Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.
40,113 vulnerabilities found (page 772 of 1605)
| CVE ID | Plugin / Theme | Severity | CVSS | Description | Fixed In | Source |
|---|---|---|---|---|---|---|
| fbc14a5f-fa6b-47fa-8e8b-502409b18ed6 | < 1.2.9 |
MEDIUM | 6.1 | The WP Popup Builder plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and includi… | — | wordfence |
| fba24935-5bab-4395-b05e-7bb5d5a1694d | < 15.3 |
MEDIUM | 6.1 | The WP Content Copy Protection & No Right Click (PRO) plugin for WordPress is vulnerable to Open Redirect in all version… | — | wordfence |
| fb892e06-b32c-4cea-92e5-e214acb91a2f | < 1.2.7 |
MEDIUM | 6.1 | The smokesignal plugin before 1.2.7 for WordPress has XSS. | — | wordfence |
| fb878e2d-3573-4a70-9968-c0cf9676056d | MEDIUM | 6.1 | The DTC Documents plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.1… | — | wordfence | |
| fb7e922a-fae0-46f9-b8c1-0986b88f2813 | < 13.2.0 |
MEDIUM | 6.1 | Cross-site scripting vulnerability exists in WP Statistics versions prior to 13.2.0 because it improperly processes a pl… | — | wordfence |
| fb7e7083-59b6-498a-ab02-e578cdf17b1f | MEDIUM | 6.1 | The Teleport plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 1.2.… | — | wordfence | |
| fb726242-84fb-47f3-ac43-b43b5b4ae7f0 | < 3.10.2 |
MEDIUM | 6.1 | The Sina Extension for Elementor plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to,… | — | wordfence |
| fb587e37-473a-4e46-afe3-8285af0fa0d0 | MEDIUM | 6.1 | The Spiritual Gifts Survey (and optional S.H.A.P.E survey) plugin for WordPress is vulnerable to Reflected Cross-Site Sc… | — | wordfence | |
| fb518425-56e0-4a8c-ac51-3c9b2c047f11 | MEDIUM | 6.1 | The WP Social Stream plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and includi… | — | wordfence | |
| fb4cefe4-a95f-4a80-a8b4-02a3c0d56795 | MEDIUM | 6.1 | The WP Custom Post RSS Feed plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and … | — | wordfence | |
| fb33f779-d045-48dd-babe-8b1fab903124 | MEDIUM | 6.1 | The Wishful Blog theme, versions up to and including 2.0.1, and Raise Mag theme, versions up to and including 1.0.7, for… | — | wordfence | |
| fb2fffb1-cc8c-46a4-b3ea-2b1aac684fbd | MEDIUM | 6.1 | The Atahualpa theme for WordPress is vulnerable to Cross-Site Scripting via several parameters in versions up to, and in… | — | wordfence | |
| fb1f22c2-fdb3-4e3c-b6d5-2e933ec889bd | < 1.4.8 |
MEDIUM | 6.1 | The 360-product-rotation plugin before 1.4.8 for WordPress has reflected XSS. | — | wordfence |
| fb1dbbec-c8c0-4934-ba07-b5b188886bac | < 2.0.0 |
MEDIUM | 6.1 | The RTMKit plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'themebuilder' parameter in all … | — | wordfence |
| fb0d093b-c339-4b19-a6cd-d2589b8e57ff | < 1.2.104 |
MEDIUM | 6.1 | The WooCommerce PDF Invoice Builder, Create invoices, packing slips and more plugin for WordPress is vulnerable to Refle… | — | wordfence |
| fb0b24b6-38da-4650-b542-a31ba8c98fb9 | < 2.3.1 |
MEDIUM | 6.1 | The "Donation Plugin and Fundraising Platform" plugin before 2.3.1 for WordPress has wp-admin/edit.php csv XSS. | — | wordfence |
| fb0971cf-f4f6-4e41-9e99-c2ba193e39df | < 1.5 |
MEDIUM | 6.1 | The Connect Contact Form 7 to Constant Contact plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in v… | — | wordfence |
| fae793f2-8cb5-49d3-9c8c-2a8377552fcd | MEDIUM | 6.1 | The Cazamba plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and including, 1… | — | wordfence | |
| fac1e55f-7027-494d-8beb-9a23e0fc2e00 | < 10.6.7 |
MEDIUM | 6.1 | The Wp EMember plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'editrecord' parameter in al… | — | wordfence |
| fabeeba6-f3c0-4f9c-a12f-c97801aad810 | < 2.8.1 |
MEDIUM | 6.1 | The NPS computy plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'data1' and 'data2' paramet… | — | wordfence |
| fabd576c-6990-40a1-9a94-ecb63e2b0189 | < 2.0.7 |
MEDIUM | 6.1 | Cross-site request forgery (CSRF) vulnerability in the CreativeMinds CM Downloads Manager plugin before 2.0.7 for WordPr… | — | wordfence |
| fabcfaee-54b5-409f-b023-71aebdda2e00 | < 1.4.8 |
MEDIUM | 6.1 | The Jaroti theme for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to 1.4.8 due to insufficie… | — | wordfence |
| faafa3d3-a4b7-40a5-9133-c953f921ba55 | MEDIUM | 6.1 | The WP IMAP Auth plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and includi… | — | wordfence | |
| faad9cf7-5d83-4ade-b121-c38fb0de78a5 | < 4.7.1 |
MEDIUM | 6.1 | The Poll Maker plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 4.… | — | wordfence |
| faa6c744-7586-47ee-b2ce-af972ee8b4f7 | < 2.8.3 |
MEDIUM | 6.1 | The Loco Translate plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘update_href’ parame… | — | wordfence |
EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.
Scan My Website →