Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.
40,369 vulnerabilities found (page 1030 of 1615)
| CVE ID | Plugin / Theme | Severity | CVSS | Description | Fixed In | Source |
|---|---|---|---|---|---|---|
| bce8b43a-a69e-44d1-adab-98253e86cb33 | < 4.4.7 |
MEDIUM | 5.5 | The WP Meta SEO WordPress plugin before 4.4.7 does not sanitise or escape the breadcrumb separator before outputting it … | — | wordfence |
| bcd12bf2-0fbe-4c9e-b6f7-43c10798eadc | MEDIUM | 5.5 | The job-portal WordPress plugin is vulnerable to Stored Cross-Site Scripting due to insufficient input validation and sa… | — | wordfence | |
| bcbb6614-09fc-4f41-81f7-d70aa92101bf | < 5.8 |
MEDIUM | 5.5 | The BulletProof Security WordPress plugin before 5.8 does not sanitise and escape some of its settings, which could allo… | — | wordfence |
| bc79e104-47c0-4f4a-9a7b-dc0d6337ea05 | < 1.4.4 |
MEDIUM | 5.5 | The Chameleon plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘wpch_news_title’ parameter … | — | wordfence |
| bc67ff08-b660-477a-9457-b681cf0381f5 | < 2.1.3 |
MEDIUM | 5.5 | The Donation Thermometer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via some of its settings para… | — | wordfence |
| bb8d81c3-4a5b-491f-9868-3bb7b431f8e4 | MEDIUM | 5.5 | The Alpine PhotoTile for Pinterest plugin for WordPress is vulnerable to Stored Cross-Site Scripting via an unknown para… | — | wordfence | |
| bb4d6d2c-a69d-492e-a2d5-fabfaef82f68 | MEDIUM | 5.5 | The OAuth Client by DigitialPixies plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, … | — | wordfence | |
| b9ef419c-3546-489b-b841-b12b8918abdd | < 2.4.8 |
MEDIUM | 5.5 | The WP Contact Slider plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘Text to display’ pa… | — | wordfence |
| b99248e9-b34f-4f99-9db1-a4dc2dd45b9c | < 2.0.1 |
MEDIUM | 5.5 | The FluentSMTP WordPress plugin before 2.0.1 does not sanitize parameters before storing the settings in the database, n… | — | wordfence |
| b9738054-058f-47be-9973-f119fbfd4396 | < 1.9.7 |
MEDIUM | 5.5 | The WP Prayer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in versions up to, an… | — | wordfence |
| b96d71cb-3af4-4d67-a4af-41bab79a7f61 | MEDIUM | 5.5 | The WP Better Emails plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including,… | — | wordfence | |
| b9394801-4a74-4327-9afd-35f4166c2abb | < 3.1 |
MEDIUM | 5.5 | The WP Home Page Menu WordPress plugin before 3.1 does not sanitise and escape its settings, allowing high privilege use… | — | wordfence |
| b92c3d68-2e3e-4500-8da9-f89373126445 | MEDIUM | 5.5 | The Scroll Triggered Box plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and includ… | — | wordfence | |
| b890d168-9ea7-49c0-b628-71c76c0c2c9c | < 2.10.4 |
MEDIUM | 5.5 | The Simple Banner WordPress plugin before 2.10.4 does not sanitise and escape one of its settings, allowing high privile… | — | wordfence |
| b8721c4d-d89b-4e97-af01-20327013cfb6 | MEDIUM | 5.5 | The Launchpad plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several of its settings parameters i… | — | wordfence | |
| b82e6dce-b130-4025-b6e3-bde2350a6362 | MEDIUM | 5.5 | The Responsive and Swipe slider plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's rsSli… | — | wordfence | |
| b778048c-22e8-42ea-9d60-6e58b31a3035 | MEDIUM | 5.5 | The Carousel CK WordPress plugin through 1.1.0 does not sanitize and escape Slide's descriptions, which could allow high… | — | wordfence | |
| b6ead872-76a7-49c3-af07-d87a4c68183f | MEDIUM | 5.5 | The RegLevel plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to,… | — | wordfence | |
| b6c9814e-e854-4420-9ec1-d843187bd9e7 | < 1.20.8 |
MEDIUM | 5.5 | The Splash Header WordPress plugin before 1.20.8 doesn't sanitise and escape some of its settings while outputting them … | — | wordfence |
| b644e61a-5842-43a6-9525-97e1339dcc94 | < 3.37.2 |
MEDIUM | 5.5 | The Wordlift plugin for WordPress is vulnerable to Stored Cross-Site Scripting via its settings parameters in versions u… | — | wordfence |
| b6119481-f399-4bba-a824-1d7346e7e155 | < 3.3.2 |
MEDIUM | 5.5 | The Hummingbird WordPress plugin before 3.3.2 does not sanitise and escape the Config Name, which could allow high privi… | — | wordfence |
| b5c715f9-8655-448e-a8d2-71f24c9d48ba | < 5.0.6 |
MEDIUM | 5.5 | The WP Attachments plugin for WordPress is vulnerable to Stored Cross-Site Scripting via some of its settings parameters… | — | wordfence |
| b53e6c9e-f78f-44e8-ad0f-8cfaaac8b53f | < 1.3.16 |
MEDIUM | 5.5 | The Appointment Hour Booking WordPress plugin before 1.3.16 does not escape some of the Calendar Form settings, allowing… | — | wordfence |
| b4ecf437-b9f5-47d3-85b2-c8159c937473 | < 5.5 |
MEDIUM | 5.5 | The Image Hover Effects plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several parameters on the … | — | wordfence |
| b4c61072-5480-43f3-ad9f-ed3f0d577ebc | < 3.9.3 |
MEDIUM | 5.5 | The Companion Auto Update plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘update_delay_days… | — | wordfence |
EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.
Scan My Website →