Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.
39,836 vulnerabilities found (page 417 of 1594)
| CVE ID | Plugin / Theme | Severity | CVSS | Description | Fixed In | Source |
|---|---|---|---|---|---|---|
| 91d72089-6ad9-401b-ab7b-0996e28d3be9 | HIGH | 7.1 | Multiple cross-site scripting (XSS) vulnerabilities in frame-maker.php in the Walk Score plugin 0.5.5 and earlier for Wo… | — | wordfence | |
| 9103c67c-d75f-469d-94f1-ce7877384417 | HIGH | 7.1 | Cross-site scripting (XSS) vulnerability in main_page.php in the Game tabs plugin 0.4.0 and earlier for WordPress allows… | — | wordfence | |
| 8ea25e80-af12-4845-b505-16654a68b009 | HIGH | 7.1 | Cross-site scripting (XSS) vulnerability in the Easy Banners plugin 1.4 for WordPress allows remote attackers to inject … | — | wordfence | |
| 8c529017-2fb9-4665-97a6-3ec062908299 | HIGH | 7.1 | The Flo Forms – Easy Drag & Drop Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SV… | — | wordfence | |
| 87e9d29b-9e0d-409c-97a5-7c444dff7382 | < 1.1 |
HIGH | 7.1 | Multiple cross-site request forgery (CSRF) vulnerabilities in the configuration screen in wp-relatedposts.php in the WP … | — | wordfence |
| 868bbe8c-6d21-4d4b-ae23-e08dfb7a1277 | < 3.0 |
HIGH | 7.1 | The Ultimate Profile Builder plugin for WordPress is vulnerable to Cross-Site Request Forgery to Cross-Site Scripting v… | — | wordfence |
| 85fd3e3c-f1cb-4384-86fd-3691f1deb963 | < 2.0.6 |
HIGH | 7.1 | Authenticated Insecure Direct Object References (IDOR) vulnerability in WordPress uListing plugin (versions <= 2.0.5). | — | wordfence |
| 84c4e3cc-1f7c-4ed9-9072-32f3e84419c9 | HIGH | 7.1 | The Booking Calendar plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on sev… | — | wordfence | |
| 822b5a6b-0be6-4511-bf5d-c32574f27865 | < 3.2.6.8 |
HIGH | 7.1 | be_teacher in class-lp-admin-ajax.php in the LearnPress plugin 3.2.6.5 and earlier for WordPress allows any registered u… | — | wordfence |
| 7bfd8c31-4f89-4f09-8d46-11340c4eea1d | HIGH | 7.1 | The Backup and Restore plugin – WordPress plugin for WordPress is vulnerable to arbitrary file deletion due to insuffi… | — | wordfence | |
| 7a4ef9e6-2299-4024-a6a9-482199ca06db | < 2.3.1 |
HIGH | 7.1 | There are unauthenticated reflected Cross-Site Scripting (XSS) vulnerabilities in CareerUp Careerup WordPress theme befo… | — | wordfence |
| 78e7d0f7-b588-407b-bb3e-068589114ab0 | HIGH | 7.1 | Cross-site scripting (XSS) vulnerability in the duwasai flashy theme 1.3 and earlier for WordPress allows remote attacke… | — | wordfence | |
| 74f8af2b-69fb-41db-b978-62709322aed3 | < 20.13.7 |
HIGH | 7.1 | The Email Newsletter plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘search’ parameter… | — | wordfence |
| 74b81d31-8ee6-47cf-a5e8-3cf0900ebea0 | < 2.6.7.2 |
HIGH | 7.1 | The Events Manager Pro, versions up to 2.6.7.2, and Events Manager, versions up to 5.9.7.2, plugins for WordPress are vu… | — | wordfence |
| 736e51d4-da1d-4252-a10f-d89eb6a68de4 | < 2.26.5 |
HIGH | 7.1 | The IP2Location Country Blocker WordPress plugin before 2.26.5 does not have authorisation and CSRF checks in the ip2loc… | — | wordfence |
| 721f7c9e-34f3-4c41-992d-df35b56f95cd | < 3.2.6 |
HIGH | 7.1 | The Count per Day plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the HTTP Referer header in ve… | — | wordfence |
| 710574a8-a6e2-4ee6-9ea7-03a34994fec7 | < 3.2.1 |
HIGH | 7.1 | The User Registration – Custom Registration Form, Login Form, and User Profile WordPress Plugin plugin for WordPress i… | — | wordfence |
| 7061781d-999b-47a7-b4b2-f0335c6247f8 | HIGH | 7.1 | The Gaxx Keywords plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including,… | — | wordfence | |
| 70544986-af4a-48e4-8497-8ee78589676e | HIGH | 7.1 | The "FLASH PLAYER PLUGIN" plugin for WordPress is vulnerable to Cross-Site Scripting via the 'plfilter' and 'search' par… | — | wordfence | |
| 6f8945e9-51db-46aa-b198-3762b6628553 | < 2.52 |
HIGH | 7.1 | Cross-site request forgery (CSRF) vulnerability in the Options in the WP-Print plugin before 2.52 for WordPress allows r… | — | wordfence |
| 6b78e1e8-2298-4889-955c-e9b7472ffbff | < 1.2.13 |
HIGH | 7.1 | The Favicon by RealFaviconGenerator plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘json… | — | wordfence |
| 6a639d27-8704-4841-b2b5-6afbf342a0ff | < 3.2.6.9 |
HIGH | 7.1 | Versions below 3.2.6.9 allow an attacker to publish or trash any existing post or page, or even set it to a nonexistent … | — | wordfence |
| 69725919-490c-4357-872c-d8112af5fe40 | < 6.4.2 |
HIGH | 7.1 | The Import all XML, CSV & TXT into WordPress plugin for WordPress is vulnerable to authorization bypass due to a missing… | — | wordfence |
| 683e10af-5414-4959-9823-93e88e84bb1b | < 2.0.21 |
HIGH | 7.1 | The Crowdsignal Dashboard – Polls, Surveys & more plugin for WordPress is vulnerable to Cross-Site Request Forgery in … | — | wordfence |
| 66ddb0f7-4d4c-4c4f-b766-9a07609cd0e5 | < 3.8.1 |
HIGH | 7.1 | The Fruitful theme for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘author’ parameter in versi… | — | wordfence |
EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.
Scan My Website →