Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.
40,113 vulnerabilities found (page 799 of 1605)
| CVE ID | Plugin / Theme | Severity | CVSS | Description | Fixed In | Source |
|---|---|---|---|---|---|---|
| ded8f958-ed2a-43ab-8688-9f6d16515469 | MEDIUM | 6.1 | The Third Party Cookie Eraser plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, an… | — | wordfence | |
| ded4b93f-fd90-4803-9d20-3109512b1a24 | MEDIUM | 6.1 | The Image Tag Manager plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'default_class’ par… | — | wordfence | |
| ded05261-36f2-4414-b30a-7467b0c79938 | MEDIUM | 6.1 | The WP Fountain WordPress plugin is vulnerable to Reflected Cross-Site Scripting due to the use of $_SERVER['PHP_SELF'] … | — | wordfence | |
| deba9cd0-2c7e-4789-8499-977c694aba8b | < 1.6.21 |
MEDIUM | 6.1 | The Events Made Easy plugin for WordPress is vulnerable to Cross-Site Request Forgery to Stored Cross-Site Scripting via… | — | wordfence |
| deb6821e-93ff-4636-912b-887deba59577 | < 3.4.7 |
MEDIUM | 6.1 | Cross-site scripting vulnerability in WP All Import plugin prior to version 3.4.7 for WordPress allows an attacker to in… | — | wordfence |
| dead051c-f28f-4859-b0ba-b27a8d6c9335 | MEDIUM | 6.1 | The Crypto and DeFi Widgets – Web3 Cryptocurrency Shortcodes plugin for WordPress is vulnerable to Reflected Cross-Sit… | — | wordfence | |
| de957e90-5758-46f3-90f8-521b47d247ff | < 1.2.1 |
MEDIUM | 6.1 | The Sender by BestWebSoft plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and in… | — | wordfence |
| de8abfac-f25e-41a4-8e94-ab01b105f3b4 | MEDIUM | 6.1 | The Shabbos and Yom Tov plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and incl… | — | wordfence | |
| de897025-e2e0-4e21-9c58-db2c20d5d3f9 | MEDIUM | 6.1 | The Key4ce osTicket Bridge plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and i… | — | wordfence | |
| de7be653-4d5b-4cbe-ad9c-6c2748f533bb | < 2.08 |
MEDIUM | 6.1 | The Push Notification for Post and BuddyPress plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via t… | — | wordfence |
| de7b0d72-9227-4ecd-a88f-a7d04b592f59 | MEDIUM | 6.1 | The Rio Video Gallery plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and includ… | — | wordfence | |
| de6d07f0-6e69-4b6d-98ee-128117f0b822 | MEDIUM | 6.1 | The Scanventory plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 1… | — | wordfence | |
| de5feed6-ef1b-4e06-9bd0-145292f613b6 | MEDIUM | 6.1 | The Local Shipping Labels for WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all ve… | — | wordfence | |
| de5d5ffc-e76a-4ea9-be68-9ca5f847a363 | < 2.0 |
MEDIUM | 6.1 | The All 404 Pages Redirect to Homepage plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multiple pa… | — | wordfence |
| de58a0d1-42d2-46d7-a8a5-6b86b438b326 | MEDIUM | 6.1 | The World Cup Predictor plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and … | — | wordfence | |
| de523bc3-3c22-4632-8f14-2f9098cb4f28 | < 3.14.0 |
MEDIUM | 6.1 | The Newspack Newsletters plugin for WordPress is vulnerable to Open Redirect in all versions up to, and including, 3.13.… | — | wordfence |
| de4f4064-cb72-4b67-b8af-0b2cec5a53d0 | MEDIUM | 6.1 | The WP Service Payment Form With Authorize.net plugin for WordPress is vulnerable to Cross-Site Request Forgery in all v… | — | wordfence | |
| de388a39-8966-4b08-a4d2-dbbcd0459c23 | MEDIUM | 6.1 | The Post Thumbs plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1… | — | wordfence | |
| de331d1d-b2f8-4cc6-a998-779595eca70c | < 1.1.16 |
MEDIUM | 6.1 | The WP Responsive Tabs horizontal vertical and accordion Tabs plugin for WordPress is vulnerable to Reflected Cross-Site… | — | wordfence |
| de20d896-1493-43ed-8e0c-c686bf2b32d6 | < 3.10.5 |
MEDIUM | 6.1 | The Master Slider plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including,… | — | wordfence |
| de159b3e-b456-4b36-ad44-41d3595b53a8 | < 1.4.0 |
MEDIUM | 6.1 | The Isolved Talent Acquisition plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up t… | — | wordfence |
| ddff1a95-64f9-4076-a81a-cdda04106c46 | MEDIUM | 6.1 | The Disconnected theme for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 1… | — | wordfence | |
| ddd2c0c2-49b5-4745-9e52-d0ae6b997640 | MEDIUM | 6.1 | The WP Design Maps & Places WordPress plugin is vulnerable to Reflected Cross-Site Scripting via the filename parameter … | — | wordfence | |
| ddca65fa-0744-4b2a-808c-a913586edc60 | MEDIUM | 6.1 | The WPGlobus Translate Options plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, a… | — | wordfence | |
| ddc889bf-8062-4a2c-9d50-d1c76a3c3386 | < 1.0.1 |
MEDIUM | 6.1 | The Emag Marketplace Connector plugin 1.0.0 for WordPress has reflected XSS because the parameter "post" to /wp-content/… | — | wordfence |
EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.
Scan My Website →