Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.
39,901 vulnerabilities found (page 645 of 1597)
| CVE ID | Plugin / Theme | Severity | CVSS | Description | Fixed In | Source |
|---|---|---|---|---|---|---|
| 674e6722-d293-4572-80bf-984e74c3e33f | < 7.6 |
MEDIUM | 6.4 | The wpbakery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Custom Heading tag attribute in a… | — | wordfence |
| 6748841a-0984-4840-90ba-0eeff8564198 | < 1.2.2 |
MEDIUM | 6.4 | The SALERT plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several parameters in versions up to, a… | — | wordfence |
| 6743a762-6d40-4ed9-95f2-f1b405683f26 | MEDIUM | 6.4 | The WP Company Info plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'class' attribute of the '… | — | wordfence | |
| 673f0910-8121-4344-b756-2ed5418fdc6b | MEDIUM | 6.4 | The Infinite theme for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘project_url’ parameter in all… | — | wordfence | |
| 672c7b4f-73f3-4133-8716-7733848298bd | < 2.3 |
MEDIUM | 6.4 | The Essential Widgets plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including… | — | wordfence |
| 6720e68e-16fc-48c2-ad56-1f44a3e78bb2 | < 2.5.8 |
MEDIUM | 6.4 | The Lpagery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via post titles in versions up to, and inc… | — | wordfence |
| 670ea03e-2f76-48a4-9f40-bc4cfd987a89 | < 1.1.4 |
MEDIUM | 6.4 | The Video PopUp plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'video_popup' shortcode in version… | — | wordfence |
| 67050673-73f5-4fc5-a9fc-576ab7ebd7a9 | < 3.1.3 |
MEDIUM | 6.4 | The WP Image Mask plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 3.… | — | wordfence |
| 6700e926-21c1-45c9-bca9-62ef0218e998 | MEDIUM | 6.4 | The Dynamic Featured Image plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘dfiFeatured’ p… | — | wordfence | |
| 67001e61-c7f5-46bc-9d32-b121ce5d6fd5 | MEDIUM | 6.4 | The esri-map-view plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's esri-map-view short… | — | wordfence | |
| 66f71440-59f4-4de4-b008-20bec4820489 | MEDIUM | 6.4 | The ElementsCSS Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to… | — | wordfence | |
| 66edd8e5-1d5e-425d-a4f4-5359683c1e36 | MEDIUM | 6.4 | The Simple Vimeo Shortcode plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘ylwm_vimeo’ sh… | — | wordfence | |
| 66e55302-f889-4054-817f-aadbdd3c88de | < 4.1 |
MEDIUM | 6.4 | The Get Custom Field Values plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Custom Meta fields in … | — | wordfence |
| 66dc7618-3d84-4a55-9bed-0f41415ed9e9 | < 3.0.0 |
MEDIUM | 6.4 | The Leaflet Map WordPress plugin before 3.0.0 does not escape some shortcode attributes before they are used in JavaScri… | — | wordfence |
| 66db1cd8-92c7-4d12-9f49-6fa5fbc98d6c | < 1.9.3 |
MEDIUM | 6.4 | The WP Last Modified Info plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and inclu… | — | wordfence |
| 66d77518-a258-4e79-b483-275855c0a416 | < 3.19.20.1 |
MEDIUM | 6.4 | The Ultimate Addons for WPBakery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's ulti… | — | wordfence |
| 66cad18d-a433-47f1-9cb6-c619c8717a0d | < 3.6.2 |
MEDIUM | 6.4 | The GD Rating System plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘extra_class’ paramet… | — | wordfence |
| 66c3c02c-0ef4-4d71-97fa-f7b786ae64b9 | MEDIUM | 6.4 | The WordPress Video plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, … | — | wordfence | |
| 66c0a19a-d94f-4de0-85a8-de7c7e489e33 | < 1.0.8 |
MEDIUM | 6.4 | The Blossom Recipe Maker plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several parameters in ver… | — | wordfence |
| 66bf7ac2-8f6b-4064-9474-f0f4192a8b33 | MEDIUM | 6.4 | The WebP & SVG Support plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all ver… | — | wordfence | |
| 66b86375-81e3-4ac8-90e3-8ae34c28c1c2 | MEDIUM | 6.4 | The Dropdown Menu Widget WordPress plugin through 1.9.7 does not have authorisation and CSRF checks when saving its sett… | — | wordfence | |
| 66b1f597-f357-4525-8c67-e0be3a07bcfa | < 5.9.8 |
MEDIUM | 6.4 | WordPress Core is vulnerable to Stored Cross-Site Scripting via the arrow navigation block attributes in versions betwee… | — | wordfence |
| 669e3015-b64c-440d-bc06-db4828c07196 | < 4.2.7 |
MEDIUM | 6.4 | The Puzzles theme for WordPress is vulnerable to Stored Cross-Site Scripting via shortcodes in versions up to, and inclu… | — | wordfence |
| 668621b0-67ef-44fc-a126-e8c4e372666e | < 1.13.7 |
MEDIUM | 6.4 | The Elementor Addon Elements plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multiple widgets in a… | — | wordfence |
| 667d964a-dba6-424a-b3f5-af433616c132 | < 2.9.1 |
MEDIUM | 6.4 | The BSK PDF Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘cat_title’ parameter … | — | wordfence |
EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.
Scan My Website →