Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.
39,898 vulnerabilities found (page 554 of 1596)
| CVE ID | Plugin / Theme | Severity | CVSS | Description | Fixed In | Source |
|---|---|---|---|---|---|---|
| bd84a7b1-76f3-4c01-a935-ffec4a48b61b | < 1.4.47 |
MEDIUM | 6.4 | The Open User Map plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.… | — | wordfence |
| bd7784dc-c450-4ce2-86ac-adaf9e2b61ad | < 2.7.7.1 |
MEDIUM | 6.4 | The JetElements For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and i… | — | wordfence |
| bd625d24-c1e9-465d-896a-bff75d8c534f | < 2.6.9 |
MEDIUM | 6.4 | The WP Project Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and includin… | — | wordfence |
| bd619c85-4804-4c19-b37b-fdfbd8266760 | < 1.3.0 |
MEDIUM | 6.4 | The Pie Calendar plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.2… | — | wordfence |
| bd581604-e2f6-42c4-81ef-10873683526b | MEDIUM | 6.4 | The kk Youtube Video plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'kkytv' shortcod… | — | wordfence | |
| bd55ce27-7d38-4d55-9b31-5b986edc7f1d | MEDIUM | 6.4 | The amoCRM WebForm plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1… | — | wordfence | |
| bd3dbc56-4833-4b5d-bd6c-facc3e1878ea | < 2.0.2 |
MEDIUM | 6.4 | The Responsive Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multiple widge… | — | wordfence |
| bd38d97d-db93-42ed-9d52-f70641fba442 | < 3.1.12 |
MEDIUM | 6.4 | The Strong Testimonials plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Full Name field parame… | — | wordfence |
| bd352c95-6e76-478f-943b-938a96b372f4 | MEDIUM | 6.4 | The Color Palette plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the βhexβ parameter in all v… | — | wordfence | |
| bd28f7f0-ed52-45d0-8d97-5ff95d17eb26 | < 1.2.2.11 |
MEDIUM | 6.4 | The Easy Video Player plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in… | — | wordfence |
| bd2754f9-11f7-4690-99dd-2204e69bf14b | MEDIUM | 6.4 | The Simple Business Data plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'simple_business_data' sh… | — | wordfence | |
| bd034f43-370c-4ad9-ad02-4cae0f48d781 | < 1.8.3 |
MEDIUM | 6.4 | The ITERAS plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multiple shortcodes (iteras-ordering, i… | — | wordfence |
| bcf8fa7c-0d9e-41ef-af60-0c33328fc5cc | < 2.7.7.26 |
MEDIUM | 6.4 | The Photo Gallery - GT3 Image Gallery & Gutenberg Block Gallery plugin for WordPress is vulnerable to Stored Cross-Site … | — | wordfence |
| bcde42fb-6f61-4174-a44a-bb28e4855062 | < 2.1.1 |
MEDIUM | 6.4 | The StatCounter β Free Real Time Visitor Stats plugin for WordPress is vulnerable to Stored Cross-Site Scripting via t… | — | wordfence |
| bcdbd108-5e17-4e67-a2a2-0f1464c1ba6c | < 5.1.1 |
MEDIUM | 6.4 | The MP3 Audio Player for Music, Radio & Podcast by Sonaar plugin for WordPress is vulnerable to Stored Cross-Site Script… | — | wordfence |
| bcd9384c-5af3-4544-8179-c2f5550dd152 | < 2.1.4 |
MEDIUM | 6.4 | The DethemeKit For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's widgets … | — | wordfence |
| bcd6c085-9fd8-43d9-b244-ab91146f610f | < 2.2.8 |
MEDIUM | 6.4 | The Enter Addons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Countdown and Image … | — | wordfence |
| bcd28bc3-f893-4eb7-946f-34a2e9c7ff27 | < 1.6.4 |
MEDIUM | 6.4 | The Back Button Widget plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) i… | — | wordfence |
| bcd25ec7-e594-4261-a743-174ceb130cf5 | MEDIUM | 6.4 | The WPB Image Widget plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including,… | — | wordfence | |
| bcbcad73-ce2a-4eb2-9b7f-91d47a93e16d | MEDIUM | 6.4 | The WP Count Down Timer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multiple parameters of the… | — | wordfence | |
| bcbc8ce6-5eb7-4599-b844-72eb2ff3093c | MEDIUM | 6.4 | Multiple plugins for WordPress are vulnerable to Stored Cross-Site Scripting via the plugin's bundled SimpleLightbox Jav… | — | wordfence | |
| bcad1d05-96a1-4559-9957-fce93c287c07 | MEDIUM | 6.4 | The Events Manager – OpenStreetMaps plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions … | — | wordfence | |
| bca16579-d852-4c68-932e-44b69a01b8ce | < 3.2.27 |
MEDIUM | 6.4 | The WP Courses LMS β Online Courses Builder, eLearning Courses, Courses Solution, Education Courses plugin for WordPre… | — | wordfence |
| bca0e8a0-d837-42d8-a9d3-35e0c820eb43 | < 9.7.7 |
MEDIUM | 6.4 | The WordPress Button Plugin MaxButtons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin'… | — | wordfence |
| bc684cd2-f01a-4c2d-b979-a47b83d01bd2 | < 12.6.6.1 |
MEDIUM | 6.4 | The WP Statistics plugin through 12.6.5 for Wordpress has stored XSS in includes/class-wp-statistics-pages.php. This is … | — | wordfence |
EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.
Scan My Website →