Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.
40,369 vulnerabilities found (page 1046 of 1615)
| CVE ID | Plugin / Theme | Severity | CVSS | Description | Fixed In | Source |
|---|---|---|---|---|---|---|
| 3f6d9c23-53e9-4393-beff-2f996c279ad8 | MEDIUM | 5.5 | The Category and Taxonomy Meta Fields plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the image me… | — | wordfence | |
| 3f5eef96-b9db-444b-82b8-86132376e29c | < 3.2.2 |
MEDIUM | 5.5 | The Salat Times plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Widget Title parameter in vers… | — | wordfence |
| 3f3aec3a-c1d3-4f7f-9f45-7a3ec42ce260 | < 1.2.53 |
MEDIUM | 5.5 | The Sliderby10Web plugin for WordPress is vulnerable to Stored Cross-Site Scripting via slider row links in versions up … | — | wordfence |
| 3e7105d3-3208-4964-8d21-172059cbbd63 | < 2.1.7 |
MEDIUM | 5.5 | The Blocksy theme for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.1.6 due… | — | wordfence |
| 3d8b8f54-b2af-42dd-af82-c1e8726c87e2 | < 4.2 |
MEDIUM | 5.5 | The Text Hover WordPress plugin before 4.2 does not sanitize and escape the text to hover, which could allow high privil… | — | wordfence |
| 3d54f585-0116-4517-84f1-271e89a05539 | < 4.5.1 |
MEDIUM | 5.5 | The ProfilePress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘wp_user_cover_default_imag… | — | wordfence |
| 3cf1983b-4cb7-4738-9f19-2c530a9939e0 | < 3.7.2 |
MEDIUM | 5.5 | The BSK PDF Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versio… | — | wordfence |
| 3cea044c-3117-4722-a696-5b7368d31d63 | < 0.1.6 |
MEDIUM | 5.5 | The WordPress Filter Gallery Plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ufg_gallery_filte… | — | wordfence |
| 3c547a2b-98fb-4936-88a5-31e5c879a364 | < 1.14.12 |
MEDIUM | 5.5 | The Form Maker by 10Web WordPress plugin before 1.14.12 does not sanitize and escape the Custom Text settings, which cou… | — | wordfence |
| 3c070b9c-5bed-4f9f-8d96-70958bf294cf | MEDIUM | 5.5 | The iFeature Slider plugin for WordPress is vulnerable to Stored Cross-Site Scripting via an unknown parameter in versio… | — | wordfence | |
| 3bb6e8f8-690a-49cb-ac00-f572bef8b8f7 | < 1.1.19 |
MEDIUM | 5.5 | An issue was discovered in the responsive-coming-soon-page plugin 1.1.18 for WordPress. XSS exists via the wp-admin/admi… | — | wordfence |
| 3b6ac92f-2ad1-4528-b157-5e49d6f224a5 | < 1.3 |
MEDIUM | 5.5 | The WP Total Branding – Complete branding solution for WordPress plugin for WordPress is vulnerable to Stored Cross-Si… | — | wordfence |
| 3b0d6b1f-5601-4c96-893c-e296511a2996 | < 10.4.3 |
MEDIUM | 5.5 | The Connections Business Directory WordPress plugin before 10.4.3 does not escape the Address settings when creating an … | — | wordfence |
| 3abbc407-f660-4b1f-9d48-436320e5fdd7 | MEDIUM | 5.5 | The Members Import plugin for WordPress is vulnerable to Self Cross-Site Scripting via the user_login parameter in an im… | — | wordfence | |
| 3a84a021-5014-4848-a77f-d3f4802c9395 | < 5.13.1 |
MEDIUM | 5.5 | The Site Reviews WordPress plugin before 5.13.1 does not sanitise some of its Review Details when adding a review as an … | — | wordfence |
| 3a75ff86-dc4d-4519-8cc5-183afc00cb65 | < 1.4.9.4 |
MEDIUM | 5.5 | The Drag & Drop Builder, Human Face Detector, Pre-built Templates, Spam Protection, User Email Notifications & more! Wor… | — | wordfence |
| 3a581d5e-11c3-468a-b4a1-6507f898f5ed | < 1.6.9.1 |
MEDIUM | 5.5 | The Backup Guard plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.6… | — | wordfence |
| 39f1ddd0-c26b-4754-a78a-c64fab75f238 | < 3.6 |
MEDIUM | 5.5 | The Generate PDF using Contact Form 7 plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several of i… | — | wordfence |
| 397e9d40-ecd3-4800-9191-c7e4805bcb31 | MEDIUM | 5.5 | The Elfsight Yottie Lite plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and includ… | — | wordfence | |
| 39722a07-abfe-4956-b5d0-8ece06913a85 | < 8.0.0 |
MEDIUM | 5.5 | The Really Simple SSL plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and inclu… | — | wordfence |
| 393a856e-dc13-4fb6-8ff3-5880631953c4 | < 4.2 |
MEDIUM | 5.5 | The Extra Product Options for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plug… | — | wordfence |
| 3936d7dc-840e-41fc-8af4-db40c0cff660 | < 2.13.10 |
MEDIUM | 5.5 | The Contact Form by Bit Form: Multi Step Form, Calculation Contact Form, Payment Contact Form & Custom Contact Form buil… | — | wordfence |
| 391d65a7-1675-4eae-b129-a1208cd95669 | < 2.0.6 |
MEDIUM | 5.5 | The Social Slider Feed plugin for WordPress is vulnerable to Stored Cross-Site Scripting via API key in versions up to, … | — | wordfence |
| 39041c15-dc85-49bc-b5d1-5b4bff05397b | < 1.9.8.4 |
MEDIUM | 5.5 | The Form Builder | Create Responsive Contact Forms WordPress plugin before 1.9.8.4 does not sanitise or escape its Form … | — | wordfence |
| 38efd6d6-b931-41a7-b55d-b98cdeef4145 | < 1.14.6 |
MEDIUM | 5.5 | The WPGraphQL plugin for WordPress is vulnerable to Server-Side Request Forgery in versions up to, and including, 1.14.5… | — | wordfence |
EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.
Scan My Website →