Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.
40,402 vulnerabilities found (page 1269 of 1617)
| CVE ID | Plugin / Theme | Severity | CVSS | Description | Fixed In | Source |
|---|---|---|---|---|---|---|
| 69a6d8a5-0325-4436-8034-8353d2a68831 | < 5.4.20 |
MEDIUM | 4.7 | The B2Bking plugin for WordPress is vulnerable to Open Redirect in all versions up to 5.4.20 (exclusive). This is due to… | — | wordfence |
| 696495c5-c8f8-4790-af89-1ee911767b1b | MEDIUM | 4.7 | The Solutions Ad Manager plugin for WordPress is vulnerable to Open Redirect in all versions up to, and including, 1.0.0… | — | wordfence | |
| 6781dcc5-db95-43ca-9042-a3c05414b7e6 | MEDIUM | 4.7 | The ShareThis Dashboard for Google Analytics plugin for WordPress is vulnerable to Sensitive Information Exposure in all… | — | wordfence | |
| 65614ad8-cec6-4768-a3f2-c550254bd418 | < 1.5.3 |
MEDIUM | 4.7 | The Accept Donations with PayPal & Stripe plugin for WordPress is vulnerable to Open Redirect in all versions up to, and… | — | wordfence |
| 62b809dc-4089-4822-8aeb-7049fcfe376e | < 3.1.5 |
MEDIUM | 4.7 | The User Registration β Custom Registration Form, Login Form, and User Profile WordPress Plugin plugin for WordPress i… | — | wordfence |
| 5fe374ff-85eb-4285-8d51-71e9275613cc | < 1.0.13 |
MEDIUM | 4.7 | The Core Web Vitals & PageSpeed Booster plugin for WordPress is vulnerable to Open Redirect in versions up to, and inclu… | — | wordfence |
| 5c8404d2-7b37-40df-b756-328f827f273d | < 1.1.5 |
MEDIUM | 4.7 | The Integration for Constant Contact and Contact Form 7, WPForms, Elementor, Ninja Forms plugin for WordPress is vulnera… | — | wordfence |
| 5c24ee66-7b57-4e4c-bbb5-0451fc24ce4b | < 8.0.7 |
MEDIUM | 4.7 | The Newsletter β Send awesome emails from WordPress plugin for WordPress is vulnerable to Cross-Site Request Forgery i… | — | wordfence |
| 5adf03ff-5b87-4ed3-b7ec-b89bc814aba6 | < 4.9.4 |
MEDIUM | 4.7 | The Spiffy Calendar plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the βpageβ parameter in… | — | wordfence |
| 59926d18-215e-4de3-acf2-19870026a13f | < 1.15.3 |
MEDIUM | 4.7 | The Lets-Box plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions before 1.15.3 due to insuf… | — | wordfence |
| 55a57b5f-2f87-4060-b1c2-77086f695dda | < 6.8.1 |
MEDIUM | 4.7 | The Simple:Press plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'sforum_[md5 hash of the W… | — | wordfence |
| 4bd91c8a-f851-4810-b99e-aadae460091f | MEDIUM | 4.7 | The Dynamic Pricing & Discounts Lite for WooCommerce plugin for WordPress is vulnerable to Cross-Site Request Forgery in… | — | wordfence | |
| 48d0e0e0-81db-46ef-ba64-daa2a4079b79 | < 3.3.0 |
MEDIUM | 4.7 | The Yoast SEO plugin for WordPress is vulnerable to Cross-Site Scripting in versions up to, and including, 3.2.5 due to … | — | wordfence |
| 4126d452-65a9-48f5-a3f5-5be1b8fff80c | < 2.9.31 |
MEDIUM | 4.7 | The Gravity Forms plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the `form_ids` parameter in t… | — | wordfence |
| 40f7fd0f-4383-44c4-8c49-f1c25e1e3681 | < 3.3 |
MEDIUM | 4.7 | The Meta Tag Manager plugin for WordPress is vulnerable to Open Redirect in all versions up to, and including, 3.2. This… | — | wordfence |
| 40a08542-5e2e-4689-b26f-99a1350185cc | < 3.1.16 |
MEDIUM | 4.7 | The Nested Pages WordPress plugin <= 3.1.15 was vulnerable to an Open Redirect via the `page` POST parameter in the `npB… | — | wordfence |
| 4071c361-3a68-49b7-ac50-4b32e2e1c3ff | < 3.6 |
MEDIUM | 4.7 | Cross-site request forgery (CSRF) vulnerability in the WordPress Simple Paypal Shopping Cart plugin before 3.6 for WordP… | — | wordfence |
| 3f937290-fa45-4ce0-84f0-a42c83cd3bdf | MEDIUM | 4.7 | The DT Chocolate theme for WordPress is vulnerable to Open Redirect in versions up to, and including, 1.0. This is due t… | — | wordfence | |
| 3c74ea5e-e25a-4b78-b04c-ed66992d4d80 | < 6.4.9.6 |
MEDIUM | 4.7 | Multiple cross-site scripting (XSS) vulnerabilities in the Google Analyticator plugin before 6.4.9.6 for WordPress allow… | — | wordfence |
| 3c2bddb3-2b23-4a75-abe2-db787441a1b2 | MEDIUM | 4.7 | The DancePress (TRWA) plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including,… | — | wordfence | |
| 3aeb5e01-0993-4628-8165-b27470332e34 | < 1.5.6 |
MEDIUM | 4.7 | The plugin KB Support β WordPress Help Desk versions up to 1.5.5 are vulnerable to Cross-Site Scripting. The vulnerabi… | — | wordfence |
| 3a1782c3-ae0b-42f1-aa5e-dabfa2a5bbcd | < 3.3 |
MEDIUM | 4.7 | The WPO365 | MICROSOFT 365 GRAPH MAILER plugin for WordPress is vulnerable to Open Redirect in all versions up to, and i… | — | wordfence |
| 3a11216c-868c-4dd9-b6d5-2a772d7d303e | < 2.7.2 |
MEDIUM | 4.7 | The Comment Press plugin for WordPress is vulnerable to Cross-Frame Scripting in versions up to, and including, 2.7.1. T… | — | wordfence |
| 390e9c30-e4c0-474d-9915-dd46f5464cea | < 9.87.1.0 |
MEDIUM | 4.7 | The VK All in One Expansion Unit plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the β$_SERVE… | — | wordfence |
| 38ccaa81-77ec-46f2-9bec-d74fa2e093f3 | < 1.9.218 |
MEDIUM | 4.7 | The WS Form LITE plugin for WordPress is vulnerable to CSV Injection in versions up to, and including, 1.9.217. This all… | — | wordfence |
EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.
Scan My Website →