Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.
40,402 vulnerabilities found (page 1260 of 1617)
| CVE ID | Plugin / Theme | Severity | CVSS | Description | Fixed In | Source |
|---|---|---|---|---|---|---|
| f2fee7aa-5289-4bf0-b175-5a64b16fdd40 | < 1.4.3 |
MEDIUM | 4.8 | The Booking.com Banner Creator WordPress plugin before 1.4.3 does not properly sanitize inputs when creating banners, wh… | — | wordfence |
| f2f4313a-568e-4ee2-b283-cd7bb62b75fa | < 3.2.4 |
MEDIUM | 4.8 | The Simple Social Media Share Buttons WordPress plugin before 3.2.4 does not escape the Share Title settings before outp… | — | wordfence |
| f20aff55-f9c9-42f7-9c7b-3f4a709f4a60 | < 2.6.5 |
MEDIUM | 4.8 | The bbPress plugin through 2.6.4 for WordPress has stored XSS in the Forum creation section, resulting in JavaScript exe… | — | wordfence |
| f15d39ba-9211-4d35-8252-20d53c6bc249 | < 1.68.7 |
MEDIUM | 4.8 | Multiple Authenticated Stored Cross-Site Scripting (XSS) vulnerabilities discovered in WP-DownloadManager WordPress plug… | — | wordfence |
| f09584f9-7ea3-4cfb-bbdf-7ca241e64bb1 | < 3.1.3 |
MEDIUM | 4.8 | Authenticated (author or higher role) Stored Cross-Site Scripting (XSS) vulnerability in Fatcat Apps Easy Pricing Tables… | — | wordfence |
| f01e9908-c4d7-4eaf-8bba-4f5da7fa7703 | < 4.5.2 |
MEDIUM | 4.8 | The Malware Scanner WordPress plugin before 4.5.2 does not sanitise and escape some of its settings, leading to maliciou… | — | wordfence |
| efd18739-3cd1-486c-9587-8deba5a0940e | MEDIUM | 4.8 | The myLinksDump plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'link_title' parameter in all … | — | wordfence | |
| eeae71a6-53b2-4eab-82c0-d23cff3f0f7c | < 2.1.2 |
MEDIUM | 4.8 | The WP GDPR plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Button Text setting in versions up… | — | wordfence |
| ee4a9dc6-fc0b-4bab-9511-fa0a713800ff | MEDIUM | 4.8 | The HPB Dashboard WordPress plugin through 1.3.1 does not sanitise and escape some of its settings, which could allow hi… | — | wordfence | |
| edcc51f8-bf79-453a-aa4d-5d1d491316eb | < 2.0.7 |
MEDIUM | 4.8 | The StatCounter WordPress plugin before 2.0.7 does not sanitise and escape the Project ID and Secure Code settings, whic… | — | wordfence |
| eaf0d324-bf2c-4da7-b2ab-f53f7b7881f2 | < 3.6.10 |
MEDIUM | 4.8 | The Ninja Forms Contact Form plugin for WordPress is vulnerable to Stored Cross-Site Scripting via field labels in versi… | — | wordfence |
| e97ed28c-b4a2-47ee-8fbe-7c995fa102cb | < 3.26.2 |
MEDIUM | 4.8 | The Stock Ticker plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up… | — | wordfence |
| e6a9ae9e-17f2-4fcb-8428-f6bf1a500bc4 | < 1.8.18 |
MEDIUM | 4.8 | The FooGallery plugin 1.8.12 for WordPress allow XSS via the post_title parameter. Please note this requires administrat… | — | wordfence |
| e6838714-4128-47c5-b596-91cfc68abade | < 1.9.5 |
MEDIUM | 4.8 | The Caldera Forms WordPress plugin before 1.9.5 does not sanitise and escape the Form Name before outputting it in attri… | — | wordfence |
| e6650eb7-143f-4c8f-b18f-056fc82972fc | < 1.4.9 |
MEDIUM | 4.8 | The Product Reviews Import Export for WooCommerce plugin for WordPress is vulnerable to CSV Injection in versions up to,… | — | wordfence |
| e608c75f-dd84-4921-ae61-2bfa5cd717a5 | MEDIUM | 4.8 | The BannerMan WordPress plugin through 0.2.4 does not sanitize or escape its settings, which could allow high-privileged… | — | wordfence | |
| e5748252-d02a-463b-abb4-537144ccd608 | < 1.16.45 |
MEDIUM | 4.8 | The E2Pdf WordPress plugin before 1.16.45 does not sanitise and escape some of its settings, which could allow high priv… | — | wordfence |
| e52f799e-9174-45a2-9ed6-7aedb26b36bd | < 6.0.14 |
MEDIUM | 4.8 | The awesome-support plugin 6.0.13 and below for WordPress allows XSS via the post_title parameter. | — | wordfence |
| e404d689-f0b5-43cc-b366-b7d6a44a9dcc | < 6.2.7 |
MEDIUM | 4.8 | Authenticated (author or higher user role) Stored Cross-Site Scripting (XSS) vulnerability discovered in MaxGalleria Wor… | — | wordfence |
| e3702936-9ae2-4efb-bdfe-9e1dfceb246b | < 0.4 |
MEDIUM | 4.8 | The Protect uploads plugin for WordPress failed to use a capability check and leaked the nonce necessary to save changes… | — | wordfence |
| e0df0a4e-282e-483a-8d5e-a192620ed2d2 | MEDIUM | 4.8 | The Call&Book Mobile Bar WordPress plugin through 1.2.2 does not sanitize and escape some of its settings, which could a… | — | wordfence | |
| df2674c9-da77-412c-a812-f1749f54d04b | < 4.5.0 |
MEDIUM | 4.8 | The MailArchiver plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up… | — | wordfence |
| dde57a98-06d5-4a3c-b100-170e9c339908 | < 5.0.07 |
MEDIUM | 4.8 | The Formidable Form Builder β Contact Form, Survey & Quiz Forms Plugin for WordPress plugin before 5.0.07 does not san… | — | wordfence |
| dab3786b-1f8e-428c-afee-afd3e43f40ba | MEDIUM | 4.8 | The Security Audit WordPress plugin through 1.0.0 does not sanitise and escape the Data Id setting, which could allow hi… | — | wordfence | |
| d6286cda-c5b1-4923-bbf3-9f5b56973d23 | MEDIUM | 4.8 | The NextCellent Gallery WordPress plugin through 1.9.35 does not sanitise and escape some of its image settings, which c… | — | wordfence |
EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.
Scan My Website →