Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.
40,113 vulnerabilities found (page 803 of 1605)
| CVE ID | Plugin / Theme | Severity | CVSS | Description | Fixed In | Source |
|---|---|---|---|---|---|---|
| dafd1821-1f37-4193-b4bf-19a3d2d15946 | < 1.1.5 |
MEDIUM | 6.1 | The fossura-tag-miner plugin before 1.1.5 for WordPress has XSS. | — | wordfence |
| dafc40bf-833a-4d42-b9bc-c7cf2b234ef5 | < 6.3 |
MEDIUM | 6.1 | The wp-greet plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 6.2.… | — | wordfence |
| dafbd32c-ef66-4c1c-aa6b-68443e12eacb | MEDIUM | 6.1 | The AlT Report plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and including… | — | wordfence | |
| daf6ae92-dd50-4592-bb61-047a7ecd3646 | MEDIUM | 6.1 | The Exhibit to WP Gallery plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, an… | — | wordfence | |
| daedec14-6177-43c7-89d4-a39c13d94ca4 | < 4.21.1 |
MEDIUM | 6.1 | The LMS by LifterLMS plugin for WordPress has a reflected cross-site scripting vulnerability in the in versions up to, a… | — | wordfence |
| dae7d642-98bd-42c8-a0d1-628402e620f1 | MEDIUM | 6.1 | The Target Notifications plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and inc… | — | wordfence | |
| dadfc9c5-79cb-4e43-bf27-8a7f059190e3 | < 2.3.6 |
MEDIUM | 6.1 | The animate-it plugin before 2.3.6 for WordPress has XSS. | — | wordfence |
| dad7ef01-cc14-423d-93a7-11fc0537473b | MEDIUM | 6.1 | The Jigoshop β Store Exporter plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, … | — | wordfence | |
| dad7078d-16bf-4ca9-9a59-7b8374a1b49e | MEDIUM | 6.1 | The mgl-instagram-gallery plugin for WordPress has XSS via the single-gallery.php media parameter. | — | wordfence | |
| dad12b10-2e04-4bc2-b5ad-c00cb287e456 | < 1.0.1 |
MEDIUM | 6.1 | The WDS Multisite Aggregate plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the use of add_quer… | — | wordfence |
| dac94b37-ba4f-43c3-88b3-066401acada2 | MEDIUM | 6.1 | The Goodlayers Hotel plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and includi… | — | wordfence | |
| dac38b2e-4d38-4b16-b6a1-ed3c0561e7c2 | < 1.9.30 |
MEDIUM | 6.1 | The WPtouch plugin for WordPress is vulnerable to Open Redirect in versions before 1.9.30. This is due to insufficient i… | — | wordfence |
| dab1dbc7-f188-4c04-9c8b-465ec0a42548 | MEDIUM | 6.1 | The Zuppler Online Ordering plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and … | — | wordfence | |
| daac4d63-3789-4262-9b06-aadb4ca1f01e | < 3.4.3 |
MEDIUM | 6.1 | The Groundhogg plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 3.… | — | wordfence |
| daa4260a-8c50-4fdb-be4f-6a1fb5bcff01 | < 3.4.7 |
MEDIUM | 6.1 | The WP2LEADS plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 3.4.… | — | wordfence |
| da9e3db0-9cbf-4b1a-bdaa-d5d86be744af | < 4.4.12 |
MEDIUM | 6.1 | The Simple File List plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the βtabβ and 'subtab'… | — | wordfence |
| da89e8f9-3843-4d72-92b2-cd2f717510cd | < 2.5.2 |
MEDIUM | 6.1 | The ShareThis Dashboard for Google Analytics WordPress plugin before 2.5.2 does not sanitise or escape the 'ga_action' p… | — | wordfence |
| da879b1d-c17b-409b-9fd3-87f44ddd14b5 | MEDIUM | 6.1 | The Advance Post Prefix plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'post' parameter in… | — | wordfence | |
| da84aa80-7ef6-4846-870d-07bf88652329 | < 6.16.2 |
MEDIUM | 6.1 | The Formidable Forms β Contact Form Plugin, Survey, Quiz, Payment, Calculator Form & Custom Form Builder plugin for Wo… | — | wordfence |
| da81eb8b-4b38-462d-a85b-c0bad39f61a2 | < 1.6 |
MEDIUM | 6.1 | The BP Email Assign Templates plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'page' parame… | — | wordfence |
| da81c849-fc85-4794-a79f-fcc3ef6a3bbc | MEDIUM | 6.1 | The WooCommerce EnvioPack WordPress plugin is vulnerable to Reflected Cross-Site Scripting via the dataid parameter foun… | — | wordfence | |
| da7c18b3-d406-4fe6-8c72-fa0cb968c0ac | MEDIUM | 6.1 | The Awesome Logos plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including,… | — | wordfence | |
| da5ba18a-97ec-42c5-a7c4-ca38611c1fcd | MEDIUM | 6.1 | The Easy Student Results plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'edit' parameter i… | — | wordfence | |
| da5b700c-ec1f-4803-8165-581382cef482 | < 5.3.16 |
MEDIUM | 6.1 | The Social Auto Poster plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and inclu… | — | wordfence |
| da4f81c5-c796-4052-ac1a-007a1e8f5a50 | < 1.2.1 |
MEDIUM | 6.1 | The Form - Contact Form WordPress plugin through 1.2.0 does not sanitize and escape Custom text fields, which could allo… | — | wordfence |
EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.
Scan My Website →