Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.
40,113 vulnerabilities found (page 829 of 1605)
| CVE ID | Plugin / Theme | Severity | CVSS | Description | Fixed In | Source |
|---|---|---|---|---|---|---|
| bfb63667-6a47-4308-83c5-3d763ea69e13 | MEDIUM | 6.1 | The Content Syndication Toolkit Reader plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions … | — | wordfence | |
| bfb329da-00df-4178-ad40-9b0b718dc30e | < 1.04 |
MEDIUM | 6.1 | The Add Custom Post Type into Post Query plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in version… | — | wordfence |
| bf90d284-9db8-464b-ae01-f1979408b351 | < 2.9.50 |
MEDIUM | 6.1 | The WordPress Download Manager plugin for WordPress is vulnerable to Reflected Cross-Site Scripting parameter in version… | — | wordfence |
| bf852d93-6d56-46a2-aebc-b222b1b73fb1 | < 1.9.17 |
MEDIUM | 6.1 | The GD Star Rating plugin for WordPress is vulnerable to Cross-Site Scripting via the 'tpl_section' parameter in version… | — | wordfence |
| bf808fec-8d84-43ab-85bc-b3b60ab4df31 | < 2.0.0 |
MEDIUM | 6.1 | Cross-site scripting (XSS) vulnerability in check.php in the Validated plugin 1.0.2 and earlier for WordPress allows rem… | — | wordfence |
| bf4cb79e-e62b-4991-8ee5-493dafe38b80 | < 3.1.78 |
MEDIUM | 6.1 | The Newsletter, SMTP, Email marketing and Subscribe forms by Brevo (formely Sendinblue) plugin for WordPress is vulnerab… | — | wordfence |
| bf3b9e43-ca89-4931-950c-b73a0bac81b8 | MEDIUM | 6.1 | The WP Mail Options plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and includin… | — | wordfence | |
| bf391432-d569-4458-947f-fe4a2ebcf8f1 | < 0.5.2 |
MEDIUM | 6.1 | The Formula theme for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘id’ parameter in the 'quali… | — | wordfence |
| bf356066-fb25-4f6a-8600-91c7f1d098bf | < 3.1.3 |
MEDIUM | 6.1 | The Easy Digital Downloads (EDD) Commissions extension for WordPress, as used with EDD 1.8.x before 1.8.7, 1.9.x before … | — | wordfence |
| bf238e9d-be91-4c9a-8506-ee01927f5173 | < 2.0.52 |
MEDIUM | 6.1 | The ultimate-member plugin before 2.0.52 for WordPress has XSS related to UM Roles create and edit operations. | — | wordfence |
| bf0f87fe-d318-4f49-993c-3255f4e77ef1 | < 5.1.2 |
MEDIUM | 6.1 | The wp-database-backup plugin before 5.1.2 for WordPress has XSS. | — | wordfence |
| bf0bbd5e-0fec-445e-9baa-e383524da648 | < 7.6.1 |
MEDIUM | 6.1 | The Link Library plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, … | — | wordfence |
| bf0a1568-e97c-41ea-b2c3-ba335f0b4360 | < 2.2.0 |
MEDIUM | 6.1 | The WPGlobus Translate Options plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘page’ p… | — | wordfence |
| bf03a656-7a3b-4227-9493-88f522d7bc13 | < 3.0.0 |
MEDIUM | 6.1 | The EU/UK VAT Manager for WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versio… | — | wordfence |
| befe5e99-204e-470e-bbbb-285b5ba0b1fb | MEDIUM | 6.1 | The Floating Social Buttons plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and … | — | wordfence | |
| befd6971-29e1-477e-95b8-e7385fbd247d | < 3.8.0 |
MEDIUM | 6.1 | The woocommerce-jetpack plugin before 3.8.0 for WordPress has XSS in the Products Per Page feature. | — | wordfence |
| befa92c2-7761-44df-a162-10f3deb9439e | < 1.0.2 |
MEDIUM | 6.1 | The Tags to Keywords plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and includi… | — | wordfence |
| bed6b603-c811-4624-9053-1e12029ba73b | < 4.26 |
MEDIUM | 6.1 | The SP Project & Document Manager WordPress plugin is vulnerable to attribute-based Reflected Cross-Site Scripting via t… | — | wordfence |
| becee157-8519-4f1f-b369-5f932773f282 | MEDIUM | 6.1 | The auto-thickbox-plus plugin through 1.9 for WordPress has wp-content/plugins/auto-thickbox-plus/download.min.php?file=… | — | wordfence | |
| bec97055-ebe1-4529-9f3b-db2745300f69 | MEDIUM | 6.1 | The Order Audit Log for WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions… | — | wordfence | |
| beaea592-5eb5-4400-a4a8-b73f9b94198b | MEDIUM | 6.1 | The Simple Headline Rotator plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and … | — | wordfence | |
| be94ba55-24e3-4d61-9f2b-e2a4699bc6f6 | MEDIUM | 6.1 | The flickr-slideshow-wrapper plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to,… | — | wordfence | |
| be7ec812-ee9e-4b19-bb99-27e8016b8013 | MEDIUM | 6.1 | The SpiderContacts plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'serch_or_not' parameter… | — | wordfence | |
| be76a310-d99f-43d8-a845-6bf20eb9a11d | < 2.3.10 |
MEDIUM | 6.1 | The Post Timeline plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and includ… | — | wordfence |
| be62e2ea-0861-4815-b98a-1ea508df952d | MEDIUM | 6.1 | The Media Folder plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and includi… | — | wordfence |
EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.
Scan My Website →