Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.
40,113 vulnerabilities found (page 776 of 1605)
| CVE ID | Plugin / Theme | Severity | CVSS | Description | Fixed In | Source |
|---|---|---|---|---|---|---|
| f7b6b59a-366f-4fa6-9e54-01372d6cea8c | MEDIUM | 6.1 | The ImmoPress plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to inclusion of a vulnerable OAut… | — | wordfence | |
| f799db97-ca61-439d-94ec-a44270d1cd07 | < 1.7.5 |
MEDIUM | 6.1 | The Import Eventbrite Events plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'page' paramet… | — | wordfence |
| f7968054-69f1-47f5-9a32-b124ee1133ce | MEDIUM | 6.1 | The Associados Amazon Plugin plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and… | — | wordfence | |
| f78e6faf-ff1d-4944-aa54-7843cc8614f4 | < 3.3.0 |
MEDIUM | 6.1 | Cross site scripting (XSS) vulnerability in the Spiffy Calendar plugin before 3.3.0 for WordPress allows remote attacker… | — | wordfence |
| f787e299-21f8-4662-935a-ff1e25c7d275 | < 0.9.4 |
MEDIUM | 6.1 | The Gmedia Photo Gallery plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and inc… | — | wordfence |
| f7857dad-a843-4e5e-9994-41d025b8a5ac | < 1.7.61 |
MEDIUM | 6.1 | The Encyclopedia / Glossary / Wiki plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions … | — | wordfence |
| f773ef2f-c33d-414e-9c2f-df22b9d00234 | < 1.1.51 |
MEDIUM | 6.1 | The EventCalendar WordPress plugin before 1.1.51 does not escape some user input before outputting it back in attributes… | — | wordfence |
| f75966a5-e593-4c86-842d-c136ae847eb0 | < 2.2.6 |
MEDIUM | 6.1 | The Post Timeline for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 2.2.5 … | — | wordfence |
| f74c419a-56de-4190-925d-876d32f712e1 | < 3.2.2 |
MEDIUM | 6.1 | The Compare Products for WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the βs_f… | — | wordfence |
| f74c392c-1d79-4498-8298-d1160af250b6 | MEDIUM | 6.1 | The go Social plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0… | — | wordfence | |
| f7485859-c155-4335-aa76-3b4363dbbe4c | < 1.7.8 |
MEDIUM | 6.1 | The Web Directory Free plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and inclu… | — | wordfence |
| f745d10e-9a03-4461-b981-189d4ad3b0a6 | MEDIUM | 6.1 | The Kumihimo plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and including, … | — | wordfence | |
| f7350dc3-82a0-4f61-9ff8-4b622108fa06 | < 3.37 |
MEDIUM | 6.1 | The Qwiz Online Quizzes and Flashcards plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the qnam… | — | wordfence |
| f70d0bea-3ac2-4235-92a2-09458b85bddd | < 6.4.2.7 |
MEDIUM | 6.1 | The Quiz Maker plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 6.… | — | wordfence |
| f70b66ad-55fb-45f8-944a-2c8712071113 | < 1.25.0 |
MEDIUM | 6.1 | The Ultimate Addons for Beaver Builder plugin for WordPress is vulnerable to Cross-Site Scripting in versions up to, and… | — | wordfence |
| f6fe59e8-78cf-47f4-90eb-920f8e4fd204 | < 1.3 |
MEDIUM | 6.1 | Cross-site scripting (XSS) vulnerability in admin/partials/uif-access-token-display.php in the Ultimate Instagram Feed p… | — | wordfence |
| f6e3e5dd-b9f1-4d24-98cc-b6ab319434e4 | < 1.6.8.5 |
MEDIUM | 6.1 | The Appointment Booking Calendar β Simply Schedule Appointments Booking Plugin plugin for WordPress is vulnerable to R… | — | wordfence |
| f6db5e9f-9b3b-44c9-a6d9-78df3ed3b1fc | < 1.3.8 |
MEDIUM | 6.1 | The Stop User Enumeration plugin for WordPress is vulnerable to Cross-Site Scripting in versions up to, and including, 1… | — | wordfence |
| f6d24786-676b-478a-ad9a-5c3f5ca3e85b | MEDIUM | 6.1 | The Scarlet theme for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions due to the inclusion of … | — | wordfence | |
| f6c7b969-04e4-409a-81e2-823a94701d41 | < 7.7.1 |
MEDIUM | 6.1 | The ANAC XML Bandi di Gara plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and i… | — | wordfence |
| f6c211bb-c7e6-41d3-8cbc-45a286bffc9e | < 1.0.40 |
MEDIUM | 6.1 | The Wishlist plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and including, … | — | wordfence |
| f68c8953-7441-4204-b1e8-8c49cf491d34 | MEDIUM | 6.1 | The Footer Flyout Widget plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and inc… | — | wordfence | |
| f682b623-f9c5-44ce-90db-c6ee4c27a93b | < 3.0.9 |
MEDIUM | 6.1 | The Customer Reviews Plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'wpcr3_debug_code' par… | — | wordfence |
| f67c4315-b73d-4eac-8ded-0e5b3a937fec | MEDIUM | 6.1 | The MercadoLibre Integration plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and… | — | wordfence | |
| f6754c9a-81e1-4b39-a125-5293ee4ff758 | < 6.1.2 |
MEDIUM | 6.1 | The YOP Poll WordPress plugin before 6.1.2 does not escape the perpage parameter before outputting it back in an attribu… | — | wordfence |
EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.
Scan My Website →