Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.
39,836 vulnerabilities found (page 398 of 1594)
| CVE ID | Plugin / Theme | Severity | CVSS | Description | Fixed In | Source |
|---|---|---|---|---|---|---|
| 32c4cb55-855c-42ed-a9ac-90f92e8583e0 | < 9.6.3 |
HIGH | 7.2 | The Salon booking system plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'sms_prefix' paramete… | — | wordfence |
| 32658119-82e7-4302-9af9-728e054374ec | HIGH | 7.2 | The Mollie for Contact Form 7 plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 5.0.… | — | wordfence | |
| 322e0a27-9119-4b46-a043-d3a68c4fcdc4 | < 1.1.7 |
HIGH | 7.2 | The Frontis Blocks plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and includin… | — | wordfence |
| 32179cca-2253-49c7-89f7-aa48bcfad716 | HIGH | 7.2 | The ExportFeed WordPress plugin through 2.0.1.0 does not sanitise and escape the product_id POST parameter before using … | — | wordfence | |
| 31f000d6-10ab-4dee-97fb-83d1d00595bb | HIGH | 7.2 | The SpaLab | Beauty Salon WordPress theme for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, … | — | wordfence | |
| 31c080b8-ba00-4e96-8961-2a1c3a017004 | < 1.8.5.4 |
HIGH | 7.2 | The WPForms Pro plugin for WordPress is vulnerable to Stored Cross-Site Scripting via form submission parameters in all … | — | wordfence |
| 31a04983-a1d9-49b3-9f1f-06fb3480531b | HIGH | 7.2 | The brickscore plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 1… | — | wordfence | |
| 3150bdc4-fe5d-47ca-bb52-338853e3e23d | < 3.29.9 |
HIGH | 7.2 | The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, an… | — | wordfence |
| 313af4a0-f32b-443f-a976-e06499d3c94b | HIGH | 7.2 | The WP-CRM WordPress plugin through 1.2.1 does not validate and sanitise fields when exporting people to a CSV file, lea… | — | wordfence | |
| 310b9365-2c94-42b2-92ca-ab9a5eab3bfe | < 1.8.9 |
HIGH | 7.2 | The VikBooking Hotel Booking Engine & PMS plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions … | — | wordfence |
| 30f791ef-3a97-4f89-b602-b42b726a8f70 | HIGH | 7.2 | The Property Lot Management System plugin for WordPress is vulnerable to arbitrary file uploads in all versions up to, a… | — | wordfence | |
| 30eda147-f02a-4b3c-a51c-665aa4c75c93 | < 3.4.1 |
HIGH | 7.2 | SQL injection vulnerability in counter-options.php in the Count Per Day plugin before 3.4.1 for WordPress allows remote … | — | wordfence |
| 30ddd0e6-a9c2-4a71-b5ab-295d5c15cf47 | < 1.0.5 |
HIGH | 7.2 | The Compress & Upload plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation i… | — | wordfence |
| 30741601-50b9-4799-a340-11f6ffa59553 | HIGH | 7.2 | The Multiple Roles per User plugin for WordPress is vulnerable to unauthorized modification of data due to a missing cap… | — | wordfence | |
| 306fa8e1-b62f-4514-8463-e696d043f6f5 | < 1.8.1 |
HIGH | 7.2 | The Simple Photo Gallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and includ… | — | wordfence |
| 306c98ad-0d42-4ad5-b82a-bf4579865aa9 | HIGH | 7.2 | The QueryWall plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 1.1.1 due to insuffi… | — | wordfence | |
| 3041bb06-504c-4de1-8a1a-12041e09400e | HIGH | 7.2 | The WP-Cufon plugin for WordPress is vulnerable to Stored Cross-Site Scripting via an unknown parameter in all versions … | — | wordfence | |
| 2fe467fb-f5b2-4e4b-8048-669dce354ace | < 2.5.0 |
HIGH | 7.2 | The Webhook Automator & Contact Form Integration to Automate 280+ Platforms β Bit Integrations plugin for WordPress is… | — | wordfence |
| 2fd2dffd-efc9-47f7-8495-50be2b80331f | < 2.8.3 |
HIGH | 7.2 | The HT Contact Form β Drag & Drop Form Builder for WordPress plugin for WordPress is vulnerable to Stored Cross-Site S… | — | wordfence |
| 2fca8dba-9fe7-4ce1-8903-589e42e5604d | < 3.5.3 |
HIGH | 7.2 | The Social Warfare plugin before 3.5.3 for WordPress has stored XSS via the wp-admin/admin-post.php?swp_debug=load_optio… | — | wordfence |
| 2facf62b-33cf-4438-a501-f96730077fa2 | HIGH | 7.2 | The Poll Plugin for WordPress is vulnerable to blind SQL Injection via the 'pollid' parameter in versions up to, and inc… | — | wordfence | |
| 2f905c0b-6b70-42bf-bf48-6f4eb785bfb8 | HIGH | 7.2 | The Logo Slider WordPress plugin through 1.4.8 does not sanitise and escape the lsp_slider_id parameter before using it … | — | wordfence | |
| 2f533b3a-6d25-4c74-929f-ee4ee3a62926 | < 14.13 |
HIGH | 7.2 | The cformsII plugin for WordPress is vulnerable to generic SQL Injection via Delete Entries or Download Entries in versi… | — | wordfence |
| 2f3ad1e0-1ae3-44cd-aa2a-dbb3a1b531f9 | < 3.1.13 |
HIGH | 7.2 | The FULL β Cliente plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the license plan parameter in… | — | wordfence |
| 2f3328c2-290f-410b-a6c8-2825d415f511 | HIGH | 7.2 | The Web Instant Messenger and LocalWeb In One plugins for WordPress are vulnerable to Stored Cross-Site Scripting in ver… | — | wordfence |
EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.
Scan My Website →