Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.
40,369 vulnerabilities found (page 1052 of 1615)
| CVE ID | Plugin / Theme | Severity | CVSS | Description | Fixed In | Source |
|---|---|---|---|---|---|---|
| 13874012-09b4-4e6a-a364-07321dbd0167 | MEDIUM | 5.5 | The Very Simple Breadcrumb WordPress plugin through 1.0 does not sanitise and escape its settings, allowing high privile… | — | wordfence | |
| 12d84de4-d97e-40cc-9805-fc9b7de8fa21 | < 1.1 |
MEDIUM | 5.5 | The Interactive SVG Image Map Builder for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in v… | — | wordfence |
| 128f0e5e-96c7-474e-bfc9-ea18536b4a54 | < 2.1.0 |
MEDIUM | 5.5 | The Accordions plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘layouts’ parameter in vers… | — | wordfence |
| 1254e0ad-852e-4fd4-8317-61bfbbc9f737 | < 2.56 |
MEDIUM | 5.5 | The External Links plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2… | — | wordfence |
| 11653fa1-c6f5-4bcc-81d2-dd469300b40a | < 1.10 |
MEDIUM | 5.5 | Virtual Robots.txt before 1.10 does not block HTML tags in the robots.txt field. | — | wordfence |
| 10ef8475-4ec5-4412-97f6-3abdb4442b92 | MEDIUM | 5.5 | The alfred24 Click & Collect plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and in… | — | wordfence | |
| 10d861c2-8ebf-4ba8-a493-0ab3aa43aa76 | < 2.1.23 |
MEDIUM | 5.5 | In the nggallery-manage-gallery page in the Photocrati NextGEN Gallery plugin 2.1.15 for WordPress, XSS is possible for … | — | wordfence |
| 10a0abd6-1905-4a90-8488-29d44df7aeb9 | < 7.0 |
MEDIUM | 5.5 | The All-in-One WP Migration plugin for WordPress is vulnerable to Cross-Site Scripting due to the fact that the backup d… | — | wordfence |
| 0ff49f18-d6a6-46c9-a0be-e80dfe407992 | < 1.1.8 |
MEDIUM | 5.5 | The Ads.txt & App-ads.txt Manager for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting in ver… | — | wordfence |
| 0fdc2dac-b3ea-40bd-987b-e6c47e74aefc | < 4.1.11 |
MEDIUM | 5.5 | The CMP – Coming Soon & Maintenance Plugin by NiteoThemes plugin for WordPress is vulnerable to Server-Side Request Fo… | — | wordfence |
| 0f3c3629-b7a9-4f83-a821-64119ed662ce | < 1.2.5 |
MEDIUM | 5.5 | The Themify Portfolio Post plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and incl… | — | wordfence |
| 0f01c9c8-acd4-44c0-8866-a0a819828006 | < 2.1 |
MEDIUM | 5.5 | The All 404 Redirect to Homepage & Broken images Redirection plugin for WordPress is vulnerable to Stored Cross-Site Scr… | — | wordfence |
| 0ec90144-bfd8-4840-8b0f-73340386b7d5 | < 1.9.9 |
MEDIUM | 5.5 | The Donations via PayPal plugin for WordPress is vulnerable to Stored Cross-Site Scripting when saving settings in versi… | — | wordfence |
| 0ebaf76d-b659-41d2-8c66-4d6204678222 | < 1.5.0 |
MEDIUM | 5.5 | The Really Simple Under Construction Page plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions … | — | wordfence |
| 0e6616d0-0690-4bf4-9228-33679b926b90 | MEDIUM | 5.5 | The Image Hover Effects Css3 plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and in… | — | wordfence | |
| 0e5674e2-593a-4f53-bb03-9184eccc3244 | < 9.13 |
MEDIUM | 5.5 | The WP Spell Check plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's settings in versio… | — | wordfence |
| 0e38b567-9567-4b08-8fab-3971547394b0 | MEDIUM | 5.5 | Directory traversal vulnerability in wp-db-backup.php in the Skippy WP-DB-Backup legacy plugin for WordPress 1.7 and ear… | — | wordfence | |
| 0de0e5d5-7023-4026-ad82-3c2443569326 | < 1.0.4 |
MEDIUM | 5.5 | The Accessibility plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.… | — | wordfence |
| 0dda8e76-22aa-400b-b4c1-b24e6e1141ac | MEDIUM | 5.5 | The Google Maps Anywhere plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several parameters from t… | — | wordfence | |
| 0d627ee7-1175-4621-a477-1e9ec2d05eee | MEDIUM | 5.5 | The Reusable Text Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'text-blocks' shortcode i… | — | wordfence | |
| 0d4c5ff9-d4aa-4270-b00b-41353b32c8e5 | MEDIUM | 5.5 | The 404 to Start plugin for WordPress is vulnerable to Stored Cross-Site Scripting via some of its settings parameters i… | — | wordfence | |
| 0d3aa440-29a8-47cd-98f4-cf1cbdf92f66 | < 9.7.8 |
MEDIUM | 5.5 | The WordPress Button Plugin MaxButtons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘Cust… | — | wordfence |
| 0cfdb6de-41f8-4bea-a017-5708fceee762 | < 2.1.1 |
MEDIUM | 5.5 | The Social Share Button plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'ssb_share_content_ico… | — | wordfence |
| 0c80cbad-39ea-4f75-a025-6b9667560845 | MEDIUM | 5.5 | The Float to Top Button plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several parameters such as… | — | wordfence | |
| 0c788d06-6a80-4e34-92bb-b87f21916810 | < 1.10.20 |
MEDIUM | 5.5 | The Data Tables Generator by Supsystic WordPress plugin before 1.10.20 does not sanitise and escape some of its Table se… | — | wordfence |
EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.
Scan My Website →