Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.
40,402 vulnerabilities found (page 1270 of 1617)
| CVE ID | Plugin / Theme | Severity | CVSS | Description | Fixed In | Source |
|---|---|---|---|---|---|---|
| 3529044f-c3d8-4370-8ba5-9df0fb71ab3c | < 2.6.6 |
MEDIUM | 4.7 | The Discount Rules for WooCommerce β Create Smart WooCommerce Coupons & Discounts, Bulk Discount, BOGO Coupons plugin … | — | wordfence |
| 33f1d8b9-3561-4347-8267-8c36d4c9071f | < 6.11.4 |
MEDIUM | 4.7 | The Smash Balloon Social Photo Feed β Easy Social Feeds Plugin plugin for WordPress is vulnerable to Reflected Cross-S… | — | wordfence |
| 32028952-ccd7-48f6-87ce-0924f40d99ae | < 3.7.1 |
MEDIUM | 4.7 | The Meta for WooCommerce plugin for WordPress is vulnerable to Open Redirect in all versions up to, and including, 3.7.0… | — | wordfence |
| 30e67229-f3b6-43e4-a0c4-2e4392f4bec5 | < 1.3.6 |
MEDIUM | 4.7 | The WP Gravity Forms FreshDesk Plugin plugin for WordPress is vulnerable to Open Redirect in all versions up to, and inc… | — | wordfence |
| 221f9cbb-7988-4671-8f14-da3e63c280e6 | < 3.3.19.1 |
MEDIUM | 4.7 | An open redirect in the Ninja Forms plugin before 3.3.19.1 for WordPress allows Remote Attackers to redirect a user via … | — | wordfence |
| 221872e2-7929-4fba-8a57-7d9fd73a76db | < 3.0.1 |
MEDIUM | 4.7 | WordPress before 3.0.1, when a Multisite installation is used, permanently retains the "site administrators can add user… | — | wordfence |
| 1f092dae-e298-42e3-b494-fc7b7669b300 | < 4.4.4 |
MEDIUM | 4.7 | The All In One WP Security & Firewall plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the tab p… | — | wordfence |
| 1d430b33-1607-46b3-8780-ac5cfbb7d6ec | < 1.1.46 |
MEDIUM | 4.7 | The Event Calendar WD plugin for WordPress is vulnerable to Cross-Site Scripting in versions up to, and including, 1.1.4… | — | wordfence |
| 1a5ac5f9-aaf4-4a7f-9d1d-fc8f5e632c21 | MEDIUM | 4.7 | The Favicon My Blog plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and includin… | — | wordfence | |
| 1646f96c-f0f4-433a-ac5e-04c1c251972d | MEDIUM | 4.7 | The CryoKey plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the βckemailβ parameter in all … | — | wordfence | |
| 125e11a3-c497-484e-940b-2bcdf7f2c1ab | < 1.15.3 |
MEDIUM | 4.7 | Insufficient Input Validation in the search functionality of Wordpress plugin Share-one-Drive prior to 1.15.3 allows una… | — | wordfence |
| 0ec8a72e-0153-4c2b-bdda-c6474cc2aadb | < 2.5.10 |
MEDIUM | 4.7 | The bbPress plugin for WordPress is vulnerable to Cross-Site Scripting in versions up to, and including, 2.5.9 due to in… | — | wordfence |
| 0c944e08-1b70-4b56-80eb-f588c0fab5b6 | < 3.4.2.14 |
MEDIUM | 4.7 | The wpDataTables β WordPress Data Table, Dynamic Tables & Table Charts Plugin plugin for WordPress is vulnerable to St… | — | wordfence |
| 04cd8da4-9da3-4c80-a77e-c2f792391593 | < 2.5.1 |
MEDIUM | 4.7 | The Ultimate Member plugin for WordPress is vulnerable to directory traversal in versions up to, and including 2.5.0 due… | — | wordfence |
| 047cd34e-f2a1-4643-a1c5-3ead926b83ca | < 8.1.5 |
MEDIUM | 4.7 | The iThemes Security plugin for WordPress is vulnerable to open redirection in versions up to, and including, 8.1.4. Thi… | — | wordfence |
| e635dfb3-002d-4197-b14a-0136a1990a75 | < 1.8.3 |
MEDIUM | 4.6 | The Page Builder: Pagelayer β Drag and Drop website builder plugin for WordPress is vulnerable to Stored Cross-Site Sc… | — | wordfence |
| 7e42954c-1ae3-41ef-8dd3-16e5820aa36f | < 3.5.2 |
MEDIUM | 4.6 | moxieplayer.as in Moxiecode moxieplayer, as used in the TinyMCE Media plugin in WordPress before 3.5.2 and other product… | — | wordfence |
| 6a6eb430-cf86-4e13-a4f7-173fada9fddf | < 3.8.1 |
MEDIUM | 4.6 | The Ninja Forms Contact Form β The Drag and Drop Form Builder for WordPress plugin for WordPress is vulnerable to Stor… | — | wordfence |
| 5d7bcd71-e299-47fe-a749-e72c49b8129e | < 7.2.1 |
MEDIUM | 4.6 | The BuddyPress plugin for WordPress was vulnerable to authorization bypass due to a misconfiguration in how the plugin h… | — | wordfence |
| 5779914a-a168-4835-8aea-e0ab2b3be4f6 | < 3.4 |
MEDIUM | 4.6 | The Go Pricing - WordPress Responsive Pricing Tables plugin for WordPress is vulnerable to unauthorized modification of … | — | wordfence |
| 4b6f9700-eb29-4391-845c-58e1a2327b0b | < 3.7.30 |
MEDIUM | 4.6 | In WordPress before 5.2.3, validation and sanitization of a URL in wp_validate_redirect in wp-includes/pluggable.php cou… | — | wordfence |
| ffd97ee6-1858-4e8b-bd91-1c509cfa5a15 | < 1.6.9 |
MEDIUM | 4.4 | The Accounting for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in a… | — | wordfence |
| ffc92f28-02bd-48b3-b803-b67feab74db2 | < 5.3.6 |
MEDIUM | 4.4 | The Bus Ticket Booking with Seat Reservation plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versio… | — | wordfence |
| ffbb85c5-e949-4c0f-8c02-2c022b802e05 | < 1.2.3 |
MEDIUM | 4.4 | The Pagination by BestWebSoft plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and i… | — | wordfence |
| ffaefd79-57a7-43b8-af1c-e108567eba67 | < 1.0.7 |
MEDIUM | 4.4 | The FileOrganizer β Manage WordPress and Website Files plugin for WordPress is vulnerable to Stored Cross-Site Scripti… | — | wordfence |
EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.
Scan My Website →