Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.
39,942 vulnerabilities found (page 728 of 1598)
| CVE ID | Plugin / Theme | Severity | CVSS | Description | Fixed In | Source |
|---|---|---|---|---|---|---|
| 1bcb9ba1-63f9-4de9-b1da-405231cd1d14 | < 1.0.8.2 |
MEDIUM | 6.4 | The EO4WP plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.0.8.1 du… | — | wordfence |
| 1bc697b3-20f6-46df-a250-f2009a60200e | < 9.97.0.0 |
MEDIUM | 6.4 | The VK All in One Expansion Unit plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the child page in… | — | wordfence |
| 1bc6508b-f646-4d52-bc8d-bdac443ed2fe | MEDIUM | 6.4 | The Wpik WordPress Basic Ajax Form plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'dname' par… | — | wordfence | |
| 1bc0aa64-57a6-44ef-974a-70991cc3820f | < 3.7.32 |
MEDIUM | 6.4 | wp_kses_bad_protocol in wp-includes/kses.php in WordPress before 5.3.1 mishandles the HTML5 colon named entity, allowing… | — | wordfence |
| 1bbba961-a1e6-440a-9b39-919363f7031d | < 2.5 |
MEDIUM | 6.4 | The WP Portfolio theme for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.4 … | — | wordfence |
| 1bb58556-29be-4272-85fc-bb2b7c72abf4 | MEDIUM | 6.4 | The Debt.com Business in a Box plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'configuration'… | — | wordfence | |
| 1bae6d3a-40eb-4af6-be4e-9bc6be1a4b07 | < 7.0.5 |
MEDIUM | 6.4 | The WP Shortcodes Plugin — Shortcodes Ultimate plugin for WordPress is vulnerable to Stored Cross-Site Scripting via t… | — | wordfence |
| 1baa93da-9b55-45e7-b9a9-db331b5d0584 | < 3.3 |
MEDIUM | 6.4 | The Bridge Core plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'formforall' shortcode in versions… | — | wordfence |
| 1b902d46-ff27-486f-836d-f55a8048f08c | < 1.0.44 |
MEDIUM | 6.4 | The Wishlist plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'wishlist_button' shortc… | — | wordfence |
| 1b87fe3d-a88d-477a-8d91-4d7c2dba4a43 | < 2.6.9.1 |
MEDIUM | 6.4 | The Exclusive Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via data attribute … | — | wordfence |
| 1b80f389-19f9-49a5-aab8-3096838ccfe5 | < 2.2 |
MEDIUM | 6.4 | The WPB Quick View for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, … | — | wordfence |
| 1b75da76-1a58-4f8e-9b4f-d2e40d09f9ea | < 4.4.0.1 |
MEDIUM | 6.4 | The Instant Images – One Click Unsplash Uploads WordPress plugin before 4.4.0.1 did not properly validate and sanitise… | — | wordfence |
| 1b73402b-444c-47ad-9c05-7be6e6440123 | < 5.5.5 |
MEDIUM | 6.4 | The The Plus Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several of the p… | — | wordfence |
| 1b57cbaa-8a5f-4a00-9c77-6b187c416594 | < 1.5.1 |
MEDIUM | 6.4 | The Audio Album plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.5.… | — | wordfence |
| 1b3948ef-11be-450d-ad20-e4bebc16e790 | < 2.9.30 |
MEDIUM | 6.4 | The MicroPayments – Fans Paysite: Paid Creator Subscriptions, Digital Assets, Tokens Wallet plugin for WordPress is vu… | — | wordfence |
| 1b38e7ec-6663-4253-9c60-61ed34be22c1 | < 1.5.15 |
MEDIUM | 6.4 | The Lightweight Accordion plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s… | — | wordfence |
| 1b34a4aa-bcaa-4be5-a059-6f2efa3a8198 | < 4.0.7 |
MEDIUM | 6.4 | The Responsive Tabs plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the tabs_color value in all ve… | — | wordfence |
| 1af8d91a-f87f-42d4-b277-d4372d580ca0 | MEDIUM | 6.4 | The TinyCode plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.2.1 d… | — | wordfence | |
| 1aedd621-73e0-46e0-8d25-3511e01d7a4e | MEDIUM | 6.4 | The EzyOnlineBookings Online Booking System Widget plugin for WordPress is vulnerable to Stored Cross-Site Scripting in … | — | wordfence | |
| 1aeafeec-7202-4ee6-b724-8dcf98591294 | MEDIUM | 6.4 | The Control horas plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'ch_registro' short… | — | wordfence | |
| 1aea8fe3-7c75-4d3a-847a-ce0d1f9700f1 | MEDIUM | 6.4 | The Button Builder – Buttons X plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the btnsx shortco… | — | wordfence | |
| 1ada39db-b316-4270-ac9c-3770b473d6a8 | < 6.1.0 |
MEDIUM | 6.4 | The Bible SuperSearch plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘selector_height’ pa… | — | wordfence |
| 1ac6422f-0bb1-4586-adbb-71b04b2a8e63 | MEDIUM | 6.4 | The WP Vegas plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.2 due… | — | wordfence | |
| 1ac58649-4c1a-4c2c-a94b-a3cf08ecb4df | < 2.1.7 |
MEDIUM | 6.4 | The CarSpot theme before 2.1.7 for WordPress has stored XSS via the Phone Number field. | — | wordfence |
| 1ac42a0f-19e9-4ce2-9708-d7aff1609c47 | MEDIUM | 6.4 | The Attendance Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and includin… | — | wordfence |
EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.
Scan My Website →