Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.
39,836 vulnerabilities found (page 411 of 1594)
| CVE ID | Plugin / Theme | Severity | CVSS | Description | Fixed In | Source |
|---|---|---|---|---|---|---|
| 06e0f191-27e7-478d-a6ad-351b22311fbf | < 2.5.49 |
HIGH | 7.2 | The Houzez Property Feed plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and includ… | — | wordfence |
| 06c63f82-fe0f-435c-9cf8-5db6a7ce0677 | < 3.4.8.3 |
HIGH | 7.2 | The Tickera WordPress plugin before 3.4.8.3 does not properly sanitise and escape the Name fields of booked Events befor… | — | wordfence |
| 06bc7a24-eafc-4b06-852e-9b596f107805 | < 1.6.0.2 |
HIGH | 7.2 | The Contact Form by WPForms plugin for WordPress has a Cross-Site Scripting vulnerability, which is caused by improper i… | — | wordfence |
| 06b31f3a-8516-427c-b819-7bcf2717705b | < 0.3.4 |
HIGH | 7.2 | The Custom Icons for Elementor plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type val… | — | wordfence |
| 066e9f46-83a5-4a2f-ae09-6d06c5c66817 | < 1.4.6 |
HIGH | 7.2 | The Form Vibes plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 1.4.5 due to insuff… | — | wordfence |
| 0659aca3-6b72-460f-8bf4-e7ad17b74773 | < 3.1 |
HIGH | 7.2 | The Product Enquiry for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to,… | — | wordfence |
| 06156cb7-baa0-4e66-a146-505b09698a4a | < 12.8.4 |
HIGH | 7.2 | The Real Estate Manager Pro plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and inc… | — | wordfence |
| 06063978-6c61-42e0-bf03-092aaa20d850 | < 2.5.3 |
HIGH | 7.2 | The Responsive Lightbox & Gallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up t… | — | wordfence |
| 05fc4b17-7922-45a4-aac8-a47b3f50ce69 | < 1.0.12 |
HIGH | 7.2 | The LTL Freight Quotes β Freightview Edition, LTL Freight Quotes β Daylight Edition and LTL Freight Quotes β Day &… | — | wordfence |
| 05f7d9fe-e95f-4ddf-9bce-2aeac3c2e946 | < 3.2.0 |
HIGH | 7.2 | The Metform Elementor Contact Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via text ar… | — | wordfence |
| 05de038f-eff4-4b00-930c-3d2335345869 | HIGH | 7.2 | The URL Preview plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, … | — | wordfence | |
| 05b434f7-6bce-4ad0-bd12-db5b01f14953 | < 1.15.19 |
HIGH | 7.2 | The Form Maker by 10Web plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'type_textarea' field … | — | wordfence |
| 05a5b6be-0253-479c-a80f-19de7d8af1a5 | HIGH | 7.2 | The Kids Zone - Children WordPress theme for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, a… | — | wordfence | |
| 057216e2-3fad-49fc-ac31-06dbd7b110f9 | HIGH | 7.2 | The Flaming Password Reset plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and incl… | — | wordfence | |
| 055d50de-8a7f-40fa-88e9-f57046c0c450 | HIGH | 7.2 | The Custom Login And Signup Widget plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, an… | — | wordfence | |
| 055979ad-84d9-4f72-872d-ee86b9b062af | < 2.6.1 |
HIGH | 7.2 | The GDPR Cookie Consent plugin for WordPress is vulnerable to Stored Cross-Site Scripting via IP headers in all versions… | — | wordfence |
| 0506f360-17c3-4cc8-9ac7-988c056c3caf | < 1.15.6 |
HIGH | 7.2 | The Form Maker plugin for WordPress is vulnerable to SQL Injection via the βidβ parameter in versions up to, and inc… | — | wordfence |
| 05042006-aff6-4ba6-ae67-249dc0dcbb93 | HIGH | 7.2 | The Broken Link Manager WordPress plugin through 0.6.5 does not sanitise, validate or escape the url GET parameter befor… | — | wordfence | |
| 04a937d0-9844-49d1-bcb5-0ee6026c3947 | < 3.0.3 |
HIGH | 7.2 | The Chaty plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 3.0.2 due to insufficien… | — | wordfence |
| 04a64a52-f0a0-4559-834d-88d3edd1bb6a | < 6.5.8 |
HIGH | 7.2 | The WP Ultimate CSV Importer plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 6.5.7… | — | wordfence |
| 049ec264-3ed1-4741-937d-8a633ef0a627 | < 1.0.88 |
HIGH | 7.2 | The BookingPress plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient filename validation in… | — | wordfence |
| 04689f95-30ea-4b68-b50c-c00ed6ab835b | < 1.13.20 |
HIGH | 7.2 | The Geo Mashup plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.13.… | — | wordfence |
| 045fdfd8-7c4a-4fa8-81fd-f749777fb9ed | < 1.6.2 |
HIGH | 7.2 | The Educare plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.6.1 du… | — | wordfence |
| 045f52f2-b77d-4ddb-a674-0fccf3e6dc7d | < 3.135.1 |
HIGH | 7.2 | The WordPress Automatic Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to 3.135… | — | wordfence |
| 0448eb1c-1a4a-465e-aa30-e4af10d27560 | HIGH | 7.2 | The Mini Cart plugin for WordPress is vulnerable to SQL Injection via the βitemβ parameter in versions up to, and in… | — | wordfence |
EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.
Scan My Website →