Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.
39,836 vulnerabilities found (page 386 of 1594)
| CVE ID | Plugin / Theme | Severity | CVSS | Description | Fixed In | Source |
|---|---|---|---|---|---|---|
| 5e911b0a-a236-4df3-b997-3631412a1b55 | < 6.1.18 |
HIGH | 7.2 | The Fluent Forms Pro plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `fluentform_step_form_sav… | — | wordfence |
| 5e83b0ff-3628-47d7-92d0-429af92067bd | < 4.23.90 |
HIGH | 7.2 | The Anti-Malware Security and Brute-Force Firewall plugin for WordPress is vulnerable to Stored Cross-Site Scripting in … | — | wordfence |
| 5e6218e5-84d9-4180-8275-7da24c554c72 | < 3.3.0 |
HIGH | 7.2 | The Unify plugin for WordPress is vulnerable to Cross-Site Scripting via several parameters in versions up to and includ… | — | wordfence |
| 5e49afbd-9038-4d1d-b545-4dc86bb1be61 | < 1.1.1 |
HIGH | 7.2 | The Video Metabox plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘video_url’ parameter in… | — | wordfence |
| 5e493f01-95db-48ba-8daf-d7ff69df29bf | < 2.2.1 |
HIGH | 7.2 | The SureForms plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the form field parameters in all ver… | — | wordfence |
| 5e441699-4c78-4277-8ac1-f33b810e78cb | < 7.34 |
HIGH | 7.2 | The WP Import – Ultimate CSV XML Importer for WordPress plugin for WordPress is vulnerable to PHP Object Injection in … | — | wordfence |
| 5e3bcd70-d19c-4c0f-80d0-a69e2ab947d2 | < 13.1.6 |
HIGH | 7.2 | The WP Statistics WordPress plugin is vulnerable to Cross-Site Scripting due to insufficient escaping and sanitization o… | — | wordfence |
| 5de24a9e-0af3-44d7-af0b-06689a3e3bc5 | < 2.5.4 |
HIGH | 7.2 | The Booking and Rental Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and … | — | wordfence |
| 5db3fd96-28c5-431e-9e0d-2aaa57d9dce3 | < 1.5.2 |
HIGH | 7.2 | The HTML Forms – Simple WordPress Forms Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting in al… | — | wordfence |
| 5d479a7a-52a6-48bd-8216-935e22ddb3ed | < 3.15.1 |
HIGH | 7.2 | The Profile Builder Pro plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and includi… | — | wordfence |
| 5d350095-125a-4445-89c1-bce437e4098c | < 7.3.12 |
HIGH | 7.2 | The Mollie Payments for WooCommerce plugin for WordPress is vulnerable to arbitrary file uploads due to missing file typ… | — | wordfence |
| 5d2e0fc0-072b-4640-b538-61356fefa0d8 | HIGH | 7.2 | The Ultimate Auction Pro plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and includ… | — | wordfence | |
| 5d281333-d9af-4eb7-bc5c-ea7ceeddac03 | < 3.6.8 |
HIGH | 7.2 | The plugin WP All Import is vulnerable to arbitrary file uploads due to missing file type validation via the wp_all_impo… | — | wordfence |
| 5d266060-2491-4b0f-8961-955ed6ee2451 | < 1.5.3.6 |
HIGH | 7.2 | The Landing Page Builder – Coming Soon page, Maintenance Mode, Lead Page, WordPress Landing Pages plugin for WordPress… | — | wordfence |
| 5d1fa835-1888-4758-97bf-f582e8ff3a04 | HIGH | 7.2 | The Zarinpal Paid Download plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validat… | — | wordfence | |
| 5cbf597e-7a2f-416c-8969-3679b487f57a | < 6.2.1 |
HIGH | 7.2 | The WooCommerce plugin for WordPress is vulnerable to path traversal via the 'file_url' parameter found in the importers… | — | wordfence |
| 5cba9501-2eb1-4702-889c-d0f4777e72e9 | < 6.9.8 |
HIGH | 7.2 | The Super Store Finder plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and incl… | — | wordfence |
| 5c8aa2c9-d925-460c-ad91-6fd417be3fb1 | < 1.0.62 |
HIGH | 7.2 | The Captcha.eu plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 1… | — | wordfence |
| 5c6ac166-d8ad-4ee0-b637-91816cb41eca | < 2.3.6 |
HIGH | 7.2 | The Foxiz theme for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 2.3.5. … | — | wordfence |
| 5bfedb93-76e6-4d3f-bf44-1e6d8947c7d1 | < 4.5 |
HIGH | 7.2 | The WpJobBoard plugin 4.4.4 for WordPress allows SQL injection via the order or sort parameter to the wpjb-job or wpjb-a… | — | wordfence |
| 5bf0267d-b84f-4ad2-8bb3-cc2aa4996af1 | < 1.0.7 |
HIGH | 7.2 | The PostmagThemes Demo Import plugin for WordPress is vulnerable to arbitrary file uploads in versions up to, and includ… | — | wordfence |
| 5bd6d250-b1c2-4c14-906d-6507ce39520f | < 2.3.3 |
HIGH | 7.2 | The Social Slider Feed plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and includin… | — | wordfence |
| 5bc531a3-e246-4f2e-8657-bbdfb91dbf39 | < 8.28.0 |
HIGH | 7.2 | The Smart Manager – WooCommerce Bulk Edit Products, Orders, Coupons, Any WordPress Post Type (Advanced) plugin for Wor… | — | wordfence |
| 5ba48e88-6e32-428f-9592-bd955e176765 | HIGH | 7.2 | A SQL injection issue is exploitable, with WordPress admin access, in the Mail Masta (aka mail-masta) plugin 1.0 for Wor… | — | wordfence | |
| 5ba22ed2-4cc2-4e1e-a475-a697a8bb697d | < 2.2.1 |
HIGH | 7.2 | The Side Menu Lite – add sticky fixed buttons WordPress plugin before 2.2.1 does not properly sanitize input values fr… | — | wordfence |
EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.
Scan My Website →