Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.
40,407 vulnerabilities found (page 1327 of 1617)
| CVE ID | Plugin / Theme | Severity | CVSS | Description | Fixed In | Source |
|---|---|---|---|---|---|---|
| 401eeb23-bf43-49a8-9c39-4fcd0db57cd3 | < 2.3.1 |
MEDIUM | 4.4 | The Accordions plugin for WordPress is vulnerable to Stored Cross-Site Scripting via parameters and attributes such as '… | — | wordfence |
| 40156caa-7b73-4b4d-825c-bd3e58ea3ff3 | MEDIUM | 4.4 | The Easy Page Transition plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and includ… | — | wordfence | |
| 400dde23-eafb-4ace-8b4a-ac88d0b200ac | MEDIUM | 4.4 | The WC Captcha plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up t… | — | wordfence | |
| 40005aed-07aa-44da-a06e-0187931105ec | MEDIUM | 4.4 | The Sitemap Index plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in versions up to… | — | wordfence | |
| 3fe3fa95-cc1d-469b-8a97-37987b9ae362 | MEDIUM | 4.4 | The OPEN-BRAIN plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'API Key' settings field in all… | — | wordfence | |
| 3facf09f-2e5d-42d0-b0b3-3aea93febe48 | < 3.5.1 |
MEDIUM | 4.4 | The Simple Share Buttons Adder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in a… | — | wordfence |
| 3f9592d1-73a0-422e-b6d2-c31cc79a1a90 | MEDIUM | 4.4 | The Viral Signup β limited opt-in with viral refferal sharing plugin for WordPress is vulnerable to Stored Cross-Site … | — | wordfence | |
| 3f56338f-1687-42c3-8fe2-f62fe962eefd | MEDIUM | 4.4 | The WordPress Jitsi Shortcode plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in al… | — | wordfence | |
| 3f54f117-0dde-49f9-8014-7650bc1a00ac | < 4.6.9 |
MEDIUM | 4.4 | The Order Minimum/Maximum Amount Limits for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scriptin… | — | wordfence |
| 3f2504ba-9432-429f-8476-a994f48836c9 | < 3.59.9 |
MEDIUM | 4.4 | The Photo Gallery, Sliders, Proofing and Themes β NextGEN Gallery plugin for WordPress is vulnerable to Stored Cross-S… | — | wordfence |
| 3f1df412-86cd-4ebc-913b-674cc3b8d89a | < 4.7.1 |
MEDIUM | 4.4 | The WP ULike β Most Advanced Marketing Toolkit plugin for WordPress is vulnerable to Stored Cross-Site Scripting via a… | — | wordfence |
| 3eece451-65a3-4c9d-a8eb-05f6f3e2d1d5 | MEDIUM | 4.4 | The Fast Custom Social Share by CodeBard plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin set… | — | wordfence | |
| 3ee86d33-5a1e-4dc5-b2f6-0beffd8a6b2e | < 7.8.6.7 |
MEDIUM | 4.4 | The WP Encryption β One Click Free SSL Certificate & SSL / HTTPS Redirect, Security & SSL Scan plugin for WordPress is… | — | wordfence |
| 3ed1c2a2-54ee-4dc8-a54d-01d7a6dbc22e | < 4.6.1 |
MEDIUM | 4.4 | The AI ChatBot plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings on the 'language' ta… | — | wordfence |
| 3ec6faa4-d8d3-4c5e-91b2-142164d3b481 | MEDIUM | 4.4 | The Font Farsi plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up t… | — | wordfence | |
| 3e75cdd9-54cb-46de-8647-b92831324774 | MEDIUM | 4.4 | The Master Popups plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including… | — | wordfence | |
| 3e72644c-138d-4733-bcca-a8305273d1a0 | < 2.6.0 |
MEDIUM | 4.4 | The Fleet Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions u… | — | wordfence |
| 3e374887-0062-4ca2-8e43-13a6c4207f84 | < 2.6.4 |
MEDIUM | 4.4 | The YouTube Embed plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.… | — | wordfence |
| 3e1864e7-bd3b-431f-9a9d-378b376298f9 | MEDIUM | 4.4 | The enigma-chartjs plugin for WordPress is vulnerable to Stored Cross-Site Scripting via an unknown parameter in version… | — | wordfence | |
| 3e0f7fa4-2d0d-4206-a3ff-97bf95c84808 | < 1.2.3 |
MEDIUM | 4.4 | The AI Chatbot for WordPress β Hyve Lite plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions… | — | wordfence |
| 3dde3216-e0a9-463f-87e8-b71552d2f3b2 | < 1.11.4 |
MEDIUM | 4.4 | The Cooked plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.11.3 du… | — | wordfence |
| 3dbe7a3c-8247-4f1f-aca6-dda4bdcc1daf | < 10.0.3 |
MEDIUM | 4.4 | The WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 10.0… | — | wordfence |
| 3db97180-9308-4891-9de9-acefe31d088f | < 4.3.0 |
MEDIUM | 4.4 | The All in One SEO Pack plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multiple parameters in ver… | — | wordfence |
| 3d40498a-b0d4-4304-bab7-e9620ef61db5 | < 2.94.10 |
MEDIUM | 4.4 | The MapPress Maps for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in … | — | wordfence |
| 3d0da23a-12e6-4e57-8413-dc86a62b1800 | MEDIUM | 4.4 | The jwp-a11y plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to,… | — | wordfence |
EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.
Scan My Website →