Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.
40,402 vulnerabilities found (page 1268 of 1617)
| CVE ID | Plugin / Theme | Severity | CVSS | Description | Fixed In | Source |
|---|---|---|---|---|---|---|
| a2e493cf-d022-404d-a501-a6671e6116f4 | < 3.23 |
MEDIUM | 4.7 | The Database Reset plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including… | — | wordfence |
| a224e745-f9c7-4ca6-b656-e94862b1dc57 | < 2.0.36 |
MEDIUM | 4.7 | The Product Vendors is vulnerable to Reflected Cross-Site Scripting via the 'vendor_description' parameter in versions u… | — | wordfence |
| a092266b-bd7f-424d-b8c4-d79e4811e6c9 | MEDIUM | 4.7 | The Responsive Column Widgets plugin for WordPress is vulnerable to Open Redirect in versions up to, and including, 1.2.… | — | wordfence | |
| a06bba7f-0259-4b87-b3fe-6ad8318fda7d | < 3.1.15 |
MEDIUM | 4.7 | The ImageRecycle pdf & image compression plugin for WordPress is vulnerable to Cross-Site Request Forgery in all version… | — | wordfence |
| 9bb026a4-02b1-4422-8c78-9983c49df43e | < 4.1.1.1 |
MEDIUM | 4.7 | The Events Calendar plugin for WordPress is vulnerable to an open redirect vulnerability in versions before 4.1.1.1. Thi… | — | wordfence |
| 9963e0f8-600c-4b1f-935d-4ac1f967698f | < 1.4.32 |
MEDIUM | 4.7 | The Open User Map PRO plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'oum_location_notificati… | — | wordfence |
| 97c68df7-69fd-4817-9473-3d3e1fd6d348 | < 2.7.0 |
MEDIUM | 4.7 | The WooCommerce Product Enquiry plugin for WordPress is vulnerable to Self-Cross-Site Scripting via the enquiry form fie… | — | wordfence |
| 95d68a5d-4d0b-4030-a80a-ada31b118af2 | < 3.119.0 |
MEDIUM | 4.7 | The WordPress Automatic Plugin plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, a… | — | wordfence |
| 95d4fbf6-e21a-48db-bfb3-32fc9116afa0 | < 1.6.12 |
MEDIUM | 4.7 | The Parcel Pro plugin for WordPress is vulnerable to Open Redirect in all versions up to, and including, 1.6.11. This is… | — | wordfence |
| 938e8f54-56f0-4066-bc78-ebfc2abe0743 | MEDIUM | 4.7 | The Flash player widget plugin for WordPress is vulnerable to Content Spoofing in versions up to, and including, 1.3. Th… | — | wordfence | |
| 92928f3b-cf45-4735-87d7-040afa4857f4 | < 3.5.0 |
MEDIUM | 4.7 | The WP STAGING WordPress Backup Plugin β Migration Backup Restore plugin for WordPress is vulnerable to Server-Side Re… | — | wordfence |
| 8db736fb-cd6c-4a52-9dd3-eefd0a8d9267 | < 6.5.0.5 |
MEDIUM | 4.7 | The wpDataTables β WordPress Data Table, Dynamic Tables & Table Charts Plugin plugin for WordPress is vulnerable to St… | — | wordfence |
| 8a6ca886-de4c-4d45-a934-3e90378e7eb3 | < 4.4.3 |
MEDIUM | 4.7 | The Simple Membership plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'Display Name' parameter… | — | wordfence |
| 81f9a4c6-971f-4f6d-8bb1-e97bf75cf8d3 | < 3.3.7 |
MEDIUM | 4.7 | The Order Tracking Pro plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the order status parameter … | — | wordfence |
| 81eb8963-548f-4e94-83bd-266a19c09aab | < 2.0.4 |
MEDIUM | 4.7 | The Checkout Field Editor (Checkout Manager) for WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site … | — | wordfence |
| 7d047fe7-bf00-4f93-91d2-c5da41664bfc | < 2.13.5 |
MEDIUM | 4.7 | The Age Gate plugin for WordPress is vulnerable to Open Redirects in versions up to, and including, 2.13.4 via the '_wp_… | — | wordfence |
| 7cc86970-7e63-47d0-9971-ddd0fc992a5a | < 1.7.15 |
MEDIUM | 4.7 | The AddToAny Share Buttons plugin for WordPress is vulnerable to Host Header Injections in versions up to, and including… | — | wordfence |
| 7bd64a61-3bc7-4d0f-b3bc-1988e75cf749 | < 1.2.9 |
MEDIUM | 4.7 | The WP Gravity Forms Zoho CRM and Bigin plugin for WordPress is vulnerable to Open Redirect in all versions up to, and i… | — | wordfence |
| 79a574c4-1faf-4572-801c-00b50923a669 | < 1.5.6 |
MEDIUM | 4.7 | The Cookie Information | Free GDPR Consent Solution plugin for WordPress is vulnerable to Stored Cross-Site Scripting vi… | — | wordfence |
| 7894a19c-b873-4c5b-8c82-6656cc306ee2 | < 2.2.5 |
MEDIUM | 4.7 | The Popup More Popups, Lightboxes, and more popup modules plugin for WordPress is vulnerable to Local File Inclusion in … | — | wordfence |
| 72b14197-560a-4dc2-9c23-a250f51dc51e | < 3.7.25 |
MEDIUM | 4.7 | WordPress through 4.9.1, when domain-based flashmediaelement.swf sandboxing is not used, allows remote attackers to cond… | — | wordfence |
| 6e77d240-475d-41a2-9b88-1332fc60b72d | < 3.3.17 |
MEDIUM | 4.7 | The My Calendar plugin for WordPress is vulnerable to Open Redirection in versions up to, and including, 3.3.16. This ma… | — | wordfence |
| 6b5d31c5-0516-4089-9867-2922670e1b04 | < 1.9.16 |
MEDIUM | 4.7 | The Gravityforms plugin for WordPress is vulnerable to Reflected Cross-Site Scripting up to, and including, 1.9.15.11 du… | — | wordfence |
| 6b36fcc5-1f09-43b9-8877-7af6c7652db7 | < 1.5.3 |
MEDIUM | 4.7 | The White Label CMS plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1… | — | wordfence |
| 69f54737-4b0f-49ba-a331-1b252a5e45cb | < 2.9.7 |
MEDIUM | 4.7 | The Translate WordPress with GTranslate WordPress plugin before 2.9.7 does not sanitise and escape the body parameter in… | — | wordfence |
EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.
Scan My Website →