Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.
40,113 vulnerabilities found (page 793 of 1605)
| CVE ID | Plugin / Theme | Severity | CVSS | Description | Fixed In | Source |
|---|---|---|---|---|---|---|
| e56ebe2a-8a7e-454b-a1cd-7103112087e0 | MEDIUM | 6.1 | Cross-site Scripting (XSS) in WordPress podPress Plugin 8.8.10.17 (and possibly more) could allow remote attackers to in… | — | wordfence | |
| e54c1a85-13f6-48c0-9db8-860b4b1f3e45 | MEDIUM | 6.1 | The WP Front-end login and register plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the email a… | — | wordfence | |
| e54b0294-6829-493f-b7d3-6349000c249c | MEDIUM | 6.1 | The Tax Rate Upload plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and incl… | — | wordfence | |
| e5438f82-2428-44ba-a7c8-e34d80804063 | < 1.0.27 |
MEDIUM | 6.1 | The PayGreen Payment Gateway plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'message_id' p… | — | wordfence |
| e532a2b4-0fb4-4256-89a9-435b55d9de91 | < 3.2.16 |
MEDIUM | 6.1 | The WordPress Membership, User Registration, Login Form, User Profile & Restrict Content Plugin – ProfilePress plugin … | — | wordfence |
| e52914cc-da0c-4b79-b378-4ef63e7974bb | < 3.0.6 |
MEDIUM | 6.1 | The Real Estate 7 Theme for WordPress is vulnerable to Reflected Cross-Site Scripting via several parameters (ct_sqft_fr… | — | wordfence |
| e51a0db0-0ee0-463b-8d82-81a991ef9222 | < 2.3.6 |
MEDIUM | 6.1 | The animate-it plugin before 2.3.6 for WordPress has XSS. | — | wordfence |
| e510fc07-c969-48f4-ac5a-7dc91f9e2cd5 | MEDIUM | 6.1 | The Wp-Scribd-List plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including… | — | wordfence | |
| e50a998e-b6f2-443a-83a9-299def2420c5 | < 3.1.0 |
MEDIUM | 6.1 | Cross-site scripting vulnerability in LearnPress prior to version 3.1.0 allows remote attackers to inject arbitrary web … | — | wordfence |
| e4fd4e36-d9f1-4fb4-8c65-4eebc2097666 | < 2.0.0 |
MEDIUM | 6.1 | The MSRP (RRP) Pricing for WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions … | — | wordfence |
| e4fa7eee-21c9-479e-bbc5-b20f41f94c25 | MEDIUM | 6.1 | The Gameplan theme for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 1.5.1… | — | wordfence | |
| e4f24b32-58a0-4b10-b8ff-65e574966b6e | < 1.4.2 |
MEDIUM | 6.1 | The Waymark plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘content’ parameter in all … | — | wordfence |
| e4e16526-89a5-4d49-ab9d-dcc7ad3bc8d0 | < 1.2.6.3 |
MEDIUM | 6.1 | The wp-editor plugin before 1.2.6.3 for WordPress has multiple XSS issues. | — | wordfence |
| e4d61b69-f3de-4408-98f7-18027a47d168 | MEDIUM | 6.1 | The xili-dictionary plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and incl… | — | wordfence | |
| e4c7ca5c-38aa-4413-83eb-29185cca2a74 | MEDIUM | 6.1 | The Word 2 Cash plugin for WordPress is vulnerable to Cross-Site Request Forgery leading to Stored Cross-Site Scripting … | — | wordfence | |
| e4c27225-f9db-4ae5-bb1f-ce8648c216eb | < 1.3.15 |
MEDIUM | 6.1 | The Magazine Blocks – Blog Designer, Magazine & Newspaper Website Builder, Page Builder with Posts Blocks, Post Grid p… | — | wordfence |
| e4baead0-7126-457a-abe0-0c9bf239ea15 | < 1.2.1 |
MEDIUM | 6.1 | The Related Videos for JW Player plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to,… | — | wordfence |
| e4ba2243-8a4f-4ecb-8f77-6f4fd24865e3 | < 0.9.5 |
MEDIUM | 6.1 | Cross-site scripting (XSS) vulnerability in the MF Gig Calendar plugin < 0.9.5 for WordPress allows remote attackers to … | — | wordfence |
| e4b94952-229c-4336-a985-d2f47c89f7de | MEDIUM | 6.1 | The InstaSqueeze Sexy Squeeze Pages plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'id' pa… | — | wordfence | |
| e4b7fa61-f760-48f4-b30e-9c63f2d388f9 | MEDIUM | 6.1 | The Simple Page Specific Sidebars plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to… | — | wordfence | |
| e4b7f31c-084e-489c-a902-c16e62b99e45 | < 1.5.9 |
MEDIUM | 6.1 | The VikBooking Hotel Booking Engine & PMS WordPress plugin before 1.5.9 does not escape the current URL before putting i… | — | wordfence |
| e4a853e0-0ebc-4ed5-b6ff-ce3973fb3ee1 | < 4.2.3 |
MEDIUM | 6.1 | The Popup Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via popups in versions up to 4.2.3 d… | — | wordfence |
| e4a5dc4f-3eb6-410e-af3d-e3b0639319f3 | < 3.8.9 |
MEDIUM | 6.1 | The PayU India plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘type’ parameter in vers… | — | wordfence |
| e4a32267-6d99-4882-8601-8c4d36575e0f | < 1.4.3 |
MEDIUM | 6.1 | Multiple cross-site request forgery (CSRF) vulnerabilities in the Sharebar plugin 1.4.2 for WordPress allow remote attac… | — | wordfence |
| e4a2d6ee-ee1b-44a1-ad74-61837d9ef4b2 | < 11.1.12 |
MEDIUM | 6.1 | The SEO Plugin by Squirrly SEO WordPress plugin before 11.1.12 does not escape the type parameter before outputting it b… | — | wordfence |
EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.
Scan My Website →