Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.
40,402 vulnerabilities found (page 1264 of 1617)
| CVE ID | Plugin / Theme | Severity | CVSS | Description | Fixed In | Source |
|---|---|---|---|---|---|---|
| 5c6f4890-8bc9-4ead-8d69-478fa51c2176 | MEDIUM | 4.8 | The W-DALIL plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘$dalil_information’ parameter… | — | wordfence | |
| 5b3081ff-9898-46a2-8e02-30cd83f4fbe4 | < 6.4.3 |
MEDIUM | 4.8 | The Easy Drag And drop All Import : WP Ultimate CSV Importer WordPress plugin before 6.4.3 does not sanitise and escaped… | — | wordfence |
| 5a563439-c1c2-4a19-b5f7-22ed7be87ad7 | < 1.4 |
MEDIUM | 4.8 | The Smooth Scroll Page Up/Down Buttons WordPress plugin through 1.4 does not properly sanitise and validate its psb_posi… | — | wordfence |
| 59cdb3e3-06ca-4325-9dae-73ad3cdfd910 | < 19.9.7 |
MEDIUM | 4.8 | The Client Invoicing by Sprout Invoices plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up… | — | wordfence |
| 58bdd837-adae-4fa9-9ca3-00633a6a1ede | < 2.0.0 |
MEDIUM | 4.8 | The WPFront Notification Bar WordPress plugin before 2.0.0 does not sanitise or escape its Custom CSS setting, allowing … | — | wordfence |
| 586137a5-8758-400e-a66a-2382f8633578 | < 1.10.1 |
MEDIUM | 4.8 | The Google Maps Easy WordPress plugin is vulnerable to Stored Cross-Site Scripting due to insufficient input validation … | — | wordfence |
| 56a362f3-dc4e-454d-9d94-9f4cb540d4b5 | < 2.11.2.1 |
MEDIUM | 4.8 | The Easy Digital Downloads WordPress plugin is vulnerable to Reflected Cross-Site Scripting via the $start_date and $end… | — | wordfence |
| 52af7568-061d-4352-b85c-11f9829bc8a5 | < 1.7 |
MEDIUM | 4.8 | An issue was discovered in the dark-mode plugin 1.6 for WordPress. XSS exists via the wp-admin/profile.php dark_mode_sta… | — | wordfence |
| 50e373bd-4408-4406-a411-3284fa71e7ef | < 3.0.4 |
MEDIUM | 4.8 | The Visual Form Builder WordPress plugin before 3.0.4 does not sanitise or escape its Form Name, allowing high privilege… | — | wordfence |
| 4dcc6225-b47a-4184-a2f3-1292e5abe1bd | < 3.1.21 |
MEDIUM | 4.8 | The Nested Pages WordPress plugin before 3.1.21 does not escape and sanitize the some of its settings, which could allow… | — | wordfence |
| 4dbaeabb-2610-4b24-8c47-a04b073bd290 | < 5.2.0 |
MEDIUM | 4.8 | The WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'Additional tax classes' field… | — | wordfence |
| 4d2d435f-d6ce-41bd-8a45-e252fb4ba419 | MEDIUM | 4.8 | The GWD Connect plugin for WordPress is vulnerable to missing authorization to limited code execution in all versions up… | — | wordfence | |
| 4bca364b-c8dc-4c32-a640-0e9f3155a40f | MEDIUM | 4.8 | The Mimetic Books WordPress plugin through 0.2.13 was vulnerable to Authenticated Stored Cross-Site Scripting (XSS) in t… | — | wordfence | |
| 4b3786d2-b1b5-4d96-9ef7-957909061186 | < 2.1.4 |
MEDIUM | 4.8 | The WP-Paginate WordPress plugin before 2.1.4 does not sanitise and escape its preset settings, allowing high privilege … | — | wordfence |
| 4a515dc9-e6d6-4083-a3e8-c22307b120a8 | MEDIUM | 4.8 | The Quiz Tool Lite WordPress plugin through 2.3.15 does not sanitize multiple input fields used when creating or managin… | — | wordfence | |
| 49fc7174-9263-4158-8cdc-cd249179eb3b | < 2.0.44 |
MEDIUM | 4.8 | The WP Courses LMS plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions before 2.0.44 due to i… | — | wordfence |
| 49ac9c7c-d457-4709-bc10-c3de8b4f097a | < 5.0.13 |
MEDIUM | 4.8 | The addthis plugin before 5.0.13 for WordPress has CSRF with resultant XSS via the wp-admin/options-general.php?page=add… | — | wordfence |
| 498087da-3887-475a-9796-676ee1d1fb99 | < 2.12.0 |
MEDIUM | 4.8 | The GiveWP – Donation Plugin and Fundraising Platform WordPress plugin before 2.12.0 did not escape the Donation Level… | — | wordfence |
| 4489d26b-dcdc-475c-b1e1-3626cc75ae75 | < 4.1.3.1 |
MEDIUM | 4.8 | The LearnPress WordPress plugin before 4.1.3.1 does not properly sanitize or escape various inputs within course setting… | — | wordfence |
| 43f6a5c2-3de0-4990-89ad-64e5d866345a | MEDIUM | 4.8 | The Sociable WordPress plugin through 4.3.4.1 does not sanitise or escape some of its settings before outputting them in… | — | wordfence | |
| 427c29e6-9bbe-4094-a2a2-46945525f5b3 | < 1.5.6 |
MEDIUM | 4.8 | The Ad Inserter plugin for WordPress is vulnerable to Cross-Site Scripting via the 'ai-active-tab' parameter in versions… | — | wordfence |
| 4107199d-e3c7-4379-b39d-1868de7d777b | < 2.2.3 |
MEDIUM | 4.8 | The WP Job Portal – A Complete Recruitment System for Company or Job Board website plugin for WordPress is vulnerable … | — | wordfence |
| 40e61b9f-2350-410e-bb3d-59329ac08658 | < 4.0.72 |
MEDIUM | 4.8 | The Limit Login Attempts WordPress plugin before 4.0.72 does not sanitise and escape some of its settings, leading to ma… | — | wordfence |
| 3f8af7fd-5800-4179-849e-a7ffaf8c3ad4 | < 2.6.3 |
MEDIUM | 4.8 | The Pixel Cat WordPress plugin before 2.6.3 does not escape some of its settings, which could allow high privilege users… | — | wordfence |
| 3eff7a6f-7098-4298-b399-91974b16fda2 | < 1.35 |
MEDIUM | 4.8 | The ClickBank Affiliate Ads WordPress plugin through 1.20 does not escape its settings, allowing high privilege users to… | — | wordfence |
EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.
Scan My Website →