Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.
40,369 vulnerabilities found (page 1048 of 1615)
| CVE ID | Plugin / Theme | Severity | CVSS | Description | Fixed In | Source |
|---|---|---|---|---|---|---|
| 31496229-bf54-466c-a87b-cc32e65500a4 | < 5.9 |
MEDIUM | 5.5 | The WP Database Backup plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several parameters in versi… | — | wordfence |
| 31058d2e-9c23-4057-89a4-5847b6012330 | < 1.1.3 |
MEDIUM | 5.5 | The TinyMCE Custom Styles plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in versio… | — | wordfence |
| 301d273e-5cd2-49b8-b2ce-b30731ab4550 | < 2.11.6 |
MEDIUM | 5.5 | The Easy Digital Downloads WordPress plugin before 2.11.6 does not sanitise and escape the Downloadable File Name in the… | — | wordfence |
| 2f226493-4787-4d99-999d-3e3916a8c41d | < 5.8.23 |
MEDIUM | 5.5 | The AdRotate WordPress plugin before 5.8.23 does not sanitise and escape Advert Names which could allow high privilege u… | — | wordfence |
| 2ef5b0de-0b8b-4286-86ea-6dca0dbc1a52 | MEDIUM | 5.5 | The Waiting: One-click countdowns plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Countdown na… | — | wordfence | |
| 2e806895-40c9-44f5-97f8-becfa52c2559 | < 2.1.0 |
MEDIUM | 5.5 | The Accordions plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘notice’ parameter used in … | — | wordfence |
| 2df8ba02-30b0-49af-82cf-a0d2fd994ea2 | < 8.4.4 |
MEDIUM | 5.5 | The Slider Hero plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the slider title parameter in vers… | — | wordfence |
| 2dccdaa8-5095-42c4-9ca8-90fb444c0ae4 | < 3.7.22 |
MEDIUM | 5.5 | Before version 4.8.2, WordPress allowed Cross-Site scripting in the plugin editor via a crafted plugin name. | — | wordfence |
| 2da02a0e-4bc5-4dc6-b46e-7e74e0eb36dd | < 3.6.4 |
MEDIUM | 5.5 | The Dokan plugin for WordPress is vulnerable to Stored Cross-Site Scripting via product reviews in versions up to, and i… | — | wordfence |
| 2d964e1e-6361-435b-8527-e241f5a28b0e | MEDIUM | 5.5 | The Comment Guestbook plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including… | — | wordfence | |
| 2d5fb5c8-3e4d-4268-8b21-b65b7d7b68f2 | < 3.0.1 |
MEDIUM | 5.5 | The Smart Post Show plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Pagination Color setting i… | — | wordfence |
| 2c4749b8-cfaf-4a6e-a093-0c2bfd22b809 | < 6.0.8 |
MEDIUM | 5.5 | The WP Maintenance plugin for WordPress is vulnerable to Cross-Site Scripting in versions up to, and including, 6.0.7 du… | — | wordfence |
| 2c2c8025-6a1b-475d-bc28-9f2ec3ad7bdc | MEDIUM | 5.5 | The WP Social Sharing plugin for WordPress is vulnerable to Stored Cross-Site Scripting via an unknown parameter in vers… | — | wordfence | |
| 2b32cc12-c8d5-40b8-9510-42699beec581 | < 1.15.28 |
MEDIUM | 5.5 | The Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder plugin for WordPress is vulnerable to Store… | — | wordfence |
| 2ae939f4-5a90-48ca-ae13-2ccbd6d8d08a | MEDIUM | 5.5 | The Simple Telegram plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including 0… | — | wordfence | |
| 2ad7fd59-e4a2-46e7-9232-d76255a6b0b4 | < 4.16.6 |
MEDIUM | 5.5 | The Leaky Paywall WordPress plugin is vulnerable to Stored Cross-Site Scripting due to insufficient input validation and… | — | wordfence |
| 2ab1a623-5726-45ca-9667-ed926c5d3364 | < 1.1.16 |
MEDIUM | 5.5 | The Alojapro Widget WordPress plugin through 1.1.15 doesn't properly sanitise its Custom CSS settings, allowing high pri… | — | wordfence |
| 2a677eed-0344-457e-aa5f-3b94a624462c | MEDIUM | 5.5 | The SEO Smart Links plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, … | — | wordfence | |
| 29eeac86-6b33-49e6-a7e1-c80dee383d6f | < 6.3 |
MEDIUM | 5.5 | The Uncanny Automator – Easy Automation, Integration, Webhooks & Workflow Builder Plugin plugin for WordPress is vulne… | — | wordfence |
| 2921ea67-e88a-489a-8c45-cfe458f29d2b | < 1.3.30 |
MEDIUM | 5.5 | The HTML Forms plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up t… | — | wordfence |
| 28e9c77c-5c36-4449-ab90-86f2385ba1ae | < 5.2.0 |
MEDIUM | 5.5 | The LatePoint – Calendar Booking Plugin for Appointments and Events plugin for WordPress is vulnerable to Stored Cross… | — | wordfence |
| 28ccae6b-c330-4811-9cd8-eeb2c91c2f55 | MEDIUM | 5.5 | The My Bootstrap Menu plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including… | — | wordfence | |
| 287c6cdc-f534-4b87-8a97-ee1e3666cd25 | < 13.0.6 |
MEDIUM | 5.5 | The Shield Security WordPress plugin before 13.0.6 does not sanitise and escape admin notes, which could allow high priv… | — | wordfence |
| 282fabde-c3a5-49d0-987a-39f106f766cf | < 3.0.7.2 |
MEDIUM | 5.5 | The TaxoPress – Create and Manage Taxonomies, Tags, Categories WordPress plugin before 3.0.7.2 does not sanitise its T… | — | wordfence |
| 27f09e0e-ddd0-4440-9a58-a7fc60b49776 | MEDIUM | 5.5 | The Easy Preloader WordPress plugin through 1.0.0 does not sanitise its setting fields, leading to authenticated (admin+… | — | wordfence |
EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.
Scan My Website →