Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.
39,901 vulnerabilities found (page 683 of 1597)
| CVE ID | Plugin / Theme | Severity | CVSS | Description | Fixed In | Source |
|---|---|---|---|---|---|---|
| 4473d3f6-e324-40f5-b92b-167f76b17332 | < 3.19.0 |
MEDIUM | 6.4 | The Elementor Website Builder – More than Just a Page Builder plugin for WordPress is vulnerable to Reflected Cross-Si… | — | wordfence |
| 446fadbc-b927-4245-9095-fd545a906b9a | MEDIUM | 6.4 | The History Timeline plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including,… | — | wordfence | |
| 446c7cb2-4050-4414-ba3c-f832ea7d6c5c | MEDIUM | 6.4 | The Posts Search plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.2… | — | wordfence | |
| 446aa338-b020-431d-a68b-b8239de3150c | MEDIUM | 6.4 | The Email Inquiry & Cart Options for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting in ve… | — | wordfence | |
| 4457d15e-2c01-498d-b94a-a6e93adcf70c | < 1.0.18 |
MEDIUM | 6.4 | The JetWidgets For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘layout_type’… | — | wordfence |
| 444f6a49-9d7a-4661-bab7-06d16f5f0317 | MEDIUM | 6.4 | The The Great Firewords of China plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to… | — | wordfence | |
| 44445c44-5ae0-4f2b-8096-aa94ae5ff0b6 | < 2.9.2 |
MEDIUM | 6.4 | The Create theme for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.9.1 due … | — | wordfence |
| 443f0664-cc9c-4e82-bde3-72cbab285cc7 | MEDIUM | 6.4 | The Elegant Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1… | — | wordfence | |
| 443d2e80-31db-40ac-9c35-88eec841ebba | < 2.4.0 |
MEDIUM | 6.4 | The Tracking Code Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the tracking code field … | — | wordfence |
| 443cfb7b-4566-4a71-ac31-5a5361c58aa2 | < 1.3.3 |
MEDIUM | 6.4 | The Discover the Best Woocommerce Product Brands Plugin for WordPress – Woocommerce Brands Plugin plugin for WordPress… | — | wordfence |
| 443ceb13-bc6e-4d8d-a415-1a0d4fecf38e | < 2.0.5 |
MEDIUM | 6.4 | The ConvertKit plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcodes in versions… | — | wordfence |
| 443c314f-c767-4169-bfdd-5d6c2d61dd39 | MEDIUM | 6.4 | The (dp) AddThis plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.0… | — | wordfence | |
| 44370988-3c55-490e-b428-da9cb6df1a4b | < 1.13 |
MEDIUM | 6.4 | The CPT Bootstrap Carousel plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode … | — | wordfence |
| 44362245-a3af-46a5-b35b-eabd5f537fca | MEDIUM | 6.4 | The Ird Slider plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'irdslider' shortcode … | — | wordfence | |
| 442995ed-bf92-4fa7-a0a2-341cb87d8fbb | < 4.5 |
MEDIUM | 6.4 | The Embed Calendly plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 4… | — | wordfence |
| 441bc9fe-3dd6-40a6-b7f3-36511115c083 | < 7.7.10 |
MEDIUM | 6.4 | The LayerSlider plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 7.7.… | — | wordfence |
| 44132f7b-31d4-46e9-8441-e27f0f4c5789 | < 1.0.8 |
MEDIUM | 6.4 | The Active Products Tables for WooCommerce. Use constructor to create tables plugin for WordPress is vulnerable to Sto… | — | wordfence |
| 440242e5-832f-4796-9317-b377e1c2fa2a | < 3.6.2 |
MEDIUM | 6.4 | An issue was discovered in the All in One SEO Pack plugin before 3.6.2 for WordPress. The SEO Description and Title fiel… | — | wordfence |
| 43fc4752-7a47-480c-82e2-54821e754f7f | MEDIUM | 6.4 | The Advanced Most Recent Posts Mod plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, … | — | wordfence | |
| 43f976ee-cba7-4f5d-b9c6-a6f66c0011d2 | < 1.8.6 |
MEDIUM | 6.4 | The Export any WordPress data to XML/CSV plugin for WordPress is vulnerable to Remote Code Execution in versions up to 1… | — | wordfence |
| 43f1a954-df53-46c6-9ecf-5fd50f490cfb | < 1.6.2 |
MEDIUM | 6.4 | The Better Post & Filter Widgets for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting in vers… | — | wordfence |
| 43e52adf-387c-452d-96b4-aad459fa75b3 | MEDIUM | 6.4 | The BuddyHolis ListSearch plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'listsearch… | — | wordfence | |
| 43d141e3-1e62-4126-b914-bdc98577de3f | MEDIUM | 6.4 | The Easy Org Chart plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 3… | — | wordfence | |
| 43ca15b7-8cb4-427f-892d-15022da17b2e | MEDIUM | 6.4 | The TCBD Tooltip plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'tcbdtooltip_text' s… | — | wordfence | |
| 43bc48a5-d97c-48ad-a80d-07f327ee859b | MEDIUM | 6.4 | The Simple Pricing Table plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and includ… | — | wordfence |
EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.
Scan My Website →