Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.
39,901 vulnerabilities found (page 677 of 1597)
| CVE ID | Plugin / Theme | Severity | CVSS | Description | Fixed In | Source |
|---|---|---|---|---|---|---|
| 4a8ac027-f376-4f02-a085-f05f1fa749f0 | MEDIUM | 6.4 | The Elemenda plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up t… | — | wordfence | |
| 4a89c812-a643-47c0-bd33-cfb2389a7646 | < 1.10.3 |
MEDIUM | 6.4 | The Delicious Recipes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'steps' block attribute … | — | wordfence |
| 4a75444e-b1e4-41e0-9209-07ded65c1498 | MEDIUM | 6.4 | The Go Night Pro | WordPress Dark Mode Plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin'… | — | wordfence | |
| 4a7345a1-ceb5-4f93-a6ba-13e8b8fb6c7d | < 4.0.3 |
MEDIUM | 6.4 | The MainWP Clone Extension plugin for WordPress is vulnerable to authorization bypass in versions up to, and including, … | — | wordfence |
| 4a4e1d08-a61d-40b8-bfbb-c112c77dd412 | MEDIUM | 6.4 | The best bootstrap widgets for elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions u… | — | wordfence | |
| 4a4c745b-f489-417c-8004-ead131a7a6c6 | < 6.4.23 |
MEDIUM | 6.4 | The Business Directory Plugin – Easy Listing Directories for WordPress plugin for WordPress is vulnerable to Stored Cr… | — | wordfence |
| 4a433565-0896-4ba9-a718-9507c6c4ba58 | < 1.1.6 |
MEDIUM | 6.4 | The StreamWeasels Kick Integration plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘vodsChan… | — | wordfence |
| 4a2ef416-4354-4e09-b9be-e36c1f655110 | < 4.1.11 |
MEDIUM | 6.4 | The Prime Slider – Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'fol… | — | wordfence |
| 4a1e77de-0207-412d-857d-ab6947116669 | < 2.5.1 |
MEDIUM | 6.4 | Cross-site scripting (XSS) vulnerability in WordPress 2.5 allows remote attackers to inject arbitrary web script or HTML… | — | wordfence |
| 4a13c7a1-f904-41b1-ab7f-2df95c9b2880 | < 2.7.2.1 |
MEDIUM | 6.4 | The Beaver Builder – WordPress Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via sett… | — | wordfence |
| 4a13b13e-72d3-43c9-b5ec-d499f3b22091 | < 1.0.6.5 |
MEDIUM | 6.4 | The Active Products Tables for WooCommerce. Use constructor to create tables plugin for WordPress is vulnerable to Store… | — | wordfence |
| 4a0c744a-d4b0-45f4-9434-06ce3dec4d75 | MEDIUM | 6.4 | The Spotify Embed Creator plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'spotify' s… | — | wordfence | |
| 49f01cc7-6e64-45cc-bc54-b263e47fe1a3 | MEDIUM | 6.4 | The Ronneby Theme Core plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and includin… | — | wordfence | |
| 49ef0bfe-9bdf-4117-81f7-1ec73b5247ae | < 2.14.24 |
MEDIUM | 6.4 | The Modula Image Gallery – Photo Grid & Video Gallery plugin for WordPress is vulnerable to Stored Cross-Site Scriptin… | — | wordfence |
| 49e9436b-c5b1-4373-bca5-60f718abba26 | MEDIUM | 6.4 | The AnyClip Luminous Studio plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and inc… | — | wordfence | |
| 49cf047f-4e8c-4f37-b8c0-d931c02fda7c | < 3.8.2 |
MEDIUM | 6.4 | The Fruitful Theme for WordPress is vulnerable to Stored Cross-Site Scripting via several parameters stored via the frui… | — | wordfence |
| 49cb8324-2245-4f7d-b289-d2313af4642e | < 5.3.7 |
MEDIUM | 6.4 | The Event Booking Manager for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions … | — | wordfence |
| 49b76f5f-03f7-48bc-b848-9ab55d875639 | MEDIUM | 6.4 | The ZoomSounds plugin for WordPress is vulnerable to Stored Cross-Site Scripting via shortcodes in versions up to, and i… | — | wordfence | |
| 49a9ade1-fca7-48c1-bb87-75fc3528e234 | < 1.2 |
MEDIUM | 6.4 | The Easy SVG Upload plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versio… | — | wordfence |
| 4999bbf3-3dbd-4c9a-b648-744192c9586c | < 5.0.3 |
MEDIUM | 6.4 | The Bold Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's bt_bb_button sh… | — | wordfence |
| 49958e9e-7f9b-48fb-bfe2-5b1b437171d6 | < 1.2.0 |
MEDIUM | 6.4 | The BMLT Tabbed Map plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'bmlt_tabbed_map'… | — | wordfence |
| 49945253-b631-47b2-9cbd-42c9effc60f4 | < 2.2.7 |
MEDIUM | 6.4 | The Donation Thermometer plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and includ… | — | wordfence |
| 498c0080-ae5e-492b-b75f-6ce3227f3ca0 | < 3.1.2 |
MEDIUM | 6.4 | The Paytium plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'get_field_data_html()' function i… | — | wordfence |
| 49816cc8-fc97-4ba2-88b6-3fe6f7bf562e | < 2.1.2 |
MEDIUM | 6.4 | The StatCounter – Free Real Time Visitor Stats plugin for WordPress is vulnerable to Stored Cross-Site Scripting in ve… | — | wordfence |
| 497e0784-8953-4726-929a-7d5ef129e98e | < 1.6.8 |
MEDIUM | 6.4 | The Formzu WP plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in all ver… | — | wordfence |
EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.
Scan My Website →