Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.
40,369 vulnerabilities found (page 1032 of 1615)
| CVE ID | Plugin / Theme | Severity | CVSS | Description | Fixed In | Source |
|---|---|---|---|---|---|---|
| a9bd9617-254a-40b3-a1ec-00d30b75e1b8 | < 2.7 |
MEDIUM | 5.5 | The Testimonials plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several parameter in versions up … | — | wordfence |
| a97b3cf1-e7b7-41c6-8b7a-e06bda77f7f7 | < 4.6.5 |
MEDIUM | 5.5 | The Astra theme for WordPress is vulnerable to Stored Cross-Site Scripting via the theme header and footer content in al… | — | wordfence |
| a90c51d9-c89a-4164-a732-89434a6e0b8e | < 2.1.0 |
MEDIUM | 5.5 | The Accordions plugin for WordPress is vulnerable to Stored Cross-Site Scripting via any parameters used in the post_oxi… | — | wordfence |
| a8f45c31-6e35-4f28-8f49-74cb08ff65bd | < 1.4.3 |
MEDIUM | 5.5 | The Typebot | Build beautiful conversational forms WordPress plugin before 1.4.3 does not sanitise and escape the Publis… | — | wordfence |
| a8e40f0a-9296-4113-8fff-0aea3c365c1a | < 4.2.6 |
MEDIUM | 5.5 | The Popup Builder β Create highly converting, mobile friendly marketing popups. plugin for WordPress is vulnerable to … | — | wordfence |
| a8546d5d-3ac0-4eb6-9502-07f2590a943b | MEDIUM | 5.5 | The Good & Bad Comments WordPress plugin through 1.0.0 does not sanitise and escape its settings, which could allow high… | — | wordfence | |
| a82c5ca7-5fe5-4817-bf5c-ee7779eb4427 | < 4.1.0 |
MEDIUM | 5.5 | Cross-site scripting vulnerability in Google XML Sitemaps Version 4.0.9 and earlier allows remote authenticated attacker… | — | wordfence |
| a81d5615-0b96-4d89-a525-7e80a10a9317 | < 1.2.6 |
MEDIUM | 5.5 | The YourChannel plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in versions up to,… | — | wordfence |
| a7d5edee-04fb-41e0-be5e-ca3681956d2d | < 2.5.5 |
MEDIUM | 5.5 | The Forms for Mailchimp by Optin Cat plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the params_st… | — | wordfence |
| a78c46ac-22dd-48f2-a10b-016205f7e7fa | < 2.2.28 |
MEDIUM | 5.5 | The Biteship plugin for WordPress is vulnerable to Stored Cross-Site Scripting via plugin settings in versions up to, an… | — | wordfence |
| a741446e-8600-4e02-af76-0d34a491bcfd | < 1.2.52 |
MEDIUM | 5.5 | The Sliderby10Web WordPress plugin before 1.2.52 does not properly sanitize and escape some of its settings, which could… | — | wordfence |
| a6b0b516-af5c-474a-a674-b52cf80207ec | < 2.0 |
MEDIUM | 5.5 | The Re:amaze Helpdesk & Live Chat plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several paramete… | — | wordfence |
| a62a3a71-0dbb-48d6-ba1a-f218fefac871 | < 2.6.12 |
MEDIUM | 5.5 | The WPeMatico RSS Feed Fetcher WordPress plugin before 2.6.12 does not escape the Feed URL added to a campaign before ou… | — | wordfence |
| a5985318-2ce6-4ecb-a92f-362bc5909bd5 | < 11.6 |
MEDIUM | 5.5 | The WP Google Review Slider plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and inc… | — | wordfence |
| a4f4605c-d3e4-4f6e-ba47-413049a27455 | MEDIUM | 5.5 | The WP Pipes plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 1.4… | — | wordfence | |
| a4c0b14a-d039-4008-a433-ab3605e2612c | MEDIUM | 5.5 | The Multi Functional Flexi Lightbox plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `arv_lb[me… | — | wordfence | |
| a4aea6ac-0b36-481c-aa22-db96665404f6 | < 7.1.7 |
MEDIUM | 5.5 | The Donorbox WordPress plugin before 7.1.7 does not sanitise and escape its Campaign URL settings before outputting it i… | — | wordfence |
| a4a885e0-84fb-4f5a-8ef5-6a0a8108d26f | < 2.0.43 |
MEDIUM | 5.5 | The Blocksy Companion plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and inclu… | — | wordfence |
| a44ce6a3-0a9d-4bce-9251-f3a38b000645 | MEDIUM | 5.5 | The Mega Main Menu plugin for WordPress is vulnerable to Stored Cross-Site Scripting via some of its settings parameters… | — | wordfence | |
| a3232aaa-189d-42cd-8eec-c167c6aa65f4 | < 8.1.15 |
MEDIUM | 5.5 | The ActiveCampaign β Forms, Site Tracking, Live Chat plugin for WordPress is vulnerable to Server-Side Request Forgery… | — | wordfence |
| a27cfa5a-e02a-4c92-8503-2c7cd32fb1f1 | < 7.4.6 |
MEDIUM | 5.5 | The Newsletter plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the preheader_text value in version… | — | wordfence |
| a246227c-89c1-46c3-a74c-b5de260d8a19 | < 1.31 |
MEDIUM | 5.5 | The RSS for Yandex Turbo WordPress plugin through 1.30 does not sanitise or escape some of its settings before saving an… | — | wordfence |
| a18baa1d-2400-496d-8e8b-1c3983484706 | < 3.1.9 |
MEDIUM | 5.5 | … | — | wordfence |
| a12f1061-3720-4e99-892d-68c850aa524c | MEDIUM | 5.5 | The Gravity Forms CSS Themes with Fontawesome and Placeholders plugin for WordPress is vulnerable to Stored Cross-Site S… | — | wordfence | |
| a107839e-b79b-4868-9232-eca050eb1551 | < 5.3.1 |
MEDIUM | 5.5 | The WP Travel Engine WordPress plugin before 5.3.1 does not escape the Description field in the Trip Destination/Activit… | — | wordfence |
EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.
Scan My Website →