Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.
40,369 vulnerabilities found (page 1053 of 1615)
| CVE ID | Plugin / Theme | Severity | CVSS | Description | Fixed In | Source |
|---|---|---|---|---|---|---|
| 0c157d70-1d4d-482e-8996-bc047a801681 | MEDIUM | 5.5 | The Event Timeline WordPress plugin through 1.1.6 does not sanitize and escape Timeline Text, which could allow high-pri… | — | wordfence | |
| 0bba9e06-4c5b-43e4-a51b-af57c5390c8a | < 2.1.28 |
MEDIUM | 5.5 | Multiple Authenticated (administrator or higher user role) Persistent Cross-Site Scripting (XSS) vulnerabilities in TMS-… | — | wordfence |
| 0b95749b-c522-42cd-aa99-36bdf15541c3 | MEDIUM | 5.5 | The Eventify plugin for WordPress is vulnerable to Stored Cross-Site Scripting parameter in versions up to, and includi… | — | wordfence | |
| 0b7da6f7-d486-44e5-9eeb-21feb119a48b | MEDIUM | 5.5 | The Add Shortcodes Actions And Filters plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up … | — | wordfence | |
| 0b458e27-331b-4ae2-ade8-8b14aeffb1e2 | MEDIUM | 5.5 | The WP Super Popup plugin for WordPress is vulnerable to Stored Cross-Site Scripting parameter in versions up to, and in… | — | wordfence | |
| 0abf9705-2716-403f-9348-e43a8d8fb1d2 | < 7.2.4 |
MEDIUM | 5.5 | The Booster for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's wcj_produ… | — | wordfence |
| 0a73d326-cd27-4719-8c26-3aa5dce837c0 | < 3.2.16 |
MEDIUM | 5.5 | The WordPress Download Manager WordPress plugin before 3.2.16 does not escape some of the Download settings when outputt… | — | wordfence |
| 09ee6179-8071-4628-9d2b-dfbb32ef1804 | < 1.0.8 |
MEDIUM | 5.5 | The Relevant Related Posts plugin up to and including version 1.0.7 for WordPress is vulnerable to stored cross-site scr… | — | wordfence |
| 09952b56-a064-46f9-b037-be86cf6df781 | < 1.4.12 |
MEDIUM | 5.5 | The Cimatti Contact Forms plugin for WordPress is vulnerable to Cross-Site Scripting in versions up to, and including, 1… | — | wordfence |
| 09613e4a-0dbe-430a-ab75-725038218803 | MEDIUM | 5.5 | The Any Hostname WordPress plugin through 1.0.6 does not sanitise or escape its "Allowed hosts" setting, leading to an a… | — | wordfence | |
| 095bee95-d3a7-4203-96eb-90f1f0eab84f | < 1.0.77.32 |
MEDIUM | 5.5 | Authenticated (admin or higher user role) Stored Cross-Site Scripting (XSS) vulnerability discovered in AMP for WP – A… | — | wordfence |
| 094c0952-4e28-4ed0-80ae-14fcf10cf2e1 | < 3.1.2 |
MEDIUM | 5.5 | The Survey Maker – Best WordPress Survey Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via … | — | wordfence |
| 0933ea77-2de0-4cd5-a589-a4c1d474f119 | < 2.1.0 |
MEDIUM | 5.5 | The Accordions plugin for WordPress is vulnerable to Stored Cross-Site Scripting via any parameters used in the 'rawdata… | — | wordfence |
| 09277f30-9b6a-4cc9-bc8c-09c360da917a | < 5.1.1 |
MEDIUM | 5.5 | The Team Members WordPress plugin before 5.1.1 does not escape some of its Team settings, which could allow high privile… | — | wordfence |
| 09023fe2-52dd-43af-ae4f-1fb46654f305 | < 2.13.1 |
MEDIUM | 5.5 | The Import WP – Export and Import CSV and XML files to WordPress plugin for WordPress is vulnerable to Server-Side Req… | — | wordfence |
| 08ffb478-7280-4fbc-bc5f-482c1348091e | < 3.4.5 |
MEDIUM | 5.5 | The Google Apps Login plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including… | — | wordfence |
| 082efb3c-dbe4-49b5-abec-da91f2d463eb | < 1.0.3 |
MEDIUM | 5.5 | The Opensea WordPress plugin before 1.0.3 does not sanitize and escape some of its settings, like its "Referer address" … | — | wordfence |
| 07c0516b-ee3a-4a80-8db7-e6372bb294a1 | < 5.8.23 |
MEDIUM | 5.5 | The AdRotate WordPress plugin before 5.8.23 does not escape Group Names, which could allow high privilege users to perfo… | — | wordfence |
| 0758e317-d67e-4767-bbaa-cfcbf86d4819 | < 1.8 |
MEDIUM | 5.5 | The Smartarget Popup plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including,… | — | wordfence |
| 06905738-7e1c-4d1a-97d2-f68f978ad8ed | < 0.5.28 |
MEDIUM | 5.5 | The Duplicator plugin for WordPress is vulnerable to Cross-Site Scripting in versions up to, and including, 0.5.26 due t… | — | wordfence |
| 06511129-fb43-4ac1-9f5d-c637c9577293 | < 2.0.3 |
MEDIUM | 5.5 | The Link Juice Keeper plugin for WordPress is vulnerable to stored cross-site scripting in versions up to, and including… | — | wordfence |
| 05fe1929-9e39-4b2f-a3fc-e692267d731b | < 4.3 |
MEDIUM | 5.5 | The DSGVO All in one for WP plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘dsdvo_customimp… | — | wordfence |
| 05ee4692-451b-4ff4-9bf0-8a16d39404ea | < 3.0.4 |
MEDIUM | 5.5 | The Top Bar plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the tpbr_message,tpbr_btn_text,tpbr_bt… | — | wordfence |
| 05dcfd2d-6488-4f82-b20b-4968e4a00796 | < 1.3.1 |
MEDIUM | 5.5 | The VikRentCar Car Rental Management System plugin for WordPress is vulnerable to Cross-Site Scripting in versions up to… | — | wordfence |
| 0551a2ca-b920-4a60-9c16-0bb14fd63a23 | < 8.0 |
MEDIUM | 5.5 | The wp-forecast plugin for WordPress is vulnerable to Stored Cross-Site Scripting via an unknown parameter in versions u… | — | wordfence |
EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.
Scan My Website →