Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.
39,891 vulnerabilities found (page 483 of 1596)
| CVE ID | Plugin / Theme | Severity | CVSS | Description | Fixed In | Source |
|---|---|---|---|---|---|---|
| 012a558c-1f80-4f36-85d9-905f4ed0b6cb | < 2.3.37 |
MEDIUM | 6.5 | The Contact Form builder with drag & drop for WordPress – Kali Forms plugin for WordPress is vulnerable to Insecure Di… | — | wordfence |
| 00aa4e06-66ec-46cb-9a24-e63d64810d83 | MEDIUM | 6.5 | The Classic Widgets with Block-based Widgets plugin for WordPress is vulnerable to unauthorized access due to a missing … | — | wordfence | |
| 00675945-4a7f-49f5-8bde-bb0669edecab | MEDIUM | 6.5 | The Ni CRM Lead plugin for WordPress is vulnerable to SQL Injection in all versions up to, and including, 1.3.0 due to i… | — | wordfence | |
| 00375b21-0395-46cc-a79a-47409769d503 | MEDIUM | 6.5 | The Theme File Duplicator plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 1.3… | — | wordfence | |
| 001a7d43-4b00-42e9-bb0c-94a9d5721166 | < 7.2.1 |
MEDIUM | 6.5 | The BuddyPress plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the Buddy… | — | wordfence |
| fffd6fc5-1578-414c-bb36-4f5dc0f27e19 | < 1.0.22 |
MEDIUM | 6.4 | The JetWidgets For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to and inc… | — | wordfence |
| ffeb766f-3684-4eec-bacb-bbf0d434aba0 | < 1.58.4 |
MEDIUM | 6.4 | The SiteOrigin Widgets Bundle plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the onclick paramete… | — | wordfence |
| ffde541b-5e2b-437b-a123-8522beca52ef | MEDIUM | 6.4 | The Current Book WordPress plugin through 1.0.1 does not sanitize user input when an authenticated user adds Author or B… | — | wordfence | |
| ffd3ecc8-8b76-453f-b2e9-a9c70c58edbf | < 1.4.0 |
MEDIUM | 6.4 | The GenerateBlocks WordPress plugin before 1.4.0 does not validate the generateblocks/container block's tagName attribut… | — | wordfence |
| ffce535f-620d-40f8-a944-11ea87a67380 | < 4.4 |
MEDIUM | 6.4 | The Sitemap plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcodes in versions up… | — | wordfence |
| ffc82708-b04d-4fba-9a79-594ad25dc965 | < 3.20.1 |
MEDIUM | 6.4 | The Flatsome Theme for WordPress is vulnerable to Stored Cross-Site Scripting via the theme's shortcodes in all versions… | — | wordfence |
| ffbb6268-5461-4291-be76-10ba060e352e | < 2.7.7 |
MEDIUM | 6.4 | The Participants Database plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and inclu… | — | wordfence |
| ffa3b85c-7d08-4f6a-889e-b75620f72a1a | < 2.4.3 |
MEDIUM | 6.4 | The TablePress – Tables in WordPress made easy plugin for WordPress is vulnerable to Stored Cross-Site Scripting via t… | — | wordfence |
| ffa252d6-0fe2-4d1f-802f-b902084822a7 | < 3.7.15 |
MEDIUM | 6.4 | Cross-site scripting (XSS) vulnerability in the column_title function in wp-admin/includes/class-wp-media-list-table.php… | — | wordfence |
| ff7f92ec-0412-414f-9afe-e1ba4fa0dbae | < 0.20 |
MEDIUM | 6.4 | The m1.DownloadList plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, … | — | wordfence |
| ff6ff104-44c8-49a9-bebd-abb82e8e1cd6 | < 7.11.7 |
MEDIUM | 6.4 | The Avada theme for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcodes in all versions u… | — | wordfence |
| ff6932c6-f3ec-46a8-a03b-95512eee5bf1 | < 9.7.9 |
MEDIUM | 6.4 | The Shareaholic plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'shareaholic' shortcode in version… | — | wordfence |
| ff4c217c-3a61-4f96-a698-b7fba1294ace | < 1.5.2 |
MEDIUM | 6.4 | The RT Mega Menu – Mega Menu Builder for Elementor & Gutenberg plugin for WordPress is vulnerable to Stored Cross-Site… | — | wordfence |
| ff41796a-0ba8-468f-8b79-274064da154e | MEDIUM | 6.4 | The Radius Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘subHeadingTagName’ para… | — | wordfence | |
| ff3a69a3-dc74-4e44-b791-d02b0f5ebedf | MEDIUM | 6.4 | The Optimate Ads plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.0… | — | wordfence | |
| ff32bc6a-0d1e-47d0-8264-946e72266b72 | < 3.3.1 |
MEDIUM | 6.4 | The Ultimate Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, … | — | wordfence |
| ff2a14b1-8752-4edf-a807-88aab453451d | MEDIUM | 6.4 | The WordPress Shortcodes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s)… | — | wordfence | |
| ff197a1c-3d5b-497f-b35c-40249a426e49 | MEDIUM | 6.4 | The Multiple Votes in one page plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and … | — | wordfence | |
| ff150706-5fbf-4881-976b-89fdaf637fb1 | < 2.11.4 |
MEDIUM | 6.4 | The Football Pool plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in all… | — | wordfence |
| ff13b72f-7175-42c1-a24a-2570dd57bb3e | MEDIUM | 6.4 | The RS WP Book Showcase plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and includi… | — | wordfence |
EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.
Scan My Website →