Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.
39,901 vulnerabilities found (page 686 of 1597)
| CVE ID | Plugin / Theme | Severity | CVSS | Description | Fixed In | Source |
|---|---|---|---|---|---|---|
| 425cd0be-d17e-4c2b-bf29-3b850905a88e | < 1.8.9 |
MEDIUM | 6.4 | The WordPress Pinterest Plugin – Make a Popup, User Profile, Masonry and Gallery Layout plugin for WordPress is vulner… | — | wordfence |
| 425af1b6-3db9-44bc-8bea-29f2912eef87 | < 3.2.9 |
MEDIUM | 6.4 | The Ni WooCommerce Cost Of Goods plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, an… | — | wordfence |
| 424c23f7-73a4-4b2b-8f52-61cb45523396 | MEDIUM | 6.4 | The Digital Events Calendar plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘column’ param… | — | wordfence | |
| 424b2145-2fe2-48b8-bb4f-08fe23a6100f | < 5.8.1 |
MEDIUM | 6.4 | The WP Scraper plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 5… | — | wordfence |
| 424a3b93-5cf6-4706-acab-0ee89f05c073 | MEDIUM | 6.4 | The User Avatar - Reloaded plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and incl… | — | wordfence | |
| 4241118f-9bcb-4dec-abd2-7172db2cf445 | < 2.2 |
MEDIUM | 6.4 | The Optio Dentistry plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'optio-lightbox' … | — | wordfence |
| 423e840e-0bc2-4481-afff-61ace85788d3 | MEDIUM | 6.4 | The WOW Entrance Effects (WEE!) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'wee'… | — | wordfence | |
| 41fdb3ea-1de4-4b90-a387-5932de7a5e7c | < 0.13.3 |
MEDIUM | 6.4 | The IndieBlocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘kind’ parameter in all ve… | — | wordfence |
| 41fc7e7e-c9bb-434a-9960-7f0f2292d922 | < 1.2.5 |
MEDIUM | 6.4 | The Maps for WP plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.2.… | — | wordfence |
| 41f6e826-9326-40fa-80d0-4cff1dd72536 | < 9.3 |
MEDIUM | 6.4 | The WordPress Button Plugin MaxButtons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via various sho… | — | wordfence |
| 41f6b12e-49bb-4bee-bbde-ce4e5ebd4cad | < 1.3.3 |
MEDIUM | 6.4 | The StreamWeasels YouTube Integration plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's… | — | wordfence |
| 41f3045f-94a3-45c4-8baa-7f198b8c24bc | < 2.1.6 |
MEDIUM | 6.4 | The BlockArt Blocks – Gutenberg Blocks, Page Builder Blocks ,WordPress Block Plugin, Sections & Template Library plugi… | — | wordfence |
| 41e2c557-e462-4d9e-916c-b8352a6df571 | < 2.88.15 |
MEDIUM | 6.4 | The MapPress Maps for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via map titles in all … | — | wordfence |
| 41c54e1b-69b9-4594-8f1e-7ef17f120791 | < 7.0.0 |
MEDIUM | 6.4 | The Uncanny Automator – Easy Automation, Integration, Webhooks & Workflow Builder Plugin plugin for WordPress is vulne… | — | wordfence |
| 41b2a4cc-fb23-41eb-b1a4-d793ae924d9a | < 3.3.4 |
MEDIUM | 6.4 | The Ultimate Blocks – WordPress Blocks Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via mu… | — | wordfence |
| 419cf912-3187-43d7-90ab-1a20a46d86e4 | < 2.1.4 |
MEDIUM | 6.4 | The User Private Files – File Upload & Download Manager with Secure File Sharing plugin for WordPress is vulnerable to… | — | wordfence |
| 41859e1c-1ae0-49f1-82d3-5af3c15994ef | < 3.4 |
MEDIUM | 6.4 | The Advanced Sermons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘sermon_video_embed’ … | — | wordfence |
| 417f636d-1b60-413a-949e-89c113e636e6 | < 1.1.1 |
MEDIUM | 6.4 | The reCAPTCHA for Asgaros Forum plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and… | — | wordfence |
| 417b9dfe-2571-4816-af55-c7cb7dfa62c6 | < 1.10 |
MEDIUM | 6.4 | The Clinked Client Portal plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'clinked-lo… | — | wordfence |
| 416da317-61dc-42b5-9ade-fa41e844263b | < 4.1.2 |
MEDIUM | 6.4 | The MainWP White Label Extension plugin for WordPress is vulnerable to authorization bypass in versions up to, and inclu… | — | wordfence |
| 415bfddb-5223-439f-8a08-535f79631ff0 | < 1.44.2 |
MEDIUM | 6.4 | The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is vulnerable to Stored C… | — | wordfence |
| 415a7201-bdff-4342-9e06-ce0e500cdc7c | < 3.11.0 |
MEDIUM | 6.4 | The Happy Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'arrow' attribu… | — | wordfence |
| 41479533-592d-4438-8162-48975b8a78a7 | MEDIUM | 6.4 | The StorePress theme for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.0.12… | — | wordfence | |
| 41437186-8802-4496-a79c-b01f7c93e486 | MEDIUM | 6.4 | The WP EASY RECIPE plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1… | — | wordfence | |
| 414173b9-d23e-4e44-bf8c-77a074bb09e9 | < 1.6.8.32 |
MEDIUM | 6.4 | The Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin plugin for WordPress is vulnerable to S… | — | wordfence |
EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.
Scan My Website →