Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.
40,402 vulnerabilities found (page 1262 of 1617)
| CVE ID | Plugin / Theme | Severity | CVSS | Description | Fixed In | Source |
|---|---|---|---|---|---|---|
| b0d8a530-53fd-4e2f-aa57-d75c89dc2a51 | < 4.19.2 |
MEDIUM | 4.8 | The WP RSS Aggregator WordPress plugin before 4.19.2 does not properly sanitise and escape the URL to Blacklist field, a… | — | wordfence |
| afbf555a-1b70-4966-9b05-46e9de04e660 | < 7.3.2 |
MEDIUM | 4.8 | The Comments - wpDiscuz WordPress plugin through 7.3.0 does not properly sanitize or escape the Follow and Unfollow mess… | — | wordfence |
| ae3d33dd-2591-4c4e-9769-77575e57ac49 | < 1.1.5 |
MEDIUM | 4.8 | The Video Gallery WordPress plugin before 1.1.5 does not escape the Title and Description of the videos in a gallery bef… | — | wordfence |
| ade346fc-d158-4485-85a8-d14d5e059554 | < 2.2.3 |
MEDIUM | 4.8 | The Custom Twitter Feeds β A Tweets Widget or X Feed Widget plugin for WordPress is vulnerable to Stored Cross-Site Sc… | — | wordfence |
| ab3033c5-95c3-44eb-8602-410288fc423f | < 1.9.7 |
MEDIUM | 4.8 | The WPGlobus plugin 1.9.6 for WordPress has XSS via the wpglobus_option[enabled_languages][en] or wpglobus_option[enable… | — | wordfence |
| a9ed9a77-5a51-4664-a8a5-579824f8eae7 | < 1.2.8 |
MEDIUM | 4.8 | The Shop Page WP WordPress plugin for WordPress is vulnerable to Cross-Site Scripting in versions up to, and including, … | — | wordfence |
| a8f91e58-942c-417f-ad82-5bd99ab5e81a | MEDIUM | 4.8 | A cross-site scripting (XSS) vulnerability in flickrRSS.php in the flickrRSS plugin 5.3.1 for WordPress allows remote at… | — | wordfence | |
| a7e58c6d-5b95-4b22-a7fc-e5e8324ed52a | MEDIUM | 4.8 | The Easily Generate Rest API Url WordPress plugin through 1.0.0 does not escape some of its settings, allowing high priv… | — | wordfence | |
| a66c2e1e-fd59-424b-bd11-0991a5c32dce | MEDIUM | 4.8 | The Storefront Footer Text WordPress plugin through 1.0.1 does not sanitize and escape the "Footer Credit Text" added to… | — | wordfence | |
| a333d5b4-cedf-40ac-8da9-f4965d2a397a | < 8.4.4 |
MEDIUM | 4.8 | The NEX-Forms - Ultimate Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via form names p… | — | wordfence |
| a27da737-d925-471f-b0e0-25bc27a95714 | < 1.68.7 |
MEDIUM | 4.8 | Authenticated Reflected Cross-Site Scripting (XSS) vulnerability discovered in WP-DownloadManager WordPress plugin (vers… | — | wordfence |
| a1eec01c-7f54-4e90-a943-c50b8ab79b22 | < 1.7.4 |
MEDIUM | 4.8 | The Slideshow Gallery WordPress plugin before 1.7.4 does not sanitise and escape the Slide "Title", "Description", and G… | — | wordfence |
| 9ec307de-600c-4fb2-b474-db9b674d4ead | MEDIUM | 4.8 | The rexCrawler plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up t… | — | wordfence | |
| 9d9cf724-9ae7-4414-88d1-10640491df34 | < 2.1.3 |
MEDIUM | 4.8 | The W3 Total Cache plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several CDN settings in version… | — | wordfence |
| 9d68ab8b-38c8-47aa-8b69-8cebe0a8d24e | < 1.15.4 |
MEDIUM | 4.8 | The Forminator WordPress plugin before 1.15.4 does not sanitize and escape the email field label, which could allow high… | — | wordfence |
| 9bf8485b-a363-44a3-93c7-a6fba034b48f | < 1.47 |
MEDIUM | 4.8 | The SrbTransLatin plugin 1.46 for WordPress has XSS via an srbtranslatoptions action to wp-admin/options-general.php wit… | — | wordfence |
| 9b8aef59-8d7a-4ffd-9619-9684a6e51e5a | < 3.1.3 |
MEDIUM | 4.8 | The Rencontre β Dating Site plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several parameters f… | — | wordfence |
| 97e9037e-7d7a-4dad-bce1-0211822c04c1 | < 1.6.61 |
MEDIUM | 4.8 | The Shared Files WordPress plugin before 1.6.61 does not sanitise and escape the Download Counter Text settings, which c… | — | wordfence |
| 96b58c2c-f292-4a48-bd1e-c33cf464c1ce | < 1.3.25 |
MEDIUM | 4.8 | The Contact Form Email WordPress plugin is vulnerable to Stored Cross-Site Scripting due to insufficient input validatio… | — | wordfence |
| 959ece75-b7a6-4729-abe8-1df9398d95f4 | MEDIUM | 4.8 | The Social Hashtags plugin for WordPress is vulnerable to Cross-Site Scripting via the new post title field in versions … | — | wordfence | |
| 94d2eaed-048b-40b6-9880-fa32fbb66f92 | < 5.9.5 |
MEDIUM | 4.8 | The Events Manager plugin 5.9.4 for WordPress has XSS via the dbem_event_reapproved_email_body parameter to the wp-admin… | — | wordfence |
| 92c16bb5-b52c-4453-9121-0c9d056a0cdb | < 1.53 |
MEDIUM | 4.8 | The Mortgage Calculators WP WordPress plugin before 1.53 does not implement any sanitisation on the color setting of the… | — | wordfence |
| 90d203b1-9426-4eff-b566-02c8a1c6adfa | < 1.18.1 |
MEDIUM | 4.8 | The Custom Post Type UI plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including,… | — | wordfence |
| 90cd3722-c3cb-4ac3-871d-cacda49be294 | < 1.9.7 |
MEDIUM | 4.8 | The WPGlobus plugin 1.9.6 for WordPress has XSS via the wpglobus_option[post_type][post] parameter to wp-admin/options.p… | — | wordfence |
| 8df4f144-0bf3-457f-8014-f603f7179044 | < 1.7.48 |
MEDIUM | 4.8 | The AddToAny Share Buttons WordPress plugin before 1.7.48 does not escape its Image URL button setting, which could lead… | — | wordfence |
EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.
Scan My Website →