Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.
39,898 vulnerabilities found (page 573 of 1596)
| CVE ID | Plugin / Theme | Severity | CVSS | Description | Fixed In | Source |
|---|---|---|---|---|---|---|
| ab650b99-ab15-4ddc-a622-cb43ab554ba7 | < 1.34.1 |
MEDIUM | 6.4 | The Schema & Structured Data for WP & AMP plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plug… | — | wordfence |
| ab63f507-6288-48e2-81c8-52b8a8c0c28c | MEDIUM | 6.4 | The Spin 360 deg and 3D Model Viewer plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to… | — | wordfence | |
| ab5f43c0-83d3-4d09-becd-a3552bebd609 | < 1.13.6 |
MEDIUM | 6.4 | The Elementor Addon Elements plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘url’ paramet… | — | wordfence |
| ab5e09d8-6fa3-4a5b-bee1-6648df4f4b3b | < 3.3.3 |
MEDIUM | 6.4 | The Visual Portfolio, Photo Gallery & Post Grid plugin for WordPress is vulnerable to Stored Cross-Site Scripting via th… | — | wordfence |
| ab5b7dc4-113d-4f58-956e-2a9284e1e25e | < 1.0.23 |
MEDIUM | 6.4 | The Email Address Encoder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's eae_shortco… | — | wordfence |
| ab518a1b-304d-4b93-b807-65ef3941dd47 | MEDIUM | 6.4 | The EG-Series plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's [series] shortcode in a… | — | wordfence | |
| ab4e8423-9169-4ea3-b519-522e858e8374 | MEDIUM | 6.4 | The Renden theme for WordPress is vulnerable to Stored Cross-Site Scripting via the post title in all versions up to, an… | — | wordfence | |
| ab478a98-3f76-4712-9a0f-99bfe27043e1 | < 6.19.5 |
MEDIUM | 6.4 | The SeedProd Pro plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to 6.19.5 due to insuf… | — | wordfence |
| ab4149e1-8378-4007-bbf2-1ac3c479e7ea | < 2.5 |
MEDIUM | 6.4 | The Code Embed plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's script embed functiona… | — | wordfence |
| ab3176b5-fa24-4e06-9c0f-f4b0db4998ef | MEDIUM | 6.4 | The Semantic Shortcode plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and includin… | — | wordfence | |
| ab29af00-587b-45ab-8be2-4a03d8039427 | < 5.4.2 |
MEDIUM | 6.4 | The Bold Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including… | — | wordfence |
| ab19f7b1-2b1e-43bc-9843-ddee0fc74f50 | < 1.0.48 |
MEDIUM | 6.4 | The SureTriggers – Connect All Your Plugins, Apps, Tools & Automate Everything! plugin for WordPress is vulnerable to … | — | wordfence |
| ab15fe2b-974c-41b0-ab6b-68322d2d3396 | < 5.5.0 |
MEDIUM | 6.4 | The The Plus Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the countdown wi… | — | wordfence |
| aafb5402-3553-4c89-86e0-4dd556d86074 | < 1.0.94 |
MEDIUM | 6.4 | The Booking for Appointments and Events Calendar – Amelia plugin for WordPress is vulnerable to Stored Cross-Site Scri… | — | wordfence |
| aade146b-029e-40c8-852f-879b6b57ee90 | < 2.1.15 |
MEDIUM | 6.4 | The Arconix Shortcodes plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and includin… | — | wordfence |
| aad6afb6-0098-4bdd-b002-9798547d27e4 | MEDIUM | 6.4 | The Stockholm theme for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 9.14.1 … | — | wordfence | |
| aad6151a-6897-4d0c-9dfb-0f424c683111 | MEDIUM | 6.4 | The Plugin README Parser plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘target’ paramete… | — | wordfence | |
| aace327b-7091-48e2-9e02-ec48a08b129b | < 5.7.2 |
MEDIUM | 6.4 | The Gutenberg Essential Blocks – Page Builder for Gutenberg Blocks & Patterns plugin for WordPress is vulnerable to St… | — | wordfence |
| aac9569e-d33d-45b3-bd03-2e7f48536ae5 | < 2.5.6 |
MEDIUM | 6.4 | The HT Mega – Absolute Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the … | — | wordfence |
| aac2b2a3-5d4f-449f-876c-d1bec295e088 | MEDIUM | 6.4 | The Integration with Hubspot Forms plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'hubspotfor… | — | wordfence | |
| aac15273-0a5d-4107-8249-7fff7f503005 | < 2.3.0 |
MEDIUM | 6.4 | The GenerateBlocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Headline Block 'linkMetaFieldTy… | — | wordfence |
| aabf1911-5c6f-4486-a750-d5c95f5815ba | MEDIUM | 6.4 | The Quick Social Login plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'quick-login' … | — | wordfence | |
| aab54795-31e7-4ef4-8a80-7443abaa3f21 | < 1.1.3 |
MEDIUM | 6.4 | The Passwordless Login plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and includin… | — | wordfence |
| aab33299-f02d-44a1-9522-5309eed6fd38 | < 3.30.0 |
MEDIUM | 6.4 | The Online Payments – Get Paid with PayPal, Square & Stripe plugin for WordPress is vulnerable to Stored Cross-Site Sc… | — | wordfence |
| aab18839-6edc-4f8f-8e1f-ae305a4ed6b3 | MEDIUM | 6.4 | The WPoperation Elementor Addons plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, an… | — | wordfence |
EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.
Scan My Website →