Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.
39,942 vulnerabilities found (page 763 of 1598)
| CVE ID | Plugin / Theme | Severity | CVSS | Description | Fixed In | Source |
|---|---|---|---|---|---|---|
| 52a03c45-1d65-43aa-b30f-13698019e05f | < 5.6.0 |
MEDIUM | 6.3 | miniOrange's Google Authenticator plugin for WordPress is vulnerable to authorization bypass due to a missing capability… | — | wordfence |
| 524a2143-b15f-4edc-98de-dafef4c5bc00 | < 3.8.23 |
MEDIUM | 6.3 | The The Ninja Forms β The Contact Form Builder That Grows With You plugin for WordPress is vulnerable to arbitrary sho… | — | wordfence |
| 511ce6f6-aea3-4c37-8312-d6e5ff2fdf6f | < 1.4.8 |
MEDIUM | 6.3 | The The Pojo Forms plugin for WordPress is vulnerable to arbitrary shortcode execution via form_preview_shortcode AJAX a… | — | wordfence |
| 501e3c8a-350e-4431-b6a2-012e837320bc | < 3.1.3 |
MEDIUM | 6.3 | Unspecified vulnerability in WordPress 3.1 before 3.1.3 and 3.2 before Beta 2 has unknown impact and attack vectors rela… | — | wordfence |
| 4fb0c069-ea6d-4eff-851e-b41c34b41152 | < 1.05 |
MEDIUM | 6.3 | Cross-site request forgery (CSRF) vulnerability in the Portfolio plugin before 1.05 for WordPress allows remote attacker… | — | wordfence |
| 4d252639-8cbe-4c62-9218-ebdcbaf98393 | < 3.3.3 |
MEDIUM | 6.3 | Multiple cross-site request forgery (CSRF) vulnerabilities in twitget.php in the Twitget plugin before 3.3.3 for WordPre… | — | wordfence |
| 4c3789d0-6872-4691-94d9-58e1ac303c31 | < 7.4.1 |
MEDIUM | 6.3 | The WooCommerce Stripe Payment Gateway plugin for WordPress is vulnerable to unauthorized access due to a missing capabi… | — | wordfence |
| 4aae4571-671a-46d7-b490-6cd0feced0af | MEDIUM | 6.3 | The WP Private Messages plugin for WordPress is vulnerable to SQL Injection via the βidβ parameter in versions up to… | — | wordfence | |
| 494d2e69-0759-419a-a603-e8870c157e49 | < 3.1.8 |
MEDIUM | 6.3 | The Classified Listing β Classified ads & Business Directory Plugin plugin for WordPress is vulnerable to unauthorized… | — | wordfence |
| 49008e63-d369-49b8-9dd7-3dff6dbea17c | < 4.2.3 |
MEDIUM | 6.3 | The WordPress plugin, Email Subscribers & Newsletters, before 4.2.3 had a flaw that allowed users with edit_post capabil… | — | wordfence |
| 46bc15d6-dc1b-40ec-8bb9-5342a4f84372 | < 5.3.9 |
MEDIUM | 6.3 | The XStore Core plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on several f… | — | wordfence |
| 461cec8c-77e4-4f20-8dff-c4f675dc235f | < 3.11.10 |
MEDIUM | 6.3 | The Easy Appointments plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including,… | — | wordfence |
| 45a870f4-7ad1-447b-81ea-5d9e9b67b1bb | < 1.9.9 |
MEDIUM | 6.3 | The WP Docs plugin for WordPress is vulnerable to Missing Authorization in versions up to, and including, 1.9.8. This is… | — | wordfence |
| 43fc47ca-15ca-4817-b1b8-389245725e73 | < 3.4 |
MEDIUM | 6.3 | The AI Post Generator | AutoWriter plugin for WordPress is vulnerable to unauthorized access, modification or deletion o… | — | wordfence |
| 413b2b38-44f2-4756-b66d-b6544c7ecaa2 | < 1.2.4 |
MEDIUM | 6.3 | The Shoppable Images Liteplugin for WordPress is vulnerable to unauthorized disclosure and modification of data in versi… | — | wordfence |
| 3e55591e-c1e9-4667-b04f-4956d2f37d51 | < 6.7.1 |
MEDIUM | 6.3 | The ARMember Premium plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, … | — | wordfence |
| 3cd02dbc-6725-4626-844b-df12bad9da37 | < 2.16.5 |
MEDIUM | 6.3 | The Relevanssi β A Better Search plugin for WordPress is vulnerable to authorization bypass due to missing capability … | — | wordfence |
| 3a1f3fdb-a786-4159-9020-648bc0658268 | < 3.0 |
MEDIUM | 6.3 | The multicons plugin before 3.0 for WordPress has CSRF with resultant XSS via the wp-admin/options-general.php?page=mult… | — | wordfence |
| 39fb0499-9ab4-4a2f-b0db-ece86bcf4d42 | < 2.0.2 |
MEDIUM | 6.3 | The Freemius SDK, as used by hundreds of WordPress plugin and theme developers, was vulnerable to Cross-Site Request For… | — | wordfence |
| 397f20d8-2400-4403-8543-f57141378012 | < 7.3.10 |
MEDIUM | 6.3 | The AWeber β Free Sign Up Form and Landing Page Builder Plugin for Lead Generation and Email Newsletter Growth plugin … | — | wordfence |
| 3942bba9-3c3a-47bf-9a53-95376917d6bb | < 5.8.1.1 |
MEDIUM | 6.3 | The TheGem theme for WordPress is vulnerable to improper authentication in versions up to 5.8.1.1. This makes it possibl… | — | wordfence |
| 391ef7e0-d4e6-4c2e-b15e-65bdba190b69 | < 6.4.1 |
MEDIUM | 6.3 | The WP Ultimate CSV Importer plugin for WordPress is vulnerable to authorization bypass due to a missing capability chec… | — | wordfence |
| 39003835-80df-49c7-982a-346bf328565c | < 2.2.2 |
MEDIUM | 6.3 | The WPGetAPI plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check o… | — | wordfence |
| 382dcf3d-1290-4e97-b0d6-a4b34461f8a4 | < 1.2.4 |
MEDIUM | 6.3 | The Plausible Analytics plugin is vulnerable to unauthorized setting changes in versions up to, and including, 1.2.3 due… | — | wordfence |
| 3758db41-a3c5-436a-bb9a-5886f10d1519 | < 2.10.0 |
MEDIUM | 6.3 | The WCFM Membership plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2… | — | wordfence |
EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.
Scan My Website →