Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.
40,369 vulnerabilities found (page 1047 of 1615)
| CVE ID | Plugin / Theme | Severity | CVSS | Description | Fixed In | Source |
|---|---|---|---|---|---|---|
| 38e831b4-8284-4fad-ac24-a2f08053c53e | < 20221201 |
MEDIUM | 5.5 | The Simple Basic Contact Form plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several of its setti… | — | wordfence |
| 38d7c79f-a4a2-447d-88a2-ad75b53ac8bc | < 3.6.10 |
MEDIUM | 5.5 | The Ninja Forms Contact Form plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'label' parameter… | — | wordfence |
| 38979e27-2023-4f84-a708-1732b4117066 | < 3.7.40 |
MEDIUM | 5.5 | WordPress Core is vulnerable to Stored Cross-Site Scripting via the Customizer in versions up to 6.0.3. This is due to i… | — | wordfence |
| 387ccc20-1b84-4e7c-b4bc-75ad6dad8376 | MEDIUM | 5.5 | The WP Next Post Navi plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including… | — | wordfence | |
| 385a82ff-50ad-4787-845b-fb5f639f6466 | < 21.1 |
MEDIUM | 5.5 | The Yoast SEO plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 21.0 d… | — | wordfence |
| 37f3aca7-b728-4a27-9e08-bdc9ca2f8f0c | < 2.9.5 |
MEDIUM | 5.5 | The Simple Job Board WordPress plugin is vulnerable to Stored Cross-Site Scripting due to insufficient escaping on the $… | — | wordfence |
| 37bfc71f-e1f9-4374-ab65-9b1c321ff386 | < 1.1.2 |
MEDIUM | 5.5 | The Error Log Viewer WordPress plugin through 1.1.1 does not validate the path of the log file to clear, allowing high p… | — | wordfence |
| 3732bf4c-e5e4-4947-9044-9a49e7547cf3 | MEDIUM | 5.5 | The WP Total Hacks plugin for WordPress is vulnerable to stored Plugin Options Update and Cross-Site Scripting in versio… | — | wordfence | |
| 36f107cf-4b85-4016-b7af-b73a706cf1a6 | < 2.6.9 |
MEDIUM | 5.5 | Cross-site scripting (XSS) vulnerability in the WooCommerce plugin before 2.6.9 for WordPress allows remote authenticate… | — | wordfence |
| 36b71a50-270a-4960-bf31-e888df84e619 | < 1.7.2 |
MEDIUM | 5.5 | The ShiftNav – Responsive Mobile Menu plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin… | — | wordfence |
| 360cba3a-dfae-4b1c-9b33-f531fb9b12e0 | < 5.0.5 |
MEDIUM | 5.5 | The WP Attachments plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘attachment’ parameter … | — | wordfence |
| 35f2d80a-891a-4616-a3f6-01bbf12f5f10 | < 3.3.2 |
MEDIUM | 5.5 | The Author Bio Box WordPress plugin is vulnerable to Stored Cross-Site Scripting due to insufficient input validation an… | — | wordfence |
| 35b46587-1c6e-4d3f-a8d0-e7797cee882d | < 1.1.2 |
MEDIUM | 5.5 | The GTM Server Side plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'GTM Server Side url' fiel… | — | wordfence |
| 35697cf5-4494-40f6-8772-dfa417ae6bcb | < 3.4.8 |
MEDIUM | 5.5 | The Profile Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, … | — | wordfence |
| 350c23c6-6201-4dd5-9594-edb7d8ad926c | MEDIUM | 5.5 | The WP Nano AD plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘blogrole_link’ parameter i… | — | wordfence | |
| 3504b703-b95b-4d22-8883-a575b398c9ea | < 2.3.8 |
MEDIUM | 5.5 | The Request a Quote WordPress plugin through 2.3.7 does not sanitise and escape some of its settings, allowing high priv… | — | wordfence |
| 35027df9-ae55-453f-bb42-4b2664d66293 | < 2.6.4 |
MEDIUM | 5.5 | The Statify – Extended Evaluation plugin for WordPress is vulnerable to CSV Injection in versions up to, and including… | — | wordfence |
| 3424c187-cf71-41f0-abb8-f0e843750465 | < 1.12.3 |
MEDIUM | 5.5 | The Forms WordPress plugin before 1.12.3 did not sanitise its input fields, leading to Stored Cross-Site scripting issue… | — | wordfence |
| 33bf39f8-6f56-4089-bb46-5d401af72953 | < 3.3.103 |
MEDIUM | 5.5 | The Zephyr Project Manager plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, a… | — | wordfence |
| 33adf97e-c0f9-488b-b9cf-e703578c4d1e | < 2.1.11.1 |
MEDIUM | 5.5 | The bbPress Voting plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in versions up t… | — | wordfence |
| 336eb1fb-dc94-417d-b9b6-488c105aab1e | < 1.3 |
MEDIUM | 5.5 | The Find and Replace All plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘findstr’ and 're… | — | wordfence |
| 33166510-41b2-4e9a-8bd7-501235729346 | < 1.0.4 |
MEDIUM | 5.5 | The WP 404 Auto Redirect to Similar Post plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin set… | — | wordfence |
| 32682598-ad1c-4aa1-bdf2-a7966a4d1dbe | < 1.1.4.1 |
MEDIUM | 5.5 | The BEAR – Bulk Editor and Products Manager Professional for WooCommerce by Pluginus.Net plugin for WordPress is vulne… | — | wordfence |
| 32272237-43c1-4b77-b586-9fad4af279e4 | < 3.2.4 |
MEDIUM | 5.5 | The Yoast Duplicate Post plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and includ… | — | wordfence |
| 31579f6d-9a89-45e3-adfb-d59823a83c07 | < 1.5.46 |
MEDIUM | 5.5 | Multiple stored XSS vulnerabilities exist in the 10Web Photo Gallery plugin before 1.5.46 WordPress. Successful exploita… | — | wordfence |
EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.
Scan My Website →