Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.
39,652 vulnerabilities found (page 341 of 1587)
| CVE ID | Plugin / Theme | Severity | CVSS | Description | Fixed In | Source |
|---|---|---|---|---|---|---|
| fa47a794-e5ce-491d-a10b-c7c5718aa853 | < 2.2.5 |
HIGH | 7.2 | The FluentSMTP plugin for WordPress is vulnerable to Stored Cross-Site Scripting via an email subject in versions up to,… | — | wordfence |
| fa37025a-7f20-4cfe-a7d0-38168f49b6d9 | < 2.4.2 |
HIGH | 7.2 | The LWS Cleaner plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation i… | — | wordfence |
| fa1e6527-d874-4003-b36b-5769c2950864 | HIGH | 7.2 | The Return and Warranty Management System for WooCommerce plugin for WordPress is vulnerable to stored Cross-Site Script… | — | wordfence | |
| fa15c0a4-c99d-40c9-a654-f3a910460502 | HIGH | 7.2 | The WordPress Visitors plugin for WordPress is vulnerable to Stored Cross-Site Scripting via a spoofed HTTP Header value… | — | wordfence | |
| f9f17c2b-ca63-4f71-af0f-7bce09ebeb9f | < 1.2 |
HIGH | 7.2 | The Answer My Question plugin for WordPress is vulnerable to Cross-Site Scripting via several parameters in versions bef… | — | wordfence |
| f9e83561-aa71-4984-8a26-207e208d70e8 | < 2.0.15 |
HIGH | 7.2 | The Advanced Ads plugin for WordPress is vulnerable to Remote Code Execution in versions up to, and including, 2.0.14 vi… | — | wordfence |
| f9e45bc2-6db6-49cd-8a4a-58489a8ddac2 | < 1.0.8 |
HIGH | 7.2 | The User Feedback plugin for WordPress is vulnerable to Stored Cross-Site Scripting via user responses for surveys in ve… | — | wordfence |
| f9d9e485-171f-4e36-943d-397d540e31f4 | < 1.68.11 |
HIGH | 7.2 | The WP-DownloadManager plugin for WordPress is vulnerable to arbitrary file deletion due to lack of restriction on the d… | — | wordfence |
| f99a918d-53c1-46bd-8e55-9ba77a92efe8 | < 2.1.6 |
HIGH | 7.2 | The Solid Mail β SMTP email and logging made by SolidWP plugin for WordPress is vulnerable to Stored Cross-Site Script… | — | wordfence |
| f9927487-99fb-46d9-a208-f19e0a371267 | < 1.0.5 |
HIGH | 7.2 | The Easy PHP Settings plugin for WordPress is vulnerable to PHP Code Injection in all versions up to, and including, 1.0… | — | wordfence |
| f96d99dc-df3a-4b01-b276-08a85860720e | < 8.2.8 |
HIGH | 7.2 | The Nelio A/B Testing β AB Tests and Heatmaps for Better Conversion Optimization plugin for WordPress is vulnerable to… | — | wordfence |
| f92784a7-f2b3-47f8-b03f-4e234b57e40a | < 2.3 |
HIGH | 7.2 | The Subscribe to Comments for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 2.1.2 vi… | — | wordfence |
| f9135799-00db-447d-b795-faafeafbce67 | < 2.10.1 |
HIGH | 7.2 | The Gravity Forms plugin for WordPress is vulnerable to Unauthenticated Stored Cross-Site Scripting in versions up to an… | — | wordfence |
| f8b34144-5516-46df-b093-95f4bf76b896 | < 5.98.0 |
HIGH | 7.2 | The Customer Reviews for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'media[].… | — | wordfence |
| f8aa8dd6-abff-4c37-98d5-39a924b15651 | < 1.6.51 |
HIGH | 7.2 | The Charitable β Donation Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, … | — | wordfence |
| f8a87f7b-471b-44c0-a0bd-06a9ba24a566 | < 11.0 |
HIGH | 7.2 | The WP Review Slider WordPress plugin before 11.0 does not sanitise and escape the pid parameter when copying a Twitter … | — | wordfence |
| f8786695-adab-4d7c-8cc1-53f37c06de12 | < 3.5.5 |
HIGH | 7.2 | The eCommerce Product Catalog Plugin for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting in … | — | wordfence |
| f866ef19-2662-49c1-a90a-920403c8799d | < 3.8.10 |
HIGH | 7.2 | The JetEngine plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 3.8.9.… | — | wordfence |
| f85a0394-cd70-419d-97bd-c75d6f721714 | < 3.2.3 |
HIGH | 7.2 | The MyBookTable Bookstore plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and in… | — | wordfence |
| f8381866-d991-4638-ab4d-3b8697acf414 | HIGH | 7.2 | The Content Syndication Toolkit plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to,… | — | wordfence | |
| f8234ea2-ff80-425f-b83d-29c422b40c6a | HIGH | 7.2 | The Accessibly plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the REST API in all versions up to,… | — | wordfence | |
| f7ad5d55-3964-4bb9-9f7b-496e99db80f4 | HIGH | 7.2 | The Official Integration for Billingo plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, … | — | wordfence | |
| f781db57-1015-439b-80b5-0e08df0bd05c | < 5.6.2 |
HIGH | 7.2 | The Grand Tour theme for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to 5.6.2 due to insuffici… | — | wordfence |
| f72b7973-2599-4833-abe1-783e2a285165 | < 5.111.0 |
HIGH | 7.2 | The Customer Reviews for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to… | — | wordfence |
| f6d39654-2c22-48c7-b545-7b02e5c4b43b | < 3.0.4 |
HIGH | 7.2 | The Contact Form to Any API plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and inc… | — | wordfence |
EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.
Scan My Website →