Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.
40,113 vulnerabilities found (page 769 of 1605)
| CVE ID | Plugin / Theme | Severity | CVSS | Description | Fixed In | Source |
|---|---|---|---|---|---|---|
| feb25e04-8cd2-49d8-a459-4302c1ec332c | MEDIUM | 6.1 | Multiple cross-site request forgery (CSRF) vulnerabilities in the Timed Popup (wp-timed-popup) plugin 1.3 for WordPress … | — | wordfence | |
| feaa2809-c804-4a21-8f5e-8149b2d490d4 | MEDIUM | 6.1 | The Shipdeo plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and including, 1… | — | wordfence | |
| fea1546c-1d8f-4478-81b7-20a9096e0217 | MEDIUM | 6.1 | The WP Image Uploader plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'file' parameter in a… | — | wordfence | |
| fe848a09-edd3-4eea-befb-909d15ba1994 | < 1.36.1 |
MEDIUM | 6.1 | The Hubbub Lite – Fast, free social sharing and follow buttons plugin for WordPress is vulnerable to Reflected Cross-S… | — | wordfence |
| fe799030-ec9c-45fd-a5a9-6589364b6056 | MEDIUM | 6.1 | The DT Chocolate theme plugin for WordPress is vulnerable to Cross-Site Scripting in all versions due to insufficient in… | — | wordfence | |
| fe71e2b9-ddd7-4d6d-97e5-5fad41f8f35c | < 2.0.0 |
MEDIUM | 6.1 | The Unilevel MLM Plan plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘page’ parameter … | — | wordfence |
| fe679ff6-6ade-48fa-8699-6a96da49f8c8 | < 1.6.8 |
MEDIUM | 6.1 | The KB Support – Customer Support Ticket & Helpdesk Plugin, Knowledge Base Plugin plugin for WordPress is vulnerable t… | — | wordfence |
| fe5f7aaf-46e3-4d62-ae3f-85bbb85a511d | MEDIUM | 6.1 | The Causes – Donation Plugin plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up t… | — | wordfence | |
| fe54c37f-1421-48aa-b502-045847d13ae3 | < 1.1.16 |
MEDIUM | 6.1 | The WP Responsive Tabs horizontal vertical and accordion Tabs plugin for WordPress is vulnerable to Reflected Cross-Site… | — | wordfence |
| fe46ec14-4795-4ac7-afd0-de92ccef877d | MEDIUM | 6.1 | The weichuncai(WP伪春菜) plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and … | — | wordfence | |
| fe2a538b-60a5-4595-b901-4477679e6b8a | < 1.5.63 |
MEDIUM | 6.1 | The users-ultra plugin before 1.5.63 for WordPress has XSS via the p_desc parameter. | — | wordfence |
| fe274dc5-3999-4fa6-88a8-57aecbb6f4c1 | < 1.1.5 |
MEDIUM | 6.1 | The MemberPress Discord Addon plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, an… | — | wordfence |
| fe18de26-ef1e-44bc-94ed-eb9ddab15331 | < 6.1.3 |
MEDIUM | 6.1 | The Course Booking System plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, an… | — | wordfence |
| fe0e4729-bf06-481c-8ea2-5fab8e8a417f | < 1.0.13 |
MEDIUM | 6.1 | The sequel plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and including, 1.… | — | wordfence |
| fe086290-f3d3-4d28-bb5c-11fbbb1364b4 | < 2.8.52 |
MEDIUM | 6.1 | The GTranslate plugin before 2.8.52 for WordPress has Reflected XSS via a crafted link. This requires use of the hreflan… | — | wordfence |
| fe025d8f-3a68-4d69-89ea-62b3113c267e | MEDIUM | 6.1 | The Forms: 3rd-Party Post Again plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, … | — | wordfence | |
| fe023bc0-11b9-4520-874a-4656f633d4ac | < 1.9.27 |
MEDIUM | 6.1 | The check_privacy_settings AJAX action of the WordPress GDPR WordPress plugin before 1.9.26, available to both unauthent… | — | wordfence |
| fdf6d876-631f-493d-a324-3bb8efedd84a | < 1.2.2 |
MEDIUM | 6.1 | The WP Hardening – Fix Your WordPress Security WordPress plugin before 1.2.2 did not sanitise or escape the historyval… | — | wordfence |
| fdf6b2ea-5a6a-481b-9431-650c895f54ef | < 2.1 |
MEDIUM | 6.1 | The Binary MLM Woocommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'page’ paramet… | — | wordfence |
| fdc1289a-abd1-43db-89b7-3e81878a0f9a | < 1.0.25 |
MEDIUM | 6.1 | The ProductDyno plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘res’ parameter in all … | — | wordfence |
| fdb822e8-583e-4437-a735-b116aa8886e2 | < 2.4.1 |
MEDIUM | 6.1 | The WP-Optimize plugin and SrbTransLatin plugin for WordPress are vulnerable to Cross-Site Scripting via the 's' paramet… | — | wordfence |
| fdb6c326-bd48-440a-9eba-7073b6a68844 | MEDIUM | 6.1 | The FrescoChat Live Chat plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and inc… | — | wordfence | |
| fda7ad16-d66b-47fc-bbd6-18fd0b1c1e03 | MEDIUM | 6.1 | The WP PT-Viewer plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and includi… | — | wordfence | |
| fda1be79-ba45-4e8f-bfc3-355f9cdbad82 | < 6.2.7.0 |
MEDIUM | 6.1 | The Community by PeepSo – Social Network, Membership, Registration, User Profiles plugin for WordPress is vulnerable t… | — | wordfence |
| fd8cafa4-594e-47e5-9a1b-666a5b23feea | < 2.5 |
MEDIUM | 6.1 | The Simple Membership Custom Messages plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versio… | — | wordfence |
EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.
Scan My Website →