Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.
39,901 vulnerabilities found (page 678 of 1597)
| CVE ID | Plugin / Theme | Severity | CVSS | Description | Fixed In | Source |
|---|---|---|---|---|---|---|
| 49589caf-232b-4067-a607-2902e932553e | MEDIUM | 6.4 | The Clients plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.1.4 du… | — | wordfence | |
| 49581614-14a8-4450-8f83-d8d22a3feee9 | < 2.0.79 |
MEDIUM | 6.4 | The Radio Player β Live Shoutcast, Icecast and Any Audio Stream Player for WordPress plugin for WordPress is vulnerabl… | — | wordfence |
| 4956eb18-92b8-4ba3-89a8-71edf08dc502 | < 4.1.1 |
MEDIUM | 6.4 | The Better Search plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 4.… | — | wordfence |
| 49460db5-a0cd-4b29-85f2-8ededabf5599 | MEDIUM | 6.4 | The Social Proof (Testimonial) Slider plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's… | — | wordfence | |
| 491c7680-d270-41ed-a756-9397a0bd86bc | MEDIUM | 6.4 | The Charts Ninja: Create Beautiful Graphs & Charts and Easily Add Them to Your Website plugin for WordPress is vulnerabl… | — | wordfence | |
| 4917652a-1c83-4570-98c5-1a34e637814e | < 6.2.3 |
MEDIUM | 6.4 | The Essential Addons for Elementor β Popular Elementor Templates & Widgets plugin for WordPress is vulnerable to DOM-B… | — | wordfence |
| 490944a6-96e8-4416-a63b-c7a7ba9172ae | < 1.13.7 |
MEDIUM | 6.4 | The Clean Login plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcodes in version… | — | wordfence |
| 49005688-fa40-458d-9c96-5ec2ca7adcd3 | MEDIUM | 6.4 | The Visualmodo Elements plugin for WordPress is vulnerable to Stored Cross-Site Scripting via REST API SVG File uploads … | — | wordfence | |
| 48fdece5-2996-426f-b77c-ae0b35bcd0ce | < 4.10.29 |
MEDIUM | 6.4 | The Premium Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's post… | — | wordfence |
| 48fa5f3b-000b-406e-b7ee-51af5720cf72 | < 2.9.13 |
MEDIUM | 6.4 | The Premium Addons PRO plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's IHover widget … | — | wordfence |
| 48f42d27-18eb-4606-beb5-c3bfe9f72647 | MEDIUM | 6.4 | The News, Magazine and Blog Elements plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to… | — | wordfence | |
| 48ee5ef5-0fac-496d-b770-91aa846ed5a9 | < 7.9 |
MEDIUM | 6.4 | The WP Visitor Statistics (Real Time Traffic) plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all v… | — | wordfence |
| 48e62d66-d058-419c-93cf-0cb890177751 | MEDIUM | 6.4 | The Skip to Timestamp plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'skipto' shortcode in al… | — | wordfence | |
| 48e2129f-6a2c-45e4-a0cf-7d8d5f563a7f | < 5.3.6 |
MEDIUM | 6.4 | The Modal Window plugin for WordPress is vulnerable to Stored Cross-Site Scripting via shortcodes in versions up to, and… | — | wordfence |
| 48c114d7-3d53-4157-a335-19cf4b47eed5 | MEDIUM | 6.4 | The Simple Football Scoreboard plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'ytmr_fb_scoreb… | — | wordfence | |
| 48bf9bf4-1b8a-41cc-adc9-a618d075c7f2 | < 6.4.0 |
MEDIUM | 6.4 | The Modern Events Calendar Lite WordPress plugin before 6.4.0 does not sanitize and escape some of the Hourly Schedule p… | — | wordfence |
| 48b9f3e3-b7fd-4d7c-8f8b-b11ed977aa92 | < 17.6.0 |
MEDIUM | 6.4 | The Surbma | GDPR Proof Cookie Consent & Notice Bar plugin for WordPress is vulnerable to Stored Cross-Site Scripting in… | — | wordfence |
| 48b66fb1-2b3e-499d-bf1f-3c445f4b5e3a | MEDIUM | 6.4 | The AchillesTheme-shortcodes plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and in… | — | wordfence | |
| 48b47968-e853-4f32-b66e-8a25e1d7009d | < 2.7.7 |
MEDIUM | 6.4 | The FluentCommunity β Ultra-Fast High-Performance Social Network, Community, LMS & Online Courses plugin for WordPress… | — | wordfence |
| 48a13fb7-bf1a-4bf2-ac3b-3b5a75fec616 | < 2.6.5 |
MEDIUM | 6.4 | The Jeg Elementor Kit plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the countdown widget's attri… | — | wordfence |
| 4890cd48-a448-4af1-ae1e-6456300434e5 | < 5.5.3 |
MEDIUM | 6.4 | The The Plus Addons for Elementor β Elementor Addons, Page Templates, Widgets, Mega Menu, WooCommerce plugin for WordP… | — | wordfence |
| 488ac848-786e-4100-a387-5a40e8fc4175 | < 3.6.2 |
MEDIUM | 6.4 | The ElementsKit Pro plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the βurlβ parameter in ver… | — | wordfence |
| 487731cd-da5a-45b6-8f39-4ae6420dd252 | < 4.15.9 |
MEDIUM | 6.4 | The ProfilePress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ProfilePress User Panel widge… | — | wordfence |
| 4876e05e-efa6-46c6-832b-9ecc42934998 | < 8.3.5 |
MEDIUM | 6.4 | The Newsletter plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'np1' parameter in all versions… | — | wordfence |
| 486ffdc9-a3e7-4f4c-89b1-b668a5d41aa5 | MEDIUM | 6.4 | The WP Radio β Worldwide Online Radio Stations Directory for WordPress plugin for WordPress is vulnerable to Stored Cr… | — | wordfence |
EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.
Scan My Website →