Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.
40,113 vulnerabilities found (page 780 of 1605)
| CVE ID | Plugin / Theme | Severity | CVSS | Description | Fixed In | Source |
|---|---|---|---|---|---|---|
| f36df17d-4633-42e0-b106-908b994d8cb7 | MEDIUM | 6.1 | The Ultimate Endpoints With Rest Api plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'page'… | — | wordfence | |
| f36af71c-78af-402c-9d3a-3752368e7584 | < 14.0.0 |
MEDIUM | 6.1 | The Contest Gallery plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and includin… | — | wordfence |
| f34f98a0-9df4-4b50-ae6a-7912e4b12bb2 | < 1.9.20 |
MEDIUM | 6.1 | Cross-site scripting (XSS) vulnerability in lib/includes/auth.inc.php in the WPtouch plugin 1.9.19.4 and 1.9.20 for Word… | — | wordfence |
| f34e397a-beaa-4c09-bedb-c41515d1adfa | MEDIUM | 6.1 | The WP Cleaner plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 1.… | — | wordfence | |
| f34b7518-5cb3-4b4e-8b18-927c08c045f7 | < 1.6.7 |
MEDIUM | 6.1 | The Accounting for WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of ad… | — | wordfence |
| f34825a5-f7ef-42f8-8995-d41ab79b9082 | MEDIUM | 6.1 | The Easy Post Duplicator plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and inc… | — | wordfence | |
| f338b8a9-7b0a-46bd-b624-ebda897651f1 | MEDIUM | 6.1 | The 10CentMail plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 2.… | — | wordfence | |
| f3158e77-39b3-4151-8f10-5824000a585a | < 1.3.6.4 |
MEDIUM | 6.1 | The HUSKY – Products Filter Professional for WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Sc… | — | wordfence |
| f2fad774-f140-4891-8c6f-fbd684e19dc2 | < 1.1.8 |
MEDIUM | 6.1 | The Montezuma theme for WordPress is vulnerable to Reflected Cross-Site Scripting due to the inclusion of a vulnerable v… | — | wordfence |
| f2e6f09e-0ebc-47e3-84f3-9aede2781f42 | MEDIUM | 6.1 | The GD Star Rating plugin for WordPress is vulnerable to Cross-Site Scripting via the 'wpfn' parameter in versions up to… | — | wordfence | |
| f2c6d446-75cd-4f42-a5f2-f4c59d4084ce | MEDIUM | 6.1 | The House Manager – Easy Renter Management System for WordPress plugin for WordPress is vulnerable to Reflected Cross-… | — | wordfence | |
| f2bc0449-b5cc-403b-a943-f53d0d9c663a | < 1.1.0 |
MEDIUM | 6.1 | Manual Purchases Add-on for iThemes Exchange before 1.1.0 for WordPress has XSS via add_query_arg() and remove_query_arg… | — | wordfence |
| f2b70e27-87fb-4905-bbfa-62cca3dbb433 | MEDIUM | 6.1 | The Laborator Xenon theme 1.3 for WordPress allows Reflected XSS via the data/typeahead-generate.php q (aka name) parame… | — | wordfence | |
| f2b4f946-036d-4136-81b8-a8cd2a68e097 | < 2.2 |
MEDIUM | 6.1 | The NaturaLife Extensions plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and in… | — | wordfence |
| f2a87cb3-5cce-4b5a-937d-71e96aeef7c9 | < 3.2.3 |
MEDIUM | 6.1 | The User Registration, Login Form, User Profile & Membership WordPress plugin before 3.2.3 does not sanitise and escape … | — | wordfence |
| f2a5d8ef-109c-471b-a135-c834f090eb5b | < 2.9.9 |
MEDIUM | 6.1 | The WPC Smart Wishlist for WooCommerce WordPress plugin before 2.9.9 does not sanitise and escape a parameter before out… | — | wordfence |
| f2a59015-eb29-44fe-bc21-ba8832ac750b | < 1.13.40 |
MEDIUM | 6.1 | The Form Maker plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 1.… | — | wordfence |
| f29a843d-a8c5-4477-b7cc-620b19b5f585 | < 3.5.1 |
MEDIUM | 6.1 | The Clearpay Gateway for WooCommerce plugin is vulnerable to Reflected Cross-Site Scripting via the ‘orderToken’ par… | — | wordfence |
| f294575d-ce83-4301-ae38-3f0761d9b610 | < 2.0.15 |
MEDIUM | 6.1 | The WP Booking System WordPress plugin before 2.0.15 was affected by a reflected xss in wp-booking-system on the wpbs-ca… | — | wordfence |
| f294175e-dfcd-4d8d-84ee-a945ec7ac7e3 | < 2.3.2 |
MEDIUM | 6.1 | The soundcloud-is-gold plugin before 2.3.2 for WordPress has XSS via the wp-admin/admin-ajax.php?action=get_soundcloud_p… | — | wordfence |
| f2888dcc-86f3-43a7-8c48-116e382d051f | < 1.1.8 |
MEDIUM | 6.1 | The CRM Perks Forms plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and includin… | — | wordfence |
| f281c9a5-1663-4dca-968f-685d933f99b1 | < 3.3.0 |
MEDIUM | 6.1 | The Kudos Donations – Easy donations and payments with Mollie plugin for WordPress is vulnerable to Reflected Cross-Si… | — | wordfence |
| f268974a-db92-42d2-9e1d-f990ea067740 | < 1.4.2 |
MEDIUM | 6.1 | The Contact Form Manager plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'formId' parameter… | — | wordfence |
| f267527d-5fb5-4fc2-bb35-bc60854f1a68 | MEDIUM | 6.1 | The WP Foodbakery plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including,… | — | wordfence | |
| f260495e-d62f-41c9-b6ac-ea015e17ee2f | MEDIUM | 6.1 | The Aphorismus plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.… | — | wordfence |
EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.
Scan My Website →