Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.
39,652 vulnerabilities found (page 340 of 1587)
| CVE ID | Plugin / Theme | Severity | CVSS | Description | Fixed In | Source |
|---|---|---|---|---|---|---|
| fec015e1-7f64-4917-a242-90bd1135f680 | < 5.1.9 |
HIGH | 7.2 | The Poll Maker β Best WordPress Poll Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting due to a… | — | wordfence |
| feab189a-bd89-461d-b553-f137b8032e94 | < 1.2.4 |
HIGH | 7.2 | The Easy Social Icons plugin for WordPress is vulnerable to generic SQL Injection via the βidβ parameter in versions… | — | wordfence |
| fe98bd8c-6db3-4094-8ff2-ab21c8778698 | < 3.1.0 |
HIGH | 7.2 | The Catch Themes Demo Import plugin for WordPress is vulnerable to arbitrary file uploads in versions up to, and includi… | — | wordfence |
| fe4774ee-16f2-478f-92e3-8a7da7b30336 | < 4.1.1 |
HIGH | 7.2 | The Telegram Bot & Channel plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Telegram username i… | — | wordfence |
| fdfa2336-dda2-4945-9278-1a85f8b5f88b | < 5.2.4 |
HIGH | 7.2 | The Wordfence plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the '$_SERVER['REQUEST_URI']' parame… | — | wordfence |
| fdf18ae2-f0d4-44d4-9dd1-6ac36d859d68 | < 1.4.4 |
HIGH | 7.2 | The Action Network plugin for WordPress is vulnerable to SQL Injection via the 'bulk-action' parameter in version 1.4.3 … | — | wordfence |
| fd9a81eb-2211-42e9-a456-fb60f3ca2c0f | < 1.56.2 |
HIGH | 7.2 | The Forminator Forms β Contact Form, Payment Form & Custom Form Builder plugin for WordPress is vulnerable to Stored C… | — | wordfence |
| fd903ec3-893e-4dd8-ad90-2e25a926ac4f | < 2.4 |
HIGH | 7.2 | Multiple cross-site scripting (XSS) vulnerabilities in the WP-FeedStats before 2.4 plugin for WordPress allow remote att… | — | wordfence |
| fd8fb3e9-34eb-4b37-9a7e-00309a1ca81d | < 1.1.9 |
HIGH | 7.2 | The Booking Ultra Pro plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including… | — | wordfence |
| fd2b816a-fbb1-4c6f-8f0a-4ef2e77f845e | HIGH | 7.2 | The Note Press WordPress plugin through 0.1.10 does not sanitise and escape the Update parameter before using it in a SQ… | — | wordfence | |
| fd12a952-2e99-41f7-b74c-55c2b7d8deed | < 2.3.2 |
HIGH | 7.2 | The Flexible Checkout Fields for WooCommerce plugin for WordPress is vulnerable to Unauthenticated Arbitrary Plugin Set… | — | wordfence |
| fcd02dfa-688e-4375-92cb-8d0e7cbaaa6e | < 18.5.8 |
HIGH | 7.2 | The Shield Security plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the getColumnContent_Page func… | — | wordfence |
| fcb76d10-fc60-4b19-9b47-1b98f8400a96 | < 2.5.9 |
HIGH | 7.2 | The bbPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the bbp_mention_filter function in ver… | — | wordfence |
| fcb4bd86-c187-4c73-be91-d0edbc5d9215 | < 1.4.0 |
HIGH | 7.2 | The SureRank plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.3.2 d… | — | wordfence |
| fc8b133f-d952-4776-80a2-c856bcb1ee89 | < 2.2.13 |
HIGH | 7.2 | The WP Tabs plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 2.2.12 via dese… | — | wordfence |
| fc6af287-4228-4f05-b439-fac6c057b0a5 | < 1.23.1 |
HIGH | 7.2 | The Timber plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.23.0 via d… | — | wordfence |
| fbc3643c-6116-42d3-b309-2e6aeedfbe4f | < 1.4.22 |
HIGH | 7.2 | The WPZOOM Portfolio Lite β Filterable Portfolio Plugin plugin for WordPress is vulnerable to Stored Cross-Site Script… | — | wordfence |
| fbbe006c-1afc-4c8b-a9f3-ffb21cdabb54 | < 8.0.10 |
HIGH | 7.2 | The WordPress form builder plugin for contact forms, surveys and quizzes β Tripetto plugin for WordPress is vulnerable… | — | wordfence |
| fb7fc87c-4680-477e-94f5-9c502edce61d | < 4.16.4.5 |
HIGH | 7.2 | The WooCommerce Affiliate Plugin WordPress plugin before 4.16.4.5 does not have authorization and CSRF checks on a speci… | — | wordfence |
| fae9f282-eb67-4ad9-be2d-677238527934 | < 3.1.2 |
HIGH | 7.2 | The XCloner plugin 3.1.1 for WordPress and 3.5.1 for Joomla! provides the MySQL username and password on the command lin… | — | wordfence |
| fab8c244-9767-45ed-a6c8-85f66fa41122 | < 3.0.6.8 |
HIGH | 7.2 | The WP Lightbox 2 plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including… | — | wordfence |
| faac4bcd-678a-4618-95ba-3e5567f0e971 | < 3.3.6 |
HIGH | 7.2 | The FancyBox for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via image title attributes … | — | wordfence |
| fa91912d-5794-4c96-8a13-bd54ce0f1deb | < 5.2.7 |
HIGH | 7.2 | The SlimStat Analytics plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the resource parameter in a… | — | wordfence |
| fa75366a-651c-43d0-a32b-cdabf5b07b66 | < 2.7.8 |
HIGH | 7.2 | The JS Help Desk plugin for WordPress is vulnerable to arbitrary file uploads in versions up to, and including, 2.7.7. T… | — | wordfence |
| fa5c97bc-b06f-4ee8-bbc5-72c348d2c92a | < 1.4.1 |
HIGH | 7.2 | The Simple Events Calendar WordPress plugin through 1.4.0 does not sanitise, validate or escape the event_id POST parame… | — | wordfence |
EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.
Scan My Website →