Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.
39,898 vulnerabilities found (page 563 of 1596)
| CVE ID | Plugin / Theme | Severity | CVSS | Description | Fixed In | Source |
|---|---|---|---|---|---|---|
| b495d7e4-09fd-4e38-9912-bed3f6a7a745 | MEDIUM | 6.4 | The Embed Chessboard plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including,… | — | wordfence | |
| b4905ca1-3096-45c5-838b-1237888fb969 | MEDIUM | 6.4 | The WP Flot plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'linechart' shortcode in … | — | wordfence | |
| b48df04d-1f96-44fb-96d7-122597da2efa | MEDIUM | 6.4 | The Themedy Toolbox plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, … | — | wordfence | |
| b4827732-41ff-4a14-bb5e-4f7888ffd733 | MEDIUM | 6.4 | The GHActivity plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.0.0… | — | wordfence | |
| b478d88d-1423-4a33-b8ef-08b9e66a5d98 | < 3.2.94 |
MEDIUM | 6.4 | The Download Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'wpdm_modal_logi… | — | wordfence |
| b47505a5-fb7f-4e41-a6de-6f0b330aa495 | < 1.0.6 |
MEDIUM | 6.4 | The Mini Course Generator | Embed mini-courses and interactive content plugin for WordPress is vulnerable to Stored Cros… | — | wordfence |
| b4737bb2-1bb4-4986-9df5-5978fc46f2ec | MEDIUM | 6.4 | The Theron Lite theme for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘url’ parameter within the … | — | wordfence | |
| b46e9771-37ff-4825-9af9-02ecde424653 | MEDIUM | 6.4 | The WP Radio – Worldwide Online Radio Stations Directory for WordPress plugin for WordPress is vulnerable to unauthori… | — | wordfence | |
| b46c3f25-6879-47b1-9026-4297fdd003b0 | < 5.3.6 |
MEDIUM | 6.4 | The Team Members plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the first and last name fields in… | — | wordfence |
| b4603b58-0972-4e04-91ac-ffc846964722 | < 2.10.31 |
MEDIUM | 6.4 | The Orbit Fox by ThemeIsle plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the form widget addr2_w… | — | wordfence |
| b4540b21-ef63-4cd2-b605-c66a7b76934f | MEDIUM | 6.4 | The 소셜 공유 버튼 By 코스모스팜 plugin for WordPress is vulnerable to Stored Cross-Site Scripting in version… | — | wordfence | |
| b44ef21f-464e-487a-ba5a-fe889e4c488c | < 3.16.5 |
MEDIUM | 6.4 | The Elementor Website Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the get_inline_svg()… | — | wordfence |
| b44b3cf5-a976-407f-b23b-4b7448a18263 | MEDIUM | 6.4 | The Typing Text plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.2.… | — | wordfence | |
| b43a61f4-2d1c-47ce-ae0d-a5969bdb43f1 | MEDIUM | 6.4 | The WordPress Portfolio Builder – Portfolio Gallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting … | — | wordfence | |
| b4347123-83a9-46be-9216-759906531d73 | MEDIUM | 6.4 | The User Specific Content plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and inclu… | — | wordfence | |
| b421d80f-408e-4fb0-9894-b7e5707d8d5f | < 1.3.7 |
MEDIUM | 6.4 | The Magical Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, an… | — | wordfence |
| b40a40d1-d12f-4fe6-b155-83a1f1a5a494 | < 2.19.1 |
MEDIUM | 6.4 | The Seriously Simple Podcasting plugin for WordPress is vulnerable to Stored Cross-Site Scripting via shortcode in versi… | — | wordfence |
| b406f0b8-16b5-49ca-88d8-7717bef1ae61 | < 3.3.2 |
MEDIUM | 6.4 | The Free Responsive Testimonials, Social Proof Reviews, and Customer Reviews – Stars Testimonials plugin for WordPress… | — | wordfence |
| b3e95dc2-0f50-4009-9cc0-a02f9977ce58 | MEDIUM | 6.4 | The VI: Include Post By plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'class_container' attr… | — | wordfence | |
| b3db2be5-a9d2-4bc0-a8cf-d67da024c0e6 | MEDIUM | 6.4 | The 3D Presentation plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, … | — | wordfence | |
| b3c84ad1-10c7-4b2f-82f3-7546fc8e337d | MEDIUM | 6.4 | The Map My Locations plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'map_my_location… | — | wordfence | |
| b3bae191-9395-481c-93bf-b17cf5f87271 | < 1.1.9.1 |
MEDIUM | 6.4 | The Chained Quiz for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘chained_admin_subject', 'chained_… | — | wordfence |
| b3b40b73-4dec-4a96-a634-3bd3d74616ba | < 1.3.2 |
MEDIUM | 6.4 | The WordPress Book Plugin for Displaying Books in Grid, Flip, Slider, Popup Layout and more plugin for WordPress is vuln… | — | wordfence |
| b3ae99bb-03c3-4869-9314-0dbd76ca25c0 | < 3.0.7 |
MEDIUM | 6.4 | The ElementsKit Elementor addons Lite plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up t… | — | wordfence |
| b3aa7b27-a335-4f82-a50a-45becdd5ef4e | < 5.16.5 |
MEDIUM | 6.4 | Unvalidated input and lack of output encoding in the Modern Events Calendar Lite WordPress plugin, versions before 5.16.… | — | wordfence |
EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.
Scan My Website →