Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.
39,836 vulnerabilities found (page 365 of 1594)
| CVE ID | Plugin / Theme | Severity | CVSS | Description | Fixed In | Source |
|---|---|---|---|---|---|---|
| adbc23b3-fa9d-4303-8283-1cabb2a6bb71 | < 1.3.9 |
HIGH | 7.2 | The Database for Contact Form 7, WPforms, Elementor forms plugin for WordPress is vulnerable to Stored Cross-Site Script… | — | wordfence |
| adb87ef2-8741-4144-b414-56e82dd35c89 | < 6.03.01 |
HIGH | 7.2 | The Event Registration plugin for WordPress is vulnerable to Stored Cross-Site Scripting via attendees first and last na… | — | wordfence |
| adab6dd8-3054-42ca-99ae-1fc65108f823 | < 1.3.51 |
HIGH | 7.2 | The Web-Dorado "Photo Gallery by WD - Responsive Photo Gallery" plugin before 1.3.51 for WordPress has a SQL injection v… | — | wordfence |
| ad85b322-204a-4d74-8dde-38571fb68dd0 | < 1.3 |
HIGH | 7.2 | The view submission functionality in the Hotscot Contact Form WordPress plugin before 1.3 makes a get request with the s… | — | wordfence |
| ad6747da-394a-4f63-864d-bd52813fad69 | HIGH | 7.2 | The M-vSlider plugin for WordPress is vulnerable to blind SQL Injection via the βrs_id POSTβ parameter in versions u… | — | wordfence | |
| ad48145b-24c5-49ac-a192-08c496e08e00 | < 2.6.1 |
HIGH | 7.2 | The Responsive Lightbox & Gallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to 2.… | — | wordfence |
| ad34d657-da59-46ff-a54a-64e6c8974b69 | < 3.7 |
HIGH | 7.2 | The DoLogin Security plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'X-Forwarded-For' header … | — | wordfence |
| ad20ddd2-33d0-4d49-bca0-ea2a829da6c8 | HIGH | 7.2 | The Radio Forge Muses Player with Skins plugin for WordPress is vulnerable to Cross-Site Scripting via an unknown parame… | — | wordfence | |
| ad159b18-0ad1-4cab-932e-6850cf7a867f | < 0.9.1 |
HIGH | 7.2 | The Link Whisper Free plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the user_id parameter in all… | — | wordfence |
| ac9d2b64-aff6-418a-bfe7-ec91b177ad6b | < 1.7.9 |
HIGH | 7.2 | The S2B AI Assistant β ChatBot, ChatGPT, OpenAI, Content & Image Generator plugin for WordPress is vulnerable to arbit… | — | wordfence |
| ac6f7b03-6527-4d10-9320-4f94ed386f54 | < 2.7.0 |
HIGH | 7.2 | The Responsive Slider β Image Slider β Slideshow for WordPress plugin for WordPress is vulnerable to multiple SQL In… | — | wordfence |
| ac0455a2-1fa8-4a37-a72f-9ed5cca1d9ee | < 1.0.23 |
HIGH | 7.2 | The Lucky Wheel Giveaway plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and includin… | — | wordfence |
| abc8ee11-c149-4a2b-a388-7bd234c2cc64 | < 1.1.1 |
HIGH | 7.2 | The Drag and Drop Multiple File Upload for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting… | — | wordfence |
| abc056b0-55a2-439c-b7f6-4a2fc48c9823 | < 1.0.10 |
HIGH | 7.2 | The User Feedback β Create Interactive Feedback Form, User Surveys, and Polls in Seconds plugin for WordPress is vulne… | — | wordfence |
| abac57e7-2256-4592-a85d-89b71c444fe2 | < 8.8.6 |
HIGH | 7.2 | The Admin and Site Enhancements (ASE) Pro plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions … | — | wordfence |
| aaf0e58c-0430-44fe-980f-8ea469802c86 | < 10.6.6 |
HIGH | 7.2 | The RSVPMaker plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'email' parameter in versions u… | — | wordfence |
| aade1230-bc25-4391-a85b-7bcf661f8213 | HIGH | 7.2 | A SQL injection issue was discovered in the Mail Masta (aka mail-masta) plugin 1.0 for WordPress. This affects /inc/camp… | — | wordfence | |
| aaa2f738-4764-467c-9544-889ca8ba73d1 | < 2.1.8 |
HIGH | 7.2 | The DELUCKS SEO plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the saveSettings() function that h… | — | wordfence |
| aa8daa65-dc64-4cbf-9b49-2db08b64b02e | < 3.5.17 |
HIGH | 7.2 | The Modal Dialog plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 3.5.1… | — | wordfence |
| aa8c5c44-235a-4839-9dc4-064ef25abfac | < 1.1.2 |
HIGH | 7.2 | The CubeWP Forms β All-in-One Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all ve… | — | wordfence |
| aa4e18b0-f871-4476-af92-42e55aabdf93 | < 3.7.4 |
HIGH | 7.2 | The Prismatic plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'prismatic_encoded' pseudo-short… | — | wordfence |
| aa1bac80-4927-4fee-942c-c23d51b18abd | < 4.5.0 |
HIGH | 7.2 | The GetGenie plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 4.4.3 d… | — | wordfence |
| a9f6ab26-f4e4-4774-8663-d003efe27762 | HIGH | 7.2 | The PeproDev Ultimate Invoice plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and i… | — | wordfence | |
| a9d11f3a-eb28-4a80-8970-8ad05284a5b4 | < 1.9.1 |
HIGH | 7.2 | The Easy PayPal & Stripe Buy Now Button plugin for WordPress is vulnerable to Open Redirect in all versions up to, and i… | — | wordfence |
| a9cc5c6d-4396-4ebf-8788-f01dd9e9cfbc | < 7.13.0 |
HIGH | 7.2 | The Abandoned Cart Lite for WooCommerce and Abandoned Cart Pro for WooCommerce plugins for WordPress are vulnerable to S… | — | wordfence |
EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.
Scan My Website →