Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.
40,402 vulnerabilities found (page 1261 of 1617)
| CVE ID | Plugin / Theme | Severity | CVSS | Description | Fixed In | Source |
|---|---|---|---|---|---|---|
| d3ace116-69e1-44b1-a63f-693153ab4679 | < 1.3.6 |
MEDIUM | 4.8 | The Weather Effect WordPress plugin before 1.3.6 does not properly validate and escape some of its settings (like *_size… | — | wordfence |
| cfc59270-d08c-4b78-9863-4bb88120b878 | < 1.0.19 |
MEDIUM | 4.8 | The Petfinder Listings WordPress plugin through 1.0.18 does not escape its settings, allowing high privilege users such … | — | wordfence |
| cf44a96e-0efb-4363-9f49-ba4a82924569 | < 1.9.6 |
MEDIUM | 4.8 | The Video Lightbox plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several parameters in versions … | — | wordfence |
| cede7e6f-e3e8-479b-9c7b-91c390ed3936 | < 2.0.69 |
MEDIUM | 4.8 | The Export customers list csv plugin for WooCommerce is vulnerable to CSV Injection in versions up to, and including, 2.… | — | wordfence |
| cde35356-daba-47ff-9278-21447337f0c7 | < 1.0.11 |
MEDIUM | 4.8 | The Remove Footer Credit WordPress plugin before 1.0.11 does properly sanitise its settings, allowing high privilege use… | — | wordfence |
| cdb3cdf8-7563-4ccd-83fe-7ebd13fa7936 | < 1.7.7 |
MEDIUM | 4.8 | The WP Google Map WordPress plugin before 1.7.7 did not sanitise or escape the Map Title before outputting them in the p… | — | wordfence |
| cbd4f08c-9989-4af9-b615-1db82909a1db | < 3.6.3 |
MEDIUM | 4.8 | The Import any XML or CSV File to WordPress plugin before 3.6.3 does not escape the Import's Title and Unique Identifier… | — | wordfence |
| cb714378-ed60-4bf1-8c9c-b37515ddb353 | < 3.5.9 |
MEDIUM | 4.8 | The Erident Custom Login and Dashboard WordPress plugin before 3.5.9 did not properly sanitise its settings, allowing hi… | — | wordfence |
| c95210ba-65f6-4bf8-8986-f537f1854d02 | < 2.7.8 |
MEDIUM | 4.8 | The Autoptimize WordPress plugin before 2.7.8 does not check for malicious files such as .html in the archive uploaded v… | — | wordfence |
| c6e7ada1-c5ff-4a05-92e1-d681fc659956 | MEDIUM | 4.8 | The Per page add to head WordPress plugin through 1.4.4 does not properly sanitise one of its setting, allowing maliciou… | — | wordfence | |
| c32824cc-8895-462f-bd5b-03b8da4db680 | < 1.9.7 |
MEDIUM | 4.8 | The WPGlobus plugin 1.9.6 for WordPress has XSS via the wpglobus_option[post_type][page] parameter to wp-admin/options.p… | — | wordfence |
| c1a0d446-63b6-4265-a542-345d766faf15 | < 1.8.1 |
MEDIUM | 4.8 | The CLUEVO LMS, E-Learning Platform WordPress plugin before 1.8.1 does not sanitise and escape Course's module, which co… | — | wordfence |
| c0dfa035-78fe-426f-a018-7bb2f22f0dd7 | < 4.03 |
MEDIUM | 4.8 | The Maintenance WordPress plugin before 4.03 does not sanitise or escape some of its settings, allowing high privilege u… | — | wordfence |
| c09536b3-9f8d-4b11-b69a-684b65078870 | < 1.9.7 |
MEDIUM | 4.8 | The WPGlobus plugin 1.9.6 for WordPress has XSS via the wpglobus_option[browser_redirect][redirect_by_language] paramete… | — | wordfence |
| bede3241-6383-4bdb-ac28-cd9781b608d1 | < 1.68.7 |
MEDIUM | 4.8 | Multiple Authenticated Stored Cross-Site Scripting (XSS) vulnerabilities discovered in WP-DownloadManager WordPress plug… | — | wordfence |
| bdc46d3e-dfb7-4586-86d2-8e4b3805ec22 | < 10.0.4 |
MEDIUM | 4.8 | The WP Editor.md plugin before 10.0.4 for WordPress allows XSS via the comment area. | — | wordfence |
| bdb5ae36-6ce2-4c26-8047-6bbbdce530c6 | < 2.0.3 |
MEDIUM | 4.8 | WordPress Popups, Welcome Bar, Optins and Lead Generation Plugin β Icegram (versions <= 2.0.2) vulnerable at "Headline… | — | wordfence |
| bd650510-2d1c-48a1-a5fa-d4c26f3d030c | < 1.8.176 |
MEDIUM | 4.8 | The WS Form LITE and Pro WordPress plugins before 1.8.176 do not sanitise and escape their Form Name, which could allow … | — | wordfence |
| ba677822-a588-484e-a0aa-a9eda2954d01 | < 2.5.1.9 |
MEDIUM | 4.8 | These vulnerabilities require administrative privileges to exploit. There is an XSS vulnerability in integration-contact… | — | wordfence |
| b8a598cf-bdd6-4249-a367-e3e8c6e3ef15 | MEDIUM | 4.8 | A cross-site scripting (XSS) vulnerability in flickrRSS.php in the flickrRSS plugin 5.3.1 for WordPress allows remote at… | — | wordfence | |
| b67710d7-976b-4a65-bad3-091a97aceb00 | < 2.7.5 |
MEDIUM | 4.8 | The Better Messages β Live Chat for WordPress, BuddyPress, PeepSo, Ultimate Member, BuddyBoss plugin for WordPress is … | — | wordfence |
| b6616c4b-6021-42c8-afe1-bfd789b895ca | < 1.7.0 |
MEDIUM | 4.8 | The WP Sitemap Page WordPress plugin before 1.7.0 does not properly sanitise and escape some of its settings, which coul… | — | wordfence |
| b5018aac-59fb-4d95-bbdd-8ceaa4f8fad1 | < 1.8.3 |
MEDIUM | 4.8 | The WP YouTube Live WordPress plugin before 1.8.3 does not validate, sanitise and escape various of its settings, which … | — | wordfence |
| b3c65619-e96c-47e1-b42a-a85d0b5237d9 | < 1.7.0 |
MEDIUM | 4.8 | The wpForo plugin 1.6.5 for WordPress allows XSS via the wp-admin/admin.php?page=wpforo-phrases s parameter. | — | wordfence |
| b13f6a3f-cab6-4aff-a96e-58250fcf655a | < 3.7.35 |
MEDIUM | 4.8 | is_blog_installed in wp-includes/functions.php in WordPress before 5.5.2 improperly determines whether WordPress is alre… | — | wordfence |
EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.
Scan My Website →