Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.
40,369 vulnerabilities found (page 1054 of 1615)
| CVE ID | Plugin / Theme | Severity | CVSS | Description | Fixed In | Source |
|---|---|---|---|---|---|---|
| 051a987a-944a-4898-872b-0456f0f59b27 | < 6.5 |
MEDIUM | 5.5 | The LiteSpeed Cache plugin for WordPress is vulnerable to Stored Cross-Site Scripting via plugin debug settings in all v… | — | wordfence |
| 04e0b17e-efab-4b08-8c8a-93e3e4baffaa | < 3.7.31 |
MEDIUM | 5.5 | WordPress before 5.2.4 does not properly consider type confusion during validation of the referer in the admin pages, po… | — | wordfence |
| 04aa7307-03c6-42f9-8219-fb6002c85050 | < 4.1.1 |
MEDIUM | 5.5 | The Culture Object plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 4… | — | wordfence |
| 045717f4-0e31-41f8-b0c3-8118c768b648 | < 1.21 |
MEDIUM | 5.5 | The underConstruction WordPress plugin before 1.21 does not sanitise or escape the "Display a custom page using your own… | — | wordfence |
| 043263a1-ce87-45a2-83ee-4b826c7ffd7d | < 1.2.56 |
MEDIUM | 5.5 | The Slider by 10Web – Responsive Image Slider plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all… | — | wordfence |
| 03cd1f6e-2400-44e7-b2b0-32c9890e1c1b | < 1.8.0 |
MEDIUM | 5.5 | The Custom Product Tabs plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and includi… | — | wordfence |
| 03a1724c-8fea-4e9f-a4a1-9de236e1f15a | MEDIUM | 5.5 | The Export Users Data Distinct plugin for WordPress is vulnerable to CSV Injection in versions up to, and including, 1.3… | — | wordfence | |
| 03725477-7d7b-4ec9-8b9f-5ce9f8905243 | < 3.4.7 |
MEDIUM | 5.5 | The Jetpack Boost – Website Speed, Performance and Critical CSS plugin for WordPress is vulnerable to Server-Side Requ… | — | wordfence |
| 0306c785-0dc3-44fb-a3cc-9afb5ab81651 | < 1.5.13 |
MEDIUM | 5.5 | The WP Admin UI Customize plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘footer text’ pa… | — | wordfence |
| 028a90c7-ded7-45ad-90ea-9f1a7d3743a0 | < 1.1.7 |
MEDIUM | 5.5 | The Conversational Forms for ChatBot for WordPress is vulnerable to Stored Cross-Site Scripting via a form name in versi… | — | wordfence |
| 0252d07a-cf84-479d-a71b-a9b13a9765d5 | < 1.90 |
MEDIUM | 5.5 | The WP Reset – Most Advanced WordPress Reset Tool WordPress plugin before 1.90 did not sanitise or escape its extra_da… | — | wordfence |
| 02319fc2-8a7e-4b3e-8711-724dcff7a233 | < 8.8.5 |
MEDIUM | 5.5 | The Newsletter – Send awesome emails from WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting … | — | wordfence |
| 012e7aed-04d9-4795-9ea9-40dd72fa612f | MEDIUM | 5.5 | The Skimlinks Affiliate Marketing Tool plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions… | — | wordfence | |
| 0016c624-9c0c-4157-8597-8b374dff7f14 | < 7.3 |
MEDIUM | 5.5 | The WP Socializer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘misc_additional_css’ pa… | — | wordfence |
| 0004db27-9ea6-4387-ab1d-b95558784ed9 | < 1.38 |
MEDIUM | 5.5 | The We’re Open! plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several of its setting parameter… | — | wordfence |
| ff937860-c4e0-4172-9f0f-d66578fa7203 | < 2.0.46 |
MEDIUM | 5.4 | The Easy Table of Contents plugin for WordPress is vulnerable to unauthorized modification of data and loss of data due … | — | wordfence |
| ff7e7539-6a09-461a-a9a7-33630c396f1a | < 1.0.4 |
MEDIUM | 5.4 | The Auto YouTube Importer plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and includ… | — | wordfence |
| fec9a7a6-c515-4b43-8efc-9b3c86f0fd4b | < 7.9.8 |
MEDIUM | 5.4 | The Admin and Site Enhancements (ASE) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File upl… | — | wordfence |
| fe25ac93-c3b6-49db-b36c-b31e9cce242c | < 11.12.7 |
MEDIUM | 5.4 | The PowerPress Podcasting plugin by Blubrry plugin for WordPress is vulnerable to Server-Side Request Forgery in all ver… | — | wordfence |
| fe14b92b-1784-4083-9b9f-23d7f69a3215 | < 2.1.13 |
MEDIUM | 5.4 | The Minify HTML plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2… | — | wordfence |
| fdc57b06-bae9-49a3-84dd-f593705330e9 | < 3.15.2 |
MEDIUM | 5.4 | The Avada (Fusion) Builder plugin for WordPress is vulnerable to Arbitrary WordPress Action Execution in all versions up… | — | wordfence |
| fd9f1385-6457-4bc9-9c75-0fcd399a5956 | < 6.1.11 |
MEDIUM | 5.4 | The Awesome Support plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on an un… | — | wordfence |
| fd5f370c-743f-41f1-80ab-7f0805cae38c | MEDIUM | 5.4 | The Scheduler Widget plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and i… | — | wordfence | |
| fd53b4e1-c6b7-4111-911a-04b14c7a9c4e | < 1.12.8 |
MEDIUM | 5.4 | The Elementor Addon Elements plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and inc… | — | wordfence |
| fd3bf470-f966-454d-8df3-0dec4682e883 | < 6.1.13 |
MEDIUM | 5.4 | The Fluent Forms Pro Add On Pack plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to… | — | wordfence |
EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.
Scan My Website →