Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.
40,402 vulnerabilities found (page 1265 of 1617)
| CVE ID | Plugin / Theme | Severity | CVSS | Description | Fixed In | Source |
|---|---|---|---|---|---|---|
| 3e76c4b3-af77-4c02-a923-f04a360fa6e0 | < 1.3.5 |
MEDIUM | 4.8 | The Post Views Counter WordPress plugin before 1.3.5 does not sanitise or escape its Post Views Label settings, which co… | — | wordfence |
| 3e2af005-0bc2-445c-956a-ef6139abfee4 | < 3.3.2 |
MEDIUM | 4.8 | The Image optimization & Lazy Load by Optimole WordPress plugin before 3.3.2 does not sanitise and escape its "Lazyload … | — | wordfence |
| 3d39ae72-7d45-4ca9-9de1-8532ec5e043d | < 1.15.14 |
MEDIUM | 4.8 | The Asgaros Forums WordPress plugin is vulnerable to Stored Cross-Site Scripting due to insufficient escaping via the na… | — | wordfence |
| 3d1f9fb7-fcb8-41ec-8c2f-0864e245f873 | < 1.2.3 |
MEDIUM | 4.8 | The WP Downgrade WordPress plugin before 1.2.3 only perform client side validation of its "WordPress Target Version" set… | — | wordfence |
| 371fef9c-1f32-4a21-b4f4-1fc364ade5a4 | < 1.3.56 |
MEDIUM | 4.8 | The Appointment Hour Booking WordPress plugin before 1.3.56 does not sanitise and escape a settings of its Calendar fiel… | — | wordfence |
| 33df558a-da81-46e0-bef9-ddb2bb90a5c5 | < 2.0.1 |
MEDIUM | 4.8 | The Mark Posts WordPress plugin before 2.0.1 does not escape new markers, allowing high privilege users such as admin to… | — | wordfence |
| 2fa62862-5b98-4864-9bf1-4e05deedeb9d | < 2.3.3 |
MEDIUM | 4.8 | Multiple Authenticated (admin+) Persistent Cross-Site Scripting (XSS) vulnerabilities in Adam Skaat's Countdown & Clock … | — | wordfence |
| 2f7d7ceb-b6f0-4b63-93f7-632c13a6b496 | MEDIUM | 4.8 | The Slideshow WordPress plugin through 2.3.1 does not sanitize and escape some of its default slideshow settings, which … | — | wordfence | |
| 2e889182-f02f-4b6b-bb98-357fadae3dc1 | < 3.0.16 |
MEDIUM | 4.8 | Authenticated (admin+) Stored Cross-Site Scripting (XSS) vulnerability discovered in Ultimate Reviews WordPress plugin (… | — | wordfence |
| 2e10e550-735f-4bef-8e58-bcb79c51a5a6 | < 1.6.57 |
MEDIUM | 4.8 | The Easy Download Manager and File Sharing Plugin with frontend file upload β a better Media Library β Shared Files … | — | wordfence |
| 2d853bd5-4caa-4b90-a9a6-929fb18b9337 | < 3.7.16 |
MEDIUM | 4.8 | Cross-site scripting (XSS) vulnerability in the media_handle_upload function in wp-admin/includes/media.php in WordPress… | — | wordfence |
| 2bf29d3d-98eb-40a7-88af-32b48e437572 | < 2.3.5 |
MEDIUM | 4.8 | The Request a Quote WordPress plugin before 2.3.5 does not sanitise, validate or escape some of its settings in the admi… | — | wordfence |
| 2b346ae7-e3aa-4728-8dd9-e77fc388576e | < 1.1.6 |
MEDIUM | 4.8 | The Simple Security plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'datefilter' parameter fou… | — | wordfence |
| 2a37a0e5-2db5-49fb-8b00-1b820192f1af | < 2.4 |
MEDIUM | 4.8 | The Interactive Medical Drawing of Human Body WordPress plugin before 2.4 does not sanitise and escape the Link field, a… | — | wordfence |
| 29d962c0-31dc-4320-a9ce-3ed71d4f9943 | < 7.1 |
MEDIUM | 4.8 | The SEO Redirection Plugin β 301 Redirect Manager WordPress plugin before 7.1 did not sanitise the Redirect From and R… | — | wordfence |
| 28cb1a04-5129-430a-850e-c410e95d7b87 | < 1.4 |
MEDIUM | 4.8 | The Smooth Scroll Page Up/Down Buttons WordPress plugin before 1.4 did not properly sanitise and validate its settings, … | — | wordfence |
| 28bdf97b-86e7-4d4b-a3e4-6624e9858a93 | < 1.3.1 |
MEDIUM | 4.8 | The Export any WordPress data to XML/CSV WordPress plugin before 1.3.1 does not escape its Export's Name before outputti… | — | wordfence |
| 217b4ed7-90d3-4871-b034-7e1b324dc6a2 | < 2.4.7 |
MEDIUM | 4.8 | The WP Contact Slider plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the settings of sliders in v… | — | wordfence |
| 1f862575-afd8-4e38-8780-40e86ad9b5da | < 6.0.12 |
MEDIUM | 4.8 | The Translate WordPress β Google Language Translator WordPress plugin before 6.0.12 does not sanitise and escape some … | — | wordfence |
| 1e07562d-ab3a-47bc-9bb1-b952f769f5e5 | < 1.0.0 |
MEDIUM | 4.8 | The Quotes llama WordPress plugin through 0.7 does not sanitise and escape Quotes, which could allow high privilege user… | — | wordfence |
| 1d7860bf-3f3d-4bd2-82b0-7bb94d00ff30 | < 1.3.2 |
MEDIUM | 4.8 | The Accept Donations with PayPal WordPress plugin before 1.3.2 does not escape the Amount Menu Name field of created But… | — | wordfence |
| 1bf805fc-4b27-47c4-b24e-79158cffaac4 | < 2021.18 |
MEDIUM | 4.8 | The Stop Spammers Security | Block Spam Users, Comments, Forms WordPress plugin before 2021.18 does not escape some of i… | — | wordfence |
| 1abdc53b-7abe-422b-aeea-5bf31733bdad | MEDIUM | 4.8 | The toggle-the-title (aka Toggle The Title) plugin 1.4 for WordPress has XSS via the wp-admin/admin-ajax.php?action=upda… | — | wordfence | |
| 18afd787-2b1f-452c-90d8-75e0df9322fa | < 1.7.3 |
MEDIUM | 4.8 | The Twitter Bootstrap Slider plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'wp_cache_locatio… | — | wordfence |
| 188d812c-2955-4b0c-ae1c-b42c0f60b73b | < 6.5.2 |
MEDIUM | 4.8 | The Converter for Media β Optimize images | Convert WebP & AVIF plugin for WordPress is vulnerable to Server-Side Requ… | — | wordfence |
EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.
Scan My Website →