Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.
39,942 vulnerabilities found (page 757 of 1598)
| CVE ID | Plugin / Theme | Severity | CVSS | Description | Fixed In | Source |
|---|---|---|---|---|---|---|
| 009b9b0d-6cbd-402e-bc81-24661ff16b9d | < 1.4.8 |
MEDIUM | 6.4 | The 140+ Widgets | Xpro Addons For Elementor β FREE plugin for WordPress is vulnerable to Stored Cross-Site Scripting … | — | wordfence |
| 0088d9d8-0b29-481f-ba0b-ef05764d40c2 | < 4.5.6 |
MEDIUM | 6.4 | The Social Sharing Plugin β Social Warfare plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all ve… | — | wordfence |
| 00866e54-42b0-4947-a194-48b8d5cad027 | MEDIUM | 6.4 | The Allmart plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 1.0.… | — | wordfence | |
| 0084ec4e-1c10-4bfe-a7c6-155aa9a48dc1 | MEDIUM | 6.4 | The Chess Tempo Viewer plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and includin… | — | wordfence | |
| 00733c55-1071-4406-9ff3-d67b6411353a | MEDIUM | 6.4 | The Stockholm Core plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2… | — | wordfence | |
| 0064f4c0-ca94-4ce9-ba2f-e4a74b8b2fc2 | < 2.7.15 |
MEDIUM | 6.4 | The Jobs for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and includin… | — | wordfence |
| 005fc05c-6d82-49ca-b114-a3e64a3a572f | < 4.10.37 |
MEDIUM | 6.4 | The Premium Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Anim… | — | wordfence |
| 005bf2f0-892f-4248-afe3-263ae3d2ac54 | < 7.6.19 |
MEDIUM | 6.4 | The Comments β wpDiscuz plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and i… | — | wordfence |
| 005b22a5-9899-4d67-8353-5322ed0b4ae6 | MEDIUM | 6.4 | The Tabs For WPBakery Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, … | — | wordfence | |
| 0045c5a4-0807-4e89-8639-0802e54ce6ab | < 1.62.3 |
MEDIUM | 6.4 | The SiteOrigin Widgets Bundle plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Image Grid widge… | — | wordfence |
| 00376356-4a85-4898-a101-710e1cb5c6bb | < 3.3.1 |
MEDIUM | 6.4 | Cross-site scripting (XSS) vulnerability in wp-comments-post.php in WordPress 3.3.x before 3.3.1, when Internet Explorer… | — | wordfence |
| 00234d96-cece-4217-89c9-1a329887e8da | MEDIUM | 6.4 | The WidgetShortcode plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'widget' shortcode due to … | — | wordfence | |
| 001b452e-3f8a-4605-b77a-ba8fbd0d79d7 | < 1.7.3 |
MEDIUM | 6.4 | The ID-SK Toolkit plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions… | — | wordfence |
| 00192a36-4b75-4dae-9a6e-0afb02ed5bad | < 6.1.15 |
MEDIUM | 6.4 | The Fluent Forms plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the AI Form Builder module in all… | — | wordfence |
| 00145a6b-26fd-4cba-a446-8236438075d8 | MEDIUM | 6.4 | The PhotoFade plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'time' parameter in all versions… | — | wordfence | |
| 00107941-effc-4540-aa52-9e9725a417d6 | MEDIUM | 6.4 | The MyBookTable Bookstore plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and inclu… | — | wordfence | |
| 000bf956-1781-4596-ac12-81691fdd789c | < 1.6.4 |
MEDIUM | 6.4 | The PWA β easy way to Progressive Web App plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG Fi… | — | wordfence |
| fcc0fc00-b7d6-429c-9ab3-f08971c48777 | < 8.2.4 |
MEDIUM | 6.3 | The Media Library Folders plugin for WordPress is vulnerable to unauthorized access due to missing capability checks on … | — | wordfence |
| fb6f4b0b-25b8-4dcd-b002-293ce8ab307e | < 1.10.0 |
MEDIUM | 6.3 | The NitroPack β Cache & Speed Optimization for Core Web Vitals, Defer CSS & JavaScript, Lazy load Images plugin for Wo… | — | wordfence |
| fb147a5d-65ad-4304-b13a-670f11398e63 | < 1.4.5 |
MEDIUM | 6.3 | The WPS Cleaner plugin for WordPress is vulnerable to authorization bypass in versions up to, and including, 1.4.4. This… | — | wordfence |
| fa0a296a-a93f-4c0e-9911-b4f9bdd53fad | < 1.7.15 |
MEDIUM | 6.3 | The The Drop Shadow Boxes plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and… | — | wordfence |
| f9337519-0b33-43fa-9be4-2390b8b3afb9 | < 5.1.8 |
MEDIUM | 6.3 | The ProfileGrid plugin for WordPress is vulnerable to CSV Injection in versions up to, and including, 5.1.6, via the 'pm… | — | wordfence |
| f8f27037-5dd6-467e-b633-494f30ec8b7a | < 2.0.19 |
MEDIUM | 6.3 | Multiple SQL injection vulnerabilities in pie-register/pie-register.php in the Pie Register plugin before 2.0.19 for Wor… | — | wordfence |
| f7d66176-73a8-4076-8ae0-1f1fd8260f8e | < 3.7.21 |
MEDIUM | 6.3 | In WordPress before 4.7.5, there is improper handling of post meta data values in the XML-RPC API. | — | wordfence |
| f63d494c-1d1e-4faa-930a-3fcf2b136182 | < 0.47 |
MEDIUM | 6.3 | The WP FEvents Book plugin for WordPress is vulnerable to unauthorized access of data, modification of data, and loss of… | — | wordfence |
EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.
Scan My Website →