Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.
40,113 vulnerabilities found (page 785 of 1605)
| CVE ID | Plugin / Theme | Severity | CVSS | Description | Fixed In | Source |
|---|---|---|---|---|---|---|
| ed9a6e27-c18f-4edf-b793-16021ebf0a6f | < 4.1.0 |
MEDIUM | 6.1 | The wp-live-chat-support plugin before 4.1.0 for WordPress has JavaScript injections. | — | wordfence |
| ed886fd6-7d8d-4b99-ad8e-e290ba6f32d9 | MEDIUM | 6.1 | The WP-Hijri plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 1.5.… | — | wordfence | |
| ed866cda-2244-4172-a8bd-63005bbee4fc | < 1.1.9 |
MEDIUM | 6.1 | The Feed Them Gallery plugin for WordPress is vulnerable to Cross-Site Scripting in versions up to, and including, 1.1.8… | — | wordfence |
| ed78a67c-e178-4efb-9b74-fbcfa544f737 | < 3.5.6 |
MEDIUM | 6.1 | The Grand Spa theme for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 3.5.… | — | wordfence |
| ed766000-557b-483b-9b86-c1cc6898abb7 | < 1.5.6 |
MEDIUM | 6.1 | Cross-site scripting (XSS) vulnerability in pretty-bar.php in Pretty Link Lite plugin before 1.5.6 for WordPress allows … | — | wordfence |
| ed74aebc-9d52-4fac-b308-97765db62d3d | < 0.91 |
MEDIUM | 6.1 | The formbuilder plugin before 0.91 for WordPress has XSS via a Referer header. | — | wordfence |
| ed64d0ff-4f49-4c18-86ec-2c6fbd559d2e | < 3.3.7 |
MEDIUM | 6.1 | The Order Tracking Pro plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the start_date and end_d… | — | wordfence |
| ed61c037-a73c-477e-a5b5-3b4781cec130 | < 1.2.4 |
MEDIUM | 6.1 | The Export Customers Data plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 't' parameter in … | — | wordfence |
| ed5d8b70-eb0e-4e5c-a68a-d9bff493c04c | < 0.2 |
MEDIUM | 6.1 | Cross-site scripting (XSS) vulnerability in the Trending theme before 0.2 for WordPress allows remote attackers to injec… | — | wordfence |
| ed579468-c998-4bec-b3a5-01d0ff206d35 | < 2.0.10 |
MEDIUM | 6.1 | The Tutor LMS plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'reset_key' and 'user_id' par… | — | wordfence |
| ed4c5ffa-2474-45f5-900b-59e3c60c15bc | MEDIUM | 6.1 | The Bulk Me Now! plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'status' parameter in all … | — | wordfence | |
| ed43e0ee-0b0e-4367-ba33-a8f08fafcd33 | < 4.0.2 |
MEDIUM | 6.1 | The contact-form-plugin plugin before 4.0.2 for WordPress has XSS. | — | wordfence |
| ed42e29f-d263-43fc-b06e-b7aaaa7622f7 | < 3.0.72 |
MEDIUM | 6.1 | The eCommerce Product Catalog plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘find_optio… | — | wordfence |
| ed40b50b-7d70-4abf-8895-2bf891124bae | < 1.8.5 |
MEDIUM | 6.1 | The Social Slider Widget WordPress plugin before 1.8.5 allowed Authenticated Reflected XSS in the plugin settings page a… | — | wordfence |
| ed2bb3e2-5002-4746-a4f8-b5d1752ccbbf | MEDIUM | 6.1 | The Opal Membership plugin for WordPress is vulnerable to Stored Cross-Site Scripting via checkout form fields in all ve… | — | wordfence | |
| ed0860db-0e1f-4929-90d5-ff2766ba71ad | < 3.9.3 |
MEDIUM | 6.1 | The WP eCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'add_query_arg()' and 'rem… | — | wordfence |
| ed05cd81-ca21-41de-9b02-bd84498cd74e | < 1.0.13 |
MEDIUM | 6.1 | The Pago por Redsys plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'Ds_MerchantParameters'… | — | wordfence |
| ecfcbb55-10ba-45d8-9b05-c08d0aeb7675 | MEDIUM | 6.1 | The PeoplePond plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.… | — | wordfence | |
| ecf1dfb2-8140-45c0-b75c-10d1c1fdc07a | < 1.6.8 |
MEDIUM | 6.1 | The ARForms Form Builder plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and inc… | — | wordfence |
| ece7810c-a65d-421e-ad16-03e51eafeeb6 | < 4.1.4.1 |
MEDIUM | 6.1 | The Uncanny Toolkit Pro for LearnDash plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions u… | — | wordfence |
| ece1d9b6-39f7-4f79-9ce2-c2498c005f0f | MEDIUM | 6.1 | The SpiderDisplay plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and includ… | — | wordfence | |
| ecddca6d-c977-47e8-a91c-7cf3f59f668b | MEDIUM | 6.1 | The Flying Twitter Birds plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and inc… | — | wordfence | |
| ecdcad88-c926-490f-8e83-09d92ba080f8 | < 3.7.28 |
MEDIUM | 6.1 | In WordPress before 4.9.9 and 5.x before 5.0.1, crafted URLs could trigger XSS for certain use cases involving plugins. | — | wordfence |
| ecd93c67-fe26-4ee5-af23-8c26b822dc60 | < 1.3.2 |
MEDIUM | 6.1 | The WP Quick Shop plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including,… | — | wordfence |
| ecd48e2c-343f-4bae-9d9e-260d003ef87c | MEDIUM | 6.1 | The Simple Amazon Affiliate plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'msg' parameter… | — | wordfence |
EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.
Scan My Website →