Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.
39,942 vulnerabilities found (page 764 of 1598)
| CVE ID | Plugin / Theme | Severity | CVSS | Description | Fixed In | Source |
|---|---|---|---|---|---|---|
| 35cc980b-9c52-4f0b-aeb2-4afa6efacd8f | < 1.10.6 |
MEDIUM | 6.3 | The WP ERP Plugin for WordPress is vulnerable to Sensitive Data Exposure in versions up to, and including, 1.10.5 due to… | — | wordfence |
| 3541794b-7c8a-42f8-9688-7f3dbbb08e58 | < 3.3.3 |
MEDIUM | 6.3 | The ELEX WordPress HelpDesk & Customer Ticketing System plugin for WordPress is vulnerable to Privilege Escalation in al… | — | wordfence |
| 33cf27ba-a01b-4e34-9584-b1d3fc87af34 | < 2.1.0 |
MEDIUM | 6.3 | The Discount Rules for WooCommerce plugin for WordPress is vulnerable to missing authorization via several AJAX actions … | — | wordfence |
| 2d776d94-8c81-4e88-bae3-946824a75c09 | < 2.6.12 |
MEDIUM | 6.3 | The bbPress plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.6.1… | — | wordfence |
| 2d0529df-70be-4559-a760-5537e0fd4d1e | < 3.2 |
MEDIUM | 6.3 | Unspecified vulnerability in WordPress 3.1 before 3.1.3 and 3.2 before Beta 2 has unknown impact and attack vectors rela… | — | wordfence |
| 2b81d7fc-6050-40bb-9416-e8d7d20e8ef8 | < 1.14.2.2 |
MEDIUM | 6.3 | The codection "Import users from CSV with meta" plugin before 1.14.2.2 for WordPress allows wp-admin/admin-ajax.php?acti… | — | wordfence |
| 29cc5016-005e-48e8-b929-5064798f24da | MEDIUM | 6.3 | The URL Shortener Plugin For WordPress plugin for WordPress is vulnerable to unauthorized access to functionality provid… | — | wordfence | |
| 293070c8-783f-404d-9250-392713703ce4 | MEDIUM | 6.3 | The Waiting: One-click countdowns plugin for WordPress is vulnerable to authorization bypass due to missing capability c… | — | wordfence | |
| 283fb581-8b61-4008-a5c4-2e1490fab33e | < 4.6.5 |
MEDIUM | 6.3 | The Essential Addons for Elementor plugin for WordPress is vulnerable to authorization bypass in versions up to and incl… | — | wordfence |
| 26404b5c-a0f2-4223-be61-1f03873666fb | < 3.2 |
MEDIUM | 6.3 | The Lead Form Data Collection to CRM plugin for WordPress is vulnerable to unauthorized access due to a missing capabili… | — | wordfence |
| 245ae6f7-3539-4c91-89f1-29d1e12493b7 | < 2.1.2 |
MEDIUM | 6.3 | The Abandoned Cart Recovery for WooCommerce by Autonami plugin for WordPress is vulnerable to unauthorized execution of … | — | wordfence |
| 242e99d1-db27-45fa-a90d-5a26c2d1901b | < 2.3.2 |
MEDIUM | 6.3 | The Spectra β WordPress Gutenberg Blocks plugin for WordPress is vulnerable to authorization bypass due to a missing c… | — | wordfence |
| 22eda61d-c802-4e9b-a68c-d5ff7d69890c | < 4.1.21 |
MEDIUM | 6.3 | The Eventin plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions up to, and including, 4.1… | — | wordfence |
| 20de9544-b2fe-470c-a7a4-b662b59d6d31 | < 1.5.1.15 |
MEDIUM | 6.3 | Cross-site request forgery (CSRF) vulnerability in Cart66Product.php in the Cart66 Lite plugin before 1.5.1.15 for WordP… | — | wordfence |
| 1f2d149b-fe63-4fa3-b840-02dc8c5f9323 | < 1.3.7 |
MEDIUM | 6.3 | The Food Store plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions before 1.3.7. This is due to… | — | wordfence |
| 1e1d8afa-0a38-434b-b3d8-04019010ab21 | < 1.0.9.2 |
MEDIUM | 6.3 | The Transposh WordPress Translation plugin for WordPress is vulnerable to authorization bypass due to a missing capabili… | — | wordfence |
| 1d2b7215-d3a7-4e5a-ae9b-65fecc26dceb | < 8.9.2 |
MEDIUM | 6.3 | The NEX-Forms β Ultimate Form Builder β Contact forms and much more plugin for WordPress is vulnerable to Limited Co… | — | wordfence |
| 1bda01a0-e995-4642-81e3-4a72e6754af6 | < 2.0.22 |
MEDIUM | 6.3 | The Simple Social Media Share Buttons plugin for WordPress is vulnerable to authorization bypass due to a missing capabi… | — | wordfence |
| 1a2fb050-1a7c-45cc-86c7-02331d47f780 | < 2.2.5 |
MEDIUM | 6.3 | The WPSchoolPress plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.2… | — | wordfence |
| 19f2fe7c-f702-4db6-9914-2839a62ffdd5 | < 5.0 |
MEDIUM | 6.3 | The "Discy - Social Questions and Answers WordPress Theme" theme for WordPress is vulnerable to authorization bypass due… | — | wordfence |
| 1814d2ad-73b1-4440-9cd6-7c5c569c4fb2 | < 5.0.4 |
MEDIUM | 6.3 | The Contact Form 7 plugin for WordPress is vulnerable to authorization bypass due to capability_type mishandling in regi… | — | wordfence |
| 1766727d-ba54-4b46-b362-415c14be027d | < 2.1.5 |
MEDIUM | 6.3 | The The Notibar β Notification Bar for WordPress plugin for WordPress is vulnerable to arbitrary shortcode execution v… | — | wordfence |
| 14689386-fca5-48a6-9494-4a79b920d5f8 | < 3.4.2 |
MEDIUM | 6.3 | The create_post function in wp-includes/class-wp-atom-server.php in WordPress before 3.4.2 does not perform a capability… | — | wordfence |
| 14376064-13c4-4874-afea-395af2a1933d | MEDIUM | 6.3 | The vSlider Multi Image Slider plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and i… | — | wordfence | |
| 11d49c89-43be-4e12-86b5-aa7a72a89803 | < 1.8.97 |
MEDIUM | 6.3 | The AI Power: Complete AI Pack plugin for WordPress is vulnerable to unauthorized access due to a missing capability che… | — | wordfence |
EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.
Scan My Website →