Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.
40,113 vulnerabilities found (page 778 of 1605)
| CVE ID | Plugin / Theme | Severity | CVSS | Description | Fixed In | Source |
|---|---|---|---|---|---|---|
| f59ccb78-722b-490b-874e-7026afc3511b | < 1.6.3 |
MEDIUM | 6.1 | The SKU Generator for WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of… | — | wordfence |
| f5925251-302a-4132-80ea-21ebc0c65944 | MEDIUM | 6.1 | The JNews - Frontend Submit plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and … | — | wordfence | |
| f5867f37-ae58-4f75-828e-bb99b3e5252e | < 1.0.4 |
MEDIUM | 6.1 | The Currency Switcher for WordPress plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use … | — | wordfence |
| f57ee188-2fdf-402f-b712-80de0d6f7f8d | < 4.2.1 |
MEDIUM | 6.1 | The Device Detector plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and includin… | — | wordfence |
| f5733a60-8078-48ed-9395-ea79b4199f7e | < 1.0.21 |
MEDIUM | 6.1 | The WP System Log WordPress plugin before 1.0.21 does not sanitise, validate and escape the IP address retrieved from lo… | — | wordfence |
| f5698128-f76d-4be4-8d5a-fb465b202d52 | MEDIUM | 6.1 | The MJ Contact us plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and includ… | — | wordfence | |
| f5500911-52cf-43b5-a15e-e8db5bedd5af | < 2.18.2 |
MEDIUM | 6.1 | The Real Cookie Banner plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_… | — | wordfence |
| f5442453-6b72-4c8b-8b9f-59b8536aac73 | < 1.3.7.3 |
MEDIUM | 6.1 | The WOOCS WordPress plugin before 1.3.7.3 does not sanitise and escape the custom_prices parameter before outputting it … | — | wordfence |
| f53a22a3-d3c2-44c4-8e66-a9775b69b147 | MEDIUM | 6.1 | The Varnish WordPress plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and includ… | — | wordfence | |
| f52f6d55-d0f5-4eba-bc07-ed94bded8777 | < 1.4.14 |
MEDIUM | 6.1 | The Sabai Discuss plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via several parameters in version… | — | wordfence |
| f5281d4b-c2cd-4972-b837-e101a8893c6e | < 1.38.3 |
MEDIUM | 6.1 | The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is vulnerable to Reflecte… | — | wordfence |
| f52285e0-e78d-4231-8ff9-53fbe568fcc2 | < 1.0.7 |
MEDIUM | 6.1 | The Contact Form 7 Redirect & Thank You Page plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via th… | — | wordfence |
| f4ff957a-1969-48f5-9f4e-d6bee2cbe581 | < 1.2.0 |
MEDIUM | 6.1 | The Right Click Disable OR Ban plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, a… | — | wordfence |
| f4eb46c8-77fe-4e47-9912-5d8fd4ec0918 | MEDIUM | 6.1 | The UW Freelancer plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including,… | — | wordfence | |
| f4e8ad18-fa25-414c-8a94-9ad9bd3c2e31 | < 2.3.7 |
MEDIUM | 6.1 | The XO Event Calendar plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘selected-name’ p… | — | wordfence |
| f4d41f7f-f0c6-4e50-bf5f-37ee25415f43 | < 2.0.20 |
MEDIUM | 6.1 | The Gallery Bank – WordPress Photo Gallery Plugin for WordPress is vulnerable to Multiple Reflected Cross-Site Scripti… | — | wordfence |
| f4bf4e12-5cbb-45bc-938e-62163baaa15d | < 1.1.10 |
MEDIUM | 6.1 | The Thumbnail carousel slider plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the search_term p… | — | wordfence |
| f4b69cff-31ac-4abe-8f03-07ee3fb4c285 | MEDIUM | 6.1 | The MoolaMojo WordPress plugin is vulnerable to Reflected Cross-Site Scripting via the classes parameter found in the ~/… | — | wordfence | |
| f4acd261-d924-46d5-8aef-49b026cba8ca | MEDIUM | 6.1 | The EZPZ One Click Backup plugin for WordPress is vulnerable to Cross-Site Scripting via the 'mail' parameter in version… | — | wordfence | |
| f49cafe0-2caf-4148-b7c9-1b78bbfba6e7 | MEDIUM | 6.1 | The Light Messages WordPress plugin through 1.0 is lacking CSRF check when updating it's settings, and is not sanitising… | — | wordfence | |
| f497c9b0-afd4-48b8-a701-b2a9ad2b4389 | MEDIUM | 6.1 | The Asynchronous Javascript plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and … | — | wordfence | |
| f48bb7d9-ce82-4549-aead-2876dd3081a8 | MEDIUM | 6.1 | The 3D Avatar User Profile plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and i… | — | wordfence | |
| f4835539-a66c-4d14-b3c3-9a3a64e89ea6 | < 1.3.8.5 |
MEDIUM | 6.1 | The Asset CleanUp: Page Speed Booster WordPress plugin before 1.3.8.5 does not escape the wpacu_selected_sub_tab_area pa… | — | wordfence |
| f47d38d2-d388-4a79-a47b-af41cd85e404 | MEDIUM | 6.1 | The Border Loading Bar WordPress plugin is vulnerable to Reflected Cross-Site Scripting via the `f` and `t` parameter fo… | — | wordfence | |
| f478a5b3-58ef-410e-801f-82eaa579941a | MEDIUM | 6.1 | The WP Service Payment Form With Authorize.net plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via … | — | wordfence |
EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.
Scan My Website →