Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.
40,113 vulnerabilities found (page 781 of 1605)
| CVE ID | Plugin / Theme | Severity | CVSS | Description | Fixed In | Source |
|---|---|---|---|---|---|---|
| f25f358b-f9b7-4660-8dda-673023dc1967 | < 1.5.5 |
MEDIUM | 6.1 | The Child Theme Creator by Orbisius plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions… | — | wordfence |
| f25cdb02-4624-4a46-a622-28665e1d856e | MEDIUM | 6.1 | The Amazon Link WordPress plugin through 3.2.10 does not sanitise and escape some of its settings, which could allow hig… | — | wordfence | |
| f257bb6a-442d-4475-b2d0-e97b540cd2c0 | MEDIUM | 6.1 | The Activity Reactions For Buddypress plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions u… | — | wordfence | |
| f23e7274-45f6-46da-b4c8-2eaa1bd39257 | < 20.0.6 |
MEDIUM | 6.1 | The Shield Security β Smart Bot Blocking & Intrusion Prevention Security plugin for WordPress is vulnerable to Reflect… | — | wordfence |
| f2268be8-f9b8-4028-b681-7793b2bd43f8 | < 4.7 |
MEDIUM | 6.1 | Reflected Cross-Site Scripting (XSS) vulnerability in WordPress Ivory Search plugin (versions <= 4.6.6). Vulnerable para… | — | wordfence |
| f2244c29-9d79-47d5-b077-bf04a9199cdc | < 5.9.8 |
MEDIUM | 6.1 | The Events Manager WordPress plugin before 5.9.8 does not sanitise and escape some search parameter before outputing the… | — | wordfence |
| f219b6ea-58b9-455e-a99d-8412661c8e39 | MEDIUM | 6.1 | The postMash β custom post order plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the βmβ … | — | wordfence | |
| f216abf6-3883-4978-8ddb-f3f24cb40f26 | < 2.0.0 |
MEDIUM | 6.1 | The SC Simple Zazzle plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and inc… | — | wordfence |
| f214fd49-abf7-4c66-9ad2-a5da209c22df | < 4.1 |
MEDIUM | 6.1 | The Stylish Google Sheet Reader plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, … | — | wordfence |
| f20fc354-e93c-4da4-8344-a71b07e04e56 | MEDIUM | 6.1 | The AdsPlace'r β Ad Manager, Inserter, AdSense Ads plugin for WordPress is vulnerable to Reflected Cross-Site Scr… | — | wordfence | |
| f20b79cd-4393-4c96-ac78-139ac7c11144 | < 1.1 |
MEDIUM | 6.1 | The o2s gallery plugin for WordPress is vulnerable to Cross-Site Scripting in all versions up to, and including, 1.0 due… | — | wordfence |
| f203fb35-e217-4912-aa80-0bb6b3de1830 | < 2.3.7 |
MEDIUM | 6.1 | The Easy Digital Downloads (EDD) Free Downloads extension for WordPress, as used with EDD 1.8.x before 1.8.7, 1.9.x befo… | — | wordfence |
| f1f81d9b-87b5-4164-b472-e846421f121e | MEDIUM | 6.1 | The Wp Custom CMS Block plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and incl… | — | wordfence | |
| f1f75927-34c6-4086-86e8-abbf921f3423 | MEDIUM | 6.1 | The FWD Slider plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and including… | — | wordfence | |
| f1de8404-5c7b-48d7-ab7f-7f99b309ee43 | MEDIUM | 6.1 | The timelineoptinpro plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the βidβ parameter in … | — | wordfence | |
| f1d82500-c679-49c7-aa6e-3ca9ef73fee9 | MEDIUM | 6.1 | The WP Odoo Form Integrator plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and … | — | wordfence | |
| f1a8bdfb-b89c-4474-9568-bdfc75bcd5ab | MEDIUM | 6.1 | The iONE360 configurator plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and inc… | — | wordfence | |
| f18b7523-fa8f-4c5d-acd7-db0e2135c796 | < 3.2 |
MEDIUM | 6.1 | The Product Enquiry for WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'page' … | — | wordfence |
| f160f474-de8d-4120-9f46-a185b035a627 | < 1.0.16 |
MEDIUM | 6.1 | The Team Circle Image Slider With Lightbox WordPress plugin before 1.0.16 does not sanitize and escape the order_pos par… | — | wordfence |
| f1420ec8-55e4-448d-8230-228d1e566b97 | MEDIUM | 6.1 | The JustClick registration plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, a… | — | wordfence | |
| f127f028-79dd-4671-b789-01c56b77a70e | < 3.2.3 |
MEDIUM | 6.1 | The SimplyRETS Real Estate IDX plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, a… | — | wordfence |
| f124b5a0-b58b-45ff-bd22-7a09a9abd9bd | MEDIUM | 6.1 | The Social Feed plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 2… | — | wordfence | |
| f122cba9-a6f8-46dd-90c5-c54311f2be7f | MEDIUM | 6.1 | The Jigoshop β Store Toolkit plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, a… | — | wordfence | |
| f117fffb-2bbb-4e95-b589-909972db1e5e | < 3.8.0 |
MEDIUM | 6.1 | The Language Switcher plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_a… | — | wordfence |
| f11187da-21f8-4db5-aa36-1010f191e331 | < 4.2 |
MEDIUM | 6.1 | The ARPrice - WordPress Pricing Table Plugin plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all… | — | wordfence |
EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.
Scan My Website →