Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.
40,113 vulnerabilities found (page 792 of 1605)
| CVE ID | Plugin / Theme | Severity | CVSS | Description | Fixed In | Source |
|---|---|---|---|---|---|---|
| e662761d-1dc8-4998-83b5-316ce683b5b6 | < 5.9.8 |
MEDIUM | 6.1 | The Persian Woocommerce WordPress plugin through 5.8.0 does not escape the s parameter before outputting it back in an a… | — | wordfence |
| e65cf73b-349b-4982-b6ec-a2c94d327d0a | MEDIUM | 6.1 | Cross-site scripting (XSS) vulnerability in the Marekkis Watermark plugin 0.9.4 for WordPress allows remote attackers to… | — | wordfence | |
| e6481a6e-5875-44d8-9b24-594fb73e8942 | MEDIUM | 6.1 | The Covert VideoPress Theme for WordPress is vulnerable to Reflected Cross-Site Scripting due to inclusion of a vulnerab… | — | wordfence | |
| e647fcde-e36a-4432-abec-73e414991e96 | < 3.0.15 |
MEDIUM | 6.1 | The Ditty (formerly Ditty News Ticker) WordPress plugin before 3.0.15 is affected by a Reflected Cross-Site Scripting (X… | — | wordfence |
| e632b842-b3d2-461f-aaed-e413d98964a5 | MEDIUM | 6.1 | The Support Helpdesk Ticket System Lite plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions… | — | wordfence | |
| e6270944-31c0-4d6d-a23f-87fce37ff8b0 | < 3.1.10 |
MEDIUM | 6.1 | The SyntaxHighlighter Evolved plugin for WordPress is vulnerable to Cross-Site Scripting in versions up to, and includin… | — | wordfence |
| e621c82c-ab35-4188-a592-03c09b70f0ae | < 1.7.2 |
MEDIUM | 6.1 | The Web Directory Free plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'hash' parameter in … | — | wordfence |
| e61110fc-cc2d-4207-97b6-b21459334216 | < 1.9.1 |
MEDIUM | 6.1 | The ADFO β Custom data in admin dashboard plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the… | — | wordfence |
| e60de5d9-34f8-4068-b656-11b2b6cb36d4 | < 1.5.1 |
MEDIUM | 6.1 | The Keyring plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to inclusion of a vulnerable OAuth … | — | wordfence |
| e6003a2a-dda5-4db4-8a0c-0d26d79529f2 | < 2.3.1 |
MEDIUM | 6.1 | The core plugin for kitestudio themes plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the kite_… | — | wordfence |
| e5ed3ec3-1c05-4fff-a453-11536cfbb366 | MEDIUM | 6.1 | The Pin Locations on Map plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and… | — | wordfence | |
| e5df79e6-649e-4213-b2ff-bc994b372224 | < 3.3.5.9 |
MEDIUM | 6.1 | Cross-site scripting (XSS) vulnerability in the Download Monitor plugin before 3.3.5.9 for WordPress allows remote attac… | — | wordfence |
| e5db103a-a823-47ac-a1f4-c297619cf1a4 | < 2.0.0 |
MEDIUM | 6.1 | The Z-URL Preview plugin 1.6.1 for WordPress has XSS via the class.zlinkpreview.php url parameter. | — | wordfence |
| e5d82cd5-42cc-412b-8026-53736680407d | MEDIUM | 6.1 | The Ultimate Blogroll plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and includ… | — | wordfence | |
| e5d67eb3-c399-437e-a504-2ccdda7c7882 | < 1.8.0 |
MEDIUM | 6.1 | The Contact Form, Drag and Drop Form Builder for WordPress plugin before 1.8.0 does not escape the status parameter befo… | — | wordfence |
| e5c89df2-69be-4b58-ad3c-ba0191e3d701 | MEDIUM | 6.1 | The GNUCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 1… | — | wordfence | |
| e5b98a2c-faed-4e2b-8b94-31e2be95ad40 | < 1.3.5 |
MEDIUM | 6.1 | The WPZOOM Addons for Elementor β Starter Templates & Widgets plugin for WordPress is vulnerable to Reflected Cross-Si… | — | wordfence |
| e5b00388-48b8-4e82-ab52-1cd3d02177b7 | < 0.6 |
MEDIUM | 6.1 | The [CR]Paid Link Manager plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the URL path in all v… | — | wordfence |
| e5a7b18b-3a92-4065-9c0d-9979eeacff93 | MEDIUM | 6.1 | The Awesome Studio plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including… | — | wordfence | |
| e5a53e42-ad71-4c13-b18b-9958656bbee4 | < 3.8.1 |
MEDIUM | 6.1 | The BSK Forms Blacklist plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'target' parameter … | — | wordfence |
| e599393b-f009-4a3f-a89e-6219ecf33efc | < 2.1.1 |
MEDIUM | 6.1 | The Donate by BestWebSoft β Donations Acception Extention for WordPress plugin for WordPress is vulnerable to Reflecte… | — | wordfence |
| e5986c72-ae6d-4cd2-929d-fe2ff6462b4f | < 1.3 |
MEDIUM | 6.1 | The Syndication Links plugin for WordPress is vulnerable to DOM-based Cross-Site Scripting via the genericons/example.ht… | — | wordfence |
| e5863e9b-3f98-41ea-97ed-26563493cffd | < 1.12.4 |
MEDIUM | 6.1 | The WP ERP plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 1.12.3… | — | wordfence |
| e582f3e8-f8c5-4168-bc5b-856dccab622b | < 1.7.4 |
MEDIUM | 6.1 | The tagDiv Opt-In Builder plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and in… | — | wordfence |
| e5726c70-c2c7-45b9-bd03-38cf1320646a | MEDIUM | 6.1 | The Brilliance theme for WordPress is vulnerable to Relected Cross-Site Scripting in versions up to, and including, 1.3.… | — | wordfence |
EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.
Scan My Website →