Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.
40,369 vulnerabilities found (page 1049 of 1615)
| CVE ID | Plugin / Theme | Severity | CVSS | Description | Fixed In | Source |
|---|---|---|---|---|---|---|
| 27885b7f-ef8c-45ea-995c-92cd1939e1c5 | < 3.0.1 |
MEDIUM | 5.5 | The WP Custom Cursors plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘cursor_text’ parame… | — | wordfence |
| 277942cb-f4ca-4197-8f61-2e0cb03115a6 | < 1.7.4 |
MEDIUM | 5.5 | The Digital Publications by Supsystic plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several para… | — | wordfence |
| 27478d23-961d-4a88-adf5-c3cdd79cc10c | < 1.19.2.1 |
MEDIUM | 5.5 | The Import and export users and customers WordPress plugin before 1.19.2.1 does not sanitize and escape imported CSV dat… | — | wordfence |
| 27277b3d-b4f9-4d0c-a213-988a9b8fcd34 | < 2.3.1 |
MEDIUM | 5.5 | The Invitation Based Registrations WordPress plugin through 2.2.84 does not sanitise and escape some of its settings, wh… | — | wordfence |
| 27254411-3ae7-4659-b3c1-1c18911e3bfb | < 1.5 |
MEDIUM | 5.5 | The Contact Form, Survey & Popup Form Plugin for WordPress plugin before 1.5 does not properly sanitize some of its sett… | — | wordfence |
| 269b0edd-2358-4a71-8fbe-de9a1c939807 | MEDIUM | 5.5 | The Smart Docs plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up t… | — | wordfence | |
| 2685c3e9-cb68-4d59-b7ef-ebe40419fb59 | MEDIUM | 5.5 | The Awesome Surveys plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, … | — | wordfence | |
| 26529849-c52c-40e5-8085-6764c22a03e7 | < 2.3.1 |
MEDIUM | 5.5 | The User Registration plugin for WordPress is vulnerable to Stored Cross-Site Scripting via field settings in versions u… | — | wordfence |
| 26237984-d7b5-4a55-91f8-a2816f3d2e94 | < 1.0.3 |
MEDIUM | 5.5 | The Accessibility plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'attachments_alt' and 'attac… | — | wordfence |
| 259ed1a0-1bfa-4d38-845c-e5655c330702 | < 3.1.9.2 |
MEDIUM | 5.5 | The WordPress Countdown Widget plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several parameters … | — | wordfence |
| 2505ffdd-d697-4c69-8f75-0bc4d09e1b1f | < 3.0.5 |
MEDIUM | 5.5 | The Inline Related Posts plugin for WordPress is vulnerable to Cross-Site Scripting in versions up to, and including, 3.… | — | wordfence |
| 24eb524c-1705-43a5-8041-4549ebb49155 | MEDIUM | 5.5 | The IP Blacklist Cloud plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and includin… | — | wordfence | |
| 24bdffdc-1a4d-4a1c-8393-cf89f0a63bf9 | MEDIUM | 5.5 | The Cookie Notice Bar plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and inclu… | — | wordfence | |
| 24ba8d30-843f-4178-9b10-3c3dc720205c | < 2.3.3 |
MEDIUM | 5.5 | Authenticated (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Adam Skaat's Countdown & Clock plugin <= 2.3.2… | — | wordfence |
| 24a041d0-d443-453d-bd7d-65cceee48b14 | < 1.8.9 |
MEDIUM | 5.5 | The WPFrom Email plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in versions up to… | — | wordfence |
| 247a095b-0a92-4fee-85cf-c3041a061d62 | MEDIUM | 5.5 | The HTML5 Responsive FAQ plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and includ… | — | wordfence | |
| 244a23a2-8899-4ab4-8f8d-62756e4ea56b | < 2.0.11 |
MEDIUM | 5.5 | Authenticated Cross site Scripting exists in the User Profile & Membership plugin before 2.0.11 for WordPress via the "A… | — | wordfence |
| 240691c4-35c5-40e1-b1ab-a500ffcdac73 | < 2.45.1 |
MEDIUM | 5.5 | The Simple Giveaways plugin for WordPress is vulnerable to Stored Cross-Site Scripting via certain form, prize, and shar… | — | wordfence |
| 23f58949-6cc7-45a3-a6a0-58213bb03679 | MEDIUM | 5.5 | Authenticated (contributor of higher user role) Stored Cross-Site Scripting (XSS) vulnerability discovered in WordPress … | — | wordfence | |
| 23a2fd80-65cb-4e92-978d-c365f08b4c0b | MEDIUM | 5.5 | The Subpages Extended plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘subpages_save_postdat… | — | wordfence | |
| 22fa9343-0b6e-47d5-9ebc-2c8902428b8b | < 1.1.0 |
MEDIUM | 5.5 | The Limit Login Attempts Plus plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in ve… | — | wordfence |
| 22de2da7-f7db-46de-9305-52bce6e56937 | MEDIUM | 5.5 | The WP LESS to CSS plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several parameters in versions … | — | wordfence | |
| 2294565a-987e-4837-ab22-6e7bff498044 | < 2.1.0 |
MEDIUM | 5.5 | The Accordions plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘pages’ parameter used in t… | — | wordfence |
| 222aa8cb-95f4-4fe1-82c8-3acf82960cc0 | < 3.1.4 |
MEDIUM | 5.5 | The Simply Static plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions u… | — | wordfence |
| 222678d0-cb1f-43c6-a6f0-37ea0be8cd3d | < 3.6.11 |
MEDIUM | 5.5 | The Ninja Forms Contact Form plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several parameters fo… | — | wordfence |
EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.
Scan My Website →