Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.
40,113 vulnerabilities found (page 784 of 1605)
| CVE ID | Plugin / Theme | Severity | CVSS | Description | Fixed In | Source |
|---|---|---|---|---|---|---|
| eeca3208-2cab-4c03-935f-8f657d7ca87f | MEDIUM | 6.1 | The Blaze Online eParcel for WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in version… | — | wordfence | |
| eebe1bf7-0366-4226-bcbc-027186136008 | < 3.1.6 |
MEDIUM | 6.1 | The Cart Lift – Abandoned Cart Recovery for WooCommerce and EDD plugin for WordPress is vulnerable to Reflected Cross-… | — | wordfence |
| eea754db-495a-4518-840e-0eeeeb1c31b9 | MEDIUM | 6.1 | The JH 404 Logger WordPress plugin through 1.1 doesn't sanitise the referer and path of 404 pages, when they are output … | — | wordfence | |
| ee8731e6-92e9-4cc6-8e1c-0c7727420af7 | MEDIUM | 6.1 | The Contact Us By Lord Linus plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and… | — | wordfence | |
| ee862f44-903d-4b1c-9a5c-98e63379d5cb | < 2.12.0 |
MEDIUM | 6.1 | The WP Menu Cart plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg wi… | — | wordfence |
| ee8167f0-bb92-4844-be8c-4cc886c946f9 | MEDIUM | 6.1 | The Campus Explorer Widget plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and i… | — | wordfence | |
| ee7408d2-3cff-4c80-bc07-b0418676e961 | < 1.9.12 |
MEDIUM | 6.1 | The Tumult Hype Animations plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and i… | — | wordfence |
| ee5de6df-e387-44e8-8fab-c07af4a2155c | MEDIUM | 6.1 | The ZhinaTwitterWidget plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and inclu… | — | wordfence | |
| ee5af42d-71d8-4e65-bd74-55456480da8b | MEDIUM | 6.1 | The WP Image Resizer plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘src’ parameter du… | — | wordfence | |
| ee504315-de76-4f1d-b648-3f2904770988 | < 2.2 |
MEDIUM | 6.1 | The Multimedia Playlist Slider Addon for WPBakery Page Builder plugin for WordPress is vulnerable to Reflected Cross-Sit… | — | wordfence |
| ee4e08e0-25b7-47b2-9ec2-de93afc437a6 | < 5.6 |
MEDIUM | 6.1 | The events-manager plugin before 5.6 for WordPress has XSS. | — | wordfence |
| ee3fdeb2-9e2a-4fe7-aa74-aaf60a74c060 | MEDIUM | 6.1 | Controller/controller-comments.php in WP GDPR plugin through 2.1.1 has unauthenticated stored XSS. | — | wordfence | |
| ee3ed678-c77c-4c87-babe-576e6f9e5018 | MEDIUM | 6.1 | The azurecurve Floating Featured Image plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versi… | — | wordfence | |
| ee36fec3-1fc1-43e8-8428-301cb4e5b689 | MEDIUM | 6.1 | The Digitally theme for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 1.0.… | — | wordfence | |
| ee1b6961-1453-4f59-b03a-ab78b2e3f9d4 | < 1.2.6 |
MEDIUM | 6.1 | Cross-site scripting (XSS) vulnerability in ZeroClipboard.swf and ZeroClipboard10.swf in ZeroClipboard before 1.0.8, as … | — | wordfence |
| ee1a3105-ebb2-44ce-bbbe-3ab95d69670a | < 3.0 |
MEDIUM | 6.1 | The Target First WordPress Plugin v2.0, also previously known as Watcheezy, suffers from a critical unauthenticated stor… | — | wordfence |
| ee13ee9a-dd53-4124-a7e9-679afe362f58 | < 1.1.2 |
MEDIUM | 6.1 | The instalinker plugin before 1.1.2 for WordPress has includes/instalinker-admin-preview.php?client_id= XSS. | — | wordfence |
| edf64bd8-dc4e-4e39-8958-39df046ac374 | MEDIUM | 6.1 | The PAFacile plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and including, … | — | wordfence | |
| ede6c4d1-e4bd-44c0-a66a-fffc0e1b22f6 | < 1.1.41 |
MEDIUM | 6.1 | The Gallery Photoblocks plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the GET 'id' parameter … | — | wordfence |
| ede4b8ad-3c12-4ed8-9eda-806afa580bad | < 2.4.7 |
MEDIUM | 6.1 | The WooODT Lite plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 2… | — | wordfence |
| edd1f4f9-c0d7-4b7b-bb5e-7388e0935e32 | < 3.4.2 |
MEDIUM | 6.1 | The colorway theme before 3.4.2 for WordPress has XSS via the contactName parameter. | — | wordfence |
| edc83f3a-c573-4555-bbeb-1a9f1dbba19d | MEDIUM | 6.1 | The Revision Diet plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including,… | — | wordfence | |
| edc35f8c-f916-433e-9d3f-4992e8c9d7cd | < 1.7.0 |
MEDIUM | 6.1 | The WP Bannerize Pro plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and includi… | — | wordfence |
| edb8505b-3caa-4ccf-b0fc-69264f95b7ca | < 2024.04.30 |
MEDIUM | 6.1 | The Swift Framework plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'listing_id' parameter … | — | wordfence |
| ed9db9c1-c6b5-459e-9820-ec4ee47b244e | < 5.1 |
MEDIUM | 6.1 | The tagDiv Composer plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘envato_code[]’ par… | — | wordfence |
EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.
Scan My Website →