Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.
40,383 vulnerabilities found (page 1082 of 1616)
| CVE ID | Plugin / Theme | Severity | CVSS | Description | Fixed In | Source |
|---|---|---|---|---|---|---|
| 69401e9f-6bd3-49b8-8ebd-6904db680610 | < 2.0.0 |
MEDIUM | 5.4 | The Responsive Tabs Plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘post_title’ parameter… | — | wordfence |
| 693fbac2-46b8-4771-99b5-6cd97096286e | < 5.5 |
MEDIUM | 5.4 | The WP Visitor Statistics (Real Time Traffic) WordPress plugin before 5.5 does not have authorisation and CSRF checks in… | — | wordfence |
| 691b7428-73e5-4800-85a1-19daa85aff4e | < 3.11.11 |
MEDIUM | 5.4 | The Prime Slider – Addons For Elementor plugin for WordPress is vulnerable to unauthorized access of data due to a mis… | — | wordfence |
| 689f3667-2dda-40a8-8627-d38c6c6816fc | < 2.0.63 |
MEDIUM | 5.4 | The Contests by Rewards Fuel plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and… | — | wordfence |
| 67e0e59d-879c-434f-9ffb-1b97d8105bfa | < 1.7.2 |
MEDIUM | 5.4 | The Cookie Notice & Consent Banner for GDPR & CCPA Compliance WordPress plugin before 1.7.2 does not properly sanitize i… | — | wordfence |
| 67d2364c-6c8b-4b30-8a0e-2f9ee94a3c26 | < 2.1 |
MEDIUM | 5.4 | The Side Cart Woocommerce (Ajax) plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions before 2.1… | — | wordfence |
| 67790c0b-c078-4955-a175-977a695392fc | < 1.13.4 |
MEDIUM | 5.4 | The Elementor Addon Elements plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Twitter … | — | wordfence |
| 6767cc8e-f327-4891-8d3c-555ba7f5062c | MEDIUM | 5.4 | The Post Teaser plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the init… | — | wordfence | |
| 67351a37-a457-48d6-b40a-95a7e3a0d746 | < 6.15.16.1 |
MEDIUM | 5.4 | The The Events Calendar plugin for WordPress is vulnerable to unauthorized modification of data and loss of data due to … | — | wordfence |
| 670e92d6-4136-48f1-88d1-69a9fa772a65 | < 2.11.2.1 |
MEDIUM | 5.4 | The Easy Digital Downloads plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'start-date' and… | — | wordfence |
| 66efc65e-48d3-4ef9-a369-51448e47686a | MEDIUM | 5.4 | The Responsive Image Gallery, Gallery Album plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions… | — | wordfence | |
| 66d70cf6-494f-4221-af3b-ee76cf22a305 | < 1.8 |
MEDIUM | 5.4 | The Responsive Cookie Consent plugin before 1.8 for WordPress mishandles number fields, leading to XSS. | — | wordfence |
| 66abfe6b-c706-4e70-b35b-ee04da613933 | MEDIUM | 5.4 | The Remote Content Shortcode plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'remote_content' … | — | wordfence | |
| 66a7ffcc-6929-4c66-bfab-15c0f0097a49 | < 1.3.10 |
MEDIUM | 5.4 | The Contact Form, Survey & Form Builder – MightyForms plugin for WordPress is vulnerable to unauthorized access due to… | — | wordfence |
| 662116f0-0d32-4d24-868a-a8eccb3ad401 | < 25.05.13 |
MEDIUM | 5.4 | The The Team Showcase plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to 25.05.13… | — | wordfence |
| 659f5a99-84f4-44b0-8546-445831c7e0d1 | < 1.9.6 |
MEDIUM | 5.4 | The fitness calculators WordPress plugin before 1.9.6 add calculators for Water intake, BMI calculator, protein Intake, … | — | wordfence |
| 65465de9-c527-4b18-8a52-c9cd2d594f72 | < 3.5.2 |
MEDIUM | 5.4 | WordPress before 3.5.2 allows remote attackers to read arbitrary files via an oEmbed XML provider response containing an… | — | wordfence |
| 6528041a-0217-43d5-bf29-9208e23aadd9 | < 3.4 |
MEDIUM | 5.4 | The Weblizar Pin It Button On Image Hover And Post plugin for WordPress is vulnerable to authorization bypass due to a m… | — | wordfence |
| 64cce528-0ad0-45ec-a8f6-e8791b0bece0 | < 1.3.60 |
MEDIUM | 5.4 | The Royal Elementor Addons plugin for WordPress is vulnerable to insufficient access control in the 'wpr_import_template… | — | wordfence |
| 64ae36a3-d102-4d51-b685-395283155101 | < 3.10.0 |
MEDIUM | 5.4 | The Happy Addons for Elementor plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to 3… | — | wordfence |
| 64a833df-1cb8-40a1-9a8f-c53dcf50c877 | < 0.9.97.21 |
MEDIUM | 5.4 | ampforwp_save_steps_data in the AMP for WP plugin before 0.9.97.21 for WordPress allows stored XSS. | — | wordfence |
| 64a0bfa9-beb3-4926-bfed-af55a101aff1 | < 3.1.7 |
MEDIUM | 5.4 | The Login With Ajax plugin for WordPress is vulnerable to Cross-Site Scripting in versions up to, and including, 3.1.6 d… | — | wordfence |
| 6471b075-8115-4d38-a7dd-2308dca69f15 | < 4.2.9 |
MEDIUM | 5.4 | The Splitit plugin for WordPress is vulnerable to unauthorized modification of data due to missing capability checks on … | — | wordfence |
| 645ab4b9-e421-4610-b99b-960a7fbb7779 | < 2.7.9 |
MEDIUM | 5.4 | The Schema Pro plugin for WordPress is vulnerable to unauthorized access, modification, or loss of data due to a missing… | — | wordfence |
| 642e2c46-9e42-4c00-bb91-a43497094e12 | < 2.9.11 |
MEDIUM | 5.4 | The ListingPro Reviews plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a … | — | wordfence |
EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.
Scan My Website →