Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.
39,942 vulnerabilities found (page 739 of 1598)
| CVE ID | Plugin / Theme | Severity | CVSS | Description | Fixed In | Source |
|---|---|---|---|---|---|---|
| 11867941-bc8d-49eb-9b0e-5d141cf7bf58 | < 19.9.9.7 |
MEDIUM | 6.4 | The REHub Framework plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and excluding, … | — | wordfence |
| 11807042-be3c-4780-bb47-ecc54aead5f2 | MEDIUM | 6.4 | The FAT Event Lite plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1… | — | wordfence | |
| 11681152-e4f0-4cea-8fc8-f297368e4b15 | < 2.2.9 |
MEDIUM | 6.4 | The insert-php (aka Woody ad snippets) plugin before 2.2.9 for WordPress allows authenticated XSS via the winp_item para… | — | wordfence |
| 11542fc6-33e2-40b9-be74-9fbb788f6915 | < 3.4.1 |
MEDIUM | 6.4 | The MX Time Zone Clocks WordPress plugin before 3.4.1 does not escape the time_zone attribute of the mxmtzc_time_zone_cl… | — | wordfence |
| 1144ed12-57bd-4f80-9df8-0aee1fcf6343 | < 5.6.0 |
MEDIUM | 6.4 | The Activity Log plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 5.5… | — | wordfence |
| 1144e0d9-692e-45a5-ac63-bcdd64a8bd8a | < 2.17.14 |
MEDIUM | 6.4 | The Shortcodes and extra features for Phlox theme plugin for WordPress is vulnerable to Stored Cross-Site Scripting via … | — | wordfence |
| 11419311-4369-4882-9841-9523571b2d35 | < 7.4.0 |
MEDIUM | 6.4 | The Shortcodes Ultimate plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and includi… | — | wordfence |
| 113c154d-94a0-41da-a5ed-d9b2617e1c2c | < 12.5.1 |
MEDIUM | 6.4 | The BuddyPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘display_name’ parameter in… | — | wordfence |
| 11386b6a-632c-451a-b726-846f74b6f42d | < 2.7.19 |
MEDIUM | 6.4 | The PowerPack Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Twitter Twe… | — | wordfence |
| 1137f15c-4adc-49d5-94a4-f1ea543b0dac | MEDIUM | 6.4 | The WPB Elementor Addons plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and includ… | — | wordfence | |
| 111a0507-aa51-4e4e-a582-9007041c811b | < 2.4.0 |
MEDIUM | 6.4 | The App Embed plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'appizy' shortcode in a… | — | wordfence |
| 110a1b28-50e0-430e-82d4-c254d73836e2 | < 5.0.8 |
MEDIUM | 6.4 | The Smart Custom Fields plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and includi… | — | wordfence |
| 1102b3ef-5f55-46ce-bcd9-c364b2f7e82f | < 1.1.2 |
MEDIUM | 6.4 | The Project Showcase plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including,… | — | wordfence |
| 10f7688e-019c-4c6b-a6ac-dacb66bcc36f | < 6.4.4 |
MEDIUM | 6.4 | The ElementsReady Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up … | — | wordfence |
| 10ea8f3a-35d6-494e-90f6-9165320cf99c | MEDIUM | 6.4 | The Print-O-Matic plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'print-me' shortcod… | — | wordfence | |
| 10d926d7-bcc9-4424-8422-90edc36f0ad4 | < 1.5.5 |
MEDIUM | 6.4 | The Scrollsequence plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1… | — | wordfence |
| 10cfc6e2-1502-45cb-b868-32228b3ccdd9 | < 1.6.2 |
MEDIUM | 6.4 | The Custom Add to Cart Button Label and Link plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versio… | — | wordfence |
| 10b47054-29cc-4859-bdfc-4dde1437c037 | < 9.0.2 |
MEDIUM | 6.4 | The Quiz and Survey Master (QSM) – Easy Quiz and Survey Maker plugin for WordPress is vulnerable to Stored Cross-Site … | — | wordfence |
| 10b08a05-3561-4d05-985b-6a2339a547a7 | < 4.2.6.7 |
MEDIUM | 6.4 | The LearnPress – WordPress LMS Plugin plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘… | — | wordfence |
| 10aaf8de-677d-466e-8736-bf1c5ca17495 | MEDIUM | 6.4 | The Google Maps for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and i… | — | wordfence | |
| 10945855-675a-4a85-8bb2-84bc40c1b826 | < 8.5 |
MEDIUM | 6.4 | The WPBakery Page Builder for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multiple P… | — | wordfence |
| 10933105-50d7-407a-b123-10b5f00ba688 | MEDIUM | 6.4 | The Textboxes plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 0.1.3.… | — | wordfence | |
| 109317dc-630a-4670-8871-85b3dcc1d006 | < 3.6.3 |
MEDIUM | 6.4 | The BuddyPress Members Only plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and inc… | — | wordfence |
| 108f3e7b-f4c1-445c-914c-97960b21b5fa | < 4.0.0 |
MEDIUM | 6.4 | The WP Dark Mode plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in vers… | — | wordfence |
| 108e9578-e586-4ed8-b0b2-dc6c26bf530e | < 1.5.7 |
MEDIUM | 6.4 | The Meteor Slides plugin for WordPress is vulnerable to Stored Cross-Site Scripting via shortcode in versions up to, and… | — | wordfence |
EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.
Scan My Website →