Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.
39,836 vulnerabilities found (page 394 of 1594)
| CVE ID | Plugin / Theme | Severity | CVSS | Description | Fixed In | Source |
|---|---|---|---|---|---|---|
| 3fffdda5-91ed-4b79-bc04-77a1c44e3b67 | < 0.32.7 |
HIGH | 7.2 | The Rent Fetch plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'keyword' parameter in all vers… | — | wordfence |
| 3fdc6a04-ef39-498a-b739-f40d5d8af47e | < 1.2.5 |
HIGH | 7.2 | The Custom Product Tabs For WooCommerce plugin for WordPress is vulnerable to PHP Object Injection in all versions up to… | — | wordfence |
| 3fbfb185-d901-4789-9a13-137f72234ed4 | HIGH | 7.2 | The Online Booking & Scheduling Calendar for WordPress by vcita plugin for WordPress is vulnerable to Stored Cross-Site … | — | wordfence | |
| 3f8cbbbb-2089-4966-8fd3-da4f76fb2517 | < 3.9.0 |
HIGH | 7.2 | The Post SMTP β Complete Email Deliverability and SMTP Solution with Email Logs, Alerts, Backup SMTP & Mobile App plug… | — | wordfence |
| 3f7a5e27-af7e-4e32-be9b-08e1133bb323 | < 2.5.4 |
HIGH | 7.2 | The Export and Import Users and Customers plugin for WordPress is vulnerable to PHP Object Injection in all versions up … | — | wordfence |
| 3f6291ab-99d1-41e2-9928-f31beee0df8b | HIGH | 7.2 | The Wise Forms plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 1… | — | wordfence | |
| 3f1b63a2-31c7-4c76-8969-fee3f7138cfe | < 1.0.5 |
HIGH | 7.2 | The Spreadr Woocommerce Plugin β Amazon Importer for Dropshipping and Affiliate plugin for WordPress is vulnerable to … | — | wordfence |
| 3f0866a4-0edf-4fb7-8628-4b8e18a2b4bb | HIGH | 7.2 | The Simple Fields plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the maybe_do_import() function i… | — | wordfence | |
| 3f04a742-56be-42e9-9080-2131c6e98325 | < 1.0.2 |
HIGH | 7.2 | The Travel Map plugin for WordPress is vulnerable to Cross-Site Scripting in versions up to, and including, 1.0.1 due to… | — | wordfence |
| 3eedc57b-79cc-4569-b6d6-676a22aa1e06 | < 4.1.5 |
HIGH | 7.2 | The Active Directory Integration plugin for WordPress is vulnerable to time-based SQL Injection via the orderby and orde… | — | wordfence |
| 3eec5823-f1ee-464c-8344-eed3ee991602 | < 1.1 |
HIGH | 7.2 | Cross-site scripting (XSS) vulnerability in the skeltoac stats (Automattic Stats) 1.0 plugin for WordPress allows remote… | — | wordfence |
| 3ebdb591-4fd4-4ea3-a0db-b934c67176de | < 2.2.12 |
HIGH | 7.2 | The RapidLoad 2.2 β Speed Monster in One Plugin plugin for WordPress is vulnerable to Server-Side Request Forgery in a… | — | wordfence |
| 3ebac8bc-1dca-4bcd-a033-fb8ed210bf4e | < 1.33.0 |
HIGH | 7.2 | The Name Directory plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'name_directory_name' param… | — | wordfence |
| 3e8a881d-d6d0-4bcc-9894-286ce0468393 | < 1.6.9 |
HIGH | 7.2 | SQL Injection exists in the Tribulant Slideshow Gallery plugin 1.6.8 for WordPress via the wp-admin/admin.php?page=slide… | — | wordfence |
| 3e747b4b-3865-4e31-b584-e11e35d4c3c4 | HIGH | 7.2 | The ThemeEgg ToolKit plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in… | — | wordfence | |
| 3e63a70c-924b-4736-a712-80538bfd7ca7 | < 0.7 |
HIGH | 7.2 | The supportflow plugin before 0.7 for WordPress has XSS via a discussion ticket title if 'run_wptexturize' is disabled. | — | wordfence |
| 3e62eba7-1ac9-4420-8692-58a169aa4330 | HIGH | 7.2 | The LiquidPoll β Polls, Surveys, NPS and Feedback Reviews plugin for WordPress is vulnerable to Stored Cross-Site Scri… | — | wordfence | |
| 3e619e8e-e04b-4e42-9cee-65e5dedff3b6 | < 1.4.4 |
HIGH | 7.2 | Cross-site scripting (XSS) vulnerability in wpcommentremix.php in WP Comment Remix plugin before 1.4.4 for WordPress all… | — | wordfence |
| 3e292a1f-d475-4c52-b790-b5215e1870ad | < 1.2.2 |
HIGH | 7.2 | The CTHthemes CityBook before 2.3.4, TownHub before 1.0.6, and EasyBook before 1.2.2 themes for WordPress allow Persiste… | — | wordfence |
| 3e1a84c6-e28b-42fe-a16a-aeb227cfe956 | < 5.2.6 |
HIGH | 7.2 | The AutomatorWP β Automator plugin for no-code automations, webhooks & custom integrations in WordPress plugin for Wor… | — | wordfence |
| 3da5ddc2-2004-4abd-87ef-154121e37d57 | < 4.1.08 |
HIGH | 7.2 | The WorkScout theme for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 4.1.07 … | — | wordfence |
| 3da37b4d-3dd7-450f-8169-28141eeb19c7 | HIGH | 7.2 | The Game Server Status WordPress plugin through 1.0 does not validate or escape the server_id parameter before using it … | — | wordfence | |
| 3d9f4fbe-6da6-4620-a071-00b7a462de45 | < 3.7.6 |
HIGH | 7.2 | Multiple cross-site scripting (XSS) vulnerabilities in WordPress before 4.1.2, when MySQL is used without strict mode, a… | — | wordfence |
| 3d76a21c-bb79-4183-99ea-a07c18dfa180 | < 7.3.11 |
HIGH | 7.2 | The Quiz And Survey Master plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and incl… | — | wordfence |
| 3d300517-8939-431d-b33b-e74806e5887c | < 6.5.1 |
HIGH | 7.2 | The LiteSpeed Cache plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'X-LSCACHE-VARY-VALUE' hea… | — | wordfence |
EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.
Scan My Website →