Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.
39,836 vulnerabilities found (page 418 of 1594)
| CVE ID | Plugin / Theme | Severity | CVSS | Description | Fixed In | Source |
|---|---|---|---|---|---|---|
| 65db2345-4b55-466c-b148-7d954de96a87 | < 1.7.5 |
HIGH | 7.1 | Cross-site scripting (XSS) vulnerability in fs-admin/wpf-add-forum.php in the ForumPress WP Forum Server plugin before 1… | — | wordfence |
| 637a53b5-6d2f-4671-8126-f218c3ca73de | < 1.9.9.5.2 |
HIGH | 7.1 | The WPLMS plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in all … | — | wordfence |
| 6309258e-e4fc-4edf-a771-2d82a9a85a5c | < 3.8 |
HIGH | 7.1 | The "Buy Me a Coffee – Button and Widget Plugin" plugin for WordPress is vulnerable to Cross-Site Request Forgery due … | — | wordfence |
| 62dacee5-9b55-4d0e-aa35-d97a1666f9e1 | < 1.5.1 |
HIGH | 7.1 | Cross-site request forgery (CSRF) vulnerability in wlcms-plugin.php in the White Label CMS plugin before 1.5.1 for WordP… | — | wordfence |
| 6290c671-c8e5-4cc3-a233-9fed584ca02f | < 1.5.1 |
HIGH | 7.1 | There is a Cross-Site Scripting vulnerability in the JobSearch WP JobSearch WordPress plugin before 1.5.1 via search_tit… | — | wordfence |
| 62128061-1ecc-484c-a054-4925f9ac6105 | < 1.2.5 |
HIGH | 7.1 | Cross-site scripting (XSS) vulnerability in the Unconfirmed plugin before 1.2.5 for WordPress allows remote attackers to… | — | wordfence |
| 61d3f1f4-4cb9-4dd2-bda7-d08b2ccdbcba | < 2.15 |
HIGH | 7.1 | A flaw in the WordPress plugin, Minimal Coming Soon & Maintenance Mode through 2.10, allows authenticated users with bas… | — | wordfence |
| 6173d307-9917-4d76-b6bf-d5646b9e33d6 | < 2.4.4 |
HIGH | 7.1 | The WP Activity Log plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘notice’ parameter … | — | wordfence |
| 6156a351-d681-4661-9131-62251b715a94 | < 1.3.65 |
HIGH | 7.1 | The Role Scoper plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘id’ parameter in versi… | — | wordfence |
| 5d9ab83f-6d0b-4fe4-a121-87b09dcc0953 | HIGH | 7.1 | The Cart2Cart: Magento to WooCommerce Migration plugin for WordPress is vulnerable to unauthorized modification of data … | — | wordfence | |
| 5d380b66-675e-451d-a7e3-4efe1fbd08b2 | < 10.1.3 |
HIGH | 7.1 | The MonsterInsights – Google Analytics Dashboard for WordPress (Website Stats Made Easy) plugin for WordPress is vulne… | — | wordfence |
| 5c637882-1854-4502-9907-88053d141cfc | < 1.22 |
HIGH | 7.1 | Cross-site scripting (XSS) vulnerability in wp-cumulus.php in the WP-Cumulus Plug-in before 1.22 for WordPress allows re… | — | wordfence |
| 5b333a3d-e416-42aa-9722-5406df0a64b3 | < 3.6.6 |
HIGH | 7.1 | The Paid Memberships Pro plugin for WordPress is vulnerable to unauthorized modification and disruption of Stripe webhoo… | — | wordfence |
| 5b2db550-c1cf-4c5b-91b1-349da3fd859d | HIGH | 7.1 | The MSMC Redirect After Comment plugin for WordPress is vulnerable to Cross-Site Request Forgery to Stored Cross-Site Sc… | — | wordfence | |
| 598e2c2e-7dd5-435e-a366-6c7569243f2a | < 2.2.3 |
HIGH | 7.1 | The Export WP Page to Static HTML/CSS plugin for WordPress is vulnerable to Open Redirect in all versions up to, and inc… | — | wordfence |
| 596d1083-2030-41f0-92d4-82e98bf07331 | < 1.04 |
HIGH | 7.1 | Cross-site scripting (XSS) vulnerability in skysa-official/skysa.php in Skysa App Bar Integration plugin, possibly befor… | — | wordfence |
| 58a83ec8-e294-4fb6-9f1a-19562b2e499d | < 2.1.10 |
HIGH | 7.1 | The School Management System – WPSchoolPress plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via … | — | wordfence |
| 588afcb3-9bba-4514-ac58-a53bcc3521c3 | HIGH | 7.1 | The Blrt WP Embed plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and includ… | — | wordfence | |
| 57896fa8-9360-41e8-a60e-8b95d01c25ac | < 5.7.0 |
HIGH | 7.1 | The WP Cleanfix plugin for WordPress is vulnerable to unauthorized access of data and modification of data due to a miss… | — | wordfence |
| 52c7edcc-d8dd-401a-9d36-e395fa7189bf | < 16.01 |
HIGH | 7.1 | The WP Symposium Pro plugin for WordPress is vulnerable to Cross-Site Scripting via the 'wpspro_country' parameter in ve… | — | wordfence |
| 5294af95-e85f-4425-9c4b-0a92dfac4bd1 | HIGH | 7.1 | The Digital Climate Strike WP for WordPress contains a malicious redirect in versions up to, and including, 1.0.0. This … | — | wordfence | |
| 52383075-2d39-4fd9-8319-15a5354ff25f | < 1.8.8 |
HIGH | 7.1 | The MP3-jPlayer plugin for WordPress is vulnerable to Cross-Site Scripting via several parameters in versions before 1.8… | — | wordfence |
| 5222ce69-ac9f-4bb0-9832-8cdff1f8b078 | < 3.19.15 |
HIGH | 7.1 | The Ultimate Addons for WPBakery plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and i… | — | wordfence |
| 518771c1-b52b-47b7-99f1-4f40115ba4cf | < 2.0.15 |
HIGH | 7.1 | The Pie Register plugin for WordPress is vulnerable to Cross-Site Scripting via the 'notice' parameter in versions befor… | — | wordfence |
| 501aed34-537b-4d35-a04f-a984297adb39 | < 0.7.25 |
HIGH | 7.1 | The Job Manager plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘jobman-rating’ paramet… | — | wordfence |
EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.
Scan My Website →