Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.
40,369 vulnerabilities found (page 1022 of 1615)
| CVE ID | Plugin / Theme | Severity | CVSS | Description | Fixed In | Source |
|---|---|---|---|---|---|---|
| fe44fe7f-0ccf-4297-a9a7-107695abfe13 | < 2.3.1 |
MEDIUM | 5.5 | The Uji Countdown plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's settings in version… | — | wordfence |
| fe31346e-a06e-4b4d-b13c-7a98dca53274 | < 2.11.17 |
MEDIUM | 5.5 | The Welcart e-Commerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via settings in all versions up… | — | wordfence |
| fde163fa-2dbf-43bc-8edc-cbbab2a35bd0 | MEDIUM | 5.5 | The DrawBlog WordPress plugin through 0.90 does not sanitise or validate some of its settings before outputting them bac… | — | wordfence | |
| fdd14863-5498-4598-8b22-8e5a607869e4 | < 1.3.11 |
MEDIUM | 5.5 | Video Gallery – YouTube Playlist, Channel Gallery by YotuWP is vulnerable to Stored Cross-Site Scripting in versions u… | — | wordfence |
| fd3298dd-af80-481e-8d20-d33e7bb9bb85 | MEDIUM | 5.5 | The KJM Admin Notices WordPress plugin is vulnerable to Stored Cross-Site Scripting due to insufficient input validation… | — | wordfence | |
| fd235256-e48c-4f1b-a51b-25669b560c77 | MEDIUM | 5.5 | The gee Search Plus, improved WordPress search plugin for WordPress is vulnerable to Stored Cross-Site Scripting via adm… | — | wordfence | |
| fc3c22a2-b766-419c-a481-48e6a73b084c | < 5.1.3.4 |
MEDIUM | 5.5 | The Survey Maker plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘ays_sections[5][questions]… | — | wordfence |
| fbee3720-6ab9-4470-b2d2-09824db8de4d | < 1.3.2 |
MEDIUM | 5.5 | The Where Did You Hear About Us Checkout Field for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site S… | — | wordfence |
| fbb9b4c8-18b6-4215-a7ee-c5a49977aec7 | MEDIUM | 5.5 | The Epeken All Kurir plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including,… | — | wordfence | |
| fb87726f-868d-4b2e-b818-d303e695c69c | < 4.59.4 |
MEDIUM | 5.5 | The amr users WordPress plugin before 4.59.4 does not sanitise and escape some of its settings, which could allow high p… | — | wordfence |
| fb2f463f-2c99-4a6c-92b9-45fb2192381d | MEDIUM | 5.5 | The Video Thumbnails plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's settings in vers… | — | wordfence | |
| fa3d4308-0e34-4749-a7da-935d416ad2d0 | < 1.9 |
MEDIUM | 5.5 | The Feedweb plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'wp_post_id' parameter in versions… | — | wordfence |
| fa181ff8-5324-4782-ad45-4a701ac63b8c | < 1.7.6 |
MEDIUM | 5.5 | The CM Ad Changer plugin for WordPress is vulnerable to Cross-Site Scripting via several parameters in versions before 1… | — | wordfence |
| fa139703-e83e-4a19-a801-464b72a2acc4 | < 3.7.40 |
MEDIUM | 5.5 | WordPress Core is vulnerable to Stored Cross-Site Scripting, exploitable during comment editing, in versions up to 6.0.3… | — | wordfence |
| fa05ad02-8625-4bf9-983e-548fbb7634f3 | MEDIUM | 5.5 | The Qe SEO Handyman plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 1.0 due to ins… | — | wordfence | |
| f9ad3a88-fcfd-45c5-a23d-ca544cad3ab2 | MEDIUM | 5.5 | The Content Repeater plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including,… | — | wordfence | |
| f9478d3e-d2f9-458b-a6ca-3baef21db60e | < 2.1.0 |
MEDIUM | 5.5 | The Accordions plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘license’ parameter used in… | — | wordfence |
| f8e6bfd4-9003-4ac6-96a1-0c7024b2a800 | < 7.4.1 |
MEDIUM | 5.5 | The Link Library plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's settings in versions… | — | wordfence |
| f8d093ae-e0b1-49c2-a492-e01f2e954ddb | < 1.30.3 |
MEDIUM | 5.5 | The MPL-Publisher WordPress plugin is vulnerable to Stored Cross-Site Scripting due to insufficient input validation and… | — | wordfence |
| f7cb3540-ffdb-4b4c-a518-4ca8232ab53f | < 9.1.3 |
MEDIUM | 5.5 | The WP Statistics plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'Check for online users ever… | — | wordfence |
| f7c9fb37-bda0-4a5d-811e-1f422c58bb06 | MEDIUM | 5.5 | The WP Featured Content Slider plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and … | — | wordfence | |
| f787cad3-cf99-413a-952f-082fae973bef | < 3.1.1 |
MEDIUM | 5.5 | The Autoptimize plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the critical css settings rules in… | — | wordfence |
| f6e47659-90d9-4990-a19d-3954d65417df | MEDIUM | 5.5 | The Job Manager WordPress plugin is vulnerable to Stored Cross-Site Scripting due to insufficient input validation and s… | — | wordfence | |
| f6cba253-dfb0-485d-8b81-8e3bbaec8441 | < 1.1.9 |
MEDIUM | 5.5 | The RSS Feed Pro plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.1… | — | wordfence |
| f6c4ec70-22b5-49e1-a00b-5b29aab5fc91 | < 1.8.5 |
MEDIUM | 5.5 | The Split Test For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and in… | — | wordfence |
EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.
Scan My Website →