Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.
39,836 vulnerabilities found (page 397 of 1594)
| CVE ID | Plugin / Theme | Severity | CVSS | Description | Fixed In | Source |
|---|---|---|---|---|---|---|
| 366b5051-d042-4425-9aad-b77d93bcd485 | < 32.8.0 |
HIGH | 7.2 | The SUMO Reward Points plugin for WordPress is vulnerable to Unauthenticated Stored Cross-Site Scripting via the REST AP… | — | wordfence |
| 365b90dc-b9a1-4e04-9546-860f057f29f8 | HIGH | 7.2 | The Woocommerce – Recent Purchases plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, a… | — | wordfence | |
| 36304098-fea7-4e67-a138-5670761c6338 | < 2.17.1 |
HIGH | 7.2 | The Age Gate plugin for WordPress is vulnerable to Stored Cross-Site Scripting via data imports in versions up to, and i… | — | wordfence |
| 3604b314-6b85-4d11-aa71-63f9198dbbdb | < 1.6.4.0 |
HIGH | 7.2 | The Message Filter for Contact Form 7 plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up t… | — | wordfence |
| 35db7137-aba0-4299-ad8a-c650d6db5199 | < 6.0.12 |
HIGH | 7.2 | The Kirki – Freeform Page Builder, Website Builder & Customizer plugin for WordPress is vulnerable to Stored Cross-Sit… | — | wordfence |
| 35d8e0d9-08d5-4e39-a235-06e624f2e764 | < 3.2.0 |
HIGH | 7.2 | The Bit Form plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 3.1.0 d… | — | wordfence |
| 35ac717c-e299-4a56-bead-cb1d050da75c | < 1.5.1.3 |
HIGH | 7.2 | Multiple cross-site scripting (XSS) vulnerabilities in post.php in WordPress 1.5.1.2 and earlier allow remote attackers … | — | wordfence |
| 35ac7049-6453-4235-82bd-d2bc6ffccabe | < 4.6.4 |
HIGH | 7.2 | The Product Table and List Builder for WooCommerce Lite plugin for WordPress is vulnerable to Stored Cross-Site Scriptin… | — | wordfence |
| 353804e8-0d5a-4633-974c-6eb7a3eeba61 | < 1.4.3 |
HIGH | 7.2 | The WP Super Cache plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `$details[ ‘key’ ]` va… | — | wordfence |
| 352cd9e6-ef1e-4a6b-bedb-6cf8ce9d4270 | < 2.7.3 |
HIGH | 7.2 | The Paytm Payment Gateway plugin for WordPress is vulnerable to Server-Side Request Forgery in versions up to, and inclu… | — | wordfence |
| 34fd5045-cd38-4eab-9e97-98f1e3d7423a | < 3.3.5 |
HIGH | 7.2 | The Wise Chat plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the X-Forwarded-For header in all ve… | — | wordfence |
| 34d6ad4a-f27c-4775-a26d-adf2d4755862 | < 3.1.58 |
HIGH | 7.2 | The Ditty – Responsive News Tickers, Sliders, and Lists plugin for WordPress is vulnerable to Server-Side Request Forg… | — | wordfence |
| 3486dc6f-d40a-426a-9d46-ded10789ec62 | HIGH | 7.2 | The ListingHub plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to 1.2.6 due to insuffic… | — | wordfence | |
| 346a49ff-4e61-466b-b1fe-98cf5766accb | < 2.2.8 |
HIGH | 7.2 | The WordPress Calls to Action plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘shortcode’ … | — | wordfence |
| 34526c98-caf8-42d9-8782-7ea9b3a75e9d | < 2.6.8 |
HIGH | 7.2 | The Watu Quiz plugin for WordPress is vulnerable to SQL Injection via the 'quiz' parameter in versions up to, and includ… | — | wordfence |
| 33f17152-f273-46d0-ad37-55953adee919 | < 2.3.2 |
HIGH | 7.2 | The Greek Multi Tool – Fix peralinks, accents, auto create menus and more plugin for WordPress is vulnerable to Stored… | — | wordfence |
| 33c16b47-3202-4f26-bf45-98172b8cac45 | < 1.9.1 |
HIGH | 7.2 | The Custom Product Tabs Lite for WooCommerce plugin for WordPress is vulnerable to PHP Object Injection in all versions … | — | wordfence |
| 33c0838a-5f86-4368-8bf9-da0582acbabf | < 4.10 |
HIGH | 7.2 | The Newsletters plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 4.9.9.9… | — | wordfence |
| 33727746-4481-4b7f-8d2a-100027b7d1c3 | < 1.8.12 |
HIGH | 7.2 | The Blog Designer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'custom_css' parameter in ve… | — | wordfence |
| 3352b264-eae8-4ce3-86ee-5febcd2e7fcc | < 2.3.7 |
HIGH | 7.2 | The Membee Login plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.3… | — | wordfence |
| 332909d5-e3bf-42a7-af52-c4e50b05f97e | < 4.24.8 |
HIGH | 7.2 | The WordPress File Upload plugin for WordPress is vulnerable to Stored Cross-Site Scripting via custom text fileds in al… | — | wordfence |
| 3320fe6a-dafc-4640-8d8b-7f62fc6e7753 | < 4.2.8 |
HIGH | 7.2 | The Optimole – Optimize Images | Convert WebP & AVIF | CDN & Lazy Load | Image Optimization plugin for WordPress is vu… | — | wordfence |
| 32fa4d64-0cdd-4c47-aaf7-816824b27175 | < 1.2.12 |
HIGH | 7.2 | The Favicon Rotator plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, … | — | wordfence |
| 32f47b68-e1ae-4ed1-9513-bba60aab65fb | < 1.3.7 |
HIGH | 7.2 | The WP CSV Exporter plugin for WordPress is vulnerable to generic SQL Injection via the $query_select value in versions … | — | wordfence |
| 32ccbde2-b6a9-4748-907d-b948937dad09 | HIGH | 7.2 | The Piotnet Addons For Elementor Pro plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions u… | — | wordfence |
EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.
Scan My Website →