Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.
39,901 vulnerabilities found (page 676 of 1597)
| CVE ID | Plugin / Theme | Severity | CVSS | Description | Fixed In | Source |
|---|---|---|---|---|---|---|
| 4b42ba6a-b618-4633-9372-879c3253a956 | < 4.1.4 |
MEDIUM | 6.4 | The WC Marketplace plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 4… | — | wordfence |
| 4b3380a1-ef0f-471f-b016-16f3431fb619 | MEDIUM | 6.4 | The SimaCookie plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.3.2… | — | wordfence | |
| 4b32e8b6-0365-411c-b262-12fe46521b73 | < 4.2.4 |
MEDIUM | 6.4 | The افزونه حمل و نقل ووکامرس (پست پیشتاز و سفارشی، پیک موتوری) plugin for … | — | wordfence |
| 4b2fa1b7-a5af-4ea6-9bee-19a6cdfd7701 | < 28.1 |
MEDIUM | 6.4 | The Yoast SEO – Advanced SEO with real-time guidance and built-in AI plugin for WordPress is vulnerable to Stored Cros… | — | wordfence |
| 4b1944a9-4bc4-4ac2-83c3-55d6d61f405c | < 1.1.4 |
MEDIUM | 6.4 | The WP Google Street View (with 360° virtual tour) & Google maps + Local SEO plugin for WordPress is vulnerable to Stor… | — | wordfence |
| 4b1568d6-4fea-4ed3-9931-f293932eaa3a | < 0.9.32 |
MEDIUM | 6.4 | The Power's WHOIS Domain Check plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several parameters … | — | wordfence |
| 4b0f0db2-13bc-48fd-b78c-9e0eb644aec1 | MEDIUM | 6.4 | The GMap Shortcode plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2… | — | wordfence | |
| 4b002e40-712d-4c3f-b168-9132e7b77e60 | < 1.3.2 |
MEDIUM | 6.4 | The Easy!Appointments plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'easyappointmen… | — | wordfence |
| 4afc8de7-0d7e-4dee-972e-3eb707cd7b2b | MEDIUM | 6.4 | The Beek Widget Extention plugin for WordPress is vulnerable to Stored Cross-Site Scripting via shortcodes in versions u… | — | wordfence | |
| 4afbe34b-121e-41d2-ab12-c3d70a0d80d5 | < 1.5.6 |
MEDIUM | 6.4 | The Better Comments plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'nickname' field in all ve… | — | wordfence |
| 4afa0148-ad08-493d-9642-0edbde5e8349 | < 1.3 |
MEDIUM | 6.4 | The Ragic Shortcode plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'ragic' shortcode… | — | wordfence |
| 4af9c623-1539-4afc-9dcd-3f97d29aa4f3 | < 1.11.16 |
MEDIUM | 6.4 | The Easy Google Maps plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's file upload feat… | — | wordfence |
| 4af762d6-bc93-4724-b27d-4873a8bb4f38 | < 7.8.1 |
MEDIUM | 6.4 | The miniOrange Social Login and Register (Discord, Google, Twitter, LinkedIn) plugin for WordPress is vulnerable to Stor… | — | wordfence |
| 4af66bb2-febe-4022-9526-39b1ecd8b01d | < 2.1.7 |
MEDIUM | 6.4 | The Site Search 360 plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'ss360-resultbloc… | — | wordfence |
| 4af2f136-5806-4d5e-a72d-486c4839a695 | < 2.1.5 |
MEDIUM | 6.4 | The The Pack Elementor addon plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘slider_options… | — | wordfence |
| 4af04219-26c5-401d-94ef-11d2321f98bf | < 3.5.1 |
MEDIUM | 6.4 | The Sponsors plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'sponsors' shortcode in … | — | wordfence |
| 4aebd497-d3c7-4a85-bde4-07e8eade836f | < 2.16.10 |
MEDIUM | 6.4 | The Seraphinite Post .DOCX Source plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up t… | — | wordfence |
| 4ac7c825-aa5e-42fb-b1df-8be72945941c | MEDIUM | 6.4 | The Catch Popup plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'catch-popup' shortco… | — | wordfence | |
| 4ac57705-24ce-44b5-95d9-972bf58e4cd1 | < 2.8.2 |
MEDIUM | 6.4 | The Page Builder: KingComposer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via an unknown paramete… | — | wordfence |
| 4ac29d1c-0aae-4355-90df-24c99d23c411 | < 3.1.1 |
MEDIUM | 6.4 | Cross-site scripting (XSS) vulnerability in WordPress before 3.1.1 allows remote attackers to inject arbitrary web scrip… | — | wordfence |
| 4ab53ebb-c18e-4791-b4dc-84b84aea65c6 | < 3.0.0 |
MEDIUM | 6.4 | The Nepali Date Converter plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and inclu… | — | wordfence |
| 4aa09e5b-fc3d-4409-bf2c-dd8aae69eeda | MEDIUM | 6.4 | The quote-posttype-plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Author field in all … | — | wordfence | |
| 4aa04db0-8878-42b7-a923-03257230a7c1 | MEDIUM | 6.4 | The PhotoShelter for Photographers Blog Feed Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting in… | — | wordfence | |
| 4a920dd5-e4a0-4bc3-8eb8-58069d0ae336 | MEDIUM | 6.4 | The Font Awesome WP plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, … | — | wordfence | |
| 4a9021b4-54f8-4ba3-bc81-49271dde1b44 | MEDIUM | 6.4 | The Contact Form and Calls To Action by vcita plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the … | — | wordfence |
EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.
Scan My Website →