Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.
40,402 vulnerabilities found (page 1284 of 1617)
| CVE ID | Plugin / Theme | Severity | CVSS | Description | Fixed In | Source |
|---|---|---|---|---|---|---|
| d170af2a-9b8c-43ad-b712-b89bcfadd5b7 | < 1.2.16 |
MEDIUM | 4.4 | The Ultimate Maps by Supsystic plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in a… | — | wordfence |
| d16a3da0-9539-4555-8dfc-65cb4f4d7b4d | < 3.1.7 |
MEDIUM | 4.4 | The Autoptimize plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the critical css rules in versions… | — | wordfence |
| d1647a2c-d21d-4b4b-a22e-32351022404e | < 1.2.1 |
MEDIUM | 4.4 | The Logo Scheduler plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in versions up t… | — | wordfence |
| d131115b-e2c9-42c6-9262-a19272944652 | < 1.5.1 |
MEDIUM | 4.4 | The Panorama β WordPress Project Management Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting v… | — | wordfence |
| d0e6900c-21a3-4b46-bb61-8c41e2234a26 | MEDIUM | 4.4 | The Continually plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up … | — | wordfence | |
| d09ea234-f04e-4337-851e-b42bbf6f8901 | MEDIUM | 4.4 | The WP Biographia plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 4.… | — | wordfence | |
| d082c6e6-a18a-44e2-9478-7189f9777198 | < 4.9.5 |
MEDIUM | 4.4 | The WP Maps β Google Maps,OpenStreetMap,Mapbox,Store Locator,Listing,Directory & Filters plugin for WordPress is vulne… | — | wordfence |
| d050b5a4-efd1-45d5-a3f7-13fa9e19ab37 | < 2.3.15 |
MEDIUM | 4.4 | The Responsive Gallery Grid plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all … | — | wordfence |
| d00c6fe3-5914-46e1-9a00-0641d17aa79f | < 4.15.20 |
MEDIUM | 4.4 | The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content β ProfilePr… | — | wordfence |
| CVE-2026-6812 | MEDIUM | 4.4 | The Ona theme for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 1.26 via … | — | nvd | |
| CVE-2026-2716 | MEDIUM | 4.4 | The Client Testimonial Slider plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'Testimonial Hea… | — | nvd | |
| CVE-2026-2499 | MEDIUM | 4.4 | The Custom Logo plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up … | — | nvd | |
| CVE-2026-2498 | MEDIUM | 4.4 | The WP Social Meta plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions … | — | nvd | |
| CVE-2026-2489 | MEDIUM | 4.4 | The TP2WP Importer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'Watched domains' textarea … | — | nvd | |
| CVE-2026-2292 | MEDIUM | 4.4 | The Morkva UA Shipping plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versi… | — | nvd | |
| CVE-2026-2289 | MEDIUM | 4.4 | The Taskbuilder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up … | — | nvd | |
| CVE-2026-2282 | MEDIUM | 4.4 | The Slidorion plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to… | — | nvd | |
| CVE-2026-2281 | MEDIUM | 4.4 | The Private Comment plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'Label text' setting in al… | — | nvd | |
| CVE-2026-1649 | MEDIUM | 4.4 | The Community Events plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'ce_venue_name' parameter… | — | nvd | |
| CVE-2026-1055 | MEDIUM | 4.4 | The TalkJS plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, a… | — | nvd | |
| CVE-2026-1047 | MEDIUM | 4.4 | The salavat counter Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'image_url' paramet… | — | nvd | |
| CVE-2026-1044 | MEDIUM | 4.4 | The Tennis Court Bookings plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all ve… | — | nvd | |
| CVE-2026-1043 | MEDIUM | 4.4 | The PostmarkApp Email Integrator plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin settin… | — | nvd | |
| CVE-2025-12451 | MEDIUM | 4.4 | The Easy SVG Support plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG file uploads in all versi… | — | nvd | |
| CVE-2025-12037 | < 1.0.6 |
MEDIUM | 4.4 | The WP 404 Auto Redirect to Similar Post plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin set… | — | nvd |
EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.
Scan My Website →