Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.
40,113 vulnerabilities found (page 830 of 1605)
| CVE ID | Plugin / Theme | Severity | CVSS | Description | Fixed In | Source |
|---|---|---|---|---|---|---|
| be60027e-9d6a-4740-b20c-6be3e115d9fe | < 1.8.7 |
MEDIUM | 6.1 | The Easy Digital Downloads (EDD) core component 1.8.x before 1.8.7, 1.9.x before 1.9.10, 2.0.x before 2.0.5, 2.1.x befor… | — | wordfence |
| be53bdbd-e797-4198-8ef9-bc01b5da68f4 | MEDIUM | 6.1 | Cross-site scripting (XSS) vulnerability in the bib2html plugin 0.9.3 for WordPress allows remote attackers to inject ar… | — | wordfence | |
| be4f5da0-77ec-41eb-85bd-c019e71d4c9d | < 2.3.11 |
MEDIUM | 6.1 | The GigPress plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘gp-page’ parameter in ver… | — | wordfence |
| be44a7e0-f0e0-4e2e-ac1e-0550d8e5d994 | < 2.13.3 |
MEDIUM | 6.1 | The SpeakOut! Email Petitions plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘searchStri… | — | wordfence |
| be3208c8-aceb-4ac9-91e1-d5de5a85f74d | < 5.1 |
MEDIUM | 6.1 | The which template file plugin for WordPress is vulnerable to Cross-Site Scripting in versions up to, and including, 5.0… | — | wordfence |
| be16c229-1092-4090-83bc-38e42f6377b6 | MEDIUM | 6.1 | The flog plugin 0.1 for WordPress has XSS via the url parameter. | — | wordfence | |
| be151552-827c-43a6-a0e0-da19884448fd | MEDIUM | 6.1 | The 10Web Social Post Feed plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_qu… | — | wordfence | |
| be0e9e67-efc1-4a21-ba32-4a963166350d | < 1.2.8 |
MEDIUM | 6.1 | The Injection Guard plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the $_SERVER['REQUEST_URI']… | — | wordfence |
| be03bf77-69ec-466b-bad1-22174e0d5e89 | MEDIUM | 6.1 | The WPCHURCH plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 2.7.… | — | wordfence | |
| bddbbcdf-dfcb-47dd-97e7-8563eaf70cbd | MEDIUM | 6.1 | The Tax Rate Upload plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and incl… | — | wordfence | |
| bdd0bdf3-6952-4b87-a3e8-156757d22e74 | < 4.11.0.2 |
MEDIUM | 6.1 | The WooCommerce Affiliate Plugin – Coupon Affiliates plugin for WordPress is vulnerable to Reflected Cross-Site Script… | — | wordfence |
| bdce01f2-7c79-4b1d-8da2-f6ce118856a1 | < 1.2.27 |
MEDIUM | 6.1 | The ARI Stream Quiz – WordPress Quizzes Builder plugin for WordPress is vulnerable to Reflected Cross-Site Scripting v… | — | wordfence |
| bdc8f6e2-ee2a-4a8e-9c6f-2c69b0b597e5 | MEDIUM | 6.1 | The Custom Smilies plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and inclu… | — | wordfence | |
| bdc39e21-f39c-4581-895a-04e352e9b383 | < 3.3.7 |
MEDIUM | 6.1 | The Wordfence plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘email’ parameter in vers… | — | wordfence |
| bdc33ecc-da54-4852-8426-bfafe0dca41b | < 5.1 |
MEDIUM | 6.1 | The WP Attachments plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘attachment_id’ para… | — | wordfence |
| bdc21e2e-288e-459b-86d3-739aa4acb32d | MEDIUM | 6.1 | The EmailPress plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and including… | — | wordfence | |
| bdb7e239-75c4-480e-a283-dc2354fe3375 | < 1.2.21 |
MEDIUM | 6.1 | The All In One Slider plugin (formerly known as All In One Carousel) for WordPress is vulnerable to Reflected Cross-Site… | — | wordfence |
| bda3c8f8-fd0f-432d-a382-e8ac55d34bb9 | MEDIUM | 6.1 | The Markdown on Save Improved plugin 2.5 for WordPress has a stored XSS vulnerability in the content of a post. | — | wordfence | |
| bd9ef48f-b501-4fca-a6a5-78452c316497 | MEDIUM | 6.1 | The WP Google Maps Integration plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the `page` param… | — | wordfence | |
| bd9e97df-2082-45d2-aa26-65383522de7d | MEDIUM | 6.1 | The Google News plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2… | — | wordfence | |
| bd879bd9-d195-4146-b9dc-3ba7252645de | < 1.0.17 |
MEDIUM | 6.1 | The10WebFAQ plugin for WordPress is vulnerable to Cross-Site Scripting in versions up to, and including, 1.0.14 due to i… | — | wordfence |
| bd861a13-4215-4a69-adb5-cd28dce4509b | < 5.4.9 |
MEDIUM | 6.1 | The Booster for WooCommerce WordPress plugin before 5.4.9 does not sanitise and escape the wcj_delete_role parameter bef… | — | wordfence |
| bd7bf023-4a18-4918-9600-12720c1b4ad8 | < 2.3.0 |
MEDIUM | 6.1 | The Hebrew Date plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.1.0… | — | wordfence |
| bd748b6c-110a-46b6-a609-64d093dfc3e5 | < 2.4.7 |
MEDIUM | 6.1 | The Seraphinite Bulk Discounts for WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due … | — | wordfence |
| bd718f4a-bad4-4e6a-ab4b-b0fb6bd25da3 | MEDIUM | 6.1 | The Social Crowd plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, … | — | wordfence |
EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.
Scan My Website →