Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.
40,113 vulnerabilities found (page 771 of 1605)
| CVE ID | Plugin / Theme | Severity | CVSS | Description | Fixed In | Source |
|---|---|---|---|---|---|---|
| fca6ddae-df77-4636-bfe1-29e8726386d4 | MEDIUM | 6.1 | The Snippy plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and including, 1.… | — | wordfence | |
| fca4040d-3c6c-4e31-9bed-d1b6bf5b2bed | < 7.1.14 |
MEDIUM | 6.1 | Cross-site scripting vulnerability in Quiz And Survey Master versions prior to 7.1.14 allows a remote attacker to inject… | — | wordfence |
| fc9bd62c-0be2-4722-8d11-f7d3c68af7fc | MEDIUM | 6.1 | The Hospital Management System for Wordpress plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in ver… | — | wordfence | |
| fc8b0944-f669-40d3-899b-d7f91b1a1fea | MEDIUM | 6.1 | The Woo Manage Fraud Orders plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'page' paramete… | — | wordfence | |
| fc7b19c7-a850-4783-9f8b-e338e03998eb | < 5.13.8 |
MEDIUM | 6.1 | There are several endpoints in the Store Locator Plus for WordPress plugin through 5.12.3 that could allow unauthenticat… | — | wordfence |
| fc787bba-d696-49b4-a734-ef5f81a7f494 | MEDIUM | 6.1 | The Storyform plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 0.6… | — | wordfence | |
| fc72e388-9ffc-4b99-8835-4b4b6ef46f95 | < 1.4.7 |
MEDIUM | 6.1 | The moreAds SE plugin for WordPress is vulnerable to Cross-Site Scripting in versions up to, and including, 1.4.6 due to… | — | wordfence |
| fc672bc6-3fb7-4e32-bbdb-1f0116872b55 | < 4.3.4 |
MEDIUM | 6.1 | The RH Frontend Publishing Pro plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, a… | — | wordfence |
| fc4f4a78-7224-4f58-a103-7ad4df0eb36e | < 3.0.6 |
MEDIUM | 6.1 | The Pixel Cat β Conversion Pixel Manager plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to t… | — | wordfence |
| fc43e782-c3e3-4503-a1cb-13386cb5bf56 | < 1.13.0 |
MEDIUM | 6.1 | The Post Status Notifier Lite plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, an… | — | wordfence |
| fc40be19-9256-4c90-8438-b71b9481625d | MEDIUM | 6.1 | Multiple cross-site request forgery (CSRF) vulnerabilities in the wpCommentTwit plugin 0.5 and earlier for WordPress all… | — | wordfence | |
| fc3d84f3-bd9d-40e6-bc88-90c840a928c0 | < 1.4.2 |
MEDIUM | 6.1 | … | — | wordfence |
| fc3af81e-7fa3-43a0-a403-87a042253632 | < 2.2.2 |
MEDIUM | 6.1 | The Bulk Price Update for Woocommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the βpa… | — | wordfence |
| fc240e5a-da4b-4705-9d10-14ae2804fdb7 | MEDIUM | 6.1 | The Base64 Encoder/Decoder plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and i… | — | wordfence | |
| fc0d1427-d01e-4054-8ba7-59d6878cfbea | MEDIUM | 6.1 | The Newsletter Subscriptions plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'token_type' p… | — | wordfence | |
| fc08e4cf-3964-406e-9046-420e749df4b5 | < 8.3.5 |
MEDIUM | 6.1 | The WP VR plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via tab parameters in versions up to, and… | — | wordfence |
| fc06ba09-9562-4d97-90ff-5464399feced | < 7.0 |
MEDIUM | 6.1 | The Real Estate Manager β Property Listing and Agent Management plugin for WordPress is vulnerable to Reflected Cross-… | — | wordfence |
| fc06640e-3243-4369-bf1d-fb33f4d76ff7 | < 1.1.5 |
MEDIUM | 6.1 | The Taboola Pixel plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including,… | — | wordfence |
| fc060a36-7e51-4868-8179-d75e80cc6528 | < 1.2 |
MEDIUM | 6.1 | The Check Pincode For Woocommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to… | — | wordfence |
| fbee8f75-6b02-4f85-9680-585646d61a1b | MEDIUM | 6.1 | The Global Meta Keyword & Description plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions u… | — | wordfence | |
| fbe4688e-19a4-412a-8fe3-167badcfafdf | < 1.9.0 |
MEDIUM | 6.1 | Multiple cross-site scripting (XSS) vulnerabilities in the DMSGuestbook 1.8.0 and 1.7.0 plugin for WordPress allow remot… | — | wordfence |
| fbdf2216-82a9-4a89-8a18-9d5667b7d29d | < 4.2.4 |
MEDIUM | 6.1 | The Primer MyData for Woocommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to… | — | wordfence |
| fbda7303-2393-438a-9305-5642975f0419 | MEDIUM | 6.1 | The Shoutbox theme for WordPress is vulnerable to Cross-Site Scripting due to insufficient input sanitization and output… | — | wordfence | |
| fbc3d194-9e55-4a3d-ac50-024a0b810a50 | < 3.4.11 |
MEDIUM | 6.1 | The Post Grid Master plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and includi… | — | wordfence |
| fbc393a6-8357-47b2-9abd-aa611b09eb1c | < 5.8.0 |
MEDIUM | 6.1 | Cross-site scripting (XSS) vulnerability in admin/google_search_console/class-gsc-table.php in the Yoast SEO plugin befo… | — | wordfence |
EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.
Scan My Website →