Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.
40,407 vulnerabilities found (page 1343 of 1617)
| CVE ID | Plugin / Theme | Severity | CVSS | Description | Fixed In | Source |
|---|---|---|---|---|---|---|
| 073db945-becb-4b81-a1f9-7b73c30a8c50 | MEDIUM | 4.4 | The AM Events plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.13.1… | — | wordfence | |
| 07372843-f7d3-4ae4-96b4-ef3f475504ff | < 2.1.15 |
MEDIUM | 4.4 | The Yatra plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'activity_image_id' and 'destination… | — | wordfence |
| 07357de3-bbf5-40d3-a171-3b624b572e6c | < 0.5.6.2 |
MEDIUM | 4.4 | The Advanced Post List plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versi… | — | wordfence |
| 071b5c32-b6ac-402a-af74-6ecd05279d93 | MEDIUM | 4.4 | The Kanban Boards for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in … | — | wordfence | |
| 07043be9-c81e-4021-90af-976ae57c0bec | MEDIUM | 4.4 | The qnotsquiz plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'qnotsquiz_custom_start_text' pa… | — | wordfence | |
| 06c86c87-840c-4ca6-9582-98254194eb1b | MEDIUM | 4.4 | The Vertical Marquee Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the admin settings in … | — | wordfence | |
| 06c76b28-3a0a-4070-be37-1aa5908eb888 | < 1.3.3 |
MEDIUM | 4.4 | The Include Me plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.3.2… | — | wordfence |
| 06a29065-8e20-4ead-865f-addd84917336 | MEDIUM | 4.4 | The Append extensions on Pages plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and … | — | wordfence | |
| 06503fb4-1891-4279-bce9-9667d00f69e1 | < 3.3.9.3 |
MEDIUM | 4.4 | The WordPress WP-Advanced-Search plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in… | — | wordfence |
| 063a245d-bd9e-49ac-bdf0-549a25eba9fe | MEDIUM | 4.4 | The FitVids for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all ve… | — | wordfence | |
| 06294c35-6d58-4270-b143-757831fc5da6 | < 1.8.2 |
MEDIUM | 4.4 | The Campaign URL Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multiple form fields with… | — | wordfence |
| 0616a69a-20a5-476c-904a-881b31b9da18 | MEDIUM | 4.4 | The Logo Slider , Logo Carousel , Logo showcase , Client Logo plugin for WordPress is vulnerable to Stored Cross-Site Sc… | — | wordfence | |
| 05f5addb-ab1d-4b67-b969-3b95d43be790 | < 3.0 |
MEDIUM | 4.4 | The wSecure Lite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in versions up to,… | — | wordfence |
| 05b3c8de-6802-4eb2-855c-b13a9005963f | < 1.5.3 |
MEDIUM | 4.4 | The CM On Demand Search And Replace plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to,… | — | wordfence |
| 05aa6132-7591-4d2a-a44b-7d57a24ca8d8 | MEDIUM | 4.4 | The cookieBAR plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.7.0 … | — | wordfence | |
| 059e262b-ee63-4f8b-82ab-c12bcf70f879 | < 7.3.1 |
MEDIUM | 4.4 | The Optima Express + MarketBoost IDX Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin … | — | wordfence |
| 059d3ba9-8530-4977-b59a-f1c2976641d7 | < 2.93 |
MEDIUM | 4.4 | The MapPress Maps for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in … | — | wordfence |
| 0587bf5f-96cf-4a59-9209-6b559a013517 | < 1.7.36 |
MEDIUM | 4.4 | The Login with phone number plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and inc… | — | wordfence |
| 0584611c-39eb-4ed9-9e2b-aa04013f8f74 | < 1.1.6 |
MEDIUM | 4.4 | The WP Google Street View plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and inclu… | — | wordfence |
| 05614ee6-ce14-44fe-a819-8f116563dbdd | < 1.0.74 |
MEDIUM | 4.4 | The EZP Coming Soon Page Plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and includ… | — | wordfence |
| 055cc26b-1e24-4e39-89c8-bdc4a69ce938 | < 4.4 |
MEDIUM | 4.4 | The Rocket Maintenance Mode & Coming Soon Page plugin for WordPress is vulnerable to Stored Cross-Site Scripting via adm… | — | wordfence |
| 052be7d6-bc76-4af9-bf65-2494a46156fc | MEDIUM | 4.4 | The Landing pages and Domain aliases for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting in … | — | wordfence | |
| 05206a31-033e-49b9-9b66-5a6165782643 | < 2309 |
MEDIUM | 4.4 | The Table of Contents Plus plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in versi… | — | wordfence |
| 0516aa04-ff94-4da4-80b7-ea351d11a288 | MEDIUM | 4.4 | The Admin Menu Post List plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and includ… | — | wordfence | |
| 04df6505-46c1-4e66-a363-4ccebacb5e42 | < 1.2 |
MEDIUM | 4.4 | The Call Now Accessibility Button plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings i… | — | wordfence |
EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.
Scan My Website →