Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.
40,407 vulnerabilities found (page 1334 of 1617)
| CVE ID | Plugin / Theme | Severity | CVSS | Description | Fixed In | Source |
|---|---|---|---|---|---|---|
| 261b21b7-6bed-4df9-bbb6-f395c0fd4f22 | MEDIUM | 4.4 | The Simple Link List Widget plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and inc… | — | wordfence | |
| 25cfa88b-5b13-43d9-823b-c5d2064f5888 | MEDIUM | 4.4 | The Contact Info Widget plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and includi… | — | wordfence | |
| 25c35a42-9f1a-4f67-a074-c6359e8b1a41 | < 4.1.7 |
MEDIUM | 4.4 | The Secure Copy Content Protection and Content Locking plugin for WordPress is vulnerable to Stored Cross-Site Scripting… | — | wordfence |
| 25a566ed-9ed6-4c72-9728-49a0edfb5ba5 | < 1.1.0 |
MEDIUM | 4.4 | The Auto Rename Media On Upload plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in … | — | wordfence |
| 25a55dc6-6bfe-40dc-afae-e91670f6b73c | < 1.07.7 |
MEDIUM | 4.4 | The Advance Portfolio Grid plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and incl… | — | wordfence |
| 257eb4c5-ca32-42ac-9f04-21adddcc96f0 | MEDIUM | 4.4 | The Popup4Phone plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up … | — | wordfence | |
| 2567ecc4-1346-4092-8c99-ffa5064e6a3f | < 4.2.18 |
MEDIUM | 4.4 | The Social Icons Widget & Block by WPZOOM plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin se… | — | wordfence |
| 251b17a7-781f-4f17-af90-9a6fbae69243 | < 2.0.7 |
MEDIUM | 4.4 | The Counter Box: Add Engaging Countdowns, Timers & Counters to Your WordPress Site plugin for WordPress is vulnerable to… | — | wordfence |
| 25018b54-9938-4261-80fb-d0c59d7fe456 | < 5.1.8.9 |
MEDIUM | 4.4 | The Survey Maker plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 5.1… | — | wordfence |
| 24fc2554-375a-4216-91bf-41921cc4b436 | < 1.0.9 |
MEDIUM | 4.4 | The WP Roadmap β Product Feedback Board plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin se… | — | wordfence |
| 24226595-6ae7-44c2-a159-5b69808273fa | < 1.5.4 |
MEDIUM | 4.4 | The Product Labels For Woocommerce (Sale Badges) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via t… | — | wordfence |
| 24184443-9737-4117-89cf-02cf1e2a07f2 | < 0.7.3 |
MEDIUM | 4.4 | The Logo Manager For Enamad plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all … | — | wordfence |
| 23fc3221-73b0-4407-a5d7-f145c3dbc1e6 | < 1.8.9 |
MEDIUM | 4.4 | The File Manager Pro plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including,… | — | wordfence |
| 23f7f4ad-f9d5-44b7-8354-5145b003fd20 | MEDIUM | 4.4 | The WordPress Custom Settings plugin is vulnerable to Stored Cross-Site Scripting via admin settings in versions up to, … | — | wordfence | |
| 23ad80bd-3e35-4610-b917-7242a4292adf | < 5.2.8 |
MEDIUM | 4.4 | The Generate Images β Magic Post Thumbnail plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin… | — | wordfence |
| 23a2b1ac-2183-48ae-8376-fb950fe83fd9 | MEDIUM | 4.4 | The Custom Post Type Generator plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin settings… | — | wordfence | |
| 2363b377-b74e-43ad-969f-6bce0bac6000 | < 1.23 |
MEDIUM | 4.4 | The Add Code To Head plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including,… | — | wordfence |
| 234c8c32-0661-4f54-ab16-c630d9aae82e | MEDIUM | 4.4 | The SensorPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.0 … | — | wordfence | |
| 23447ee8-e852-4ddf-a333-5d0df01c4195 | < 1.5.2 |
MEDIUM | 4.4 | The Smart Maintenance Mode plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all v… | — | wordfence |
| 23334d94-e5b8-4c88-8765-02ad19e17248 | < 4.19.2 |
MEDIUM | 4.4 | The WordPress File Upload and WordPress File Upload Pro plugins for WordPress are vulnerable to Stored Cross-Site Script… | — | wordfence |
| 233319cc-10fc-4a15-be35-df772e700639 | < 3.6.9 |
MEDIUM | 4.4 | The Logo Slider β Logo Showcase, Logo Carousel, Logo Gallery and Client Logo Presentation plugin for WordPress is vuln… | — | wordfence |
| 232378ba-5992-4ac0-975b-8c329bce83b6 | < 3.2.7.1 |
MEDIUM | 4.4 | The Pods β Custom Content Types and Fields plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin… | — | wordfence |
| 22ff0b0c-ffd9-4aae-9e49-069fd1b47f17 | < 3.8.7 |
MEDIUM | 4.4 | The Popup Box β Best WordPress Popup Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admi… | — | wordfence |
| 22bc7a0c-8a89-461b-8838-788dd6d5c63b | < 1.5.49 |
MEDIUM | 4.4 | The Unlimited Elements For Elementor (Free Widgets, Addons, Templates) plugin for WordPress is vulnerable to Stored Cros… | — | wordfence |
| 22a32bb6-fe22-4c5e-91f6-de3c38d7d19e | MEDIUM | 4.4 | The Viet Nam Affiliate plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versi… | — | wordfence |
EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.
Scan My Website →