Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.
40,407 vulnerabilities found (page 1323 of 1617)
| CVE ID | Plugin / Theme | Severity | CVSS | Description | Fixed In | Source |
|---|---|---|---|---|---|---|
| 4d3d76b3-9aca-46ac-acb7-353261dbec79 | MEDIUM | 4.4 | The Post Read Time plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1… | — | wordfence | |
| 4d16e945-1576-4d9b-8e1b-995ec457215b | < 13.3.1 |
MEDIUM | 4.4 | The Widgets for Google Reviews plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in a… | — | wordfence |
| 4d10d609-eb0f-492a-be87-2ac7db9c63b4 | < 1.7.5 |
MEDIUM | 4.4 | The Client Portal : SuiteDash Direct Login plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions… | — | wordfence |
| 4cf894fd-37c7-4006-b868-d5d33f66cc5a | MEDIUM | 4.4 | The Advanced Social Feeds Widget & Shortcode plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin… | — | wordfence | |
| 4cab3c9c-39c6-4279-9573-858b0592c3fa | MEDIUM | 4.4 | The WP-Cirrus plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in versions up to, an… | — | wordfence | |
| 4c8850df-e835-4068-8114-11966014e6eb | < 1.4.14 |
MEDIUM | 4.4 | The Prisna GWT β Google Website Translator plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin… | — | wordfence |
| 4c64ec9f-c9ca-49c1-9126-b31defb826dd | < 1.97.0 |
MEDIUM | 4.4 | The Advanced Form Integration plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and i… | — | wordfence |
| 4c293c3a-383d-4e3c-bf1b-4d64e9cd3eb5 | < 2.0 |
MEDIUM | 4.4 | The WP Login and Logout Redirect plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in… | — | wordfence |
| 4c1adf5b-5377-40a3-a53d-e93cf38d949d | MEDIUM | 4.4 | The WP Front User Submit / Front Editor plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up… | — | wordfence | |
| 4bf456a3-3d42-42e8-b89b-dcdd8cbc7d9a | MEDIUM | 4.4 | The BMo Expo plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.0.15 … | — | wordfence | |
| 4baa79da-ae4d-4e45-855f-8c7d713fb2f9 | MEDIUM | 4.4 | The Special Box for Content plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all … | — | wordfence | |
| 4ba46475-bf54-49a8-9b0e-fae3fb4e1df9 | MEDIUM | 4.4 | The Short Comment Filter plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'Minimum Count' setti… | — | wordfence | |
| 4b8a3e10-bdd9-4d5f-8632-bd7f0247b8f1 | < 3.10.1 |
MEDIUM | 4.4 | The Ninja Forms β The Contact Form Builder That Grows With You plugin for WordPress is vulnerable to Stored Cross-Site… | — | wordfence |
| 4b51d69d-2026-4e2c-b031-93046c24b2dd | < 2.7.0 |
MEDIUM | 4.4 | The WP Abstracts plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.6… | — | wordfence |
| 4b5078ca-dec9-4252-8dd9-42bbb9ddef55 | MEDIUM | 4.4 | The WooMS plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 9.12 due t… | — | wordfence | |
| 4b334ebe-6988-4caf-aad4-b599dc6be969 | < 2.4.1 |
MEDIUM | 4.4 | The IP Based Login plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions … | — | wordfence |
| 4af920a9-15fb-44c9-be31-7c9ed5bc2031 | MEDIUM | 4.4 | The binlayerpress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions u… | — | wordfence | |
| 4aedc055-34f7-48aa-90d4-0c16f219f599 | < 1.2.62 |
MEDIUM | 4.4 | The Slider by 10Web β Responsive Image Slider plugin for WordPress is vulnerable to Stored Cross-Site Scripting via ad… | — | wordfence |
| 4ada2055-3c4a-4b6f-8803-2eac8ede5ec7 | < 1.50.3 |
MEDIUM | 4.4 | The Forminator Forms β Contact Form, Payment Form & Custom Form Builder plugin for WordPress is vulnerable to Stored C… | — | wordfence |
| 4ac9262a-96a6-439a-a2b0-a05f24654d06 | < 2.3.4 |
MEDIUM | 4.4 | The Button Generator β easily Button Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via adm… | — | wordfence |
| 4a7bfa47-1c83-4af7-8ddd-0b90a117b9c7 | MEDIUM | 4.4 | The Expert Invoice plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions … | — | wordfence | |
| 4a77675b-5a31-4bc1-b4bd-36dd9a612b7c | MEDIUM | 4.4 | The Social Feed | All social media in one place plugin for WordPress is vulnerable to Stored Cross-Site Scripting via ad… | — | wordfence | |
| 49d0315e-fcb2-4232-8797-0421cf5d3cd8 | < 2.0.7 |
MEDIUM | 4.4 | The Chartify β WordPress Chart Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin sett… | — | wordfence |
| 49c65776-130d-4c22-b4f8-ababac8cf341 | < 2.14.3 |
MEDIUM | 4.4 | The WebinarIgnition plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'appname' and 'webinar_des… | — | wordfence |
| 49bd0848-afc0-4aa2-86a4-1b697206b925 | < 5.0.17 |
MEDIUM | 4.4 | The Ninja Tables β Easy Data Table Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via a CSV… | — | wordfence |
EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.
Scan My Website →