Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.
39,942 vulnerabilities found (page 755 of 1598)
| CVE ID | Plugin / Theme | Severity | CVSS | Description | Fixed In | Source |
|---|---|---|---|---|---|---|
| 0297cdfa-0798-417b-ba49-119669df329d | < 1.18.0 |
MEDIUM | 6.4 | The ParOne Feeds plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.1… | — | wordfence |
| 0293f989-a5fa-46e3-896e-84f58c4e171e | MEDIUM | 6.4 | The WP Responsive Video plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and includi… | — | wordfence | |
| 02737f71-7ea6-4ce7-87e8-3988e3759f00 | < 1.2.9 |
MEDIUM | 6.4 | The Gutenberg Blocks β Unlimited blocks For Gutenberg plugin for WordPress is vulnerable to Stored Cross-Site Scriptin… | — | wordfence |
| 026b72f5-b650-4d48-8564-450a22ea7784 | MEDIUM | 6.4 | The Top Flash Embed plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, … | — | wordfence | |
| 024af9de-d4c7-43ec-a602-c45ded3ddad3 | < 4.11.9 |
MEDIUM | 6.4 | The Premium Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the data-countdow… | — | wordfence |
| 024a6a0f-f819-40e7-9618-71219c27aa64 | MEDIUM | 6.4 | The Zypento Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Table of Contents block in … | — | wordfence | |
| 0241a9fc-ce42-4a97-9f33-f07cf53c0f52 | < 2.10.32 |
MEDIUM | 6.4 | The Orbit Fox by ThemeIsle plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Post Type … | — | wordfence |
| 02396b9d-5b13-48ad-b44a-da8eeb059514 | MEDIUM | 6.4 | The Easy Magazine plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.… | — | wordfence | |
| 02103a32-4fac-401a-b995-e86dd734484b | < 3.5.25 |
MEDIUM | 6.4 | The Easy Property Listings plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'facebook' User Contact… | — | wordfence |
| 020d14f8-e8e2-4da2-9a4b-4d15cb0994c8 | < 3.1.10 |
MEDIUM | 6.4 | The Page Builder Gutenberg Blocks β CoBlocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the… | — | wordfence |
| 02073716-4f6a-4a51-933f-c5ab8dfbc08c | < 3.2.18 |
MEDIUM | 6.4 | The Robo Gallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 3.2… | — | wordfence |
| 020052ba-dece-4e70-88e7-8bd8918b8376 | < 2.10.33 |
MEDIUM | 6.4 | The Orbit Fox by ThemeIsle plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Registration Form w… | — | wordfence |
| 01ebc1b1-2dd3-4e91-93b2-fc8e5e93e925 | < 3.7.25 |
MEDIUM | 6.4 | WordPress before 4.9.2 has XSS in the Flash fallback files in MediaElement (under wp-includes/js/mediaelement). | — | wordfence |
| 01cf3196-1817-4506-8f70-ca54cc5e09f9 | MEDIUM | 6.4 | The Workable Api plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's workable_jobs shortc… | — | wordfence | |
| 01cd05c3-9629-4da4-ae9d-f99003253b95 | < 3.6.5 |
MEDIUM | 6.4 | The Block, Suspend, Report for BuddyPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'lin… | — | wordfence |
| 01ccc7b8-3dd4-4b83-bd53-687f7479b214 | < 1.1.8 |
MEDIUM | 6.4 | The MAS Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions… | — | wordfence |
| 01b1ebc8-e489-4053-9dbf-511cd83270d6 | < 3.5.27 |
MEDIUM | 6.4 | The WPFunnels plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 3.5.26… | — | wordfence |
| 01a6dcf2-6f0b-494b-a18c-04bd9c44e0ce | < 3.1.44 |
MEDIUM | 6.4 | The WP Event Manager β Events Calendar, Registrations, Sell Tickets with WooCommerce plugin for WordPress is vulnerabl… | — | wordfence |
| 01a6cca8-cca9-4863-a879-20fdca23b334 | < 4.3.2.2 |
MEDIUM | 6.4 | The EventPrime β Events Calendar, Bookings and Tickets plugin for WordPress is vulnerable to Stored Cross-Site Scripti… | — | wordfence |
| 019f85c8-e52b-40f7-8930-a2ddff0aaf97 | < 1.5.3 |
MEDIUM | 6.4 | The Advanced FAQ Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and includ… | — | wordfence |
| 019c5e06-1345-4c8e-abb9-dc0ea5d55ef5 | MEDIUM | 6.4 | The Ideal Interactive Map plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and inclu… | — | wordfence | |
| 0191e5b0-b669-439b-8ad4-9f860e6ee637 | < 3.5.1.14 |
MEDIUM | 6.4 | The Smart Slider 3 plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in ve… | — | wordfence |
| 0189d8cf-237f-4b5b-89f7-6346455d35a9 | MEDIUM | 6.4 | The G Meta Keywords plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, … | — | wordfence | |
| 0184b2b5-0b50-407e-8911-b0845714ea17 | < 3.3.54 |
MEDIUM | 6.4 | The Download Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including,… | — | wordfence |
| 0183625a-611c-4353-9d2a-7a25ae12709a | MEDIUM | 6.4 | The Silesia theme for WordPress is vulnerable to Stored Cross-Site Scripting via the βlinkβ attribute within the the… | — | wordfence |
EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.
Scan My Website →