Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.
39,898 vulnerabilities found (page 537 of 1596)
| CVE ID | Plugin / Theme | Severity | CVSS | Description | Fixed In | Source |
|---|---|---|---|---|---|---|
| cbde3644-4ac3-4082-9dc2-676c47c43532 | < 8.6.9 |
MEDIUM | 6.4 | The Soledad theme for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 8.6.8 due… | — | wordfence |
| cbd5dc98-ac5b-4548-9f98-faa91f5b1e2b | < 2.26 |
MEDIUM | 6.4 | The Cool Tag Cloud WordPress plugin before 2.26 does not escape the style attribute of the cool_tag_cloud shortcode, whi… | — | wordfence |
| cbce42a0-29a7-40df-973c-1fe7338f6c94 | < 1.23.11.6 |
MEDIUM | 6.4 | The SendPress Newsletters plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s… | — | wordfence |
| cbcb1acb-1784-4ba2-83de-0fb89f5bd4d5 | < 5.2.0 |
MEDIUM | 6.4 | The Da Reactions plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 5.1… | — | wordfence |
| cbca88e0-1563-43cb-adf4-4f89856a07d0 | < 1.3 |
MEDIUM | 6.4 | The Dan's Embedder for Google Calendar plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin'… | — | wordfence |
| cbc3fa27-630d-4048-b727-903da09ad644 | < 1.0.6 |
MEDIUM | 6.4 | The OneClick Chat to Order plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and incl… | — | wordfence |
| cbc39f4e-6965-4c5e-b3e6-9ddecff0745b | < 3.3.1 |
MEDIUM | 6.4 | The Bridge Core plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to 3.3.1 due to insuffi… | — | wordfence |
| cbc26607-a588-4059-9a37-afede7c9e3f6 | MEDIUM | 6.4 | The Woocommerce – Products By Custom Tax plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'wo… | — | wordfence | |
| cbbbf5fe-0369-4de6-9b2f-957286b6f394 | < 1.0.3 |
MEDIUM | 6.4 | The Koalendar – Events & Appointments Booking Calendar plugin for WordPress is vulnerable to Stored Cross-Site Scripti… | — | wordfence |
| cbba866d-93dd-4ef5-9670-ab958f61f06e | < 3.3.3 |
MEDIUM | 6.4 | The AI Engine plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 3.… | — | wordfence |
| cbb3bd9b-ac1f-4488-931f-2ba37576df2d | < 2.0.6 |
MEDIUM | 6.4 | The Futurio Extra plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘header_size’ attribute … | — | wordfence |
| cbb3378a-d3e8-4a31-9ed2-f580960878cf | < 1.6 |
MEDIUM | 6.4 | The Divelogs Widget plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'latestdive' shor… | — | wordfence |
| cba546d8-df3e-4ada-9cf9-663baf175dd0 | < 1.6 |
MEDIUM | 6.4 | The Mikado Core plugin for WordPress is vulnerable to Stored Cross-Site Scripting via shortcodes in versions up to, and … | — | wordfence |
| cb8ecbbc-ada9-4887-92e6-25a587ecfb84 | < 7.6 |
MEDIUM | 6.4 | The wpbakery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Post Author tag attribute in all … | — | wordfence |
| cb823899-e90d-4857-9f72-aa7fe60aaca2 | MEDIUM | 6.4 | The Jibu Pro plugin through 1.7 for WordPress is prone to Stored XSS via the wp-content/plugins/jibu-pro/quiz_action.php… | — | wordfence | |
| cb75b6ba-feb7-4e18-91f6-7ca1e90ef039 | < 1.5.4 |
MEDIUM | 6.4 | The ImageLinks Interactive Image Builder for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting… | — | wordfence |
| cb725044-01c3-4c0c-b276-291f897f11e7 | MEDIUM | 6.4 | The Twitter Feeds plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'tweet_title' parameter in t… | — | wordfence | |
| cb6d11ad-0983-4a4b-b52b-824eae8b8e3c | MEDIUM | 6.4 | The Google Maps Plugin by Intergeo plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'intergeo' shor… | — | wordfence | |
| cb64952e-170e-47c5-87fd-d2ec60192b65 | < 1.1.40 |
MEDIUM | 6.4 | The Magical Addons For Elementor ( Header Footer Builder, Free Elementor Widgets, Elementor Templates Library ) plugin f… | — | wordfence |
| cb6457ea-6353-4a69-ad72-cd5acd47ed8c | < 15.0 |
MEDIUM | 6.4 | The Yoast SEO: Local plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including,… | — | wordfence |
| cb5ca73c-1a1d-4a93-bbcb-8af606189f26 | < 1.1.6 |
MEDIUM | 6.4 | The B Carousel Block – Responsive Image and Content Carousel plugin for WordPress is vulnerable to Server-Side Request… | — | wordfence |
| cb49f48e-98bf-4838-8eb0-91a7daad182c | < 2.3.85 |
MEDIUM | 6.4 | The GeoDirectory plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.3… | — | wordfence |
| cb472bdb-de35-45e4-bcea-04f27d425817 | MEDIUM | 6.4 | The Wikiloops Track Player plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's `wikiloops… | — | wordfence | |
| cb46d7fa-9667-4479-8136-837cb61eaf4c | MEDIUM | 6.4 | Anber Elementor Addon plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the $anber_item['button_link… | — | wordfence | |
| cb3f3bc7-9127-43ba-80ad-e32fd7c3b05e | MEDIUM | 6.4 | The Essential Doo Components for Visual Composer plugin for WordPress is vulnerable to Stored Cross-Site Scripting in ve… | — | wordfence |
EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.
Scan My Website →