Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.
39,901 vulnerabilities found (page 696 of 1597)
| CVE ID | Plugin / Theme | Severity | CVSS | Description | Fixed In | Source |
|---|---|---|---|---|---|---|
| 382de43a-a714-4538-be12-76e74ad77327 | < 2.0.2 |
MEDIUM | 6.4 | The Easy restaurant menu manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's nsc_… | — | wordfence |
| 3823fedd-f5b9-420d-98b5-8b7bfc6b02de | MEDIUM | 6.4 | The Echoza plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 0.1.1 due… | — | wordfence | |
| 381ecc5f-5961-4756-9685-fda3990bc3a3 | < 1.1 |
MEDIUM | 6.4 | The Dynamic Text Field For Contact Form 7 plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions … | — | wordfence |
| 3808ca2a-e78e-4118-890b-c22a71f8e855 | < 1.2.2 |
MEDIUM | 6.4 | The Mega Elements plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Button widget in al… | — | wordfence |
| 37f8eced-905c-4623-b382-055561fd25a0 | MEDIUM | 6.4 | The GNTT Post Title Ticker plugin for WordPress is vulnerable to Stored Cross-Site Scripting in version 1.0 via the `tit… | — | wordfence | |
| 37f60fe5-2ece-48aa-8005-e220541bdd62 | < 3.1.4 |
MEDIUM | 6.4 | In the Elementor Website Builder WordPress plugin before 3.1.4, the image box widget (includes/widgets/image-box.php) ac… | — | wordfence |
| 37db075a-c335-4532-86cb-8cfa2897e02e | < 2.5.9 |
MEDIUM | 6.4 | The WP AdCenter plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.5.… | — | wordfence |
| 37d48295-357b-47c3-9adf-ce49dc73f337 | < 4.2.9 |
MEDIUM | 6.4 | The WPC Smart Messages for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up … | — | wordfence |
| 37c18340-d7aa-4410-be17-c61c286838ce | < 2.7.4 |
MEDIUM | 6.4 | The Jobs for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via "Working Hours" in all vers… | — | wordfence |
| 37afe2eb-0671-4dba-babc-f0b286dcb84f | < 1.1.12 |
MEDIUM | 6.4 | The HelloAsso plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.1.11… | — | wordfence |
| 37ab838d-7247-40db-8d78-e3f84116b415 | < 0.1.37 |
MEDIUM | 6.4 | The BlockStrap Page Builder - Bootstrap Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting in vers… | — | wordfence |
| 37a4a181-82ba-43bd-9caf-3a56cacb86a9 | < 2.3.28 |
MEDIUM | 6.4 | The GigPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode in versions up… | — | wordfence |
| 379b8a8a-bb6f-435f-a2bd-e3569e7b142e | < 1.4.0 |
MEDIUM | 6.4 | The WPCasa plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.3.2 due… | — | wordfence |
| 379825e2-61bf-4d11-8eea-05ad08200e9e | < 4.1.18 |
MEDIUM | 6.4 | The Church Admin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘meta-text’ parameter in … | — | wordfence |
| 3785938d-d55a-487d-8709-2d3bdd4b8c0f | < 1.3.4 |
MEDIUM | 6.4 | The Workscout Core WordPress plugin before 1.3.4, used by the WorkScout Theme did not sanitise the chat messages sent vi… | — | wordfence |
| 377e232b-1245-48ff-9f79-26a049e20063 | MEDIUM | 6.4 | The Course Migration for LearnDash plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up … | — | wordfence | |
| 37731e51-33ce-4ef3-8a13-976c005dc983 | < 10.9.3 |
MEDIUM | 6.4 | The WP Booking Calendar plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'booking' sho… | — | wordfence |
| 376e2638-a873-4142-ad7d-067ae3333709 | < 2.1.2 |
MEDIUM | 6.4 | The Feeds for YouTube plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'youtube-feed' shortcode in … | — | wordfence |
| 376404a5-176e-4c73-8281-27b138218879 | < 1.8 |
MEDIUM | 6.4 | The WP Flipclock plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the flipclock display settings in… | — | wordfence |
| 3763d893-83a0-4b6a-9c21-34a69313d555 | < 4.2.2 |
MEDIUM | 6.4 | The Save as PDF Plugin by Pdfcrowd plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 's… | — | wordfence |
| 375ed04b-a3cb-4e60-83c8-18bff583aaf4 | < 2.5.2 |
MEDIUM | 6.4 | The Code Embed plugin for WordPress is vulnerable to Stored Cross-Site Scripting via custom field meta values in all ver… | — | wordfence |
| 37506a9e-a225-4519-a24e-8678c31cc106 | < 3.6.1 |
MEDIUM | 6.4 | The BSK PDF Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and includi… | — | wordfence |
| 374c0b68-4f06-4b81-9bf9-a43a868e1e7b | MEDIUM | 6.4 | The WPSHARE247 Elementor Addons plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and… | — | wordfence | |
| 374a26dd-dd62-4583-8aff-90e5ae6b7468 | MEDIUM | 6.4 | The My Geo Posts Free plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'mygeo_city' shortcode i… | — | wordfence | |
| 37326225-60b8-4d80-8db5-22421f0dc427 | MEDIUM | 6.4 | The Tooltipy plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 5.5.9 d… | — | wordfence |
EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.
Scan My Website →