Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.
40,369 vulnerabilities found (page 1023 of 1615)
| CVE ID | Plugin / Theme | Severity | CVSS | Description | Fixed In | Source |
|---|---|---|---|---|---|---|
| f65cb1f6-e72e-4848-b72c-99b83e5401e8 | MEDIUM | 5.5 | The Cookie Law Bar plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1… | — | wordfence | |
| f63bf296-b34c-4f89-90eb-bba2a0461d57 | < 2.0.5 |
MEDIUM | 5.5 | The Related Posts for WordPress plugin through 2.0.4 does not sanitise its heading_text and CSS settings, allowing high … | — | wordfence |
| f5e88393-c76b-49b6-a55c-06094e6f82d8 | < 1.4.9 |
MEDIUM | 5.5 | The Login with Cognito plugin for WordPress is vulnerable to Stored Cross-Site Scripting via an unknown parameter in ver… | — | wordfence |
| f5531449-c70f-488f-95ee-5208138968d1 | < 2.1.4 |
MEDIUM | 5.5 | The Post SMTP Mailer/Email Log plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘input_tmp_di… | — | wordfence |
| f4b1e7da-dbcd-4206-b908-4c814cde39d9 | < 1.5.0 |
MEDIUM | 5.5 | The Post Grid, Slider & Carousel Ultimate WordPress plugin before 1.5.0 does not sanitise and escape the Header Title, w… | — | wordfence |
| f4a4e3ef-ee88-4175-8628-c5511c20bf23 | < 3.7.17 |
MEDIUM | 5.5 | Multiple cross-site scripting (XSS) vulnerabilities in wp-admin/update-core.php in WordPress before 4.7.1 allow remote a… | — | wordfence |
| f477761d-3fad-4d35-8d41-d1710ec090f7 | < 4.4.0 |
MEDIUM | 5.5 | The Church Admin plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including,… | — | wordfence |
| f3efd8d5-fa85-4910-8552-f38e92d7515e | MEDIUM | 5.5 | The WP Parallax Content Slider plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and … | — | wordfence | |
| f3e94710-66c5-4b96-a32b-525760ee4570 | < 3.7.0 |
MEDIUM | 5.5 | The Sina Extension for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, an… | — | wordfence |
| f3d52baf-0f2b-4791-96ce-ec57502ed646 | < 2.4 |
MEDIUM | 5.5 | The WP Zillow Review Slider WordPress plugin before 2.4 does not escape a settings, which could allow high privilege use… | — | wordfence |
| f37fbbd8-234f-41bd-bb46-44de440f977c | MEDIUM | 5.5 | The Beaf – Photo Comparison Block plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up… | — | wordfence | |
| f328b938-355d-426f-a9cf-646929a7c155 | < 3.9.31 |
MEDIUM | 5.5 | The Locatoraid Store Locator plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all… | — | wordfence |
| f2ce4a14-5c56-4ca0-9deb-80cd609b71e6 | MEDIUM | 5.5 | The WP Config File Editor WordPress plugin through 1.7.1 was affected by an Authenticated Stored Cross-Site Scripting (X… | — | wordfence | |
| f27853e0-1785-4670-a7b2-f72c19f4a6ac | MEDIUM | 5.5 | The WP Clictracker plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1… | — | wordfence | |
| f2675177-8b85-4fb8-ba10-ae02cb5c6c72 | < 3.2.4 |
MEDIUM | 5.5 | The Booking calendar plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in versions up… | — | wordfence |
| f25b2a4b-d863-4f24-ae67-4c8e41602c6f | < 3.1.42 |
MEDIUM | 5.5 | The WP Event Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including,… | — | wordfence |
| f2329a5d-0649-498e-a18c-a17de7b30df4 | < 6.5.2 |
MEDIUM | 5.5 | The Modern Events Calendar Lite plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and… | — | wordfence |
| f21c70aa-22be-456d-93bb-f478b70deaef | < 3.7.21 |
MEDIUM | 5.5 | In WordPress before 4.7.5, a cross-site scripting (XSS) vulnerability related to the Customizer exists, involving an inv… | — | wordfence |
| f2126761-cbff-4d46-a6df-4566d15216d7 | < 5.1.0 |
MEDIUM | 5.5 | The MW WP Form plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 5.0.6… | — | wordfence |
| f1666371-9401-4b62-b44e-abc7fb4c6138 | < 1.4.0 |
MEDIUM | 5.5 | Authenticated (admin user role) Persistent Cross-Site Scripting (XSS) in Mark Daniels Night Mode plugin <= 1.0.0 on Word… | — | wordfence |
| f10fdf31-6941-4d41-8c15-90ed61addc2f | < 3.7.17 |
MEDIUM | 5.5 | Cross-site scripting (XSS) vulnerability in the theme-name fallback functionality in wp-includes/class-wp-theme.php in W… | — | wordfence |
| f00cdef3-d733-4e85-8099-204ef76096b4 | < 9.8.5 |
MEDIUM | 5.5 | The Image Hover Effects Ultimate plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several values th… | — | wordfence |
| f002e61b-7395-4ba7-8695-da17cfc001cc | < 6.0.6 |
MEDIUM | 5.5 | The WP Maintenance plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 6… | — | wordfence |
| eff9fcce-01b2-4698-a2c2-ee5991bfd963 | < 1.8.2 |
MEDIUM | 5.5 | The Patreon WordPress plugin for WordPress is vulnerable to Cross-Site Scripting in versions up to, and including, 1.8.1… | — | wordfence |
| ee95976d-6454-466b-96b3-7c33ccc03d41 | MEDIUM | 5.5 | The Simple Real Estate Pack WordPress plugin through 1.4.8 does not sanitise and escape some of its settings, which coul… | — | wordfence |
EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.
Scan My Website →