Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.
40,113 vulnerabilities found (page 814 of 1605)
| CVE ID | Plugin / Theme | Severity | CVSS | Description | Fixed In | Source |
|---|---|---|---|---|---|---|
| CVE-2025-11706 | < 3.0.3 |
MEDIUM | 6.1 | The Aruba HiSpeed Cache plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the dbstatus parameter … | — | nvd |
| cffe745d-2fe2-4959-9641-9a0ae33bff4c | < 4.2.1 |
MEDIUM | 6.1 | The Simple Payment Donations plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and… | — | wordfence |
| cff6b26e-bafa-4b85-b7f1-eea9bb4b6476 | < 3.3 |
MEDIUM | 6.1 | The Advanced Sermons plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'sermon_dates' paramet… | — | wordfence |
| cff04656-5930-4324-9ddf-43a2166cdf04 | < 4.6.20 |
MEDIUM | 6.1 | The Molongui plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'page' parameter in versions u… | — | wordfence |
| cfecc35a-30e2-4474-b727-ec2fcbf07e0c | MEDIUM | 6.1 | The Custom CSS Addons plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and includ… | — | wordfence | |
| cfec4c31-ba09-4832-a095-4ca5f5192674 | MEDIUM | 6.1 | The ENL Newsletter plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including… | — | wordfence | |
| cfe4d99c-9cbd-4255-8f90-f904313d46b4 | < 3.4.4 |
MEDIUM | 6.1 | The Dashboard Widgets Suite plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'tab' parameter… | — | wordfence |
| cfd3f0e3-e73e-4ec2-ac67-da1cc15aa217 | < 3.5.7 |
MEDIUM | 6.1 | The Simple Membership plugin for WordPress is vulnerable to Cross-Site Scripting in versions up to, and including, 3.5.6… | — | wordfence |
| cfcc1a4d-c6c7-4ca8-afe5-79298e7ad3d7 | < 1.3.3 |
MEDIUM | 6.1 | The Balkon theme for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 1.3.2 d… | — | wordfence |
| cfc09dee-9af6-49ff-bfe2-abcc616940d7 | < 4.3 |
MEDIUM | 6.1 | The MW Font Changer plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'size' parameter in ver… | — | wordfence |
| cfbd41fa-15f0-473a-be5a-862e8a14b287 | < 3.2.3 |
MEDIUM | 6.1 | The Restrict Content plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via POST data from the rcp_aja… | — | wordfence |
| cfb6e263-efcc-4ecb-8c9a-91f73f82b55a | MEDIUM | 6.1 | The Scroll Styler plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including,… | — | wordfence | |
| cfb52a38-2894-4b43-b936-a11fa6257741 | MEDIUM | 6.1 | The AffiliateImporterEb plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'module' parameter … | — | wordfence | |
| cf8817fd-b49a-4fb3-9c91-09e952ff0953 | MEDIUM | 6.1 | The WP Click Info plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and includ… | — | wordfence | |
| cf67d95a-7819-49b7-8a2a-ea945a0167b1 | MEDIUM | 6.1 | The My Marginalia plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including,… | — | wordfence | |
| cf6182b6-c291-4020-a016-5c6b96039549 | MEDIUM | 6.1 | The PRIMER by chloédigital plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and … | — | wordfence | |
| cf5f0f9f-b0b1-4ac8-a8c2-e349dfb9e6c3 | MEDIUM | 6.1 | The WP Finance plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.… | — | wordfence | |
| cf4e9b41-20e8-4dba-a51c-6e8f09232ffb | < 3.6.22 |
MEDIUM | 6.1 | The Ninja Forms Contact Form plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'title' parame… | — | wordfence |
| cf4d42a2-746b-4c23-b0fe-b66eafb76303 | < 1.2.3 |
MEDIUM | 6.1 | Multiple cross-site scripting (XSS) vulnerabilities in the Sniplets 1.1.2 and 1.2.2 plugin for WordPress allow remote at… | — | wordfence |
| cf458f57-2c8b-44d1-8e36-bbfc1a66c2e2 | MEDIUM | 6.1 | Cross-site scripting (XSS) vulnerability in shortcode-generator/preview-shortcode-external.php in the OMFG Mobile Pro pl… | — | wordfence | |
| cf3f82dc-3820-4c9d-adbb-ca0375078876 | < 2.3.2 |
MEDIUM | 6.1 | The IDPay for Contact Form 7 WordPress plugin through 2.1.2 does not sanitise and escape the idpay_error parameter befor… | — | wordfence |
| cf3a16b6-7256-4fad-b3f2-d1d9d833f45e | < 2.2.1 |
MEDIUM | 6.1 | TheConvertKit plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'page' parameter in versions … | — | wordfence |
| cf2f2474-50d6-46da-a97c-731edb514ae5 | < 1.1.1 |
MEDIUM | 6.1 | The Manage Calameo Publications by Athlon for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘attac… | — | wordfence |
| cf2d14ff-d02a-4bed-9604-ff2489d4bef9 | MEDIUM | 6.1 | The Corona theme for WordPress is vulnerable to Cross-Site Scripting due to insufficient input sanitization and output e… | — | wordfence | |
| cf21c4a8-2e26-4235-8c9b-cda31a687a87 | MEDIUM | 6.1 | The Musicbox plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'webdesignby-musicbox-filter' … | — | wordfence |
EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.
Scan My Website →