Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.
39,652 vulnerabilities found (page 342 of 1587)
| CVE ID | Plugin / Theme | Severity | CVSS | Description | Fixed In | Source |
|---|---|---|---|---|---|---|
| f6c302d8-ab4f-474c-98ad-356c61c01adc | < 2.4.4 |
HIGH | 7.2 | The Homey Core plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.4.3… | — | wordfence |
| f67b5cd8-bae8-48ca-87d5-7445724791f6 | < 20240223 |
HIGH | 7.2 | The Simple Ajax Chat β Add a Fast, Secure Chat Box plugin for WordPress is vulnerable to Stored Cross-Site Scripting v… | — | wordfence |
| f64336f7-ab2a-4e22-a76f-d077c51f9c57 | < 1.52.2 |
HIGH | 7.2 | The Advanced Ads plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.52.1… | — | wordfence |
| f6424fc9-f118-4654-89a7-1f7e6efa2c02 | < 1.9 |
HIGH | 7.2 | The SMTP for Amazon SES β YaySMTP plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to,… | — | wordfence |
| f5e6cb50-8262-406b-b01e-37d62a4bd394 | < 4.11.1 |
HIGH | 7.2 | The Ajax Search Lite plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and includi… | — | wordfence |
| f58b3971-e1e4-4337-82a3-99c9079c6696 | < 7.2.5 |
HIGH | 7.2 | The Booster for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in ve… | — | wordfence |
| f5863132-90a7-414f-abcb-e8b6a9d229c5 | < 2.0.2 |
HIGH | 7.2 | The Responsive Contact Form Builder & Lead Generation Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scr… | — | wordfence |
| f56a632d-4c5f-4d89-9cd9-8fc3697ff3ca | HIGH | 7.2 | The Membership by Supsystic plugin for WordPress is vulnerable to time-based blind SQL Injection via the 'sidx' and 'sea… | — | wordfence | |
| f56494b7-0552-42d3-b3c6-fe26096f6cf5 | < 1.26.3 |
HIGH | 7.2 | The Import and export users and customers plugin for WordPress is vulnerable to PHP Object Injection in all versions up … | — | wordfence |
| f5524582-5aac-48b4-ad67-7c4829d63ed0 | < 2.4.3 |
HIGH | 7.2 | The Video Gallery β Best WordPress YouTube Gallery Plugin plugin for WordPress is vulnerable to time-based SQL Injecti… | — | wordfence |
| f54527ce-8137-4ba9-b4e6-52cea6cfe2da | HIGH | 7.2 | A SQL injection issue is exploitable, with WordPress admin access, in the Mail Masta (aka mail-masta) plugin 1.0 for Wor… | — | wordfence | |
| f509f1c6-6094-434d-8e70-ad8419250aa2 | < 7.6.57 |
HIGH | 7.2 | The Comments β wpDiscuz plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the guest commenter 'Web… | — | wordfence |
| f4e3b796-af9a-4403-8d9a-1b56d7253b45 | HIGH | 7.2 | The Omnichannel for WooCommerce: Google, Amazon, eBay & Walmart Integration β Powered by Codisto plugin for WordPress … | — | wordfence | |
| f4e25aa6-8028-4c85-98c4-6f47a1502427 | < 1.4.113 |
HIGH | 7.2 | The Motors β Car Dealership & Classified Listings Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scrip… | — | wordfence |
| f4daf910-1768-4cfd-af92-66a2ee7f52a5 | HIGH | 7.2 | The Ultimate Auction Pro plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and includ… | — | wordfence | |
| f4d421df-310b-4a83-b521-c0d00045df52 | < 2.1.5 |
HIGH | 7.2 | The W3 Total Cache WordPress plugin before 2.1.5 was affected by a reflected Cross-Site Scripting (XSS) issue within the… | — | wordfence |
| f4c3f9c5-5086-416b-a601-2890f52547c0 | < 1.70 |
HIGH | 7.2 | The Advanced Woo Search plugin for WordPress is vulnerable to Cross-Site Scripting in versions up to, and including, 1.6… | — | wordfence |
| f49e48cb-7d0b-4bcf-9090-869472b8442a | < 3.5.20 |
HIGH | 7.2 | The Ultra Addons for Contact Form 7 plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Database m… | — | wordfence |
| f45b4c43-c6c4-41da-bd59-9a355800815a | < 2.1.4 |
HIGH | 7.2 | The Import XML and RSS Feeds plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type valid… | — | wordfence |
| f444568c-fe4c-4fa6-9b83-2d069f851360 | < 6.0.0 |
HIGH | 7.2 | The Advanced Page Visit Counter WordPress plugin through 5.0.8 does not sanitise and escape some input before outputting… | — | wordfence |
| f436ab65-a59c-4b2a-abc8-a7fc038678dd | < 1.6.22 |
HIGH | 7.2 | The weForms plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'Referer' HTTP header in all versi… | — | wordfence |
| f432f32c-9ebb-4444-baf0-d523b1ceba02 | < 15.0.7 |
HIGH | 7.2 | The Simple Link Directory Pro plugin for WordPress is vulnerable to Server-Side Request Forgery in versions up to, and i… | — | wordfence |
| f4213452-33f7-46d4-ab4a-544a9bef475a | < 1.4.30 |
HIGH | 7.2 | The WPZOOM Portfolio Lite β Filterable Portfolio Plugin plugin for WordPress is vulnerable to Stored Cross-Site Script… | — | wordfence |
| f419eceb-a3e7-4cf7-a37e-dcc57a26d7f5 | < 2.35.1 |
HIGH | 7.2 | The AffiliateWP plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.35… | — | wordfence |
| f40dde67-b6af-4a57-a067-09adcbb981ac | HIGH | 7.2 | The REAL WordPress Sidebar plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and … | — | wordfence |
EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.
Scan My Website →