Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.
40,402 vulnerabilities found (page 1263 of 1617)
| CVE ID | Plugin / Theme | Severity | CVSS | Description | Fixed In | Source |
|---|---|---|---|---|---|---|
| 8a5bf903-9da0-46fd-8134-3abe8e97e3b4 | < 2.10.4 |
MEDIUM | 4.8 | The GiveWP β Donation Plugin and Fundraising Platform WordPress plugin before 2.10.4 did not sanitise or escape the Ba… | — | wordfence |
| 8703c76b-89c6-438a-b953-03847d965096 | < 3.5.8.2 |
MEDIUM | 4.8 | The Ninja Forms Contact Form WordPress plugin before 3.5.8.2 does not sanitise and escape the custom class name of the f… | — | wordfence |
| 850f554f-abb5-4b9f-9b7b-67439abb1a31 | < 2.1.17 |
MEDIUM | 4.8 | The School Management System β WPSchoolPress WordPress plugin before 2.1.17 sanitise some fields using sanitize_text_f… | — | wordfence |
| 82173c1b-dce8-4713-87c7-2c54ba8cc02c | MEDIUM | 4.8 | The User Registration, Login & Landing Pages WordPress plugin is vulnerable to Stored Cross-Site Scripting due to insuff… | — | wordfence | |
| 816ec7bd-dd0f-4c52-b73f-72cd25c410b2 | < 2.0.3 |
MEDIUM | 4.8 | The Print-O-Matic WordPress plugin before 2.0.3 does not escape some of its settings before outputting them in attribute… | — | wordfence |
| 81141b8c-9677-4267-9026-33267e3135f5 | < 4.7.0 |
MEDIUM | 4.8 | The iFlyChat WordPress plugin before 4.7.0 does not sanitise its APP ID setting before outputting it back in the page, l… | — | wordfence |
| 7ccf6945-6f18-410b-9f1a-6d52a3cdda1a | < 2.17.3 |
MEDIUM | 4.8 | The GiveWP WordPress plugin before 2.17.3 does not escape the json parameter before outputting it back in an attribute i… | — | wordfence |
| 7c84b432-4d33-47ad-8057-0bc831929879 | < 1.2.3 |
MEDIUM | 4.8 | Authenticated (admin or higher user role) Stored Cross-Site Scripting (XSS) in PlausibleHQ Plausible Analytics (WordPres… | — | wordfence |
| 7bde915d-092a-452b-a0e0-ce5c2ce203dc | < 4.1.1 |
MEDIUM | 4.8 | The LearnPress Export Import β WordPress extension for LearnPress plugin for WordPress is vulnerable to unauthorized l… | — | wordfence |
| 76b11177-782a-4d9c-a974-4cb9ff55fa99 | < 1.9.7 |
MEDIUM | 4.8 | The WPGlobus plugin 1.9.6 for WordPress has XSS via the wpglobus_option[more_languages] parameter to wp-admin/options.ph… | — | wordfence |
| 73c3dfc7-58de-4b24-ad91-0f8040d1f75e | < 4.3.21 |
MEDIUM | 4.8 | Authenticated (admin user role) Stored Cross-Site Scripting (XSS) in WP-Appbox (WordPress plugin) <= 4.3.20. | — | wordfence |
| 736cb9a4-bd43-4aaa-a918-d15ca3ff4dbf | < 5.4.1 |
MEDIUM | 4.8 | The Ivory Search WordPress plugin before 5.4.1 does not escape some of the Form settings, which could allow high privile… | — | wordfence |
| 728cec6e-a246-4e2c-a906-750518bae0a4 | < 3.0.5 |
MEDIUM | 4.8 | The Fathom Analytics WordPress plugin is vulnerable to Stored Cross-Site Scripting due to insufficient input validation … | — | wordfence |
| 6f7e0aa7-8834-4ff1-9ced-5d740936c721 | < 6.8.0 |
MEDIUM | 4.8 | The Advanced Access Manager WordPress plugin before 6.8.0 does not escape some of its settings when outputting them, all… | — | wordfence |
| 6d7f9291-5a57-4aca-b18f-623bf07348a4 | < 2.10.5 |
MEDIUM | 4.8 | The WooCommerce PDF Invoices & Packing Slips WordPress plugin before 2.10.5 does not escape the tab and section paramete… | — | wordfence |
| 6d564606-695e-4e8c-90de-1d55afc06103 | < 1.5.67 |
MEDIUM | 4.8 | The Photo Gallery by 10Web - Mobile-Friendly Image Gallery WordPress plugin before 1.5.67 did not properly sanitise the … | — | wordfence |
| 6c31f7d3-1f2f-4ec5-802b-ec0b22087d43 | < 3.1.23 |
MEDIUM | 4.8 | The WP Event Manager WordPress plugin before 3.1.23 does not escape some of its Field Editor settings when outputting th… | — | wordfence |
| 6bfc0128-a8ef-4bb9-b5c8-7003f270aa36 | < 1.0.8 |
MEDIUM | 4.8 | The Login With OTP Over SMS, Email, WhatsApp and Google Authenticator WordPress plugin before 1.0.8 does not escape its … | — | wordfence |
| 6b8ed659-0590-411f-9017-f695c9c2f322 | < 7.3.2 |
MEDIUM | 4.8 | The Quiz And Survey Master WordPress plugin before 7.3.2 does not escape the Quiz Url Slug setting before outputting it … | — | wordfence |
| 674f75d7-83de-4d0b-80f2-ee83dd474728 | < 2.2.45 |
MEDIUM | 4.8 | Imagely NextGEN Gallery version 2.2.30 and earlier contains a Cross Site Scripting (XSS) vulnerability in Image Alt & Ti… | — | wordfence |
| 64b49f24-db48-4199-9ce2-3ea70c68d6af | < 0.9.9.4 |
MEDIUM | 4.8 | The Recent Posts Widget Extended plugin for WordPress is vulnerable to Cross-Site Scripting in versions up to, and inclu… | — | wordfence |
| 64338fc4-e8c9-4fa5-bb77-861fb5142286 | < 4.1.8 |
MEDIUM | 4.8 | The Ninja Tables WordPress plugin before 4.1.8 does not sanitise and escape some of its table fields, which could allow … | — | wordfence |
| 63089b8f-0e0f-4951-9f8b-8b64d539b4c0 | < 3.8.6 |
MEDIUM | 4.8 | The The WooCommerce Product Table Lite plugin for WordPress is vulnerable to arbitrary shortcode execution in all versio… | — | wordfence |
| 606b9002-5f3a-49ef-9714-49eeac86f800 | < 1.7.0 |
MEDIUM | 4.8 | The Cybersoldier WordPress plugin before 1.7.0 does not sanitise and escape the URL settings before outputting it in an … | — | wordfence |
| 5d432ea5-9ffd-43da-8988-6dd77b907655 | < 2.5.2 |
MEDIUM | 4.8 | The Floating Notification Bar, Sticky Menu on Scroll, and Sticky Header for Any Theme β myStickymenu WordPress plugin … | — | wordfence |
EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.
Scan My Website →