Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.
40,369 vulnerabilities found (page 1043 of 1615)
| CVE ID | Plugin / Theme | Severity | CVSS | Description | Fixed In | Source |
|---|---|---|---|---|---|---|
| 56ce85d3-89f3-461a-8268-7d549e9c2baf | MEDIUM | 5.5 | The Media-Tags WordPress plugin through 3.2.0.2 does not sanitise and escape any of its Labels settings, which could all… | — | wordfence | |
| 56953c6f-7ff9-45bf-9265-01240938e395 | < 2.4.9 |
MEDIUM | 5.5 | The WooCommerce plugin for WordPress is vulnerable to Cross-Site Scripting via the pay_price() function, in versions up … | — | wordfence |
| 567c4487-32e3-4afd-aec7-2f8171a49ebc | < 1.2.3.10 |
MEDIUM | 5.5 | The UsersWP plugin for WordPress is vulnerable to CSV Injection in versions up to, and including, 1.2.3.9 via the proces… | — | wordfence |
| 5617f917-ecb5-4c64-b421-e4af14c17eb7 | < 1.3.9.9 |
MEDIUM | 5.5 | The Asset CleanUp: Page Speed Booster plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions … | — | wordfence |
| 55f7914f-9731-4b43-b2c0-b3474508e40a | MEDIUM | 5.5 | The reCAPTCHA plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.6 du… | — | wordfence | |
| 553255fb-2bec-48e8-bb16-1e7f66674282 | < 3.0.7 |
MEDIUM | 5.5 | The Spacer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several parameters in versions up to, a… | — | wordfence |
| 550fcbbd-254d-4b3c-a240-8afcf9f6937e | < 0.2.18 |
MEDIUM | 5.5 | The 4ECPS Web Forms plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, … | — | wordfence |
| 546d4f19-0e6f-447b-95c9-d86291477c80 | MEDIUM | 5.5 | The Database Browser plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several parameters including … | — | wordfence | |
| 53ddfd2d-7af1-4561-ab76-5cb3238e8f8b | < 2.21.0 |
MEDIUM | 5.5 | Authenticated Arbitrary File Creation via Export function vulnerability in GiveWP's GiveWP plugin <= 2.20.2 at WordPress… | — | wordfence |
| 52cd845d-9c63-4f96-8ce6-fdaa6f535447 | < 2.3 |
MEDIUM | 5.5 | The Send From plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.2 du… | — | wordfence |
| 52944aa6-a6ee-46ce-bd0c-18c69fe1ada7 | < 1.3 |
MEDIUM | 5.5 | The WP Duplicate Page WordPress plugin before 1.3 does not sanitize and escape some of its settings, which could allow h… | — | wordfence |
| 5269ea0a-b0e9-433a-a166-28d23bfb6b4e | < 1.30 |
MEDIUM | 5.5 | … | — | wordfence |
| 52574d99-1ffe-4152-bf13-9cdd11d7300a | < 3.6.5 |
MEDIUM | 5.5 | The TaxoPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Related Posts functionality in v… | — | wordfence |
| 5223d6c3-9fe0-4ac5-bd69-990a13b17826 | MEDIUM | 5.5 | The 3dady real-time web stats plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘dady_input_te… | — | wordfence | |
| 51e4f7ac-efc5-492c-b7a4-eea6d5f69e0d | MEDIUM | 5.5 | The PlanSo Forms WordPress plugin through 2.6.4 does not escape the title of its Form before outputting it in attributes… | — | wordfence | |
| 5193d1c0-5111-4e97-a433-a41a76acbde9 | < 3.5.2 |
MEDIUM | 5.5 | The WooCommerce plugin for WordPress is vulnerable to Cross-Site Scripting due to sanitization and escaping on an unspec… | — | wordfence |
| 514aa001-24c8-4624-8e25-f17b8454354c | < 1.5.9 |
MEDIUM | 5.5 | The Direct Checkout – Quick View – Buy Now For WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site S… | — | wordfence |
| 51178e18-ae8b-4a7f-974d-23346a8dbc52 | < 6.3.6 |
MEDIUM | 5.5 | The Advanced Custom Fields plugin for WordPress is vulnerable to Stored Cross-Site Scripting via field groups in all ver… | — | wordfence |
| 50b811e0-c1f4-4970-a340-8c1619456e29 | < 2.21.3 |
MEDIUM | 5.5 | The GiveWP WordPress plugin before 2.21.3 does not properly sanitise and escape the currency settings, which could allow… | — | wordfence |
| 50b0eb50-fe25-487f-b5bc-13659be58ae4 | < 1.7 |
MEDIUM | 5.5 | The Simple Tracking WordPress plugin before 1.7 does not sanitise and escape its settings, allowing high privilege users… | — | wordfence |
| 50518a54-16d8-4467-beca-a6b8196ed9b9 | < 1.7.1007 |
MEDIUM | 5.5 | The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to Server-Side Request Forgery in all versio… | — | wordfence |
| 4f997c20-38f6-4968-b7de-8f28f825c7fd | < 3.8.4 |
MEDIUM | 5.5 | The Social Media Share Buttons plugin for WordPress is vulnerable to stored cross-site scripting in versions up to, and … | — | wordfence |
| 4f93fb48-3963-4a98-9c70-eef667b254df | MEDIUM | 5.5 | The Auto More Tag plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several parameters in versions u… | — | wordfence | |
| 4f60a6aa-8420-4f7e-9863-5b69774201ef | MEDIUM | 5.5 | The Confirm User Registration plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and i… | — | wordfence | |
| 4ef11b08-534b-47eb-989c-7cc1c8853fb8 | < 1.1.4.5 |
MEDIUM | 5.5 | The BEAR plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.1.4.4 due… | — | wordfence |
EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.
Scan My Website →