Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.
39,901 vulnerabilities found (page 647 of 1597)
| CVE ID | Plugin / Theme | Severity | CVSS | Description | Fixed In | Source |
|---|---|---|---|---|---|---|
| 6593b0de-db7a-4b7e-bd74-cc2b1e36ac60 | < 1.2.1 |
MEDIUM | 6.4 | The EmbedSocial – Social Media Feeds, Reviews and Galleries plugin for WordPress is vulnerable to Stored Cross-Site Sc… | — | wordfence |
| 658fdcf6-17e0-4cc7-accd-32c4e1e02779 | MEDIUM | 6.4 | The Codeless Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and inclu… | — | wordfence | |
| 6571a899-f217-434f-bbed-b1faf77a8d8b | < 4.25.2 |
MEDIUM | 6.4 | The Divi theme for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 4.25.1 d… | — | wordfence |
| 656c6236-55e6-4989-8f3d-2d2f81ab0093 | < 2.3 |
MEDIUM | 6.4 | The WP Masonry & Infinite Scroll plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'wmi… | — | wordfence |
| 656bf2b4-1930-4e96-b92b-01593889a43f | < 3.4.19 |
MEDIUM | 6.4 | Multiple XSS vulnerabilities in the Final Tiles Gallery plugin before 3.4.19 for WordPress allow remote attackers to inj… | — | wordfence |
| 65645065-5c17-45f5-9741-26aa2b5d8815 | MEDIUM | 6.4 | The Table of Contents Block plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and inc… | — | wordfence | |
| 655cd6ec-088f-4610-ae7f-76a959c290af | < 3.0.8 |
MEDIUM | 6.4 | The Edwiser Bridge – WordPress Moodle LMS Integration plugin for WordPress is vulnerable to Server-Side Request Forger… | — | wordfence |
| 655077b2-7152-4fc6-845d-068a5af730bb | < 5.3.4 |
MEDIUM | 6.4 | The Team Members plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 5.3… | — | wordfence |
| 65504747-7f1b-43f9-be4d-48b9547e7c45 | < 3.7.2 |
MEDIUM | 6.4 | The Content Views – Post Grid & Filter, Recent Posts, Category Posts, & More (Gutenberg Blocks and Shortcode) plugin f… | — | wordfence |
| 6543e6e2-e052-466e-ad19-656fd8d01805 | < 2.5.52 |
MEDIUM | 6.4 | The Supreme Modules Lite – Divi Theme, Extra Theme and Divi Builder plugin for WordPress is vulnerable to Stored Cross… | — | wordfence |
| 6543b8ad-e3f3-43c7-93f9-23f7df07e391 | MEDIUM | 6.4 | The StageShow plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘anchor’ parameter in all ve… | — | wordfence | |
| 65395034-0b20-462c-93ee-e755e5c888a4 | < 3.2.12 |
MEDIUM | 6.4 | The Strong Testimonials plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Testimonial Custom Fie… | — | wordfence |
| 651a7036-d421-41b7-91db-102e60d8274e | < 1.54.1 |
MEDIUM | 6.4 | The Schema & Structured Data for WP & AMP plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'sas… | — | wordfence |
| 650b5677-7c70-415f-81bf-12514393e4c9 | < 4.8.9 |
MEDIUM | 6.4 | The Bold Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's AI features all… | — | wordfence |
| 6500b559-4c26-47e8-b131-100ece3ca3bd | MEDIUM | 6.4 | The Partnerský systém Martinus plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'mar… | — | wordfence | |
| 64fe64aa-4f55-470d-960b-3b39a4912090 | < 1.7.2 |
MEDIUM | 6.4 | The SiteGround Email Marketing plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and … | — | wordfence |
| 64f3d36c-8211-4360-9235-3020395891a1 | < 1.5.7 |
MEDIUM | 6.4 | The Restaurant & Cafe Addon for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions … | — | wordfence |
| 64f30329-ecf2-4e30-bc23-9d447e239e08 | < 5.5.4 |
MEDIUM | 6.4 | The Bold Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin 'bt_bb_tabs' shor… | — | wordfence |
| 64f11bc9-88b5-43d5-bc76-129dc5909210 | < 3.5.5 |
MEDIUM | 6.4 | The Sina Extension for Elementor (Slider, Gallery, Form, Modal, Data Table, Tab, Particle, Free Elementor Widgets & Elem… | — | wordfence |
| 64f04129-c833-4c2e-a00d-d4e8e435f4a5 | < 2.25 |
MEDIUM | 6.4 | The PlayerJS plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.24 du… | — | wordfence |
| 64ed8547-0dc1-4f0a-8b0b-27ce20b8bbd6 | < 2.4.6 |
MEDIUM | 6.4 | The W4 Post List plugin for WordPress is vulnerable to Stored Cross-Site Scripting via block options in versions up to, … | — | wordfence |
| 64d6099e-2435-4a3a-9dcc-dba4a674c711 | < 2.0.7 |
MEDIUM | 6.4 | The Top and footer bars for announcements, notifications, advertisements, promotions – YooBar plugin for WordPress is … | — | wordfence |
| 64d4fec3-2477-4b0a-b05f-4836563fb4c0 | MEDIUM | 6.4 | The Advanced Blog Post Block plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and in… | — | wordfence | |
| 64d2d161-678a-4c0a-b0c5-c28a29a66a5b | < 2.6.0 |
MEDIUM | 6.4 | The Real Testimonials plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode in ve… | — | wordfence |
| 64d0c9f4-bc44-4349-977a-2ba3f12d7398 | MEDIUM | 6.4 | The iframe to embed plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, … | — | wordfence |
EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.
Scan My Website →