Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.
40,113 vulnerabilities found (page 789 of 1605)
| CVE ID | Plugin / Theme | Severity | CVSS | Description | Fixed In | Source |
|---|---|---|---|---|---|---|
| e9bf506f-17b1-4ec3-87ce-1ed78db6fb0b | < 51.02 |
MEDIUM | 6.1 | The Broadcast plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'do_check' parameter in all v… | — | wordfence |
| e9b918e1-9bf7-4f90-9e77-829bc8012cbb | < 1.2.8 |
MEDIUM | 6.1 | The CM Custom Reports plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'date_from' and 'date… | — | wordfence |
| e99d5841-9fd0-451f-b6fe-bac0851f4aaf | MEDIUM | 6.1 | The CodeBard Help Desk plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and inclu… | — | wordfence | |
| e98b1bc7-8dcb-4fcf-9238-598ce53e443e | < 1.01 |
MEDIUM | 6.1 | The dwnldr plugin before 1.01 for WordPress has XSS via the User-Agent HTTP header. | — | wordfence |
| e98ab8ba-d165-4813-abdb-c7d47a93d30f | MEDIUM | 6.1 | The Hello Followers plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and includin… | — | wordfence | |
| e9885db9-b1eb-4cc6-a7ea-af2c34b1d065 | < 2.0.3.1 |
MEDIUM | 6.1 | A Cross-site Scripting (XSS) vulnerability exists in the All in One SEO Pack plugin before 2.0.3.1 for WordPress via the… | — | wordfence |
| e9688229-90e8-4530-9039-5ba8c8bcf93e | < 1.0.8 |
MEDIUM | 6.1 | The B2i Investor Tools plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and inclu… | — | wordfence |
| e9489254-dbdc-4754-86d0-d28756b269a9 | < 5.1.1 |
MEDIUM | 6.1 | The ProfileGrid plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘id’ parameter in versi… | — | wordfence |
| e947abb8-be40-4090-80a6-5255692ef693 | < 3.6.3 |
MEDIUM | 6.1 | The BuddyStream plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'link' parameter in all ver… | — | wordfence |
| e938c126-e24d-4299-891a-438e7ba513e7 | MEDIUM | 6.1 | The MMX – Make Me Christmas plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, an… | — | wordfence | |
| e928ed4b-5f27-4e0d-af0b-30256b851454 | MEDIUM | 6.1 | The Dashing Memberships plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and incl… | — | wordfence | |
| e9178920-d865-45d3-bfdf-b8ad207d4546 | < 2015.0426 |
MEDIUM | 6.1 | The FeedWordPress plugin for WordPress is vulnerable to Cross-Site Scripting via several parameters in versions before 2… | — | wordfence |
| e9171908-5b6e-44f3-ab93-899932be527f | < 1.6.9.2 |
MEDIUM | 6.1 | The Zoho CRM Lead Magnet plugin 1.6.9.1 for WordPress allows XSS via module, EditShortcode, or LayoutName. | — | wordfence |
| e915f1b5-50cd-4c2a-ad01-feab799d071f | < 10.46 |
MEDIUM | 6.1 | The Subscribe2 plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 10… | — | wordfence |
| e8fa1f97-72f6-4e84-bee4-0d3f7e16eb96 | MEDIUM | 6.1 | The Uploadify Integration plugin for WordPress is vulnerable to Multiple Reflected Cross-Site Scripting via several para… | — | wordfence | |
| e8f6d6f8-42c6-4613-88bf-c00fcc6a9ffe | MEDIUM | 6.1 | The Podčlánková inzerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, a… | — | wordfence | |
| e8f6cabb-ecf5-44f1-bc39-20d9dc989600 | MEDIUM | 6.1 | The Custom DataBase Tables plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and i… | — | wordfence | |
| e8f20aae-37e2-44f6-ac2d-692a87bf5728 | < 3.0 |
MEDIUM | 6.1 | The memphis-documents-library plugin before 3.0 for WordPress has XSS via $_REQUEST. | — | wordfence |
| e8db52ce-fbc3-4fe1-b9b4-cb2ce7d88a67 | < 0.9.3 |
MEDIUM | 6.1 | The Maspik – Spam Blacklist plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the efas_add_to_log … | — | wordfence |
| e8cbd8ee-1bd5-43ea-8e67-5ad893258512 | MEDIUM | 6.1 | The Advance WP Query Search Filter plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up t… | — | wordfence | |
| e8c74105-3f0c-4322-96f3-e6bf4760cc2f | MEDIUM | 6.1 | The Blaze Theme for WordPress is vulnerable to Reflected Cross-Site Scripting via an unknown parameter in all versions d… | — | wordfence | |
| e8bc24df-4d95-44b7-a58c-00a1b24f91e9 | < 1.23 |
MEDIUM | 6.1 | The LH Add Media From Url plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, an… | — | wordfence |
| e8a864ff-2c0e-40c3-8c4e-dc034d8838b9 | < 3.3.8 |
MEDIUM | 6.1 | Cross-site scripting (XSS) vulnerability in the Relevanssi plugin before 3.3.8 for WordPress allows remote attackers to … | — | wordfence |
| e88bb3a8-de24-46fb-a3e4-9ca3fdd4cca7 | < 1.0.23 |
MEDIUM | 6.1 | The video carousel slider with lightbox plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the sea… | — | wordfence |
| e88afde4-6920-4086-940e-34b4a4ee30c5 | MEDIUM | 6.1 | The WordPress InviteBox Plugin for viral Refer-a-Friend Promotions WordPress plugin is vulnerable to Reflected Cross-Sit… | — | wordfence |
EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.
Scan My Website →