Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.
39,652 vulnerabilities found (page 348 of 1587)
| CVE ID | Plugin / Theme | Severity | CVSS | Description | Fixed In | Source |
|---|---|---|---|---|---|---|
| e11662b0-5f67-4c27-abdb-522204acb35e | < 2.88.3 |
HIGH | 7.2 | The WP-UserOnline plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'X-Forwarded-For' header in … | — | wordfence |
| e10e3382-8bb9-4bb3-b881-0aaabd2412a0 | HIGH | 7.2 | The Mobile App Editor β WordPress to Android App Builder plugin for WordPress is vulnerable to arbitrary file uploads … | — | wordfence | |
| e10c0d8d-718d-45dd-9ac3-a2673a6a16af | HIGH | 7.2 | The Super Simple Contact Form plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'sscf_name' p… | — | wordfence | |
| e0d9b77d-d7b6-48cd-9db9-ba62bd97c7b3 | < 4.2.1 |
HIGH | 7.2 | The TemplateSpare β 1000+ WordPress Starter Templates & Full Site Migration Tool | 1-Click Import/Export & No-Code Bui… | — | wordfence |
| e0d6ef49-288b-47d9-bbf2-dc31a6e3621e | < 1.6.3 |
HIGH | 7.2 | Cross-site scripting (XSS) vulnerability in open-flash-chart.swf in Open Flash Chart (aka Open-Flash Chart), as used in … | — | wordfence |
| e0cf5711-a02b-4db7-9bf7-47d512680428 | < 1.2 |
HIGH | 7.2 | The safe-editor plugin before 1.2 for WordPress has no se_save authentication, with resultant XSS. | — | wordfence |
| e08c3db4-6353-4bca-ab89-af46e5a0a128 | < 3.1.6 |
HIGH | 7.2 | The Similar Posts WordPress plugin through 3.1.5 allow high privilege users to execute arbitrary PHP code in an hardened… | — | wordfence |
| e05d4320-01d0-40c4-9a9a-457171ef7f5c | < 1.23.0 |
HIGH | 7.2 | The Popup Maker β Boost Sales, Conversions, Optins, Subscribers with the Ultimate WP Popup Builder plugin for WordPres… | — | wordfence |
| e02e8d8d-5b20-420d-b213-eeb0ef8d20b7 | < 5.1.8.9 |
HIGH | 7.2 | The Survey Maker plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 5.1… | — | wordfence |
| dfe07cd7-e448-4468-8280-3514690d8648 | HIGH | 7.2 | The Post Content XMLRPC WordPress plugin through 1.0 does not sanitise or escape multiple GET/POST parameters before usi… | — | wordfence | |
| dfcc3d8c-c36a-4994-aa79-99953d9adfc1 | < 6.5.6 |
HIGH | 7.2 | The Google Analyticator plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 6.5… | — | wordfence |
| dfb2dda8-1389-4b19-a5cd-d6b3436ab3b6 | < 1.3 |
HIGH | 7.2 | Multiple cross-site scripting (XSS) vulnerabilities in roomcloud.php in the Roomcloud plugin before 1.3 for WordPress al… | — | wordfence |
| df97321f-4cd6-44c8-9017-7824c9ba150b | < 3.1.8 |
HIGH | 7.2 | The FluentCRM β Email Newsletter, Automation, Email Marketing, Email Campaigns, Optins, Leads, and CRM Solution plugin… | — | wordfence |
| df657cdc-00fc-476a-a64f-abfdd6b30739 | < 2.7 |
HIGH | 7.2 | The wp-cerber plugin before 2.7 for WordPress has XSS via the X-Forwarded-For HTTP header when "I'm behind a proxy" opti… | — | wordfence |
| df406e59-94d9-4704-82a3-02c2c1773c82 | < 2.1.8 |
HIGH | 7.2 | The Checkout Field Editor (Checkout Manager) for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scr… | — | wordfence |
| dee712ce-d49c-4706-964a-b8885cb6546e | < 2.0.85 |
HIGH | 7.2 | The Radio Player β Live Shoutcast, Icecast and Any Audio Stream Player for WordPress plugin for WordPress is vulnerabl… | — | wordfence |
| ded73f27-6b3a-435a-861f-5e10938d6d1a | < 2.2.5 |
HIGH | 7.2 | The Appointment Bookings for Zoom GoogleMeet and more β Wappointment plugin for WordPress is vulnerable to Stored Cros… | — | wordfence |
| dececd27-d311-41c0-a10c-3b9cc8b8f128 | < 3.6.13 |
HIGH | 7.2 | The Ninja Forms Contact Form β The Drag and Drop Form Builder for WordPress plugin for WordPress is vulnerable to PHP … | — | wordfence |
| de8ac20f-d6ae-4e55-9337-4fb5ebd4f24a | HIGH | 7.2 | The WP Church Donation plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several donation form submi… | — | wordfence | |
| de0c8922-b290-4582-9079-e79da684bcff | < 3.3.2 |
HIGH | 7.2 | The Use-your-Drive | Google Drive plugin for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting… | — | wordfence |
| de09c677-6399-4af3-a378-8dd16dcd2819 | < 7.6.1 |
HIGH | 7.2 | The Jannah theme for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 7.6.0 due … | — | wordfence |
| dd9f10c6-911e-41d2-b1fe-e0cce9c48b48 | < 1.10.2 |
HIGH | 7.2 | The SureDash β Community, Courses & Member Dashboard plugin for WordPress is vulnerable to Stored Cross-Site Scripting… | — | wordfence |
| dd7312ec-9654-4ddc-aec6-71c7e684fac0 | < 0.9.6 |
HIGH | 7.2 | The Customizer Export/Import for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 0.9.5… | — | wordfence |
| dd4f0925-e3bf-4014-af05-b0d193b06493 | < 10.1.03 |
HIGH | 7.2 | The WP Google Maps Pro plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and includin… | — | wordfence |
| dd3fc3a4-ba32-4c05-bc93-ed7b86c426fa | < 1.8.4 |
HIGH | 7.2 | The Contact Form 7 extension for Google Map fields plugin for WordPress is vulnerable to Stored Cross-Site Scripting via… | — | wordfence |
EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.
Scan My Website →