Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.
39,901 vulnerabilities found (page 658 of 1597)
| CVE ID | Plugin / Theme | Severity | CVSS | Description | Fixed In | Source |
|---|---|---|---|---|---|---|
| 5b77982e-15ab-4376-89d3-7a2609b118eb | < 5.10.3 |
MEDIUM | 6.4 | The Element Pack Elementor Addons (Header Footer, Template Library, Dynamic Grid, Carousel and Remote Arrows) plugin for… | — | wordfence |
| 5b74d6aa-ad59-42be-b454-9c27428cab01 | < 3.4.1 |
MEDIUM | 6.4 | The ElementsKit Elementor addons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Imag… | — | wordfence |
| 5b655b04-1f2f-4745-8237-7ef3f8e31ace | MEDIUM | 6.4 | The Betheme theme for WordPress is vulnerable to Stored Cross-Site Scripting via several of the plugin's shortcodes in a… | — | wordfence | |
| 5b624e9b-d21e-43d2-83ad-7760ed63a75c | < 2.6.9 |
MEDIUM | 6.4 | The Jeg Elementor Kit plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including… | — | wordfence |
| 5b494334-6feb-4a10-9636-3f1b1d0d5c66 | < 7.5.4 |
MEDIUM | 6.4 | The Sirv plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 7.5.3 due t… | — | wordfence |
| 5b33aa60-ac20-42c3-a3ab-b29ddfe2284a | < 3.1.1 |
MEDIUM | 6.4 | The Powerkit β Supercharge your WordPress Site plugin for WordPress is vulnerable to Stored Cross-Site Scripting via '… | — | wordfence |
| 5b3214a5-7044-4005-a200-c969d4487be2 | < 6.6.3 |
MEDIUM | 6.4 | The Essential Addons for Elementor β Popular Elementor Templates & Widgets plugin for WordPress is vulnerable to Store… | — | wordfence |
| 5b2e599c-48de-4d3a-94a3-b98badfb7a98 | MEDIUM | 6.4 | The QR Code for WooCommerce order emails, PDF invoices, packing slips plugin for WordPress is vulnerable to Stored Cross… | — | wordfence | |
| 5b2bef63-c871-45e4-bb05-12bbba20ca5e | < 6.2 |
MEDIUM | 6.4 | The Weaver Xtreme Theme for WordPress is vulnerable to stored Cross-Site Scripting due to insufficient escaping of the p… | — | wordfence |
| 5b17e416-7ca5-4447-ad7e-d3da2fddab86 | < 1.0.2 |
MEDIUM | 6.4 | The About Author Box WordPress plugin before 1.0.2 does not sanitise and escape the Social Profiles field values before … | — | wordfence |
| 5b16df88-7d9f-4ee2-90ab-6da50c69148e | MEDIUM | 6.4 | The QR Twitter Widget plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode in ve… | — | wordfence | |
| 5b15575f-0638-40ec-b152-20ba2225a725 | < 2.10.1.2 |
MEDIUM | 6.4 | The Beaver Builder Page Builder β Drag and Drop Website Builder plugin for WordPress is vulnerable to Stored Cross-Sit… | — | wordfence |
| 5afb3c3a-17d1-4cfb-9058-ae6a58e04c6b | < 2.4.2 |
MEDIUM | 6.4 | The collectchat plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.4.… | — | wordfence |
| 5af467b9-6974-4123-a3e3-67f1fcec01cf | MEDIUM | 6.4 | The Simple-Audioplayer plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and includin… | — | wordfence | |
| 5ac3ac02-d496-46cb-9aff-ffeeb8fd80fa | < 2.4.8 |
MEDIUM | 6.4 | The Ultimate FAQ Accordion plugin for WordPress is vulnerable to Stored Cross-Site Scripting via FAQ content in all vers… | — | wordfence |
| 5ac1145b-5ab1-47a9-9117-4870c52a70fc | < 2025.0 |
MEDIUM | 6.4 | The Advanced iFrame plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'advanced_iframe'… | — | wordfence |
| 5abf4742-c9db-449c-a814-c9a0abb19efc | MEDIUM | 6.4 | The Photographer Connections plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and in… | — | wordfence | |
| 5abae31f-2e1b-42c1-a8b0-6847aa853fb4 | MEDIUM | 6.4 | The Infusionsoft Web Form JavaScript plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to… | — | wordfence | |
| 5aab3dea-5d14-4316-9a4c-97b0d30762bf | MEDIUM | 6.4 | The Elementor Inline SVG plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all v… | — | wordfence | |
| 5a9db562-6810-4da1-9e5f-6f6eadca76ac | MEDIUM | 6.4 | The WP Easy Toggles plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'toggles' shortco… | — | wordfence | |
| 5a9c5f98-3457-443c-a87d-64f9c26b4f79 | < 3.0.0 |
MEDIUM | 6.4 | The "SoundPress Plugin" plugin for WordPress is vulnerable to Cross-Site Scripting in versions up to, and including, 2.6… | — | wordfence |
| 5a92916c-42d4-44a6-a9b7-ff0338042b2a | < 0.5.8.2 |
MEDIUM | 6.4 | The Off-Canvas Sidebars & Menus (Slidebars) plugin for WordPress is vulnerable to Stored Cross-Site Scripting in version… | — | wordfence |
| 5a922aa8-1625-44a9-b283-245e27e6db66 | MEDIUM | 6.4 | The Awesome Fitness Testimonials plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, an… | — | wordfence | |
| 5a91e786-f570-4c6c-b1c7-0110774cb808 | < 2.3.49 |
MEDIUM | 6.4 | The GeoDirectory β WordPress Business Directory Plugin, or Classified Directory plugin for WordPress is vulnerable to … | — | wordfence |
| 5a8f4ec8-d66e-4892-9770-67450aaa83d9 | < 2.10.0 |
MEDIUM | 6.4 | The HurryTimer β An Scarcity and Urgency Countdown Timer for WordPress & WooCommerce plugin for WordPress is vulnerabl… | — | wordfence |
EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.
Scan My Website →