Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.
39,898 vulnerabilities found (page 532 of 1596)
| CVE ID | Plugin / Theme | Severity | CVSS | Description | Fixed In | Source |
|---|---|---|---|---|---|---|
| CVE-2025-14142 | MEDIUM | 6.4 | The Electric Enquiries plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'button' parameter of t… | — | nvd | |
| CVE-2025-14042 | MEDIUM | 6.4 | The Automotive Car Dealership Business WordPress Theme for WordPress is vulnerable to Stored Cross-Site Scripting via th… | — | nvd | |
| CVE-2025-14040 | MEDIUM | 6.4 | The Automotive Car Dealership Business WordPress Theme for WordPress is vulnerable to Stored Cross-Site Scripting via th… | — | nvd | |
| CVE-2025-13959 | MEDIUM | 6.4 | The Filestack plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'filepicker' shortcode … | — | nvd | |
| CVE-2025-13738 | < 2.0.79 |
MEDIUM | 6.4 | The Easy Table of Contents plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's `ez-toc` s… | — | nvd |
| CVE-2025-13617 | MEDIUM | 6.4 | The Apollo13 Framework Extensions plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘a13_alt_l… | — | nvd | |
| CVE-2025-13612 | MEDIUM | 6.4 | The Album and Image Gallery plus Lightbox plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plug… | — | nvd | |
| CVE-2025-12375 | MEDIUM | 6.4 | The Printful Integration for WooCommerce plugin for WordPress is vulnerable to Server-Side Request Forgery in all versio… | — | nvd | |
| CVE-2025-12117 | MEDIUM | 6.4 | The Renden theme for WordPress is vulnerable to Stored Cross-Site Scripting via the post title in all versions up to, an… | — | nvd | |
| CVE-2025-12116 | MEDIUM | 6.4 | The Drift theme for WordPress is vulnerable to Stored Cross-Site Scripting via the post title in all versions up to, and… | — | nvd | |
| CVE-2025-11737 | < 9.112.4 |
MEDIUM | 6.4 | The VK All in One Expansion Unit plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'vkExUnit_sns… | — | nvd |
| cff64b97-b3cf-41e7-aea6-004ab764e8e8 | < 2.0.0 |
MEDIUM | 6.4 | The Magical Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1… | — | wordfence |
| cff2e5be-0de0-4e62-a881-6156760b7d99 | < 3.2.37 |
MEDIUM | 6.4 | The Gutenberg Blocks with AI by Kadence WP – Page Builder Features plugin for WordPress is vulnerable to Stored Cross-… | — | wordfence |
| cfe548ce-5dc9-4073-b755-d28e37720808 | MEDIUM | 6.4 | The GC Social Wall plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'gc_social_wall' s… | — | wordfence | |
| cfdff272-fd65-4dfb-8b02-6d266ce4a1cc | MEDIUM | 6.4 | The Provide Forex Signals plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and inclu… | — | wordfence | |
| cfcd59ae-085f-47d2-a4d2-2d1239f035d2 | < 4.5.4 |
MEDIUM | 6.4 | The Essential Blocks – Page Builder Gutenberg Blocks, Patterns & Templates plugin for WordPress is vulnerable to Store… | — | wordfence |
| cfaa8ffd-549e-4803-aa17-d1317a606e7a | < 3.3.3 |
MEDIUM | 6.4 | The Sky Addons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `sky-custom-scripts` custom pos… | — | wordfence |
| cf810967-9fb9-4d6b-9671-1f41176248bb | < 7.0.1 |
MEDIUM | 6.4 | The Ecwid Shopping Cart plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and includi… | — | wordfence |
| cf7c3ffe-079e-4db4-9dc4-3405527c0a99 | < 3.0 |
MEDIUM | 6.4 | The Image Over Image For WPBakery Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the… | — | wordfence |
| cf7adeb3-4c6b-4181-af07-0acb1fc8cdb0 | MEDIUM | 6.4 | The Fancy Testimonials plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'author' shortcode attr… | — | wordfence | |
| cf7987ed-bde8-41a1-b679-299e7b09e282 | < 9.0.13 |
MEDIUM | 6.4 | The teachPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 9.0.1… | — | wordfence |
| cf6e3552-9616-4da1-8d8e-a6144ba1d0a3 | < 1.1.11 |
MEDIUM | 6.4 | The Easy PayPal Shopping Cart plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortco… | — | wordfence |
| cf6c13de-e666-4c80-aa4c-6f610d899d03 | < 3.19.0 |
MEDIUM | 6.4 | The Flatsome theme for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in all versi… | — | wordfence |
| cf68401a-0a79-43f0-adee-fd0594d5dee0 | < 4.7.0 |
MEDIUM | 6.4 | The PDF Invoices for WooCommerce + Drag and Drop Template Builder plugin for WordPress is vulnerable to Stored Cross-Sit… | — | wordfence |
| cf665438-20d2-4df9-b3ff-54123343a46d | < 3.2.2 |
MEDIUM | 6.4 | The Rencontre – Dating Site plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘facebook’ p… | — | wordfence |
EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.
Scan My Website →