Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.
39,898 vulnerabilities found (page 580 of 1596)
| CVE ID | Plugin / Theme | Severity | CVSS | Description | Fixed In | Source |
|---|---|---|---|---|---|---|
| a4eeaf05-ec86-4d99-bc00-81f7f99e88ce | < 5.2.8 |
MEDIUM | 6.4 | The Featured Image from URL (FIFU) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via a post's Featur… | — | wordfence |
| a4e982d1-7ad9-490e-b606-695cafbc7f0b | MEDIUM | 6.4 | The Steam Group Viewer WordPress plugin through 2.1 does not sanitise or escape its "Steam Group Address" settings befor… | — | wordfence | |
| a4d16ccd-149a-4f70-84b4-59429827baa5 | < 2.9.29 |
MEDIUM | 6.4 | The Gravity Forms plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including… | — | wordfence |
| a4ccc7f8-c8e0-457a-b437-2a23530a9df4 | < 2.4.1 |
MEDIUM | 6.4 | The Better Messages – Live Chat for WordPress, BuddyPress, PeepSo, Ultimate Member, BuddyBoss plugin for WordPress is … | — | wordfence |
| a4cad5b2-eb0f-41f8-b43b-fcb70d185c25 | MEDIUM | 6.4 | The Fitness Park theme for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.1.… | — | wordfence | |
| a4c7c932-5955-4fce-a64d-3b5c5de95356 | < 1.3.14 |
MEDIUM | 6.4 | The Video Gallery – YouTube Playlist, Channel Gallery by YotuWP plugin for WordPress is vulnerable to Local File Inclu… | — | wordfence |
| a4c480be-0987-4ce2-ac6c-c08d02786398 | < 6.1 |
MEDIUM | 6.4 | The Penci Shortcodes & Performance plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to 6… | — | wordfence |
| a4b89902-5616-443f-b67d-bf3330308ef9 | MEDIUM | 6.4 | Multiple Authenticated (contributor or higher user role) Stored Cross-Site Scripting (XSS) vulnerabilities in Nicdark d.… | — | wordfence | |
| a4b44d89-6f1e-4a23-91ea-e79fc3221183 | < 3.1.7 |
MEDIUM | 6.4 | The ColorMag theme for WordPress is vulnerable to Stored Cross-Site Scripting via a user's Display Name in all versions … | — | wordfence |
| a4b353bf-f9be-465a-8723-9ea721b5baab | < 1.7.1 |
MEDIUM | 6.4 | The Royal Elementor Addons plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and incl… | — | wordfence |
| a4a0bf16-1a13-4955-8198-fa195fb65905 | < 1.0.48 |
MEDIUM | 6.4 | The Amelia WordPress plugin before 1.0.48 does not have proper authorisation when handling Amelia SMS service, allowing … | — | wordfence |
| a49f8150-a27d-4801-8923-31af335c3cbd | < 2.17.11 |
MEDIUM | 6.4 | The Phlox theme for WordPress is vulnerable to Stored Cross-Site Scripting via the `data-caption` HTML attribute in all … | — | wordfence |
| a49eaeb9-1395-4ec3-b030-1de898ad0769 | < 2.0.6 |
MEDIUM | 6.4 | The B Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.0.5 d… | — | wordfence |
| a49e4f5a-ac9d-4f9b-8de2-c7871da8de35 | < 2.7.4.3 |
MEDIUM | 6.4 | The Beaver Builder – WordPress Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the … | — | wordfence |
| a49ba7e1-ef85-43d6-8685-4cb4e6b7208e | < 2.1.0 |
MEDIUM | 6.4 | The Master Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and… | — | wordfence |
| a49773ea-981a-4667-a56f-577db0fbf9c7 | MEDIUM | 6.4 | The WP-Revive Adserver plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and includin… | — | wordfence | |
| a496d065-5821-4128-9363-79f388fdd246 | < 3.0.7 |
MEDIUM | 6.4 | The Database for Contact Form 7 plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and… | — | wordfence |
| a47df134-21e1-4e36-b1b7-ea3e3115f0b6 | < 1.4.8 |
MEDIUM | 6.4 | The Attesa Extra plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.4… | — | wordfence |
| a47d79c1-ff14-4185-a088-25a65990a993 | MEDIUM | 6.4 | The Power BI Embedded for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to,… | — | wordfence | |
| a47c5496-2647-47f0-a772-b4e406a51c09 | < 2.0.0 |
MEDIUM | 6.4 | The Pretty Google Calendar plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and incl… | — | wordfence |
| a4601d9e-02bb-4b27-b16e-7cfc0fc19919 | < 1.6.6 |
MEDIUM | 6.4 | The RTMKit Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Accor… | — | wordfence |
| a459bc57-0442-42bc-b60c-6eaf43aac7a6 | MEDIUM | 6.4 | The Glossy Blog theme for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.0.3… | — | wordfence | |
| a4541890-4c0d-4348-91df-42cf4b575514 | < 2.15.6 |
MEDIUM | 6.4 | The Shortcodes and extra features for Phlox theme plugin for WordPress is vulnerable to Stored Cross-Site Scripting via … | — | wordfence |
| a45417ce-d5dd-4706-adbb-d44670de6eb7 | < 1.4.1 |
MEDIUM | 6.4 | The OpenSheetMusicDisplay plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘className’ para… | — | wordfence |
| a452cb6f-8381-4f23-b808-3473db159894 | < 0.7.5 |
MEDIUM | 6.4 | The EmbedStories plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in ver… | — | wordfence |
EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.
Scan My Website →