Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.
40,113 vulnerabilities found (page 783 of 1605)
| CVE ID | Plugin / Theme | Severity | CVSS | Description | Fixed In | Source |
|---|---|---|---|---|---|---|
| efb37c6a-e1a0-4960-b53a-858b22b6e706 | < 1.0.9 |
MEDIUM | 6.1 | The "SagePay Server Gateway for WooCommerce" plugin before 1.0.9 for WordPress has XSS via the includes/pages/redirect.p… | — | wordfence |
| efaf589c-a808-4263-9734-3b335b06e7ca | MEDIUM | 6.1 | The WP Background Tile plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and inclu… | — | wordfence | |
| efa7ce77-45dc-4fe4-b759-c80f3f18c594 | MEDIUM | 6.1 | The NextGEN Gallery Voting plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and i… | — | wordfence | |
| efa01956-7c03-4f0f-9054-6920013a2b32 | < 6.19 |
MEDIUM | 6.1 | Cross-site scripting vulnerability in MaxButtons prior to version 6.19 and MaxButtons Pro prior to version 6.19 allows r… | — | wordfence |
| ef9ba9ff-b979-40c9-bead-0d665ef92287 | MEDIUM | 6.1 | The HM Portfolio plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and includi… | — | wordfence | |
| ef96782e-d3a6-43de-bf6a-801bbe2e43ed | < 4.54 |
MEDIUM | 6.1 | The Hide My WP plugin for WordPress is vulnerable to Cross-Site Scripting in versions up to, and including, 4.53 due to … | — | wordfence |
| ef91b68e-c4f2-4691-8daa-0ffa4d4ee96e | MEDIUM | 6.1 | The 百度分享按钮 plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and inclu… | — | wordfence | |
| ef8a592a-8100-4347-8407-189ca2867c3b | MEDIUM | 6.1 | The Progressive License WordPress plugin through 1.1.0 is lacking any CSRF check when saving its settings, which could a… | — | wordfence | |
| ef828667-f241-4c5c-92a8-0a4f366e190f | MEDIUM | 6.1 | The Abundatrade Plugin plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and inclu… | — | wordfence | |
| ef80a076-98cb-42c1-8d7d-0a6b38d7bfc8 | < 1.6.6 |
MEDIUM | 6.1 | The Country Selector Plugin is vulnerable Cross-Site Scripting. The payload executes whenever the user tries to access t… | — | wordfence |
| ef7d7378-fa94-4964-916b-a41f69866d76 | < 11.6 |
MEDIUM | 6.1 | The VS Contact Form plugin for WordPress may be vulnerable to Reflected Cross-Site Scripting via the $_SERVER['REQUEST_U… | — | wordfence |
| ef6538e7-8cde-4c49-9965-0624a25ffe65 | < 0.8.8.6 |
MEDIUM | 6.1 | The WP Fastest Cache plugin 0.8.8.5 for WordPress has XSS via the rules[0][content] parameter in a wpfc_save_exclude_pag… | — | wordfence |
| ef60f4c3-e38f-4f95-80cd-5e1f5512ebf5 | < 3.9.7 |
MEDIUM | 6.1 | The Outdoor theme for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 3.9.6 … | — | wordfence |
| ef52026b-1bfc-481c-8eb7-511d1910a35e | MEDIUM | 6.1 | The Image Gallery plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and includ… | — | wordfence | |
| ef4a7a20-663e-4e6a-af23-e8a87b18521e | MEDIUM | 6.1 | Multiple cross-site scripting (XSS) vulnerabilities in eshop-orders.php in the eShop plugin 6.3.14 for WordPress allow r… | — | wordfence | |
| ef3b11ef-c328-489e-8c12-331621a0327c | < 8.0.18 |
MEDIUM | 6.1 | The wp-live-chat-support plugin before 8.0.18 for WordPress has wp-admin/admin.php?page=wplivechat-menu-gdpr-page term X… | — | wordfence |
| ef20da8c-6baf-4c21-b249-65e0b8901469 | < 0.10.0 |
MEDIUM | 6.1 | The Songkick Concerts and Festivals plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up … | — | wordfence |
| ef14c7b4-8cad-4139-a170-42470202ec24 | MEDIUM | 6.1 | The MOLIE WordPress plugin through 0.5 does not escape the course_id parameter before outputting it back in the admin da… | — | wordfence | |
| ef08c1ad-fc85-4154-8634-21c506436317 | < 1.1.1 |
MEDIUM | 6.1 | The Easy Digital Downloads (EDD) QR Code extension for WordPress in versions up to, and including, 1.1.0, as used with E… | — | wordfence |
| ef0866ea-1edd-4d45-b3b9-75a0244e8951 | MEDIUM | 6.1 | The Tiki Time theme for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 1.3 … | — | wordfence | |
| eee91d95-afdb-45e3-b639-50eb3c46115d | < 2.4 |
MEDIUM | 6.1 | Cross-site scripting (XSS) vulnerability in pixabay-images.php in the Pixabay Images plugin before 2.4 for WordPress all… | — | wordfence |
| eee87b71-713e-4e97-90a4-4ed71d264053 | MEDIUM | 6.1 | The NativeChurch theme for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 4… | — | wordfence | |
| eee27f2c-bc21-4b0f-9de5-da1035c54857 | < 6.1.5 |
MEDIUM | 6.1 | The Awesome Support – WordPress HelpDesk & Support Plugin plugin for WordPress is vulnerable to Reflected Cross-Site S… | — | wordfence |
| eedada2a-5543-46b1-a3d2-5e5b86a05ff9 | < 4.0.0 |
MEDIUM | 6.1 | The Careerfy - Job Board WordPress Theme theme for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘… | — | wordfence |
| eed6306a-317b-40ed-b7f5-7f930b3509e0 | < 2.4.4 |
MEDIUM | 6.1 | The Conference Scheduler WordPress plugin before 2.4.4 does not sanitize and escape the tab parameter before outputting … | — | wordfence |
EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.
Scan My Website →