Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.
39,836 vulnerabilities found (page 396 of 1594)
| CVE ID | Plugin / Theme | Severity | CVSS | Description | Fixed In | Source |
|---|---|---|---|---|---|---|
| 39487908-5cc5-42ac-8af4-65626694b1e4 | < 1.2.5 |
HIGH | 7.2 | The Contact Form to Any API plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Contact Form 7 form fi… | — | wordfence |
| 3940232c-b3d4-488b-830d-797bdab9cfbe | HIGH | 7.2 | The WP RSS By Publishers plugin for WordPress is vulnerable to generic SQL Injection via an unspecified parameter in ver… | — | wordfence | |
| 39075385-f8b8-4f40-9ec1-8f9f8d2bee0c | < 1.6.01 |
HIGH | 7.2 | The Royal Elementor Addons plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to 1.7.1041 … | — | wordfence |
| 38e40a74-c4b7-4960-880d-a14e77fe1904 | < 1.1.7 |
HIGH | 7.2 | The Contact Form Entries WordPress plugin before 1.1.7 does not validate, sanitise and escape the IP address retrieved v… | — | wordfence |
| 38da66f4-2db8-4e8e-819f-d7dd9533e045 | < 2.13.11 |
HIGH | 7.2 | The Contact Form by Bit Form: Multi Step Form, Calculation Contact Form, Payment Contact Form & Custom Contact Form buil… | — | wordfence |
| 38ce5790-f6b8-43a0-a1a3-290a86eb49cb | < 5.4.3 |
HIGH | 7.2 | The Classified Listing β AI-Powered Classified ads & Business Directory plugin for WordPress is vulnerable to Stored C… | — | wordfence |
| 38a1fb65-b0f6-4d3a-9b07-c40f80de4685 | < 2.2.5 |
HIGH | 7.2 | The Wholesale Suite β B2B, Dynamic Pricing & Wholesale Prices for WooCommerce plugin for WordPress is vulnerable to Pr… | — | wordfence |
| 3892579a-d7fd-4f11-88fd-7452fa312000 | < 1.3.1 |
HIGH | 7.2 | The Best WordPress Shortcode Plugin in 2025 β AIO Shortcodes plugin for WordPress is vulnerable to Stored Cross-Site S… | — | wordfence |
| 3825c80c-e4b1-4dd8-be77-38f718920b9a | < 4.9.9.8 |
HIGH | 7.2 | The Newsletters plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the logging functionality in all v… | — | wordfence |
| 38227a1c-30a7-436c-853f-7205e421bd19 | < 2.8.18 |
HIGH | 7.2 | The WPeMatico RSS Feed Fetcher plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and … | — | wordfence |
| 381708ae-3180-4058-a6f4-e925bfc658ec | HIGH | 7.2 | WordPress Plugin mb.miniAudioPlayer-an HTML5 audio player for your mp3 files is prone to multiple vulnerabilities, inclu… | — | wordfence | |
| 3816a6cf-8157-4ad9-83f6-93c9b6c6275f | < 2.6.1 |
HIGH | 7.2 | The Post SMTP plugin for WordPress is vulnerable to time-based SQL Injection via the log_id parameter in versions up to,… | — | wordfence |
| 37dc80d0-1834-40a7-9454-a8129d9b4cdd | < 18.1 |
HIGH | 7.2 | The WP Google Review Slider plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and inc… | — | wordfence |
| 37bfb60d-8e2d-4c77-880c-3d17a6a434b8 | < 2.6.0 |
HIGH | 7.2 | The WooCommerce Google Feed Manager plugin for WordPress is vulnerable to SQL Injection via the 'id' parameter in all ve… | — | wordfence |
| 37820930-4705-41af-9a9d-c99409d7bbe3 | < 1.3.6 |
HIGH | 7.2 | The Beaver Builder Addons by WPZOOM plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, an… | — | wordfence |
| 37734c25-cce3-41fb-babf-714ba7a4bced | < 2.2.9 |
HIGH | 7.2 | The Download Plugin plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in … | — | wordfence |
| 37725a72-0478-4f56-b87f-e427b1f5fb58 | < 1.3.3 |
HIGH | 7.2 | The Ninja Job Board β Ultimate WordPress Job Board Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scri… | — | wordfence |
| 37471ecc-ee8f-4246-a126-b7b7013b5ceb | < 2.56.1 |
HIGH | 7.2 | The WP-Stats plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 2.5… | — | wordfence |
| 3745b681-cb09-4a5b-a57b-c7f35b8c5133 | HIGH | 7.2 | The WP RSS By Publishers plugin for WordPress is vulnerable to generic SQL Injection via an unspecified parameter in ver… | — | wordfence | |
| 37441cc0-c43c-40e4-a170-1be59e112272 | < 2.0.05 |
HIGH | 7.2 | The Fluent Booking plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multiple parameters in all vers… | — | wordfence |
| 37198f2f-2b45-40d3-b4ae-aa94213996bd | HIGH | 7.2 | The Link Fixer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via broken links in all versions up to,… | — | wordfence | |
| 3718c252-2ca3-4f7d-b43a-3c1b2e6b34c0 | HIGH | 7.2 | The Tripetto plugin for WordPress is vulnerable to Stored Cross-Site Scripting via File uploads in all versions up to, a… | — | wordfence | |
| 36c32212-0d52-435e-bb6a-39ea07363a86 | < 4.4.4 |
HIGH | 7.2 | The get_gallery_categories() and get_galleries() functions in the Photo Gallery by Ays β Responsive Image Gallery Word… | — | wordfence |
| 36777e39-be45-41f2-beca-2971e15b77cd | < 10.44 |
HIGH | 7.2 | The Subscribe2 β Form, Email Subscribers & Newsletters plugin for WordPress is vulnerable to Stored Cross-Site Scripti… | — | wordfence |
| 366dfbf1-870c-4ce3-abc4-a2b2f4e72175 | < 3.1.0 |
HIGH | 7.2 | The Post SMTP plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the from and subject parameter in al… | — | wordfence |
EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.
Scan My Website →