Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.
40,369 vulnerabilities found (page 1041 of 1615)
| CVE ID | Plugin / Theme | Severity | CVSS | Description | Fixed In | Source |
|---|---|---|---|---|---|---|
| 68ec28e8-345c-4017-ab0d-04ac4facd60c | < 1.3.2.6 |
MEDIUM | 5.5 | The Chained Quiz plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.3… | — | wordfence |
| 68d7b5d0-c777-4ff9-bdef-a7762cfbdf1a | < 2.9.3 |
MEDIUM | 5.5 | The WPLegalPages plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'wplegalpage' shortcode in versio… | — | wordfence |
| 68d44dd9-cfe4-4bc0-aa2e-9b7fb766870a | MEDIUM | 5.5 | The ScrollReveal.js Effects WordPress plugin through 1.2 does not sanitise and escape its settings, which could allow hi… | — | wordfence | |
| 6867d573-4ba1-4b82-b285-0696134d42fc | MEDIUM | 5.5 | The th23 Social WordPress plugin through 1.2.0 does not sanitise and escape some of its settings, which could allow high… | — | wordfence | |
| 68394503-d989-40d8-b033-24c011294158 | < 2.7.3 |
MEDIUM | 5.5 | The Tutor LMS plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.7.2 … | — | wordfence |
| 67b5d20b-4032-4d41-8ab7-6063b7e47827 | MEDIUM | 5.5 | The Great Quotes WordPress plugin through 1.0.0 does not sanitise and escape the Quote and Author fields of its Quotes, … | — | wordfence | |
| 67953bf3-5465-4f25-874c-46dff59b2199 | < 2.12.0 |
MEDIUM | 5.5 | The Simple Banner WordPress plugin before 2.12.0 does not properly sanitize its "Simple Banner Text" Settings allowing h… | — | wordfence |
| 674df25e-fc37-4f8e-a657-7c493e9bbb15 | MEDIUM | 5.5 | The PopAd plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 1.0.4.… | — | wordfence | |
| 66519150-7719-4598-8302-b3437719f0a0 | < 7.63 |
MEDIUM | 5.5 | The All-in-One WP Migration plugin for WordPress is vulnerable to cross-site scripting via the 'storage' parameter in ve… | — | wordfence |
| 6619b370-dd2a-4945-a776-1fecf407119e | < 6.2 |
MEDIUM | 5.5 | The wp-Monalisa plugin for WordPress is vulnerable to Stored Cross-Site Scripting via its emoticon parameters in version… | — | wordfence |
| 66082207-33b6-45e4-ae93-24c9a9611300 | < 2.3 |
MEDIUM | 5.5 | The Sitewide Notice WP WordPress plugin before 2.3 does not sanitise some of its settings before outputting them in fron… | — | wordfence |
| 65a3604d-eb6b-484f-834a-b3d75fe3bda7 | MEDIUM | 5.5 | The Simple add pages or posts plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, a… | — | wordfence | |
| 65526517-aec5-454b-94c0-973359d840e1 | < 1.9.2 |
MEDIUM | 5.5 | The Tutor LMS – eLearning and online course solution WordPress plugin before 1.9.2 did not escape the Summary field of… | — | wordfence |
| 650f7232-7279-401d-beb1-26f70c69164b | < 1.4.5 |
MEDIUM | 5.5 | The connectDaily plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via several parameters in versions… | — | wordfence |
| 64f4009e-2715-4c58-acbd-e516f1a76646 | < 1.8.8 |
MEDIUM | 5.5 | Unvalidated input and lack of output encoding in the Constant Contact Forms WordPress plugin, versions before 1.8.8, lea… | — | wordfence |
| 6447de64-b484-4f64-ad78-7df81b5a0ed7 | < 2.9.4 |
MEDIUM | 5.5 | The Page Builder: KingComposer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via via shortcode in ve… | — | wordfence |
| 642c03f4-f12c-4ae2-a4ab-4f49d6bd033c | < 4.4 |
MEDIUM | 5.5 | The GD bbPress Attachments plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several parameters in v… | — | wordfence |
| 63c1e570-c0de-44e0-ac39-0b9006c43efa | < 1.1.0 |
MEDIUM | 5.5 | The All in One Invite Codes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the '$message_text' pa… | — | wordfence |
| 63192a95-778b-452b-9081-cf20dc7f7ec1 | MEDIUM | 5.5 | The Developer Formatter plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Custom CSS in all vers… | — | wordfence | |
| 626dac34-6b25-42c9-8f7d-9899e4bcc039 | MEDIUM | 5.5 | The WordSurvey plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘sounding_title’ parameter … | — | wordfence | |
| 6230275e-8742-40f4-869f-a0e0984d85ba | < 1.40 |
MEDIUM | 5.5 | The Playlist for Youtube plugin for WordPress is vulnerable to Stored Cross-Site Scripting via settings in all versions … | — | wordfence |
| 61ec0e78-b367-438f-929d-94e055c83477 | MEDIUM | 5.5 | The Recently viewed and most viewed products plugin for WordPress is vulnerable to Stored Cross-Site Scripting via an un… | — | wordfence | |
| 61d6b2b8-dcaa-4419-b61d-4def743def95 | MEDIUM | 5.5 | The Bookshelf WordPress plugin through 2.0.4 does not sanitise or escape its "Paypal email address" setting before outpu… | — | wordfence | |
| 617c850f-8d7b-42d4-ac40-2381c4c6bde6 | MEDIUM | 5.5 | The WP Humans.txt plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.… | — | wordfence | |
| 60ea00e2-e33d-452d-969b-4022d6a00417 | < 1.4.4 |
MEDIUM | 5.5 | The Mobile Events Manager WordPress plugin before 1.4.4 does not sanitise and escape various of its settings, allowing h… | — | wordfence |
EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.
Scan My Website →