Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.
40,383 vulnerabilities found (page 1096 of 1616)
| CVE ID | Plugin / Theme | Severity | CVSS | Description | Fixed In | Source |
|---|---|---|---|---|---|---|
| 1b038c9e-9053-43aa-99f2-cba660d2a7ff | MEDIUM | 5.4 | The Min and Max Purchase for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versio… | — | wordfence | |
| 1accc41e-41d2-49e3-a80a-6b95b02cb42e | < 6.10.3 |
MEDIUM | 5.4 | The Site Reviews plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability che… | — | wordfence |
| 1a5d9290-b480-45f7-9ac7-a20475b805e8 | < 2.0.4 |
MEDIUM | 5.4 | Unvalidated input and lack of output encoding within the Related Posts for WordPress plugin before 2.0.4 lead to a Refle… | — | wordfence |
| 1a0fcd50-e9d6-49a5-979f-61f953b1a1cd | < 1.9.6 |
MEDIUM | 5.4 | The Safe SVG plugin for WordPress is vulnerable to Cross-Site Scripting in versions up to, and including, 1.9.5 due to i… | — | wordfence |
| 19e9a9f7-d2e3-4ebb-b121-99c7c81ede4f | < 4.16.3 |
MEDIUM | 5.4 | The WordPress File Upload WordPress plugin before 4.16.3, wordpress-file-upload-pro WordPress plugin before 4.16.3 allow… | — | wordfence |
| 19d724f3-96fb-4834-aa56-6b8d30f0e34d | < 1.8.4 |
MEDIUM | 5.4 | The HD Quiz WordPress plugin before 1.8.4 does not escape some of its Answers before outputting them in attribute when g… | — | wordfence |
| 19c88a9a-1f97-4a46-b759-9ca030d577e7 | < 3.7.40 |
MEDIUM | 5.4 | WordPress Core is vulnerable to open redirect in versions up to 6.0.3. This is due to insufficient validation of the 'Re… | — | wordfence |
| 1998cadb-2eb3-4819-aa7c-59e4f777c7f8 | < 2024.5 |
MEDIUM | 5.4 | The Stop Spammers Security | Block Spam Users, Comments, Forms plugin for WordPress is vulnerable to Cross-Site Request … | — | wordfence |
| 191d5bcc-70d8-430b-9215-00ffdc04be87 | < 2.7.1 |
MEDIUM | 5.4 | The JSM file_get_contents() Shortcode plugin for WordPress is vulnerable to Server-Side Request Forgery in versions up t… | — | wordfence |
| 18e2e0e5-495f-4f55-b7d8-94193fc2ad12 | < 1.13.3 |
MEDIUM | 5.4 | The Elementor Addon Elements plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's widgets … | — | wordfence |
| 18dd1b86-3206-4cd7-a20b-33240c139aa5 | < 3.1.5 |
MEDIUM | 5.4 | The MailChimp Forms by MailMunch plugin for WordPress is vulnerable to unauthorized modification of data and loss of dat… | — | wordfence |
| 18b64b4a-e290-4efb-baa6-5cceb988ac87 | MEDIUM | 5.4 | The The Job Board Manager plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and… | — | wordfence | |
| 18b2d99a-f55c-4a05-8442-e1fddd59181f | < 4.10.25 |
MEDIUM | 5.4 | The Premium Addons for Elementor plugin for WordPress is vulnerable to DOM-Based Stored Cross-Site Scripting via the plu… | — | wordfence |
| 18acd104-a5a5-4811-9aea-abc227a1712c | MEDIUM | 5.4 | The Basic Log Viewer plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, … | — | wordfence | |
| 18a41bef-feed-4096-a1f4-9c99caac6ce9 | < 1.1.5 |
MEDIUM | 5.4 | The Redirection plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.1.4… | — | wordfence |
| 17f8e2a0-b23f-4706-8438-7a6573a29933 | < 1.0.95.1 |
MEDIUM | 5.4 | The Rank Math SEO plugin for WordPress is vulnerable to Server Side Request Forgery in versions up to, and including 1.0… | — | wordfence |
| 17f2a0d5-6640-4ef9-a219-93a92571a5d3 | < 1.1.12 |
MEDIUM | 5.4 | Pinboard 1.1.10 theme for Wordpress has XSS. | — | wordfence |
| 179eb680-e8d8-4918-96e3-e67217771c29 | < 1.9.5.1 |
MEDIUM | 5.4 | The WPForms β Easy Form Builder for WordPress β Contact Forms, Payment Forms, Surveys, & More plugin for WordPress i… | — | wordfence |
| 179c4920-5a03-4cf4-9e77-a814c3004769 | < 2.04 |
MEDIUM | 5.4 | The display-widgets plugin before 2.04 for WordPress has XSS via the wp-admin/admin-ajax.php?action=dw_show_widget id_ba… | — | wordfence |
| 16f40b76-8f69-46de-a3e0-b7124dc74c00 | < 6.3.2 |
MEDIUM | 5.4 | The Advanced Custom Fields Pro plugin for WordPress is vulnerable to unauthorized access due to a missing capability che… | — | wordfence |
| 16800ece-da9c-431b-a015-42bd30b646e2 | < 1.8.2 |
MEDIUM | 5.4 | The Bricks theme for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.8.1. This… | — | wordfence |
| 1671e437-09f0-46bc-87ef-3a5712c3dc98 | < 1.3.13 |
MEDIUM | 5.4 | The Dynamics 365 Integration plugin for WordPress is vulnerable to unauthorized modification of data due to a missing ca… | — | wordfence |
| 1665f2d0-899b-4f9b-91b1-e5799c3b4d3d | < 5.4.22 |
MEDIUM | 5.4 | The Woffice Core plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, … | — | wordfence |
| 160740a2-f5e1-49d6-a380-e6bf33646300 | MEDIUM | 5.4 | The examapp plugin 1.0 for WordPress has XSS via exam input text fields. | — | wordfence | |
| 15c8addc-e40b-4ad2-9e7b-c721d10164d6 | MEDIUM | 5.4 | The GS Insever Portfolio plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and includi… | — | wordfence |
EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.
Scan My Website →