Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.
39,836 vulnerabilities found (page 420 of 1594)
| CVE ID | Plugin / Theme | Severity | CVSS | Description | Fixed In | Source |
|---|---|---|---|---|---|---|
| 35246286-c0df-4f82-84b8-ebefe966a4dc | < 1.4.8.1 |
HIGH | 7.1 | The Contact Form by WPForms for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and includi… | — | wordfence |
| 34a6c9af-1616-4b5d-8660-4f141bdd25c9 | HIGH | 7.1 | Cross-site scripting (XSS) vulnerability in ajax_functions.php in the GEO Redirector plugin 1.0.1 and earlier for WordPr… | — | wordfence | |
| 33e010dd-d9b2-410c-8397-638def946fbe | < 2.0.9 |
HIGH | 7.1 | The Human Presence – Stop Form Spam Without ReCaptcha plugin for WordPress is vulnerable to Reflected Cross-Site Scrip… | — | wordfence |
| 334570f7-967b-4792-934c-ebe4c4f18490 | < 3.3.25 |
HIGH | 7.1 | The My Calendar plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 3.3.2… | — | wordfence |
| 32a24a9d-b902-4a66-83d5-c8e3b8dd7923 | HIGH | 7.1 | The Delete Old Orders WordPress plugin through 0.2 does not sanitize and escape the date parameter before outputting it … | — | wordfence | |
| 308b4cfa-3d4f-46a1-a6a8-eaa2653b4953 | < 3.8.6.2 |
HIGH | 7.1 | The WP SpreadPlugin plugin for WordPress is vulnerable to Cross-Site Scripting in versions before 3.8.6.2 due to insuffi… | — | wordfence |
| 2f3c706f-fcce-4bcb-9773-ced011bf6407 | < 1.60 |
HIGH | 7.1 | The Inactive User Deleter plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and includ… | — | wordfence |
| 2dabb790-4f5e-447a-ad65-3f62ac7f6176 | < 2.4 |
HIGH | 7.1 | The LWS Tools plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.3.1. … | — | wordfence |
| 2c8ff4ec-9b40-4d59-b3b0-382f91042a4a | < 2.4.3 |
HIGH | 7.1 | The RapidLoad – Optimize Web Vitals Automatically plugin for WordPress is vulnerable to unauthorized access of data an… | — | wordfence |
| 2ba556d0-48f9-4953-a5aa-876284e56360 | < 4.2.13 |
HIGH | 7.1 | The Gutenberg Template Library & Redux Framework plugin <= 4.2.12 for WordPress used an incorrect authorization check in… | — | wordfence |
| 29c47391-5d37-4f49-8806-1f378a6306d0 | < 4.5.3 |
HIGH | 7.1 | The WP Meta SEO plugin for WordPress is vulnerable to unauthorized execution of tasks due to a missing capability check … | — | wordfence |
| 2950eb91-a232-42c5-8a28-96b770cb7c48 | < 3.9 |
HIGH | 7.1 | The Real-Time Find and Replace plugin for WordPress is vulnerable to Cross-Site Scripting via the ‘REQUEST_URI’ para… | — | wordfence |
| 28286b89-0fcd-4616-8246-d8a19d632674 | < 13.04 |
HIGH | 7.1 | Cross-site scripting (XSS) vulnerability in invite.php in the WP Symposium plugin before 13.04 for WordPress allows remo… | — | wordfence |
| 2553a858-bbea-4ef2-8d45-e0a665123065 | HIGH | 7.1 | Cross-site scripting (XSS) vulnerability in magpie_debug.php in the Twitter Feed plugin (wp-twitter-feed) 2.2 and below … | — | wordfence | |
| 2482ef4b-697a-45a0-b45e-85b2af5b4735 | < 1.4.3 |
HIGH | 7.1 | The Material Design Icons for Page Builders plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions… | — | wordfence |
| 242ad509-32fd-4b28-b6e2-6c49b7288dde | HIGH | 7.1 | The WP Html Page Sitemap plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and inc… | — | wordfence | |
| 22476135-8951-4012-845b-46a5dfbfc1f5 | < 1.2.0 |
HIGH | 7.1 | The Gallery PhotoBlocks plugin for WordPress is vulnerable to Cross-Site Scripting in versions up to, and including, 1.1… | — | wordfence |
| 2111df14-63a3-4e3c-87b8-d0e71812d32c | < 1.5.1 |
HIGH | 7.1 | Cross-site scripting (XSS) vulnerability in nextend-facebook-settings.php in the Nextend Facebook Connect plugin before … | — | wordfence |
| 1f9760f8-459d-4dcf-941d-f8f3f1e266ce | < 2.6 |
HIGH | 7.1 | Multiple cross-site scripting (XSS) vulnerabilities in captcha\captcha.php in the Captcha! 2.5d and earlier plugin for W… | — | wordfence |
| 1e4e27e0-bbb0-498a-b425-9e9d60dfed0f | < 1.1.11 |
HIGH | 7.1 | The Premmerce Wholesale Pricing for WooCommerce plugin for WordPress is vulnerable to SQL Injection via the 'ID' paramet… | — | wordfence |
| 1e4d03f0-408c-47da-bae9-38614603f02b | HIGH | 7.1 | The SimpleDark Theme for WordPress is vulnerable to Cross-Site Scripting via the 's' parameter in versions up to, and in… | — | wordfence | |
| 1bcc6192-b9fa-4444-b06d-2b44d53d9cfe | HIGH | 7.1 | The WP Elegant Testimonial plugin for WordPress is vulnerable to Cross-Site Scripting via several parameters in versions… | — | wordfence | |
| 1665fda6-005d-42ba-883d-2e3ad7abe0ba | < 2.1.7 |
HIGH | 7.1 | The WooCommerce Warranty Requests plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via an unknown pa… | — | wordfence |
| 150a6dda-84de-49b1-9a8a-fcc1e0ba73d1 | < 1.3.1 |
HIGH | 7.1 | The PDF & Print Button Joliprint plugin for WordPress is vulnerable to Cross-Site Scripting via multiple parameters in v… | — | wordfence |
| 14026e96-7e21-45db-b258-13b014ec478c | < 1.0.6 |
HIGH | 7.1 | The WP Private Message plugin for WordPress is vulnerable to insecure direct object reference in versions up to, and inc… | — | wordfence |
EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.
Scan My Website →