Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.
40,369 vulnerabilities found (page 1027 of 1615)
| CVE ID | Plugin / Theme | Severity | CVSS | Description | Fixed In | Source |
|---|---|---|---|---|---|---|
| d5a124b3-257b-4331-ac8f-eecd7a759127 | MEDIUM | 5.5 | The WP-OliveCart plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.1… | — | wordfence | |
| d592b81d-48c7-4b48-948d-f2b98719fdfc | < 2.35 |
MEDIUM | 5.5 | The Minimal Coming Soon plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘custom_css’ and '… | — | wordfence |
| d5744ed4-f150-48a6-9f5d-d49f9d4c8454 | MEDIUM | 5.5 | The Flex Local Fonts WordPress plugin through 1.0.0 does not escape the Class Name field when adding a font, which could… | — | wordfence | |
| d542c1e8-7e9f-4687-8739-0ebcb865b998 | < 2.0.0 |
MEDIUM | 5.5 | The Media Library Categories plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘wpmediacategor… | — | wordfence |
| d4b4b5a0-b121-4ed2-b3ae-506f2950c7cf | < 3.9.1 |
MEDIUM | 5.5 | The Webling plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 3.9.0 du… | — | wordfence |
| d44f8891-cc24-4f6f-9032-3a4c632c6fb6 | < 6.8.1 |
MEDIUM | 5.5 | The Sirv plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘SIRV_ACCOUNT_EMAIL’ parameter in… | — | wordfence |
| d3b954e6-cf5d-4451-b770-777d116edd90 | < 2.0.6 |
MEDIUM | 5.5 | The Image Gallery - Responsive Photo Gallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the r… | — | wordfence |
| d3a9a836-34c1-4ef3-9cde-c7ccb3163165 | MEDIUM | 5.5 | The SEO 301 Meta WordPress plugin through 1.9.1 does not escape its Request and Destination settings, allowing high priv… | — | wordfence | |
| d2a77443-9fca-4686-be48-b3905a33c87f | < 1.1.4 |
MEDIUM | 5.5 | The TinyMCE Custom Styles plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in versio… | — | wordfence |
| d24b34d9-3aa3-46df-9000-eda8e416aa49 | < 1.11.0 |
MEDIUM | 5.5 | The WP Bannerize Pro plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and includ… | — | wordfence |
| d1d9166d-2715-4aa6-bf72-313708ac2910 | MEDIUM | 5.5 | The Weather Layer plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 4.… | — | wordfence | |
| d1b4841b-c701-4915-9592-518e68179d20 | MEDIUM | 5.5 | The Highlight Focus plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, … | — | wordfence | |
| d0e2ae5c-685d-4cf0-91e2-2f8620b2eb6b | MEDIUM | 5.5 | The Better Tag Cloud plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several setting parameters in… | — | wordfence | |
| d0586453-76ec-4ec9-9965-780af7cb31ec | < 2.21.06.29 |
MEDIUM | 5.5 | The Async Javascript plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the '&aj_gtmetrix_username=' … | — | wordfence |
| d0237d64-40db-4e4e-be61-893217135ef7 | MEDIUM | 5.5 | The AM-HiLi plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.0 due… | — | wordfence | |
| cfec9303-bdc5-4ba7-90dd-0c7559459d23 | < 2.3.9.6 |
MEDIUM | 5.5 | The plugin Countdown, Coming Soon, Maintenance – Countdown & Clock for WordPress is vulnerable to Stored Cross-Site Sc… | — | wordfence |
| cfc59e3d-13c6-4051-8a1a-d109ea06b10b | MEDIUM | 5.5 | The Opening Hours plugin for WordPress is vulnerable to Cross-Site Scripting in versions up to, and including, 2.3.0, vi… | — | wordfence | |
| cf9470c9-693b-4f36-91d9-26b2d488b377 | < 4.7 |
MEDIUM | 5.5 | Multiple Persistent cross-site scripting (XSS) issues in the Techotronic all-in-one-favicon (aka All In One Favicon) plu… | — | wordfence |
| cf753fcf-9db0-4161-97e5-0f09c3452544 | < 2.6.1 |
MEDIUM | 5.5 | The Appointment Bookings for Zoom GoogleMeet and more – Wappointment plugin for WordPress is vulnerable to Server-Side… | — | wordfence |
| ce23efed-fe21-486a-ab3b-9ed0dd26a971 | < 5.5.8 |
MEDIUM | 5.5 | The AI ChatBot for WordPress – WPBot plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin setti… | — | wordfence |
| cd93da2b-a64d-45a0-8d6c-e2a93ef20e13 | < 1.4.6 |
MEDIUM | 5.5 | The WordPress to Hootsuite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several parameters in v… | — | wordfence |
| cd8c07cc-7fdd-4474-8be1-b08d857ae109 | < 1.2.7 |
MEDIUM | 5.5 | The Page Restriction WordPress (WP) WordPress plugin before 1.2.7 allows bad actors with administrator privileges to the… | — | wordfence |
| cd2a8e7b-6fca-49f3-ba6d-bdaa418f611a | < 2.25.1 |
MEDIUM | 5.5 | The WPGet API – Connect to any external REST API plugin for WordPress is vulnerable to Server-Side Request Forgery in … | — | wordfence |
| ccf2bd2a-6041-49ca-8ff9-d8541b2d2b73 | < 1.1.2 |
MEDIUM | 5.5 | The The Wordfence plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘goolytics_web_property_id… | — | wordfence |
| cca16945-f230-4d0d-9f40-eabd5bf42e30 | < 3.2.3 |
MEDIUM | 5.5 | The Easy Social Icons plugin for WordPress was vulnerable to admin+ stored Cross-Site Scripting due to missing sanitizat… | — | wordfence |
EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.
Scan My Website →