Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.
40,369 vulnerabilities found (page 1038 of 1615)
| CVE ID | Plugin / Theme | Severity | CVSS | Description | Fixed In | Source |
|---|---|---|---|---|---|---|
| 81e1bc49-8ed0-4605-bc81-682b89f53796 | < 1.4.8 |
MEDIUM | 5.5 | The WP Optin Wheel – Gamified Optin Email Marketing Tool for WordPress and WooCommerce plugin for WordPress is vulnera… | — | wordfence |
| 81bcbf7d-d33f-4cf2-8411-613cf54095b4 | < 5.2.3 |
MEDIUM | 5.5 | The Print, PDF, Email by PrintFriendly WordPress plugin before 5.2.3 does not sanitise and escape the Custom Button Text… | — | wordfence |
| 8035023c-347f-4227-98cb-5b277fba4812 | MEDIUM | 5.5 | The Google Forms plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin settings in versions u… | — | wordfence | |
| 801132f5-e4ea-4d56-8429-9f33896f6dff | < 3.3.17 |
MEDIUM | 5.5 | … | — | wordfence |
| 7fb7dd8f-6258-46e1-9cc5-87ec73d5736c | < 5.1.8 |
MEDIUM | 5.5 | The Responsive Pricing Table plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all… | — | wordfence |
| 7f91992e-33fb-4384-af34-e27f68e1ca6e | < 4.0.0 |
MEDIUM | 5.5 | The Login by Auth0 Plugin for WordPress is vulnerable to Stored Cross-Site Scripting via an unknown parameter in version… | — | wordfence |
| 7f8839cf-9e48-4981-8a0d-bb0c06cdf441 | MEDIUM | 5.5 | The Client Dash plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up … | — | wordfence | |
| 7f6c33f4-58e7-4a0b-8293-5cb951f63ffc | < 4.2.22 |
MEDIUM | 5.5 | The Webba Booking plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 4.… | — | wordfence |
| 7f46ab3d-83fc-46a2-863e-7ce9b5391524 | < 1.2.2 |
MEDIUM | 5.5 | The Availability Calendar WordPress plugin before 1.2.2 does not sanitise or escape its Category Names before outputting… | — | wordfence |
| 7e9dcedd-aa81-47c4-9fc5-cecc7bc394b5 | < 5.3.3 |
MEDIUM | 5.5 | The MonsterInsights – Google Analytics Dashboard for WordPress plugin for WordPress is vulnerable to Stored Cross-Site… | — | wordfence |
| 7e7741d1-8b30-460d-bf1b-edc475841c71 | < 1.2.54.1 |
MEDIUM | 5.5 | The MailOptin plugin for WordPress is vulnerable to Cross-Site Scripting in versions up to, and including, 1.2.54.0 due … | — | wordfence |
| 7e49d389-0ae8-48e1-8ff7-67ddaa5b2867 | < 5.0 |
MEDIUM | 5.5 | The Social Media Follow Buttons Bar plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘alignme… | — | wordfence |
| 7e10babc-fc65-46f9-8b88-95b00f66d01b | MEDIUM | 5.5 | The Showing URL in QR Code plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and inclu… | — | wordfence | |
| 7dfa84ed-0edf-4a75-8ec3-986c3880353c | < 3.2.0 |
MEDIUM | 5.5 | The Easy Social Icons plugin for WordPress is vulnerable to admin-level stored Cross-Site Scripting due to missing sanit… | — | wordfence |
| 7d1e0423-a91b-4096-ad65-19e2d11cfea1 | MEDIUM | 5.5 | The Birthdays Widget WordPress plugin through 1.7.18 does not sanitise and escape some of its fields, which could allow … | — | wordfence | |
| 7cfeed0f-ab3e-4b35-9b69-08cc7e7ffb45 | MEDIUM | 5.5 | The Flexi Quote Rotator WordPress plugin through 0.9.4 does not sanitise and escape its settings, allowing high privileg… | — | wordfence | |
| 7cd3c84b-dacc-44e8-a236-bfc80e6dceba | MEDIUM | 5.5 | The content-grabber plugin 1.0 for WordPress has XSS via obj_field_name or obj_field_id. | — | wordfence | |
| 7c9a2045-7d24-4871-b962-32bc0fdf5476 | < 1.7.2 |
MEDIUM | 5.5 | The Video Lessons Manager WordPress plugin before 1.7.2 and Video Lessons Manager Pro WordPress plugin before 3.5.9 do n… | — | wordfence |
| 7c6ea33f-ee43-4df8-9633-60303b68b859 | < 1.1.34 |
MEDIUM | 5.5 | The AdPlugg WordPress Ad Plugin for WordPress is vulnerable to Cross-Site Scripting in versions before 1.1.34 due to ins… | — | wordfence |
| 7c4ceb2e-c718-43e2-bb7b-ab0404271134 | < 1.4.5 |
MEDIUM | 5.5 | The Passwords Manager plugin is vulnerable to Cross-Site scripting via the pwdms_csv_category parameter in versions up t… | — | wordfence |
| 7bde76d9-34f3-46c9-a05a-e5204b661b26 | MEDIUM | 5.5 | The Advanced WP Columns plugin for WordPress is vulnerable to Stored Cross-Site Scripting via various setting parameters… | — | wordfence | |
| 7bc9f86f-fd60-48bc-8df0-3b122facb0a0 | < 5.0 |
MEDIUM | 5.5 | The Learning Courses WordPress plugin before 5.0 does not sanitise and escape the Email PDT identity token settings, whi… | — | wordfence |
| 7b4d99d9-e58b-47c5-bb10-35f09b25cbf4 | < 3.90.1 |
MEDIUM | 5.5 | The FG Drupal to WordPress plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and … | — | wordfence |
| 7b49af95-2310-4f71-921b-ee66588dd6d5 | < 6.4.0 |
MEDIUM | 5.5 | The WP Affiliate Platform plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several parameters in ve… | — | wordfence |
| 79cc1f11-9b53-4e71-b0cc-8f8ebd4a5f32 | < 1.1.25 |
MEDIUM | 5.5 | The SVG Block plugin for WordPress is vulnerable to Stored Cross-Site Scripting via REST API SVG File uploads in all ver… | — | wordfence |
EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.
Scan My Website →