Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.
39,898 vulnerabilities found (page 531 of 1596)
| CVE ID | Plugin / Theme | Severity | CVSS | Description | Fixed In | Source |
|---|---|---|---|---|---|---|
| d01a7887-afd7-418b-99ad-92157582a506 | < 0.2.1 |
MEDIUM | 6.4 | The FX Currency Converter plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'fxcc_conve… | — | wordfence |
| d015e6ce-641c-4d68-b42b-03c039e973bd | < 1.3.4 |
MEDIUM | 6.4 | The Login with Vipps and MobilePay plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'c… | — | wordfence |
| d0117436-7a2a-42f3-8c05-75dfddfb9d09 | < 5.5.0 |
MEDIUM | 6.4 | The The Plus Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Age Gate wid… | — | wordfence |
| d0059382-3e13-434a-a3d1-7892d14a371b | < 2.1.12 |
MEDIUM | 6.4 | The Html5 Audio Player plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcodes in … | — | wordfence |
| CVE-2026-6646 | MEDIUM | 6.4 | The The7 theme for WordPress is vulnerable to Stored Cross-Site Scripting via the 'dt_default_button' shortcode in all v… | — | nvd | |
| CVE-2026-5070 | MEDIUM | 6.4 | The Vantage theme for WordPress is vulnerable to Stored Cross-Site Scripting via Gallery block text content in versions … | — | nvd | |
| CVE-2026-3534 | MEDIUM | 6.4 | The Astra theme for WordPress is vulnerable to Stored Cross-Site Scripting via the `ast-page-background-meta` and `ast-c… | — | nvd | |
| CVE-2026-3034 | < 2.1.25 |
MEDIUM | 6.4 | The OoohBoi Steroids for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the _ob_spacera… | — | nvd |
| CVE-2026-2583 | MEDIUM | 6.4 | The Blocksy theme for WordPress is vulnerable to Stored Cross-Site Scripting via the `blocksy_meta` metadata fields in a… | — | nvd | |
| CVE-2026-2486 | MEDIUM | 6.4 | The Master Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'ma_el_bh_tabl… | — | nvd | |
| CVE-2026-2384 | MEDIUM | 6.4 | The Quiz Maker plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's `vc_quizmaker` shortco… | — | nvd | |
| CVE-2026-2383 | MEDIUM | 6.4 | The Simple Download Monitor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via custom field in all ve… | — | nvd | |
| CVE-2026-2367 | MEDIUM | 6.4 | The Secure Copy Content Protection and Content Locking plugin for WordPress is vulnerable to Stored Cross-Site Scripting… | — | nvd | |
| CVE-2026-2362 | < 2.3.2 |
MEDIUM | 6.4 | The WP Accessibility plugin for WordPress is vulnerable to Stored DOM-Based Cross-Site Scripting via the 'alt' attribute… | — | nvd |
| CVE-2026-2029 | MEDIUM | 6.4 | The Livemesh Addons for Beaver Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `[labb_… | — | nvd | |
| CVE-2026-1941 | MEDIUM | 6.4 | The WP Event Aggregator plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'wp_events' s… | — | nvd | |
| CVE-2026-1807 | MEDIUM | 6.4 | The InteractiveCalculator for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin… | — | nvd | |
| CVE-2026-1646 | MEDIUM | 6.4 | The Advance Block Extend plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the TitleColor block attr… | — | nvd | |
| CVE-2026-1373 | MEDIUM | 6.4 | The Easy Author Image plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'author_profile_picture_… | — | nvd | |
| CVE-2026-1236 | MEDIUM | 6.4 | The Envira Gallery for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'justified_ga… | — | nvd | |
| CVE-2026-0556 | MEDIUM | 6.4 | The XO Event Calendar plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'xo_event_field… | — | nvd | |
| CVE-2026-0549 | < 3.11.0 |
MEDIUM | 6.4 | The Groups plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'groups_group_info' shortc… | — | nvd |
| CVE-2025-6460 | MEDIUM | 6.4 | The Display During Conditional Shortcode plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘me… | — | nvd | |
| CVE-2025-14851 | MEDIUM | 6.4 | The YaMaps for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `yamap` shortcode par… | — | nvd | |
| CVE-2025-14445 | MEDIUM | 6.4 | The Image Hotspot by DevVN plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'hotspot_content' c… | — | nvd |
EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.
Scan My Website →