Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.
40,117 vulnerabilities found (page 840 of 1605)
| CVE ID | Plugin / Theme | Severity | CVSS | Description | Fixed In | Source |
|---|---|---|---|---|---|---|
| b4b82bb0-8d8a-42eb-a142-1d9af34b2c66 | MEDIUM | 6.1 | The WeChat Subscribers Lite plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and… | — | wordfence | |
| b4b7adcf-c58b-4019-89ff-a69ebf8262bc | < 4.5.4 |
MEDIUM | 6.1 | The Simple Membership plugin for WordPress is vulnerable to Open Redirect in all versions up to, and including, 4.5.3. T… | — | wordfence |
| b4b61b5b-e5e8-41d4-bf37-d9427a204ea6 | MEDIUM | 6.1 | The FLOWFACT WP Connector plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via an unknown parameter … | — | wordfence | |
| b4ad6f96-22a3-420c-9ccb-a7b118fa2810 | MEDIUM | 6.1 | The WordPress HelpDesk & Support Ticket System Plugin β Octrace Support plugin for WordPress is vulnerable to Reflecte… | — | wordfence | |
| b4a229be-2991-40f3-a0e7-e322009a3ed2 | MEDIUM | 6.1 | The Simple Load More plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and includi… | — | wordfence | |
| b49c1e95-7ef4-45d7-9fdf-dd5adffd2eb0 | < 1.5.122 |
MEDIUM | 6.1 | The Unlimited Elements For Elementor (Free Widgets, Addons, Templates) plugin for WordPress is vulnerable to Reflected C… | — | wordfence |
| b4983c2f-f9f6-4bd9-9c38-0ad3756f92b6 | < 1.5.5 |
MEDIUM | 6.1 | The Catch Breadcrumb plugin before 1.5.4 for WordPress allows Reflected XSS via the s parameter (a search query). Also a… | — | wordfence |
| b4971d77-1312-43ac-ab14-970bd4ec5688 | MEDIUM | 6.1 | The Popping Content Light plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and in… | — | wordfence | |
| b489427e-f925-4058-8924-7a9557fc4ebf | < 6.3.1 |
MEDIUM | 6.1 | The Gravity PDF plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg wit… | — | wordfence |
| b483e274-94e6-4b22-8431-d3a7638218db | MEDIUM | 6.1 | The Mobile Plugin plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and includ… | — | wordfence | |
| b47b1230-bf08-4960-9fc9-56a5b37da8b5 | MEDIUM | 6.1 | The WPCode Content Ratio plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and inc… | — | wordfence | |
| b4764fe2-7bdf-4b08-ae9f-ccb46929c50a | MEDIUM | 6.1 | The Wp-ImageZoom plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via several parameter in all versi… | — | wordfence | |
| b46e2755-24df-4569-bf38-968bf890431e | MEDIUM | 6.1 | The Revamp CRM for WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, a… | — | wordfence | |
| b467fc26-242f-47c4-bcfd-38980489a0c3 | MEDIUM | 6.1 | The Snapshot Backup plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and includin… | — | wordfence | |
| b45ba98f-4cd1-406a-8661-e19d5b4c3ba8 | < 1.6.1 |
MEDIUM | 6.1 | The MC4WP: Mailchimp Top Bar plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_… | — | wordfence |
| b457db06-84c8-4b7b-b7c1-091771a11a35 | MEDIUM | 6.1 | The Lock Your Updates plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and includ… | — | wordfence | |
| b4533554-52e4-44b4-9230-b6e3feb2e4a1 | MEDIUM | 6.1 | The SEO by 10Web plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via an unknown parameter in all ve… | — | wordfence | |
| b4521959-416e-4ff5-96c0-bc4dbb0187b7 | MEDIUM | 6.1 | The Folder Gallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'foldergallery' sh… | — | wordfence | |
| b44a4d74-5c2b-454a-992a-74a3a71fa5dd | < 1.6 |
MEDIUM | 6.1 | Cross-site scripting (XSS) vulnerability in index.php in the WordPress Classic 1.5 theme in WordPress before 2.1.3 allow… | — | wordfence |
| b4309271-f93a-46ac-8b0b-d6193487ac98 | < 2.2.11 |
MEDIUM | 6.1 | Cross-site scripting (XSS) vulnerability in the WooCommerce plugin before 2.2.11 for WordPress allows remote attackers t… | — | wordfence |
| b42c0e51-676f-4f06-9e5c-b6b74bea89b5 | < 3.0.5 |
MEDIUM | 6.1 | The WP-TopBar plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to inclusion of a vulnerable vers… | — | wordfence |
| b42be363-30b4-487b-9ffc-bfa3efbd1250 | < 1.1.17 |
MEDIUM | 6.1 | The Header Footer Code Manager plugin <= 1.1.16 for WordPress is vulnerable to Reflected Cross-Site Scripting (XSS) via … | — | wordfence |
| b42882f6-ccea-4d8f-940b-1ad95b1ab760 | MEDIUM | 6.1 | The Ultimate WooCommerce CSV Importer WordPress plugin through 2.0 does not sanitise and escape the imported data before… | — | wordfence | |
| b41a91fc-86ee-4795-acb6-2ffd22c4f7af | < 1.1.2 |
MEDIUM | 6.1 | The PDF Generator for Wordpress plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via vendored exampl… | — | wordfence |
| b404c6c4-cc05-4040-b96a-7be750020acc | < 1.2.8 |
MEDIUM | 6.1 | The SW Ajax WooCommerce Search plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, a… | — | wordfence |
EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.
Scan My Website →