Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.
39,898 vulnerabilities found (page 581 of 1596)
| CVE ID | Plugin / Theme | Severity | CVSS | Description | Fixed In | Source |
|---|---|---|---|---|---|---|
| a44cde91-2f4d-40f1-98a1-ee6ed94c0155 | < 4.0.5 |
MEDIUM | 6.4 | The MainWP Google Analytics Extension plugin for WordPress is vulnerable to authorization bypass in versions up to, and … | — | wordfence |
| a443b20e-1686-4519-890d-e6f1838fb05c | < 4.3.0 |
MEDIUM | 6.4 | The Mega Addons For WPBakery Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plug… | — | wordfence |
| a43adbf2-0e85-4e70-a18f-8001a86b224e | < 3.3.5 |
MEDIUM | 6.4 | The Support Board WordPress plugin before 3.3.5 allows Authenticated (Agent+) users to perform Cross-Site Scripting atta… | — | wordfence |
| a42dce68-0e64-46a6-926e-b676071744b9 | < 2.5.17 |
MEDIUM | 6.4 | The My Calendar plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘event_time_label’ paramet… | — | wordfence |
| a427c798-f546-4ca1-98ab-32b433ee5b59 | < 3.9.15 |
MEDIUM | 6.4 | The EmbedPress – Embed PDF, Google Docs, Vimeo, Wistia, Embed YouTube Videos, Audios, Maps & Embed Any Documents in Gu… | — | wordfence |
| a4246181-d331-46b0-ad48-e2ece11b2f5f | < 3.11.5 |
MEDIUM | 6.4 | The Insert Pages plugin for WordPress is vulnerable to Stored Cross-Site Scripting via post custom field keys (meta key … | — | wordfence |
| a412e682-869a-46ba-a2d0-d84ed542adc9 | < 5.5.0 |
MEDIUM | 6.4 | The The Plus Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's ele… | — | wordfence |
| a3fbf26b-c7d8-4c44-b3c1-c4e028465a9e | < 1.6.8 |
MEDIUM | 6.4 | The Pixel Gallery Addons for Elementor – Easy Grid, Creative Gallery, Drag and Drop Grid, Custom Grid Layout, Portfoli… | — | wordfence |
| a3f22e95-4b2f-47d5-bb99-0c6497fed893 | < 1.1.29 |
MEDIUM | 6.4 | The Contact Form Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via form fields in all version… | — | wordfence |
| a3e61538-0bd9-4319-ba71-a72c9039f4d8 | < 2.4.8 |
MEDIUM | 6.4 | The Five Star Restaurant Reservations WordPress plugin before 2.4.8 does not have capability and CSRF checks in the rtb_… | — | wordfence |
| a3d14467-0c1d-4741-b533-37b9605c5fde | MEDIUM | 6.4 | The Sales Page Addon – Elementor & Beaver Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting in… | — | wordfence | |
| a3c323d5-59bc-4ecc-8211-2104fd22639f | MEDIUM | 6.4 | The iframe Shortcode plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in … | — | wordfence | |
| a3bb454c-ac0e-4915-8c6e-070596f7595a | < 4.9.0 |
MEDIUM | 6.4 | The All-in-One Video Gallery plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, an… | — | wordfence |
| a3b89d04-8a67-4744-a590-3b4dec830906 | MEDIUM | 6.4 | The Custom Content Scrollbar plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and in… | — | wordfence | |
| a3b5c7ec-eb6a-492e-962f-6ed47ee7f1f2 | < 3.1.20 |
MEDIUM | 6.4 | The Nextend Facebook Connect plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and i… | — | wordfence |
| a3b164e0-de2e-40d5-935e-31f5bebd87cf | < 2.0.8 |
MEDIUM | 6.4 | The WP-FormAssembly plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in v… | — | wordfence |
| a3ad7383-613b-4286-b1d3-ee12dc80fbe2 | < 1.0.20 |
MEDIUM | 6.4 | The Featured Video for WordPress – VideographyWP plugin for WordPress is vulnerable to Stored Cross-Site Scripting in … | — | wordfence |
| a3a3d97d-c01a-485b-80cd-f3195599e159 | < 1.9.3.2 |
MEDIUM | 6.4 | The If-So Dynamic Content Personalization plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions … | — | wordfence |
| a3a37e6a-659b-4a40-9051-9e8b3ca1ad42 | < 1.2.6 |
MEDIUM | 6.4 | Cross-site scripting (XSS) vulnerability in the SupportEzzy Ticket System plugin 1.2.5 for WordPress allows remote authe… | — | wordfence |
| a3845b4f-47c2-4b0b-af14-2d63bd74459c | < 1.5.2 |
MEDIUM | 6.4 | The DSGVO Youtube plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.… | — | wordfence |
| a3798336-e63b-4ede-9e4d-09a28249ea46 | < 1.3 |
MEDIUM | 6.4 | The LiveSmart Video Chat Live Video Chat plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugi… | — | wordfence |
| a36e599a-c8fb-42e2-acc0-d76a77dce336 | MEDIUM | 6.4 | The SEPA Girocode plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 0.… | — | wordfence | |
| a3659c4d-3a19-4f74-9f6d-26d7b24ebe56 | < 4.4.3 |
MEDIUM | 6.4 | The WpEvently plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multiple parameters in all versions … | — | wordfence |
| a362e60d-e4ab-4f19-9e18-5473d8e13d80 | < 2.0.5.6 |
MEDIUM | 6.4 | The Master Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and… | — | wordfence |
| a35b5dbd-6d29-404f-9363-a5787d35169c | MEDIUM | 6.4 | The Pastebin plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.5 due… | — | wordfence |
EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.
Scan My Website →