Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.
40,113 vulnerabilities found (page 813 of 1605)
| CVE ID | Plugin / Theme | Severity | CVSS | Description | Fixed In | Source |
|---|---|---|---|---|---|---|
| d0f35a20-ffcf-4413-b1ea-748cd6aa6f20 | MEDIUM | 6.1 | The Clockwork SMS clockwork-test-message.php component has XSS via a crafted "to" parameter in a clockwork-test-message … | — | wordfence | |
| d0ec4f27-2057-468e-bfcd-818c50952cac | < 1.3.1 |
MEDIUM | 6.1 | The Accept Donations with PayPal WordPress plugin before 1.3.1 offers a function to create donation buttons, which inter… | — | wordfence |
| d0e82bef-3857-4b13-a124-70aeaf90e8ce | MEDIUM | 6.1 | The WP-jScrollPane plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including… | — | wordfence | |
| d0c74637-97b6-44d8-89c7-4a662fc537c6 | MEDIUM | 6.1 | The Monitor.chat plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, … | — | wordfence | |
| d0b369b4-b107-4207-8d5a-4551a2adf437 | MEDIUM | 6.1 | The Access Category Password plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to,… | — | wordfence | |
| d0a38293-3730-44ae-90de-bc94a9e850b1 | MEDIUM | 6.1 | The QR Code for WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and … | — | wordfence | |
| d09b638f-4c30-41cc-84fd-ae0816e2c29e | MEDIUM | 6.1 | The Tax Report for WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up t… | — | wordfence | |
| d08db182-bfbf-42bd-8070-cbd80b3b5759 | MEDIUM | 6.1 | The TubePress.NET plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including,… | — | wordfence | |
| d089bfee-3d23-4d35-83e0-7575702a21b4 | MEDIUM | 6.1 | The Better Customer List for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versio… | — | wordfence | |
| d083cf7c-f116-40aa-bffb-91e43ba52490 | < 4.0.16 |
MEDIUM | 6.1 | The what3words Address Field plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and… | — | wordfence |
| d06a8ec6-19c0-4c76-8954-2395429bd38b | MEDIUM | 6.1 | The Cookies Pro plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1… | — | wordfence | |
| d062bc7b-0cb0-46bd-b203-90cc9a44a403 | MEDIUM | 6.1 | The Smart External Link Click Monitor [Link Log] plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in… | — | wordfence | |
| d05de50e-1d3b-4e41-bfec-079b5cd82784 | MEDIUM | 6.1 | The SH Slideshow plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, … | — | wordfence | |
| d0598341-0088-42bf-9a34-794c941a848d | MEDIUM | 6.1 | The Vikinghammer Tweet plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and inclu… | — | wordfence | |
| d02fc744-35e5-44eb-8790-66997e95d017 | < 2.6 |
MEDIUM | 6.1 | The option-tree plugin before 2.6.0 for WordPress has XSS via an add_list_item or add_social_links AJAX request. | — | wordfence |
| d021636e-2d23-4fb3-baf7-0f40d4ade3db | < 2.8.5 |
MEDIUM | 6.1 | The Elementor plugin before 2.8.5 for WordPress suffers from a reflected XSS vulnerability on the elementor-system-info … | — | wordfence |
| d0206a57-4f1e-4cd2-a854-d435d769f391 | MEDIUM | 6.1 | The Product Puller plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including… | — | wordfence | |
| d014f512-9030-49ce-945d-4900594fb373 | < 2.6.1.2 |
MEDIUM | 6.1 | The Namaste! LMS plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'course_id' parameter in … | — | wordfence |
| d0033a19-47ac-4ffc-93a4-2ea693e93397 | < 1.5.69 |
MEDIUM | 6.1 | The Photo Gallery by 10Web plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'album_gallery_i… | — | wordfence |
| CVE-2026-2506 | MEDIUM | 6.1 | The EM Cost Calculator plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and includin… | — | nvd | |
| CVE-2026-2502 | MEDIUM | 6.1 | The xmlrpc attacks blocker plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and incl… | — | nvd | |
| CVE-2026-1706 | < 4.7.5 |
MEDIUM | 6.1 | The All-in-One Video Gallery plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'vi' parameter… | — | nvd |
| CVE-2026-1666 | < 3.3.47 |
MEDIUM | 6.1 | The Download Manager plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'redirect_to' paramete… | — | nvd |
| CVE-2026-1296 | MEDIUM | 6.1 | The Frontend Post Submission Manager Lite plugin for WordPress is vulnerable to Open Redirection in all versions up to, … | — | nvd | |
| CVE-2026-0561 | MEDIUM | 6.1 | The Shield Security plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'message' parameter in … | — | nvd |
EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.
Scan My Website →