Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.
39,836 vulnerabilities found (page 401 of 1594)
| CVE ID | Plugin / Theme | Severity | CVSS | Description | Fixed In | Source |
|---|---|---|---|---|---|---|
| 273e25aa-4c00-4463-afc5-d8b2433af064 | < 12.5.0.2 |
HIGH | 7.2 | The PixelYourSite Pro β Your smart PIXEL (TAG) Manager plugin for WordPress is vulnerable to Server-Side Request Forge… | — | wordfence |
| 26e7c3fa-7ae7-4343-8494-2955cb755c6d | < 3.7.6 |
HIGH | 7.2 | The WPtouch plugin for WordPress is vulnerable to Cross-Site Scripting in versions up to, and including, 3.7.5.3 due to … | — | wordfence |
| 26926973-36b7-4ad2-8267-2de4749159ab | < 3.8.2 |
HIGH | 7.2 | The Stream WordPress plugin before 3.8.2 does not sanitise and validate the order GET parameter from the Stream Records … | — | wordfence |
| 2672ce58-3358-4ae9-a2f9-0652012b6c2e | < 1.6.5 |
HIGH | 7.2 | The Cookie Notice & Consent plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and inc… | — | wordfence |
| 266bbcab-7d41-4c38-b136-24da61728977 | HIGH | 7.2 | The AmpedSense β AdSense Split Tester plugin for WordPress is vulnerable to unspecified Cross-Site Scripting via an un… | — | wordfence | |
| 2630dbfe-2e11-4671-9a75-377237ac1ea1 | HIGH | 7.2 | The Steveas WP Live Chat Shoutbox plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Shoutboxes in ve… | — | wordfence | |
| 25f277f3-8b94-4ea2-ba84-885257690b18 | < 2.7.6 |
HIGH | 7.2 | The NextGEN Gallery Voting plugin for WordPress is vulnerable to SQL Injection via the 'nggv[limit]' parameter in versio… | — | wordfence |
| 25e145b5-719b-4b7c-aee2-343e8418bf08 | < 4.7.3 |
HIGH | 7.2 | The Simple Membership plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including… | — | wordfence |
| 25bdc101-ba13-40fa-97af-75777a2f4bf8 | < 2.15 |
HIGH | 7.2 | The Share This Image plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and includ… | — | wordfence |
| 25bdb89f-3478-4a1a-8bf0-46e88207eb21 | < 1.1.22 |
HIGH | 7.2 | The Cart All In One For WooCommerce plugin for WordPress is vulnerable to Code Injection in all versions up to, and incl… | — | wordfence |
| 25a8b9c9-da25-48b9-ada1-ca8a5941b2c2 | < 11.6 |
HIGH | 7.2 | The plugin Very Simple Contact Form in versions up to and including 11.4 uses a captcha that can be bypassed by bots. Ve… | — | wordfence |
| 2596f703-7495-4769-8400-d813f63af9c6 | < 5.5.6 |
HIGH | 7.2 | The CDI β Collect and Deliver Interface for Woocommerce plugin for WordPress is vulnerable to arbitrary file uploads d… | — | wordfence |
| 2584097a-8955-41c7-b009-c6502fe8b99b | < 1.8.0 |
HIGH | 7.2 | The Widgets for Social Photo Feed plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'feed_data' … | — | wordfence |
| 25543955-15b0-4dda-9636-c116db7f2838 | < 2.3 |
HIGH | 7.2 | Directory traversal vulnerability in the GD bbPress Attachments plugin before 2.3 for WordPress allows remote administra… | — | wordfence |
| 2535c00f-7725-48f2-a4a7-ea351b6f463b | < 2.3.12 |
HIGH | 7.2 | The ZoloBlocks β Gutenberg Block Editor Plugin with Advanced Blocks, Dynamic Content, Templates & Patterns plugin for … | — | wordfence |
| 25205cb9-6d8b-456a-82b8-7257668f2972 | HIGH | 7.2 | The WP Logs Book plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including,… | — | wordfence | |
| 24e7c30e-dac9-418a-ae0b-499f192139a4 | < 3.5.8 |
HIGH | 7.2 | The WPIDE β File Manager & Code Editor plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions u… | — | wordfence |
| 24d0229c-0f1b-42df-b89a-ce0b8a3fda7e | < 1.0.1 |
HIGH | 7.2 | The Mailtree Log Mail plugin for WordPress is vulnerable to Stored Cross-Site Scripting via an email subject in versions… | — | wordfence |
| 24c9ff14-1d24-4c8c-b3d5-c2e0b5eb25fb | < 3.8.10.1 |
HIGH | 7.2 | The JetEngine plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 3.8.10… | — | wordfence |
| 24458c37-ebcc-471b-9044-78f24667f7a6 | < 6.0 |
HIGH | 7.2 | The Bit File Manager plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 5.2.7 … | — | wordfence |
| 24118410-e5a5-46fa-ac33-ce58cb2f75a3 | < 5.0.26 |
HIGH | 7.2 | The YML for Yandex Market plugin for WordPress is vulnerable to Remote Code Execution in all versions up to 5.0.26 (excl… | — | wordfence |
| 23feb72c-7e6f-436b-b56e-dc6185302d31 | < 1.29.1 |
HIGH | 7.2 | The Forminator plugin for WordPress is vulnerable to Stored Cross-Site Scripting via an uploaded file (e.g. 3gpp file) i… | — | wordfence |
| 239f6fdc-d0d8-48e1-9ede-79087c1ee251 | HIGH | 7.2 | The Ultimate Video Player WordPress & WooCommerce Plugin plugin for WordPress is vulnerable to Server-Side Request Forge… | — | wordfence | |
| 234789db-1440-40ac-83e7-b8afb0ba4b5f | < 7.2.5 |
HIGH | 7.2 | The Booster for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via any location that typi… | — | wordfence |
| 2330005e-c3ab-4556-aba9-f194a1ace329 | HIGH | 7.2 | The WP Events plugin for WordPress is vulnerable to generic SQL Injection via the "$_GET[βedit_event']" parameter in v… | — | wordfence |
EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.
Scan My Website →