.0 |
MEDIUM | 6.3 | Several WordPress plugins by Wbcom Designs were vulnerable to arbitrary plugin installation, activation and deactivation… | — | wordfence |
| 72bdc81e-1a9d-4dd8-93a5-fb1026d6a2d9 | < 27.1.2 |
MEDIUM | 6.3 | The Betheme theme for WordPress is vulnerable to unauthorized access of functionality due to a missing capability check … | — | wordfence |
| 6efc3120-4eb0-4816-85ff-afe0aa8adbf0 | < 5.0 |
MEDIUM | 6.3 | The NebulaX Theme plugin for WordPress is vulnerable to SQL Injection via the nebula_send_to_hubspot() function in all v… | — | wordfence |
| 6ebc1b85-4682-4467-b17c-9a35cc3f0f15 | < 5.3.0 |
MEDIUM | 6.3 | The WP Easycart plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 5.2.6… | — | wordfence |
| 6e15d285-aa1d-461d-bdc2-642e7ccd789b | < 3.4.7 |
MEDIUM | 6.3 | The Print Labels with Barcodes. Create price tags, product labels, order labels for WooCommerce plugin for WordPress is … | — | wordfence |
| 6d700580-1374-4a17-a6b3-59ba1d063030 | < 3.1.23 |
MEDIUM | 6.3 | The WordPress Download Manager plugin for WordPress is vulnerable to arbitrary asset manager usage in versions before 3.… | — | wordfence |
| 6aae5b1d-9b84-4628-b0b6-7b39054e08a0 | < 4.1.2 |
MEDIUM | 6.3 | The Import any XML or CSV File to WordPress plugin for WordPress is vulnerable to authorization bypass in versions up to… | — | wordfence |
| 6aa2d172-73b6-487d-ae65-0920f915e750 | < 3.3.10 |
MEDIUM | 6.3 | The Multiple Page Generator Plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and incl… | — | wordfence |
| 67021dde-a21c-4281-b4f2-acc840efcc69 | < 2.7.2 |
MEDIUM | 6.3 | The JS Help Desk plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on an unkn… | — | wordfence |
| 64f51991-f767-4f7b-94e7-68c0e2214849 | < 3.0.6 |
MEDIUM | 6.3 | wp-admin/press-this.php in WordPress before 3.0.6 does not enforce the publish_posts capability requirement, which allow… | — | wordfence |
| 64eb3d67-7056-4a03-ba3b-a04c2e96648d | < 3.3.9 |
MEDIUM | 6.3 | The MasterStudy LMS WordPress Plugin β for Online Courses and Education plugin for WordPress is vulnerable to unauthor… | — | wordfence |
| 644624d8-c193-4ee6-bc82-7ccda5d7f2ac | < 4.7.0 |
MEDIUM | 6.3 | The Fancy Product Designer plugin for WordPress is vulnerable to unauthorized access to data and modification of plugin … | — | wordfence |
| 5fd470bb-d791-45dc-a743-6f03fc75f00c | < 1.2.1 |
MEDIUM | 6.3 | The Editorialmag theme for WordPress is vulnerable to unauthorized modification of data due to a missing capability chec… | — | wordfence |
| 5fbb2dcf-38b8-4ef1-bfea-bf5872cc7e37 | < 2.1.4.3 |
MEDIUM | 6.3 | The The InPost Gallery plugin for WordPress is vulnerable to arbitrary shortcode execution via the inpost_gallery_get_sh… | — | wordfence |
| 5f9cf9c5-d836-4414-a53f-adee2784bd96 | < 11.16 |
MEDIUM | 6.3 | The Media from FTP plugin for WordPress is vulnerable to improper privilege management due to an insufficient capability… | — | wordfence |
| 5df8983e-16c9-4a23-9bf4-331d70384e74 | < 5.3.5 |
MEDIUM | 6.3 | Cross-site request forgery (CSRF) vulnerability in he Digg Digg plugin before 5.3.5 for WordPress allows remote attacker… | — | wordfence |
| 5dec045a-b87c-4db5-960e-8888e410a950 | < 3.1 |
MEDIUM | 6.3 | Cross-site request forgery (CSRF) vulnerability in the Login With Ajax plugin before 3.1 for WordPress allows remote att… | — | wordfence |
| 5d635669-ee85-4fb5-8238-3edb3bbb8fb4 | < 2.0.16 |
MEDIUM | 6.3 | The Draw Attention plugin for WordPress is vulnerable to unauthorized modification of data due improper capability mappi… | — | wordfence |
| 5c2cc9a3-cd20-4c9e-baa4-1aea69f84331 | < 3.5.0 |
MEDIUM | 6.3 | The WCFM Marketplace plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, … | — | wordfence |
| 59b09f36-79e8-4f14-b970-a7994d193782 | < 2.2.0 |
MEDIUM | 6.3 | The WooCommerce Warranty Requests plugin for WordPress is vulnerable to unauthorized use of functionality due to a missi… | — | wordfence |
| 56f9d46f-5c21-4e8e-8e77-c96c4a0562d1 | < 1.9.92 |
MEDIUM | 6.3 | The data-tables-generator-by-supsystic plugin before 1.9.92 for WordPress lacks capability checks for AJAX actions. | — | wordfence |
| 5681101f-13c3-4fde-bbde-554810bcbe4e | < 4.1.6 |
MEDIUM | 6.3 | The Advanced Dynamic Pricing for WooCommerce plugin for WordPress is vulnerable to authorization bypass due to a missing… | — | wordfence |
| 55a942b7-5d3e-4ddf-8bc3-61ff90a7fdbd | < 2.1.6 |
MEDIUM | 6.3 | The All in One SEO plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the a… | — | wordfence |
| 557172d0-33ad-427a-b575-df529e2aaab0 | < 2.6.11 |
MEDIUM | 6.3 | Cross-site request forgery (CSRF) vulnerability in the MailPoet Newsletters (wysija-newsletters) plugin before 2.6.11 fo… | — | wordfence |
| 53199f3c-80d1-4c4e-93ef-8a234ba8ba85 | < 9.7.5 |
MEDIUM | 6.3 | The Quick Event Manager plugin for WordPress is vulnerable to authorization bypass due to missing authorization checks o… | — | wordfence |
EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.
Scan My Website →