Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.
40,113 vulnerabilities found (page 779 of 1605)
| CVE ID | Plugin / Theme | Severity | CVSS | Description | Fixed In | Source |
|---|---|---|---|---|---|---|
| f460d529-f15e-4c23-ad67-94d3f4bc0c2e | < 2.2.1 |
MEDIUM | 6.1 | Cross-site scripting (XSS) vulnerability in sidebar.php in WordPress, when custom 404 pages that call get_sidebar are us… | — | wordfence |
| f45afce1-cb37-4e7e-90b2-6ae1b6400376 | < 3.6.8 |
MEDIUM | 6.1 | The affiliate-toolkit plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via a URL in all versions up … | — | wordfence |
| f44fdbb2-abb8-488f-bdc0-ec6eea93d92a | MEDIUM | 6.1 | The wp Time Machine plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and includin… | — | wordfence | |
| f4460f0a-9417-48bf-b6b3-27a80632dd71 | < 2.7 |
MEDIUM | 6.1 | The WPB Show Core plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and includ… | — | wordfence |
| f4454376-7c18-4f0e-a192-80212a59d94b | MEDIUM | 6.1 | The Push Notifications for WordPress by PushAssist plugin for WordPress is vulnerable to Reflected Cross-Site Scripting … | — | wordfence | |
| f43b5c02-fb10-48f1-9457-f67c5008fe5b | MEDIUM | 6.1 | The Innovs HR plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 1.0… | — | wordfence | |
| f4366cf8-bf50-4d9f-9a85-2c2de7f7e90d | < 1.4.3 |
MEDIUM | 6.1 | The Action Network plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'search' parameter in ve… | — | wordfence |
| f4232656-2e97-4888-8dde-14039d8c2f9d | < 3.6.0 |
MEDIUM | 6.1 | The Seriously Simple Podcasting plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of a… | — | wordfence |
| f4211712-26b2-4f59-82b8-928e405cd08d | < 1.11.3 |
MEDIUM | 6.1 | XSS exists in the the-holiday-calendar plugin before 1.11.3 for WordPress via the thc-month parameter. | — | wordfence |
| f4143849-1cd1-4241-acf6-a34aaf7d369c | MEDIUM | 6.1 | An issue was discovered in the bestsoftinc Car Rental System plugin through 1.3 for WordPress. Persistent XSS can occur … | — | wordfence | |
| f40dd50f-fa64-4901-990c-42e9db53c081 | MEDIUM | 6.1 | The My Custom Widgets plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and includ… | — | wordfence | |
| f40c6e22-ef6c-4a5f-85df-97fd36c57f82 | MEDIUM | 6.1 | The En Masse plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 1.0 … | — | wordfence | |
| f3ff44f2-c3c2-46f5-b984-6151202f722f | < 4.2 |
MEDIUM | 6.1 | The Dreamstime Stock Photos plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, … | — | wordfence |
| f3fc6230-043f-4079-a82a-1b5d191dbf7d | MEDIUM | 6.1 | The Affiliate Plus plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including… | — | wordfence | |
| f3fc1686-06a0-4d48-bb79-470e63cd3600 | < 1.2 |
MEDIUM | 6.1 | The echosign plugin before 1.2 for WordPress has XSS via the inc.php page parameter. | — | wordfence |
| f3e94ba2-ffdd-42ac-86bf-48670f2087e5 | < 2.54 |
MEDIUM | 6.1 | The Butcher theme for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and excluding, 2.54 d… | — | wordfence |
| f3d990ef-5fa8-455d-b35a-2bff82facd45 | MEDIUM | 6.1 | The Send email only on Reply to My Comment plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the … | — | wordfence | |
| f3d535b3-ad52-4322-988e-7d560dbfe3a3 | < 3.7.1 |
MEDIUM | 6.1 | The Raptive Ads plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'poc' parameter in all vers… | — | wordfence |
| f3c5aafc-e75a-472e-9b62-10bb5a9da9b6 | < 2.4.1 |
MEDIUM | 6.1 | The Contact Form 7 β Clockwork SMS plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'to' p… | — | wordfence |
| f3a4aeb2-3929-4f6b-ac6e-bccc1c3bf0dd | < 2.2.5 |
MEDIUM | 6.1 | The WP Statistics plugin for WordPress is vulnerable to Cross-Site Scripting in versions up to, and including, 2.2.4 due… | — | wordfence |
| f389f4bf-ffff-4862-b4e2-4465ca0556ef | < 1.9.9 |
MEDIUM | 6.1 | The Helpie FAQ plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several URLs in versions up to, and… | — | wordfence |
| f3855918-960e-487d-9d5f-6dbeba45523e | < 5.127.4 |
MEDIUM | 6.1 | The CleanTalk cleantalk-spam-protect plugin before 5.127.4 for WordPress is affected by: Cross Site Scripting (XSS). The… | — | wordfence |
| f37f6d9f-cd2d-421d-a5ac-ce552f0d0181 | MEDIUM | 6.1 | The DL Leadback plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 1… | — | wordfence | |
| f3781245-14b1-4b1c-a471-a5a413cdb2ed | < 4.2.8 |
MEDIUM | 6.1 | The NextScripts: Social Networks Auto-Poster plugin before 4.2.8 for WordPress has wp-admin/admin.php?page=nxssnap-repos… | — | wordfence |
| f36ed435-3836-4c43-9e8c-ec07325e05d4 | MEDIUM | 6.1 | The Fidelo Snippet plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including… | — | wordfence |
EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.
Scan My Website →