Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.
39,901 vulnerabilities found (page 685 of 1597)
| CVE ID | Plugin / Theme | Severity | CVSS | Description | Fixed In | Source |
|---|---|---|---|---|---|---|
| 43039c47-a34f-4020-9009-473e93468e21 | < 3.0.2 |
MEDIUM | 6.4 | Multiple cross-site scripting (XSS) vulnerabilities in the request_filesystem_credentials function in wp-admin/includes/… | — | wordfence |
| 43014ecd-72d9-44cc-be24-c0c9790ddc20 | < 5.9.9 |
MEDIUM | 6.4 | The Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders plugin for WordPre… | — | wordfence |
| 42f68a01-ef94-4e7e-abdd-46571973b911 | < 11.9.18 |
MEDIUM | 6.4 | The PowerPress Podcasting plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Podcast URLs in versions… | — | wordfence |
| 42e54e09-242f-49ab-9fff-a9ffc62dd4bd | < 3.9.3 |
MEDIUM | 6.4 | The Easy Testimonials plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcodes in v… | — | wordfence |
| 42de41f1-cfb2-4413-8841-c63d0e764be3 | < 2.0.8.3 |
MEDIUM | 6.4 | The The Pack Elementor addons (Header Footer & WooCommerce Builder, Template Library) plugin for WordPress is vulnerabl… | — | wordfence |
| 42dd1eeb-10b4-48f1-b392-dfa3a9d4b9c4 | < 3.7.30 |
MEDIUM | 6.4 | WordPress before 5.2.3 has an issue with URL sanitization in wp_kses_bad_protocol_once in wp-includes/kses.php that can … | — | wordfence |
| 42db52ae-f881-4082-b475-8577a28641c6 | < 2.9.8 |
MEDIUM | 6.4 | The Elementor Website Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG image uploads in… | — | wordfence |
| 42dacf78-1feb-4cbc-9ec3-805e668be931 | MEDIUM | 6.4 | The Easy Chart Builder for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to… | — | wordfence | |
| 42d862ef-523f-43ca-a3fb-ac3fbb537c46 | < 1.4.7 |
MEDIUM | 6.4 | The Statify Widget plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1… | — | wordfence |
| 42d56d6a-365a-4fa2-977f-a1328e0ec1b3 | < 1.6 |
MEDIUM | 6.4 | The Clicky by Yoast plugin for WordPress is vulnerable to Stored Cross-Site Scripting via user settings in versions up t… | — | wordfence |
| 42cf84d1-37f5-41c1-838d-67244f17c55d | MEDIUM | 6.4 | The Particle Background plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'particlegrou… | — | wordfence | |
| 42c1d2ea-dea6-4cde-8db3-37709da9eb71 | < 1.9.0 |
MEDIUM | 6.4 | The CMSMasters Content Composer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's multi… | — | wordfence |
| 42bbe73f-3465-4e84-8de9-43a85500f316 | < 5.8010 |
MEDIUM | 6.4 | The Ebook Store plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 5.80… | — | wordfence |
| 42b682be-1a60-449d-8c92-72bd1c3abfd6 | < 0.0.11 |
MEDIUM | 6.4 | The Caching Compatible Cookie Opt-In and JavaScript plugin for WordPress is vulnerable to Stored Cross-Site Scripting in… | — | wordfence |
| 42b49a88-c6b7-47ac-89ab-c2e0d7f1c7cc | MEDIUM | 6.4 | The wp_amaps plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.7 due… | — | wordfence | |
| 42ad6fef-4280-45db-a3e2-6d7522751fa7 | < 3.6.8 |
MEDIUM | 6.4 | The FareHarbor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via shortcodes in versions up to, and i… | — | wordfence |
| 42a0345a-4ad9-4cad-a7ef-2f5661fa855f | < 5.10.5.2 |
MEDIUM | 6.4 | The TheGem Theme Elements (for WPBakery) plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions u… | — | wordfence |
| 429f697c-e101-4fc3-ab9f-557c932bded5 | < 1.1.11 |
MEDIUM | 6.4 | The Web Bricks Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to,… | — | wordfence |
| 428d44c2-ef30-4d34-8f62-030af9931441 | < 3.4.0 |
MEDIUM | 6.4 | The Gutenberg Blocks – PublishPress Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the '… | — | wordfence |
| 428b4d6b-a4db-4e60-8c15-24efdfe6aea1 | < 3.2.0 |
MEDIUM | 6.4 | The Ultimate Blocks – WordPress Blocks Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via th… | — | wordfence |
| 4281ad41-d9a4-4503-9238-24990641a9bf | MEDIUM | 6.4 | The Events In City plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'org-events' shortcode in v… | — | wordfence | |
| 42816fa2-98a7-41c6-95d9-d0bac259d741 | < 2.0.5 |
MEDIUM | 6.4 | The Uix Shortcodes plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2… | — | wordfence |
| 42743c2f-053b-4f14-bf11-865f978ec017 | < 2.8.00 |
MEDIUM | 6.4 | The Buddyboss Platform plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘link_title’ parame… | — | wordfence |
| 42629244-dd2f-4ae1-9b35-e59a71b8005b | MEDIUM | 6.4 | The PF Timer plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.0.0 d… | — | wordfence | |
| 426280c1-0ecb-4973-915e-bb63ac240bca | < 3.1.36 |
MEDIUM | 6.4 | The Ditty – Responsive News Tickers, Sliders, and Lists plugin for WordPress is vulnerable to Stored Cross-Site Script… | — | wordfence |
EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.
Scan My Website →