Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.
40,369 vulnerabilities found (page 1044 of 1615)
| CVE ID | Plugin / Theme | Severity | CVSS | Description | Fixed In | Source |
|---|---|---|---|---|---|---|
| 4e94683d-2cf3-4e43-8ab0-f797bfaaeee4 | < 1.16.11 |
MEDIUM | 5.5 | The Popup Maker plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.16… | — | wordfence |
| 4e731110-473b-4f0c-8eb1-7b964a0f9aed | MEDIUM | 5.5 | The Product Time Countdown for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions… | — | wordfence | |
| 4e51eb56-e2f7-433c-8db7-bcf7539aee29 | < 0.20220219 |
MEDIUM | 5.5 | The Books & Papers WordPress plugin through 0.20210223 does not escape its Custom DB prefix settings, allowing high priv… | — | wordfence |
| 4e4f2725-6c93-40df-93ee-51997a4ad189 | < 1.3.3 |
MEDIUM | 5.5 | The Social Rocket plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several of its settings paramete… | — | wordfence |
| 4e3e3bf4-7b95-4c0b-b660-d29796b643ed | < 3.14.2 |
MEDIUM | 5.5 | The Seriously Simple Podcasting plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to,… | — | wordfence |
| 4e0ad29a-b7a0-407e-8fb0-0917b8671afb | < 6.0.0 |
MEDIUM | 5.5 | The Actueel Financieel Nieuws β Denk Internet Solutions plugin for WordPress is vulnerable to Stored Cross-Site Script… | — | wordfence |
| 4dcb4afc-14e1-43ce-87c4-8f24f1a0d682 | < 2.7.4 |
MEDIUM | 5.5 | The Tutor LMS plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.7.3 … | — | wordfence |
| 4dbba653-e23e-43e6-9dc5-83a6c99f8dc6 | < 1.8.0 |
MEDIUM | 5.5 | The Zeno Font Resizer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in versions u… | — | wordfence |
| 4d8d15be-6a7b-485e-a338-ccf1a6eb226c | MEDIUM | 5.5 | The User Language Switch plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and in… | — | wordfence | |
| 4cf2af62-2b5a-4c0a-9e82-f80dde204a9d | < 3.0.8 |
MEDIUM | 5.5 | The Ninja Forms Webhooks plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and in… | — | wordfence |
| 4c2a88c3-5c11-4b42-b8f8-aafecf6c4c74 | < 4.9 |
MEDIUM | 5.5 | The tagDiv Composer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'single' module i… | — | wordfence |
| 4bd16698-2c44-4031-b8e0-f9d6e8feaff0 | MEDIUM | 5.5 | The SEO Backlink Monitor plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and in… | — | wordfence | |
| 4baf9b27-a06e-412f-8227-6b418e709ff1 | < 1.6.6 |
MEDIUM | 5.5 | The Page Generator plugin is vulnerable to Cross-Site Scripting in versions up to, and including, 1.6.4. This allows aut… | — | wordfence |
| 4ba416c5-47d6-4b05-8a31-af9137e04d2b | < 1.2.1.5 |
MEDIUM | 5.5 | The Codup WooCommerce Dynamic Pricing Table View plugin for WordPress is vulnerable to Stored Cross-Site Scripting via s… | — | wordfence |
| 4ba3b414-82a0-4793-9702-cec64d92271e | < 1.12.2 |
MEDIUM | 5.5 | The WP-CommentNavi plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the navi options 'pages_text', … | — | wordfence |
| 4b9741c6-4038-45ad-a7b4-fa8f65664f4a | < 2.1.8 |
MEDIUM | 5.5 | An issue was discovered in the booking-calendar plugin 2.1.7 for WordPress. XSS exists via the wp-admin/admin.php form_f… | — | wordfence |
| 4a5262d8-d9cd-4bd9-a95e-f60782095173 | MEDIUM | 5.5 | The Sticky Popup plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the β popup_title' parameter in… | — | wordfence | |
| 4939b053-2d62-428e-84ff-0de3416466ef | < 1.13.4 |
MEDIUM | 5.5 | The Login using WordPress Users (WP as SAML IDP) plugin by MiniOrange is vulnerable to Cross-Site Scripting in versions … | — | wordfence |
| 49023c6b-a236-42c1-ab24-072fa4a72967 | < 1.3.3 |
MEDIUM | 5.5 | The Chained Quiz plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including,… | — | wordfence |
| 4890ec6f-ba73-48bd-8dd7-f896d6b4a140 | < 2.0.46 |
MEDIUM | 5.5 | The Ultimate Member plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the several of the plugin's fo… | — | wordfence |
| 48758ada-4c7f-4a7f-8b43-535f820e6b3c | < 2.2.43 |
MEDIUM | 5.5 | The Accordion plugin for WordPress is vulnerable to Stored Cross-Site Scripting via parameter keys through accordion imp… | — | wordfence |
| 47f04985-dd9b-449f-8b4c-9811fe7e4a96 | < 5.6.1 |
MEDIUM | 5.5 | The FileBird plugin for WordPress is vulnerable to Stored Cross-Site Scripting via imported folder titles in all version… | — | wordfence |
| 47a99115-3e7b-4666-a00e-2b94d7d62e1a | < 2.0.3 |
MEDIUM | 5.5 | The Seed Social plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Facebook App Id and App Secret… | — | wordfence |
| 472a98fe-9cce-4e9f-b353-ccc1389506fd | < 1.9.18 |
MEDIUM | 5.5 | Cross-site scripting (XSS) vulnerability in admin/manage-images.php in the NextCellent Gallery plugin before 1.19.18 for… | — | wordfence |
| 46ca2967-5b75-49f5-8b0c-1e9274423c93 | < 1.2.13 |
MEDIUM | 5.5 | WP Subscribe versions up to 1.2.12 is vulnerable to Cross-Site Scripting. This allows authenticated attackers to inject … | — | wordfence |
EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.
Scan My Website →