Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.
40,402 vulnerabilities found (page 1266 of 1617)
| CVE ID | Plugin / Theme | Severity | CVSS | Description | Fixed In | Source |
|---|---|---|---|---|---|---|
| 171ee69a-d0d6-4d1e-b477-4d285be918f4 | < .52.5 |
MEDIUM | 4.8 | In the admin/db-backup-security/db-backup-security.php page in the BulletProof Security plugin before .52.5 for WordPres… | — | wordfence |
| 15aba6ee-8345-401d-adf9-3fde0f5169bc | < 2.5.5 |
MEDIUM | 4.8 | The Smart Floating / Sticky Buttons WordPress plugin before 2.5.5 does not sanitise and escape some parameter before out… | — | wordfence |
| 15705cf2-f396-4b19-b58a-144b000f61e5 | < 2.8.5 |
MEDIUM | 4.8 | Authenticated (admin or higher user role) Stored Cross-Site Scripting (XSS) vulnerability in Premio Chaty (WordPress plu… | — | wordfence |
| 14b334ee-ab3b-4b18-a776-c0831c4ff855 | < 4.0.6 |
MEDIUM | 4.8 | Authenticated (author or higher user role) Stored Cross-Site Scripting (XSS) vulnerability in Responsive Tabs (WordPress… | — | wordfence |
| 1212dfc7-41d4-4c16-960a-7afc882ec4db | < 1.0.2 |
MEDIUM | 4.8 | The Booking.com Product Helper WordPress plugin before 1.0.2 does not sanitize and escape Product Code when creating Pro… | — | wordfence |
| 11401ad7-6064-475c-92f6-ce72a56e9a83 | < 1.8.9 |
MEDIUM | 4.8 | The Cookie Bar WordPress plugin through 1.8.8 doesn't properly sanitise the Cookie Bar Message setting, which could allo… | — | wordfence |
| 1072ad88-5760-4f2a-82b3-d515d6f73e52 | < 3.6.8 |
MEDIUM | 4.8 | The Import any XML or CSV File to WordPress plugin before 3.6.8 accepts all zip files and automatically extracts the zip… | — | wordfence |
| 0d3fa716-6f11-428c-b2da-2bb768a92fe0 | < 4.6 |
MEDIUM | 4.8 | The WP BrowserUpdate plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the multiple parameters in ve… | — | wordfence |
| 0d00e477-8e01-4144-86e6-f1cc00fb1d0a | < 2.0.9 |
MEDIUM | 4.8 | The TranslatePress WordPress plugin before 2.0.9 does not implement a proper sanitisation on the translated strings. The… | — | wordfence |
| 0b90503b-6186-48b5-a85a-3602f318872e | MEDIUM | 4.8 | A cross-site scripting (XSS) vulnerability in flickrRSS.php in the flickrRSS plugin 5.3.1 for WordPress allows remote at… | — | wordfence | |
| 0992ac60-14c6-4432-bd6e-c11c6a7bf603 | < 1.4.4 |
MEDIUM | 4.8 | The Themify β WooCommerce Product Filter plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin s… | — | wordfence |
| 0987f9a5-eb11-4756-a09a-26dc66a8c690 | < 1.6.59 |
MEDIUM | 4.8 | The UpdraftPlus WordPress Backup Plugin WordPress plugin before 1.6.59 does not sanitise its updraft_service settings, a… | — | wordfence |
| 083d368c-ba38-433a-b499-c00d205bd331 | < 1.6.13 |
MEDIUM | 4.8 | The Funnel Builder by CartFlows β Create High Converting Sales Funnels For WordPress plugin before 1.6.13 did not sani… | — | wordfence |
| 04676263-cdad-40cd-bb54-61beb727e09d | < 0.16.18 |
MEDIUM | 4.8 | The AnWP Football Leagues plugin for WordPress is vulnerable to CSV Injection in all versions up to, and including, 0.16… | — | wordfence |
| 03d02297-0cc6-4935-b282-9b95d8292954 | MEDIUM | 4.8 | The WP Dialog WordPress plugin through 1.2.5.5 does not sanitise and escape some of its settings before outputting them … | — | wordfence | |
| 03c8ec0a-f75f-450f-86e7-a18dfbae9461 | < 2.1.1 |
MEDIUM | 4.8 | The Twitch Player plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the βswti_options_player[swti_… | — | wordfence |
| 006544c9-09ed-4cda-a903-4e3959fdb676 | < 1.3.35 |
MEDIUM | 4.8 | Stored XSS exists in the Appointment Booking Calendar plugin before 1.3.35 for WordPress. In the cpabc_appointments.php … | — | wordfence |
| ffb2ade3-d5ce-4459-ab83-e28cd4c84922 | < 2.27.7 |
MEDIUM | 4.7 | The Relevanssi β A Better Search plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Excerpt Hig… | — | wordfence |
| fa49346c-726e-41f9-8a74-adaa4a8fa5d9 | < 7.6.9 |
MEDIUM | 4.7 | The Newsletter plugin for WordPress may be vulnerable to Reflected Cross-Site Scripting via the $_SERVER['REQUEST_URI'] … | — | wordfence |
| f6d6b82d-574d-4a56-9aef-42343c4b7c43 | < 3.8.16 |
MEDIUM | 4.7 | The Ninja Forms Contact Form plugin for WordPress is vulnerable to Reflected Self-Based Cross-Site Scripting via the 'Re… | — | wordfence |
| f668c3cd-bf64-4e95-8d75-70e4f12cabce | < 7.1.1 |
MEDIUM | 4.7 | The Conversios β Google Analytics 4 (GA4), Meta Pixel & more Via Google Tag Manager For WooCommerce plugin for WordPre… | — | wordfence |
| f2b5213d-fdc5-4c98-9a05-15d83bd7308f | < 21.2.9 |
MEDIUM | 4.7 | The Photos and Files Contest Gallery β Contact Form, Upload Form, Social Share and Voting Plugin for WordPress plugin … | — | wordfence |
| f28feb11-7e28-4b97-b529-f6d266c3e534 | < 5.5.5 |
MEDIUM | 4.7 | The Formidable Form Builder plugin for WordPress is vulnerable to Server-Side Request Forgery in versions up to, and inc… | — | wordfence |
| ef6b36a2-c18a-403a-aa0b-5d3e3ef1ca90 | < 3.5.4 |
MEDIUM | 4.7 | The Easy Property Listings plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and i… | — | wordfence |
| e7819dbf-fbcc-4dca-8300-b75ec096c541 | < 7.1.14 |
MEDIUM | 4.7 | Wordfence before 7.1.14 was vulnerable in certain unusual configurations to Reflected Cross-Site Scripting, as well as f… | — | wordfence |
EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.
Scan My Website →