Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.
40,407 vulnerabilities found (page 1335 of 1617)
| CVE ID | Plugin / Theme | Severity | CVSS | Description | Fixed In | Source |
|---|---|---|---|---|---|---|
| 2290c2a0-2b13-4aee-9d04-0ea6ec20d81d | MEDIUM | 4.4 | The Locatoraid Store Locator plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and in… | — | wordfence | |
| 2290b13e-a5c6-4ec7-86c0-f2cd2a880e8e | < 1.32.0 |
MEDIUM | 4.4 | The Hubbub Lite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up … | — | wordfence |
| 227cf3fe-4e76-4827-ac92-788bca450b52 | < 2.06 |
MEDIUM | 4.4 | The WP Brutal AI plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in versions up to,… | — | wordfence |
| 2241fa07-b6b7-4e5d-8951-ae844a7b88e8 | MEDIUM | 4.4 | The WP BaiDu Submit plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in versions up … | — | wordfence | |
| 223d62cc-61ee-4818-9521-a772c1d57d59 | MEDIUM | 4.4 | The twinklesmtp β Email Service Provider For WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripti… | — | wordfence | |
| 222848a7-e079-4d56-9917-ec1d916efdcf | MEDIUM | 4.4 | The WP-reCAPTCHA-bp plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, … | — | wordfence | |
| 2210b056-49d4-4212-8e65-1215c71b7e9a | MEDIUM | 4.4 | The Himalayas theme for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.3.2 d… | — | wordfence | |
| 220766ef-29a6-46f6-8c67-d1879db79400 | < 1.8 |
MEDIUM | 4.4 | The wpShopGermany IT-RECHT KANZLEI plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings … | — | wordfence |
| 21cd81aa-c3f2-4413-8a07-06c065f47569 | < 3.4.18 |
MEDIUM | 4.4 | The Branda plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 3.4.17 du… | — | wordfence |
| 21cc5aec-ab5f-412b-aed0-bb41584a84cf | < 2.1 |
MEDIUM | 4.4 | The wpShopGermany - Protected Shops plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings… | — | wordfence |
| 21b4d1a1-55fe-4241-820c-203991d724c4 | < 1.8.19 |
MEDIUM | 4.4 | The Photo Gallery by 10Web plugin for WordPress is vulnerable to Stored Cross-Site Scripting via widgets in versions up … | — | wordfence |
| 21a3e3f1-9503-49f4-9b84-8b7c38c22e69 | < 2.0.6 |
MEDIUM | 4.4 | The Themify Audio Dock plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and includin… | — | wordfence |
| 219f732e-abd8-463c-a43e-f92371356e3d | MEDIUM | 4.4 | The Bot Block – Stop Spam Referrals in Google Analytics plugin for WordPress is vulnerable to Stored Cross-Site Sc… | — | wordfence | |
| 219de193-32d0-40b0-a471-bf8bf6e2bb62 | < 1.1.7 |
MEDIUM | 4.4 | The Cab fare calculator plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the vehicle title setting … | — | wordfence |
| 2181ede3-d8ac-4b62-98e5-7f4448a8cee4 | MEDIUM | 4.4 | The Easy Logo plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to… | — | wordfence | |
| 21238925-b87c-43ea-b4ab-9b5d311d3a0a | MEDIUM | 4.4 | The WP-Eggdrop plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up t… | — | wordfence | |
| 211ffeb3-6f6b-4b90-b229-acdee49a801a | < 0.7.0 |
MEDIUM | 4.4 | The Brave β Create Popup, Optins, Lead Generation, Survey, Sticky Elements & Interactive Content plugin for WordPress … | — | wordfence |
| 210fd125-285d-4d07-bd39-b5ea222025ea | < 3.5.2 |
MEDIUM | 4.4 | The Starbox β the Author Box for Humans plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin se… | — | wordfence |
| 20e0e651-8330-4062-8fb4-f0545befcb1a | < 5.8013 |
MEDIUM | 4.4 | The Ebook Store plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Order Details in all versions … | — | wordfence |
| 20b3cd2a-ee32-49e0-8281-16afb8e42448 | < 5.5.0 |
MEDIUM | 4.4 | The Jetpack CRM plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in versions up to, … | — | wordfence |
| 20b11bbb-fd27-4c0c-9205-fd2164c39392 | < 4.9.20 |
MEDIUM | 4.4 | The Category Posts Widget plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all ve… | — | wordfence |
| 20a6a58f-b6c0-4132-932b-c6def8e9e7c0 | MEDIUM | 4.4 | The gAppointments - Appointment booking addon for Gravity Forms plugin for WordPress is vulnerable to Stored Cross-Site … | — | wordfence | |
| 208c5ed1-879f-45ea-833e-d2e54c4f063f | < 9.0.33 |
MEDIUM | 4.4 | The WP Go Maps for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in versions up to, and incl… | — | wordfence |
| 20863474-01f7-45f7-b71f-b7ea920649ec | < 2.0.9 |
MEDIUM | 4.4 | The Legal Terms and Conditions Popup for User Login and WooCommerce Checkout β TPUL plugin for WordPress is vulnerable… | — | wordfence |
| 2083fdf7-e251-4162-b38f-8dab4395a8a7 | < 0.9.34 |
MEDIUM | 4.4 | The WPvivid Backup for MainWP plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in al… | — | wordfence |
EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.
Scan My Website →