Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.
39,836 vulnerabilities found (page 359 of 1594)
| CVE ID | Plugin / Theme | Severity | CVSS | Description | Fixed In | Source |
|---|---|---|---|---|---|---|
| c0469ece-6f5f-4774-8094-f7f67702a775 | HIGH | 7.2 | The Find And Replace content for WordPress plugin for WordPress is vulnerable to unauthorized Stored Cross-Site Scriptin… | — | wordfence | |
| c03ddcf0-6955-4645-b311-c3833ca61455 | < 5.5.1 |
HIGH | 7.2 | The LatePoint β Calendar Booking Plugin for Appointments and Events plugin for WordPress is vulnerable to Stored Cross… | — | wordfence |
| c033171a-d81f-4cae-830b-8bdc4017b85e | < 4.4.3 |
HIGH | 7.2 | The Online Booking & Scheduling Calendar for WordPress by vcita plugin for WordPress is vulnerable to Stored Cross-Site … | — | wordfence |
| c006b85d-fc05-41e7-93b2-5a09a21bec1a | < 2.68 |
HIGH | 7.2 | The Row Seats Core plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 2.66 via… | — | wordfence |
| bff9e7d2-b9ad-403e-a361-3e95e2c7909f | < 4.9.32 |
HIGH | 7.2 | The ManageWP Worker plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, … | — | wordfence |
| bfcbf652-6cb4-4f3e-9032-ad262e8c8480 | < 3.7.30 |
HIGH | 7.2 | WordPress before 5.2.3 allows XSS in stored comments. | — | wordfence |
| bfcb0b1f-50fb-4cd8-8ca3-4338c0014cc7 | < 19.6.25 |
HIGH | 7.2 | The Poll, Survey & Quiz Maker Plugin by Opinion Stage plugin for WordPress is vulnerable to Stored Cross-Site Scripting … | — | wordfence |
| bf8d34ea-cf05-4b20-9d1c-8cf0c608dfc3 | < 1.5.122 |
HIGH | 7.2 | The Unlimited Elements For Elementor (Free Widgets, Addons, Templates) plugin for WordPress is vulnerable to Remote Code… | — | wordfence |
| bf707d9b-2b96-4d1b-b798-38f7fe958eaf | < 2.0.3 |
HIGH | 7.2 | The WordPress GDPR plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'gdpr_firstname' and 'gdpr_… | — | wordfence |
| bf527307-185b-4808-a3fc-d3ecafbd34e7 | < 3.20 |
HIGH | 7.2 | The Media Library Assistant plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and inclu… | — | wordfence |
| bf4e3fc3-b9f4-4ae5-ad48-2f764879360a | < 3.7.0 |
HIGH | 7.2 | In TimelineJS before version 3.7.0, some user data renders as HTML. An attacker could implement an XSS exploit with mali… | — | wordfence |
| bf26fc68-9fd4-4e4e-b34f-c947d95891f9 | < 0.9.100 |
HIGH | 7.2 | WPvivid Backup & Migration Plugin for WordPress is vulnerable to PHAR Deserialization in all versions up to, and includi… | — | wordfence |
| bef0eeb8-ed6d-46a3-91c5-84bdd88922b4 | < 1.3.1 |
HIGH | 7.2 | The Really Simple CSV Importer plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type val… | — | wordfence |
| beceb218-34bf-4571-a07b-939abc7ead8e | HIGH | 7.2 | The WP Meta SEO plugin for WordPress is vulnerable to Unauthenticated Stored Cross-Site Scripting via the REQUEST_URI se… | — | wordfence | |
| bea1f918-d966-4214-8331-e389e4080ca5 | < 1.9 |
HIGH | 7.2 | The awesome-filterable-portfolio plugin before 1.9 for WordPress has afp_get_new_portfolio_item_page SQL injection via t… | — | wordfence |
| be6afae1-621a-4291-ae2c-793a60268fbf | HIGH | 7.2 | The Time Sheets plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, … | — | wordfence | |
| be31866c-7490-4be2-9a4d-2a3771c6fea1 | < 2.8.9 |
HIGH | 7.2 | Multiple cross-site scripting (XSS) vulnerabilities in the Ninja Forms plugin before 2.8.9 for WordPress allow (1) remot… | — | wordfence |
| be2579e3-8e40-4603-9ec1-38f43dc1aa29 | < 0.9.78.07 |
HIGH | 7.2 | The Connect Contact Form 7 and Mailchimp plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Mailchimp… | — | wordfence |
| be1bc322-1d42-4e33-adff-dbe706bb9f58 | < 2.2.34.44 |
HIGH | 7.2 | The PiWeb Product Enquiry or product catalog for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scr… | — | wordfence |
| be0b26bc-ed97-42d8-985a-edb275dabfd5 | HIGH | 7.2 | The bidorbuy Store Integrator plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and inc… | — | wordfence | |
| bd90e443-bedf-483b-84eb-3a447d79530e | < 3.7.2 |
HIGH | 7.2 | The Scheduled & Automatic Order Status Controller for WooCommerce plugin for WordPress is vulnerable to Open Redirect in… | — | wordfence |
| bd8e86b0-5e06-44e0-a94c-b05581f46e5a | < 8.5 |
HIGH | 7.2 | The Visitor Traffic Real Time Statistics plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'page… | — | wordfence |
| bd2f495e-63fd-49e4-9d6b-320ed007dacb | < 1.4.1 |
HIGH | 7.2 | The plugin Better Search Replace for WordPress is vulnerable to SQL Injection in versions up to, and including, 1.4. Thi… | — | wordfence |
| bd20e40c-cfec-4de6-a8a6-02850185003b | HIGH | 7.2 | The Wow Countdowns WordPress plugin through 3.1.2 does not sanitize user input into the 'did' parameter and uses it in a… | — | wordfence | |
| bcf205a3-be7b-49e7-ba02-3f69632ed65f | < 2.3.4 |
HIGH | 7.2 | The User Activity Log Pro plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the User-Agent header in… | — | wordfence |
EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.
Scan My Website →