Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.
40,402 vulnerabilities found (page 1290 of 1617)
| CVE ID | Plugin / Theme | Severity | CVSS | Description | Fixed In | Source |
|---|---|---|---|---|---|---|
| bfa1192b-34f5-4b71-8fff-14f2d4ac4aca | < 1.8.31 |
MEDIUM | 4.4 | The Photo Gallery by 10Web β Mobile-Friendly Image Gallery plugin for WordPress is vulnerable to Stored Cross-Site Scr… | — | wordfence |
| bf5e5eaf-b42d-49b9-8f55-6025e64748c9 | < 1.1 |
MEDIUM | 4.4 | The Cyberus Key plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'uid' in 'cyberkey_settings' p… | — | wordfence |
| bf2ffdb1-fe10-475b-9c05-553a95d7b3bc | MEDIUM | 4.4 | The Full Screen (Page) Background Image Slideshow plugin for WordPress is vulnerable to Stored Cross-Site Scripting via … | — | wordfence | |
| bf29bc2a-876a-484a-983f-a751cf2070c0 | < 1.9.2 |
MEDIUM | 4.4 | The Laposta WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and includi… | — | wordfence |
| bef1d842-5e04-47ea-b318-55f94c941be0 | < 1.3.8 |
MEDIUM | 4.4 | The Intagrate Lite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions … | — | wordfence |
| bee43fe3-d39a-475e-90c5-24fa569c646a | < 11.9 |
MEDIUM | 4.4 | The WP TripAdvisor Review Slider plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in… | — | wordfence |
| beb1268c-b680-4ebe-8fe2-65f656390038 | < 3.0.7 |
MEDIUM | 4.4 | The Orbit Fox: Duplicate Page, Menu Icons, SVG Support, Cookie Notice, Custom Fonts & More plugin for WordPress is vulne… | — | wordfence |
| be841d6b-e3b6-46d2-aba8-fee20c21e933 | < 5.2.4 |
MEDIUM | 4.4 | The Quick Page/Post Redirect plugin for WordPress is vulnerable to Stored Cross-Site Scripting via plugin settings in ve… | — | wordfence |
| be7c6cfa-6cac-46d2-8eb9-9fef8049f6e7 | < 5.1.20 |
MEDIUM | 4.4 | The Contact Form Plugin by Fluent Forms for Quiz, Survey, and Drag & Drop WP Form Builder plugin for WordPress is vulner… | — | wordfence |
| be6f660f-041a-42f2-ab5b-72aedf75727d | MEDIUM | 4.4 | The About Me 3000 widget plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in version… | — | wordfence | |
| be60b94f-d7bc-46e1-b47b-42d044597cc6 | < 2.13.4 |
MEDIUM | 4.4 | The Registrations for the Events Calendar β Event Registration Plugin plugin for WordPress is vulnerable to Stored Cro… | — | wordfence |
| be3a1bff-c20a-43c6-9f7f-3190d5b9c563 | < 1.4.0 |
MEDIUM | 4.4 | The Pixeline's Email Protector plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in a… | — | wordfence |
| be320456-acab-478b-a4b5-807feb7fb9b4 | < 1.34.4 |
MEDIUM | 4.4 | The Hubbub Lite β Fast, Reliable Social Sharing Buttons plugin for WordPress is vulnerable to Stored Cross-Site Script… | — | wordfence |
| be2d005f-a056-4c53-91a6-7de422cdec89 | < 3.0.4 |
MEDIUM | 4.4 | The Simple Banner β Easily add multiple Banners/Bars/Notifications/Announcements to the top or bottom of your website … | — | wordfence |
| be0e9463-359a-4db5-ba76-5d9995adceee | < 3.4.10 |
MEDIUM | 4.4 | The Terms descriptions plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and includin… | — | wordfence |
| be0dc9be-f597-46d8-badd-452e442a6d1a | MEDIUM | 4.4 | The WP Open Social plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in versions up t… | — | wordfence | |
| bde8b267-2bfe-4ec2-a489-6edd6269ba6e | < 1.2.18 |
MEDIUM | 4.4 | The Email Template Customizer for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versi… | — | wordfence |
| bdd35d61-0777-4e64-8a51-55fe928e75ba | < 1.0.41 |
MEDIUM | 4.4 | The Flo Forms plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in versions up to, an… | — | wordfence |
| bd5a1ab9-8d59-464a-a227-9f6ee768e35c | MEDIUM | 4.4 | The enigma-chartjs plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the chart functionality in vers… | — | wordfence | |
| bd50d7bf-33a9-4a35-855b-7278080695a5 | MEDIUM | 4.4 | The PDPA Consent for Thailand plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and i… | — | wordfence | |
| bd2bc2e7-960e-40db-9dcc-a6a60117bd83 | < 1.12.8 |
MEDIUM | 4.4 | The Elementor Addon Elements plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in ver… | — | wordfence |
| bcf6a12e-969b-4627-80c8-b51bb9b710cf | < 4.0.6 |
MEDIUM | 4.4 | The Survey Maker β Best WordPress Survey Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via … | — | wordfence |
| bcf4e969-82de-4505-8406-8638217b5cb7 | < 8.1.17 |
MEDIUM | 4.4 | The ActiveCampaign plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 8… | — | wordfence |
| bcd9df9c-e1f8-467a-8f1c-ab5c402004da | < 2.9.9.2.9 |
MEDIUM | 4.4 | The Pinpoint Booking System plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in vers… | — | wordfence |
| bcbb65eb-28f8-4b09-abc9-0f8b7d050f2f | < 3.2.1 |
MEDIUM | 4.4 | The Clearout Email Validator plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and in… | — | wordfence |
EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.
Scan My Website →