Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.
39,942 vulnerabilities found (page 723 of 1598)
| CVE ID | Plugin / Theme | Severity | CVSS | Description | Fixed In | Source |
|---|---|---|---|---|---|---|
| 20584675-0d4a-4215-8132-e9ea95bee09b | MEDIUM | 6.4 | The Widget or Sidebar Shortcode plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'side… | — | wordfence | |
| 204cfe20-9df1-4f6c-a38c-a21b43dde385 | < 3.7.9 |
MEDIUM | 6.4 | The ElementsKit Pro plugin for WordPress is vulnerable to DOM-Based Stored Cross-Site Scripting via the βurlβ parame… | — | wordfence |
| 203ab09f-7344-4cab-86bf-0c1ec545d78f | < 3.10.9 |
MEDIUM | 6.4 | The Happy Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the β_idβ param… | — | wordfence |
| 20378a65-d11a-4ef7-b604-59c962994d6a | MEDIUM | 6.4 | The Scrollbar by webxapp β Best vertical/horizontal scrollbars plugin plugin for WordPress is vulnerable to Stored Cro… | — | wordfence | |
| 20301685-9b76-4dd3-8185-3a4463f3201b | < 1.9.1 |
MEDIUM | 6.4 | The Campus Directory β Faculty, Staff & Student Directory Plugin for WordPress plugin for WordPress is vulnerable to S… | — | wordfence |
| 202dfb5c-6660-4d07-b10d-750fec28a3fe | < 1.2.7 |
MEDIUM | 6.4 | The Mega Elements plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.… | — | wordfence |
| 20283c28-6640-4082-82ca-7f8769e4ccc0 | < 2.6 |
MEDIUM | 6.4 | Cross-site scripting (XSS) vulnerability in wp-admin/wp-blogs.php in Wordpress MU (WPMU) before 2.6 allows remote attack… | — | wordfence |
| 20262161-6189-4c28-8ccb-5c4c12521928 | < 1.3.9 |
MEDIUM | 6.4 | The Ultimate WP Mail plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including,… | — | wordfence |
| 20232d70-72b2-47b7-ac7e-ad07892864ef | < 3.35.6 |
MEDIUM | 6.4 | The Elementor Website Builder β More Than Just a Page Builder plugin for WordPress is vulnerable to Stored Cross-Site … | — | wordfence |
| 20227433-a2f0-4a00-b6cc-95708135c0b8 | < 1.3.2 |
MEDIUM | 6.4 | ajax.functions.php in the MailUp plugin before 1.3.2 for WordPress does not properly restrict access to unspecified Ajax… | — | wordfence |
| 201ff7b6-d72a-43c3-a7b1-c4f917c9d27f | < 1.7.1029 |
MEDIUM | 6.4 | The Royal Elementor Addons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multiple widgets in all… | — | wordfence |
| 20199c88-1800-4d18-a0ee-0219be77b429 | MEDIUM | 6.4 | The Annual Archive plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1… | — | wordfence | |
| 2011db9d-7237-4843-8c15-63b8fb60de5d | MEDIUM | 6.4 | The WP-BibTeX plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'WpBibTeX' shortcode in… | — | wordfence | |
| 200f6173-72cd-4bf7-86b7-f5308b84364b | < 6.4.25 |
MEDIUM | 6.4 | The Business Directory Plugin β Easy Listing Directories for WordPress plugin for WordPress is vulnerable to Stored Cr… | — | wordfence |
| 2003cef3-06b0-4012-9629-19c0765553dd | < 6.11.7 |
MEDIUM | 6.4 | The Site Reviews plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 6.1… | — | wordfence |
| 2002fa81-3a4f-4a88-ba52-ed06969d51a3 | < 4.0.0 |
MEDIUM | 6.4 | The Careerfy - Job Board WordPress Theme theme for WordPress is vulnerable to Stored Cross-Site Scripting via the 'Caree… | — | wordfence |
| 1ff77089-c6c9-49af-8b08-0977a526fa23 | < 2.1.28 |
MEDIUM | 6.4 | The WP Telegram Widget and Join Link plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to… | — | wordfence |
| 1febe2d8-d354-4c78-a611-c1bb0937e53d | < 1.8.10 |
MEDIUM | 6.4 | The Graphina β Elementor Charts and Graphs plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multi… | — | wordfence |
| 1fdbddd7-8713-48c8-98d6-0a155ca68325 | MEDIUM | 6.4 | The FPW Category Thumbnails plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'id' parameter of … | — | wordfence | |
| 1fdb1314-5979-42bb-96dd-cc1648283c4e | MEDIUM | 6.4 | The Wot Elementor Widgets plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and inclu… | — | wordfence | |
| 1fd45d76-d82b-46e6-b9fc-95d2d977fcd2 | MEDIUM | 6.4 | The WP Github plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.3.3 … | — | wordfence | |
| 1fce3120-1e50-464f-bfa9-a9260e47afa2 | MEDIUM | 6.4 | The Mail Subscribe List plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and includi… | — | wordfence | |
| 1fc860d4-fa26-489a-acd5-edbf7116d817 | < 1.1.12 |
MEDIUM | 6.4 | The CBX Map for Google Map & OpenStreetMap plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions… | — | wordfence |
| 1fba61bd-d290-4fdf-8fac-a0158570a069 | MEDIUM | 6.4 | The Valenti Engine plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1… | — | wordfence | |
| 1fab5d06-ff39-4b7c-808b-bd199c2a3329 | < 6.4.1 |
MEDIUM | 6.4 | The WPBakery plugin for WordPress, in versions 6.4 and below, was designed with a flaw that could give users with contri… | — | wordfence |
EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.
Scan My Website →