Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.
39,942 vulnerabilities found (page 716 of 1598)
| CVE ID | Plugin / Theme | Severity | CVSS | Description | Fixed In | Source |
|---|---|---|---|---|---|---|
| 26337385-646f-4129-99be-7fa020f67f8e | < 4.10.70 |
MEDIUM | 6.4 | The Premium Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's link… | — | wordfence |
| 262f7690-97ce-40ca-a277-6871acbc1546 | < 1.1.6 |
MEDIUM | 6.4 | The HelloAsso plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 1.… | — | wordfence |
| 2628f9dd-a020-49e6-bcea-f839e1d1a8a0 | < 3.1.8 |
MEDIUM | 6.4 | Advanced Order Export before 3.1.8 for WooCommerce allows XSS, a different vulnerability than CVE-2020-11727. | — | wordfence |
| 2626ad96-4346-4564-b6bd-0c226bd8dfd4 | < 7.8.1 |
MEDIUM | 6.4 | The Speed Optimizer β The All-In-One Performance-Boosting Plugin plugin for WordPress is vulnerable to Stored Cross-Si… | — | wordfence |
| 26235bfb-4b06-4da9-88eb-dea16d371f16 | MEDIUM | 6.4 | The Photo Swipe plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 4.1.… | — | wordfence | |
| 2621cb32-3753-42e7-8690-88c680bdf808 | < 2.5.10 |
MEDIUM | 6.4 | The Paid Memberships Pro plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the edit order page in ve… | — | wordfence |
| 261d280b-60df-407c-9ad5-8fee77ca3070 | < 5.15.0 |
MEDIUM | 6.4 | The Avada Core plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to 5.15.0 due to insuffi… | — | wordfence |
| 261bf532-48aa-406f-ba28-2ca3ae919522 | < 2.0.10 |
MEDIUM | 6.4 | The Goodlayers Core plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, … | — | wordfence |
| 2618ccde-2bb0-4cd4-b415-68a671507709 | < 1.4.5 |
MEDIUM | 6.4 | The Appointment Booking Calendar plugin for WordPress is vulnerable to Stored Cross-Site Scripting via custom booking fi… | — | wordfence |
| 2612dab2-a4fc-4434-a107-f2d28f1a1dc8 | MEDIUM | 6.4 | The Hester theme for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.1.10 due… | — | wordfence | |
| 260c8ee3-dac5-4ad7-ba77-2312160e9348 | < 1.10.1 |
MEDIUM | 6.4 | The SureDash β Community, Courses & Member Dashboard plugin for WordPress is vulnerable to Stored Cross-Site Scripting… | — | wordfence |
| 260054fd-7cb2-438f-a5ec-0b72338627bc | < 7.8 |
MEDIUM | 6.4 | The SEOPress β On-site SEO plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the SEO Title field p… | — | wordfence |
| 25ff6cc3-02ed-470a-aa10-4843e1ec01ce | < 3.0.0 |
MEDIUM | 6.4 | The WP-FormAssembly plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'formassembly' sh… | — | wordfence |
| 25fc2600-9b57-405e-9956-b55291161700 | MEDIUM | 6.4 | The iVysilani Shortcode plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'width' shortcode attr… | — | wordfence | |
| 25f24bdd-0b78-4ec3-821b-6331e5bf65e8 | < 2.1.2 |
MEDIUM | 6.4 | The ONLYOFFICE DocSpace plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'onlyoffice-d… | — | wordfence |
| 25edb9e8-65ea-41d1-a95f-09be110ec1d2 | < 4.2.2 |
MEDIUM | 6.4 | The Starter Templates β Elementor, WordPress & Beaver Builder Templates plugin for WordPress is vulnerable to Stored C… | — | wordfence |
| 25eb1c89-0121-4ea5-a29a-43ec98c468ee | MEDIUM | 6.4 | The Magic Buttons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's magic… | — | wordfence | |
| 25ea860e-c4f8-4660-a8cb-aafc4d02bb19 | < 5.4.0 |
MEDIUM | 6.4 | The LatePoint plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'btn_wrapper_classes' attribute … | — | wordfence |
| 25e42bf8-794e-46a5-b7db-f1f8802bba00 | < 5.6.2 |
MEDIUM | 6.4 | The The Plus Addons for Elementor β Elementor Addons, Page Templates, Widgets, Mega Menu, WooCommerce plugin for WordP… | — | wordfence |
| 25e11dbd-f751-4dd1-a609-1a5ae7e333b8 | MEDIUM | 6.4 | The wBounce plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.8.1 du… | — | wordfence | |
| 25e0be55-ca6d-40c2-972f-fa37c99966c7 | < 1.1.12 |
MEDIUM | 6.4 | The Custom post type templates for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versio… | — | wordfence |
| 25d6ee47-2a7b-486e-856b-336964b387ae | < 2.8.0 |
MEDIUM | 6.4 | The Linear plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'linear_block_buy_commissi… | — | wordfence |
| 25d0921b-39b1-4abb-9197-952fc55f80e6 | MEDIUM | 6.4 | The Ungapped Widgets plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'prefillvalues' parameter… | — | wordfence | |
| 25d07a99-d425-4e1a-8adf-d12071552882 | < 2.6.2 |
MEDIUM | 6.4 | The Custom Field Template plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'cpt' short… | — | wordfence |
| 25cbaa1d-97ff-436d-8a94-c487c05acef9 | < 3.0.2 |
MEDIUM | 6.4 | The Tutor LMS Elementor Addons plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and … | — | wordfence |
EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.
Scan My Website →