Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.
40,407 vulnerabilities found (page 1311 of 1617)
| CVE ID | Plugin / Theme | Severity | CVSS | Description | Fixed In | Source |
|---|---|---|---|---|---|---|
| 77fa042d-1e4f-4344-bf5a-3860add7aae3 | MEDIUM | 4.4 | The Carrot plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in versions up to, and i… | — | wordfence | |
| 77a923d5-b73e-45cf-9617-09b4d5c8bb5a | < 1.2 |
MEDIUM | 4.4 | The Bit Assist plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in versions up to, a… | — | wordfence |
| 779df91d-bf27-42ac-9445-13a4ad63a322 | MEDIUM | 4.4 | The COVID-19 (Coronavirus) Update Your Customers plugin for WordPress is vulnerable to Stored Cross-Site Scripting in ve… | — | wordfence | |
| 77876d74-5825-4bd8-812e-87061d0470e6 | < 6.1.8 |
MEDIUM | 4.4 | The Advanced Custom Fields PRO plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in v… | — | wordfence |
| 776a441b-1bb8-46ea-9884-4abf562f6e5c | < 2.7.12 |
MEDIUM | 4.4 | The Video Share VOD – Turnkey Video Site Builder Script plugin for WordPress is vulnerable to Stored Cross-Site Script… | — | wordfence |
| 771da808-8962-46a3-8519-85d9422583f6 | MEDIUM | 4.4 | The Advanced Social Pixel plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in versio… | — | wordfence | |
| 770c64d3-3cc8-4fd9-91d6-96a1c252265a | < 4.7.2 |
MEDIUM | 4.4 | The WP Maps – Display Google Maps Perfectly with Ease plugin for WordPress is vulnerable to Stored Cross-Site Scriptin… | — | wordfence |
| 76b4e3d1-170c-4fe0-8e84-246b973d48b1 | < 1.8.4 |
MEDIUM | 4.4 | The Slideshow Gallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including… | — | wordfence |
| 76b25ae3-b813-4e79-a5e3-0af5e6eb8a06 | MEDIUM | 4.4 | The Platinum SEO plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up… | — | wordfence | |
| 765b09ef-dd6d-4c4e-a381-7bb0dc8d6652 | < 1.2.1 |
MEDIUM | 4.4 | The Easy Form by AYS plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in versions up… | — | wordfence |
| 762190dc-cd19-4bc1-8204-9219881d95e9 | < 11.1.2 |
MEDIUM | 4.4 | The Disqus Conditional Load plugin for WordPress is vulnerable to Stored Cross-Site Scripting via plugin options such as… | — | wordfence |
| 760f46b9-23a2-4f30-be40-abb29b096c01 | MEDIUM | 4.4 | The CSV Importer Improved plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all ve… | — | wordfence | |
| 75ffafcc-7126-410d-b800-b249c03885a8 | < 2.6.0 |
MEDIUM | 4.4 | The WP Discord Invite plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including… | — | wordfence |
| 75f45345-216e-48a8-b131-672aa12a0e0f | < 2.7.22 |
MEDIUM | 4.4 | The SportsPress – Sports Club & League Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via a… | — | wordfence |
| 75e89574-a0d4-4383-a6f8-bf977e2ffe4d | < 2.0.0 |
MEDIUM | 4.4 | The Simple Image Popup plugin for WordPress is vulnerable to Stored Cross-Site Scripting via popup settings in versions … | — | wordfence |
| 75da660b-04c7-4f15-b49d-2aa320ef5b4b | < 1.0.13 |
MEDIUM | 4.4 | The Chatra Live Chat + ChatBot + Cart Saver plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin … | — | wordfence |
| 75b8fce9-023d-4603-9d92-46a053d16291 | < 5.2.62 |
MEDIUM | 4.4 | The Calculated Fields Form plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all v… | — | wordfence |
| 759add85-3d72-46d5-a973-dd8dcfb9f336 | < 5.0.6 |
MEDIUM | 4.4 | The Contact Form 7 – Dynamic Text Extension plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all v… | — | wordfence |
| 758b7c61-92cc-4100-b04a-e5ff6c90f779 | < 1.8.1 |
MEDIUM | 4.4 | The Safety Exit plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.8.… | — | wordfence |
| 75824b96-8674-4340-9e56-b0cb0f52503d | < 1.4.6 |
MEDIUM | 4.4 | The Robokassa payment gateway for Woocommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admi… | — | wordfence |
| 756810c0-d805-4391-a67b-19b40597d219 | MEDIUM | 4.4 | The Yandex.News Feed by Teplitsa plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in… | — | wordfence | |
| 755c8863-33c2-47aa-880a-0ef8b2d594a3 | MEDIUM | 4.4 | The Toggles Shortcode and Widget plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘content’… | — | wordfence | |
| 750a4a94-458c-4944-a99b-a1c8e23e57d1 | MEDIUM | 4.4 | The Sticky Ad Bar plugin for WordPress is vulnerable to Stored Cross-Site Scripting via numerous plugin options paramete… | — | wordfence | |
| 74f212b1-9f70-44c8-a7bb-ee8887be9ea6 | < 4.0.9.8 |
MEDIUM | 4.4 | The MailChimp Subscribe Form, Optin Builder, PopUp Builder, Form Builder plugin for WordPress is vulnerable to Stored Cr… | — | wordfence |
| 74ea8f1e-d6ff-4a32-b8bf-5d4c8e69433e | MEDIUM | 4.4 | The Flyzoo Chat plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in versions up to, … | — | wordfence |
EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.
Scan My Website →