Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.
40,113 vulnerabilities found (page 804 of 1605)
| CVE ID | Plugin / Theme | Severity | CVSS | Description | Fixed In | Source |
|---|---|---|---|---|---|---|
| da4684b8-20f6-4dc1-8f29-d79f64ccb9d8 | < 4.1.0 |
MEDIUM | 6.1 | The Contractor Contact Form Website to Workflow Tool plugin for WordPress is vulnerable to Reflected Cross-Site Scriptin… | — | wordfence |
| da18dce3-f8f9-48ae-b767-0b72ffd75c1e | < 2.0.7 |
MEDIUM | 6.1 | The WordPress Helpdesk & Live Chat Plugin Powered by AI – ThriveDesk plugin for WordPress is vulnerable to Reflected C… | — | wordfence |
| da125e31-4747-46b7-8a46-a234388035c0 | MEDIUM | 6.1 | The Enable Accessibility plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_quer… | — | wordfence | |
| d9fbedea-15e7-4233-8e2d-9fd928fe4f2a | < 0.0.22 |
MEDIUM | 6.1 | The Learning Management System, eLearning, Course Builder, WordPress LMS Plugin – Sikshya LMS plugin for WordPress is … | — | wordfence |
| d9f9d20f-a0cd-40ed-8f75-7b57fe8e70f0 | MEDIUM | 6.1 | The 多说社会化评论框 plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to,… | — | wordfence | |
| d9e77e3f-dcd8-426a-be0f-24eb65c6709e | < 3.2 |
MEDIUM | 6.1 | The Accept Stripe Payments Using Contact Form 7 plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via… | — | wordfence |
| d9e3f310-5a5e-4ca8-806d-9a7aacfaf5ed | < 4.6.1 |
MEDIUM | 6.1 | The Search Forms page of the Ivory Search WordPress lugin before 4.6.1 did not properly sanitise the tab parameter befor… | — | wordfence |
| d9e0f3a5-35fb-4c7e-892f-8a41498e1d3c | MEDIUM | 6.1 | The Visit Counter plugin for WordPress is vulnerable to Cross-Site Request Forgery in version 1.0. This is due to missin… | — | wordfence | |
| d9d19571-f0a1-4f15-a292-89b938c49afc | < 1.1.17 |
MEDIUM | 6.1 | The Travelpayouts: All Travel Brands in One Place plugin for WordPress is vulnerable to Open Redirect in versions 0.0.0.… | — | wordfence |
| d9c20584-d791-4788-8dc3-77069b92601f | < 1.3.02 |
MEDIUM | 6.1 | The "CP Contact Form with PayPal" plugin before 1.3.02 for WordPress has XSS in CSS edition. | — | wordfence |
| d9bfae23-7b5c-46d8-9d7e-cc261280e223 | < 1.2.0 |
MEDIUM | 6.1 | The login-or-logout-menu-item plugin before 1.2.0 for WordPress has no requirement for lolmi_save_settings authenticatio… | — | wordfence |
| d9ae6150-209b-4717-835a-e5d5ea62a19b | MEDIUM | 6.1 | The Ofiz theme for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and including, 2.0 d… | — | wordfence | |
| d9a7f2ed-b2c0-4042-ad91-63070e176c2f | < 1.4.0 |
MEDIUM | 6.1 | The Agrofood theme for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and excluding, 1.4.0… | — | wordfence |
| d9a70e02-fdbc-43ee-9382-101391f363a3 | < 4.20.94 |
MEDIUM | 6.1 | The Anti-Malware Security and Brute-Force Firewall WordPress plugin before 4.20.94 does not sanitise and escape the POST… | — | wordfence |
| d99fe68c-3c0e-4a5a-96c8-de50b7a7e753 | MEDIUM | 6.1 | Cross-site scripting (XSS) vulnerability in inpage.tpl.php in the Keyword Strategy Internal Links plugin 2.0 and earlier… | — | wordfence | |
| d99a545f-e4eb-4130-8b1c-bb485c1aad13 | MEDIUM | 6.1 | The bidorbuy Store Integrator plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, an… | — | wordfence | |
| d992a9cf-f24c-4c82-a56b-22394524ba3b | < 1.2.9.3 |
MEDIUM | 6.1 | The PowerPack Lite for Beaver Builder WordPress plugin before 1.2.9.3 does not sanitise and escape the tab parameter bef… | — | wordfence |
| d9853616-e1b3-48b0-afec-c43e91c48bc0 | MEDIUM | 6.1 | The Fontsampler plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 0… | — | wordfence | |
| d97df193-28ed-4961-9d71-00098c0bec45 | < 3.4.24.2 |
MEDIUM | 6.1 | The Ninja Forms plugin before 3.4.24.2 for WordPress allows CSRF with resultant XSS. | — | wordfence |
| d96d1f33-43b3-4e20-967e-988cb32b04ee | MEDIUM | 6.1 | The Post Snippits plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including,… | — | wordfence | |
| d94c0775-3852-463f-b393-1a12e63548e0 | < 1.2.6.3 |
MEDIUM | 6.1 | The WOOF WordPress plugin before 1.2.6.3 does not sanitise and escape the woof_redraw_elements before outputing back in … | — | wordfence |
| d94bcbf7-c20e-4b04-b4de-f68f9a793b73 | < 6.2.2 |
MEDIUM | 6.1 | The Quiz And Survey Master plugin 6.2.1 for WordPress allows wp-admin/admin.php?page=mlw_quiz_results quiz_id XSS. | — | wordfence |
| d941b4b7-6b61-4559-8980-ae7285018b98 | < 2.1.5 |
MEDIUM | 6.1 | The ABA PayWay Payment Gateway for WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in v… | — | wordfence |
| d92caa38-6a0e-46e7-87db-b5c7d325d138 | < 2.0 |
MEDIUM | 6.1 | The SKT Donation – Charity and Fundraising Plugin plugin for WordPress is vulnerable to Reflected Cross-Site Scripting… | — | wordfence |
| d91a2713-238b-4c56-bff8-9129d77f4d77 | < 3.9.5 |
MEDIUM | 6.1 | The Simple Download Monitor WordPress plugin before 3.9.5 does not escape the 1) sdm_active_tab GET parameter and 2) sdm… | — | wordfence |
EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.
Scan My Website →