Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.
39,901 vulnerabilities found (page 672 of 1597)
| CVE ID | Plugin / Theme | Severity | CVSS | Description | Fixed In | Source |
|---|---|---|---|---|---|---|
| 4ea939f5-8b56-44be-bd20-b69e9ded5970 | < 4.2.25 |
MEDIUM | 6.4 | The Passster β Password Protect Pages and Content plugin for WordPress is vulnerable to Stored Cross-Site Scripting vi… | — | wordfence |
| 4ea634b5-72db-428c-96b4-15ef6025ab1d | < 1.52.2 |
MEDIUM | 6.4 | The Advanced Ads βΒ Ad Manager & AdSense plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Adv… | — | wordfence |
| 4e9f16e1-9748-4f5d-84f0-19da68d4f862 | MEDIUM | 6.4 | The Tour & Activity Operator Plugin for TourCMS plugin for WordPress is vulnerable to Stored Cross-Site Scripting via th… | — | wordfence | |
| 4e9e9afc-89a0-444d-ad5b-975e0f3c19d5 | < 2.5.1 |
MEDIUM | 6.4 | The Bootstrap Blocks for WP Editor v2 plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'gtb-boo… | — | wordfence |
| 4e97e603-b864-41ef-98c8-b0304a72ec44 | MEDIUM | 6.4 | The BootStrap Shortcodes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'class' and 'id' para… | — | wordfence | |
| 4e9563b8-7e1b-4e87-8b56-17b75adb66c3 | < 0.2.3 |
MEDIUM | 6.4 | The Markdown Shortcode plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'markdown' sho… | — | wordfence |
| 4e8ca12e-b7a7-416a-b37d-c1672375a52d | < 2.3.9 |
MEDIUM | 6.4 | The OnePress theme for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.3.8 du… | — | wordfence |
| 4e780461-3fda-491d-ac77-dee52f8197b3 | < 3.7.0 |
MEDIUM | 6.4 | The Insert Pages WordPress plugin before 3.7.0 adds a shortcode that prints out other pages' content and custom fields. … | — | wordfence |
| 4e620ae8-03fc-43b5-8e8f-5b0884e8eefb | < 6.3.1 |
MEDIUM | 6.4 | The RumbleTalk Live Group Chat β HTML5 plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugi… | — | wordfence |
| 4e4a605e-542b-4001-84d8-0a0aad044798 | < 3.0 |
MEDIUM | 6.4 | The Simple YouTube Responsive plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortco… | — | wordfence |
| 4e498706-3dbe-4c48-9c0d-0d90677aba0d | < 2.20.2 |
MEDIUM | 6.4 | The Gift Up Gift Cards for WordPress and WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting v… | — | wordfence |
| 4e481e81-f581-48f7-b699-0be85e099c84 | < 1.1.7 |
MEDIUM | 6.4 | The MAS Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.… | — | wordfence |
| 4e3d0ffd-209b-4e29-bc1d-91f2498b4632 | MEDIUM | 6.4 | The Piotnet Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'PAFE Before … | — | wordfence | |
| 4e2603e2-a89c-4fb1-b219-6cf5a7560bea | < 1.7.8 |
MEDIUM | 6.4 | The Coupons & Add to Cart by URL Links for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scrip… | — | wordfence |
| 4e1cd584-ffb8-43d6-a7b6-141c59ac463d | < 1.5.2 |
MEDIUM | 6.4 | The WishSuite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'button_text' parameter of the '… | — | wordfence |
| 4e1c2d20-013e-4cad-865d-287924c18673 | < 1.3.5 |
MEDIUM | 6.4 | The UiCore Elements plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, … | — | wordfence |
| 4e0fd492-19ee-430e-a495-99ad28043bf9 | < 1.2.24 |
MEDIUM | 6.4 | The VK Google Job Posting Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Job Descript… | — | wordfence |
| 4e0424f8-f60f-49c3-9969-a88c830dc0e2 | < 3.2.13 |
MEDIUM | 6.4 | The Robo Gallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in vers… | — | wordfence |
| 4dfc237a-9157-4da9-ba8f-9daf2ba4f20b | < 2.7.0 |
MEDIUM | 6.4 | The Contact Form and Calls To Action by vcita plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the … | — | wordfence |
| 4df635b8-4c56-4b24-8446-8e39e6fe7441 | < 3.7.28 |
MEDIUM | 6.4 | In WordPress before 4.9.9 and 5.x before 5.0.1, when the Apache HTTP Server is used, authors could upload crafted files … | — | wordfence |
| 4df5bd44-3f72-4ca3-981e-9c11c9e6ab42 | MEDIUM | 6.4 | The Real Estate Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and includi… | — | wordfence | |
| 4decc923-dda8-4aed-b431-1718ad39c376 | < 1.0.52 |
MEDIUM | 6.4 | The Flexible Refund for WooCommerce β EU One Click Return plugin for WordPress is vulnerable to Stored Cross-Site Scri… | — | wordfence |
| 4deb1527-0637-44f2-b336-d0cf2a48fa52 | < 4.7.0 |
MEDIUM | 6.4 | The WP ULike plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'wp_ulike' shortcode in … | — | wordfence |
| 4deae680-4829-4e24-b67b-4066ec9ce4da | < 2.0.6 |
MEDIUM | 6.4 | Cross-site scripting (XSS) vulnerability in wp-admin/templates.php in WordPress 2.0.5 allows remote attackers to inject … | — | wordfence |
| 4ddd9cab-f381-4343-a2e6-ef8a1be2ed4e | MEDIUM | 6.4 | The Ultimate TinyMCE plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'field' shortcode in all … | — | wordfence |
EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.
Scan My Website →