Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.
40,117 vulnerabilities found (page 845 of 1605)
| CVE ID | Plugin / Theme | Severity | CVSS | Description | Fixed In | Source |
|---|---|---|---|---|---|---|
| b0297b3a-a180-428a-9716-6ecfa5a4de94 | < 1.7.2 |
MEDIUM | 6.1 | The magic-fields plugin before 1.7.2 for WordPress has XSS via the custom-write-panel-id parameter. | — | wordfence |
| b02613dc-8c31-4c86-b800-eb1039381e1f | < 1.4.8 |
MEDIUM | 6.1 | The Invite Anyone plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including,… | — | wordfence |
| b0086de8-448f-452f-89d1-84b77b2e25a8 | < 4.4.2 |
MEDIUM | 6.1 | The Simple Membership plugin for WordPress is vulnerable to Open Redirect in all versions up to, and including, 4.4.1. T… | — | wordfence |
| b004955a-7580-4dc8-beee-e55785026fed | < 1.5.35 |
MEDIUM | 6.1 | Cross site scripting (XSS) in the photo-gallery (10Web Photo Gallery) plugin before 1.5.35 for WordPress exists via admi… | — | wordfence |
| b00290ee-ad63-4544-818a-c0d7471e60fa | < 3.5.5 |
MEDIUM | 6.1 | The Elementor plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘settings’ hash parameter… | — | wordfence |
| afff886c-92e6-41fc-9a88-befc158ad403 | MEDIUM | 6.1 | The CodeBard's Patron Button and Widgets for Patreon plugin for WordPress is vulnerable to Reflected Cross-Site Scr… | — | wordfence | |
| afff64c5-ed38-4aef-9ed6-4a44589b025c | < 5.2.4 |
MEDIUM | 6.1 | Core\Admin\PFTemplater.php in the PressForward plugin 5.2.3 and earlier for WordPress has XSS in the PATH_INFO to wp-adm… | — | wordfence |
| affc9dff-75a1-4cb3-8465-55254db6441b | MEDIUM | 6.1 | The Q2W3 Post Order plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via an unknown parameter in all… | — | wordfence | |
| aff495c6-b4b6-4389-8acf-f59676f12e1f | MEDIUM | 6.1 | The SEO Tools plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'src' parameter in all versio… | — | wordfence | |
| afd58164-8d33-4f93-a904-443b1df8b66b | < 1.3 |
MEDIUM | 6.1 | The Rimons Twitter Widget plugin for WordPress is vulnerable to Cross-Site Scripting in versions up to, and including, 1… | — | wordfence |
| afc85535-962d-479d-8580-9d02f7412930 | < 4.0.1 |
MEDIUM | 6.1 | The WP All Import – Drag & Drop Import for CSV, XML, Excel & Google Sheets plugin for WordPress is vulnerable to Refle… | — | wordfence |
| afc82959-35a3-41a3-ae72-f9184b7c331d | MEDIUM | 6.1 | The User List plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 1.5… | — | wordfence | |
| afc20673-5665-4058-9d77-ebe9c03df46f | < 8.9 |
MEDIUM | 6.1 | The MagOne theme for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 8.8 due… | — | wordfence |
| afbb1f20-188b-4874-98dd-ab1fa43bb276 | < 3.1.10 |
MEDIUM | 6.1 | The VForm plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 3.1.9 d… | — | wordfence |
| afb58149-cff0-4911-8322-c608fc00adf4 | < 14.2.1 |
MEDIUM | 6.1 | The GEO Plugin by Squirrly SEO plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, a… | — | wordfence |
| afb3e2f8-ba44-48fc-9882-d9bcd39676ee | MEDIUM | 6.1 | The upscale theme for WordPress is vulnerable to Cross-Site Scripting due to insufficient input sanitization and output … | — | wordfence | |
| afb032da-11cc-4272-be68-60b6ca6e6ca3 | < 2.5.0 |
MEDIUM | 6.1 | The Image Slider by Ays- Responsive Slider and Carousel box plugin for WordPress is vulnerable to Reflected Cross-Site S… | — | wordfence |
| af99651a-2975-4985-a7de-bdd8ab0d92d0 | MEDIUM | 6.1 | The Rich Text Editor plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and includi… | — | wordfence | |
| af838653-d575-48fc-bded-f0068a6c6ebf | < 4.0.2 |
MEDIUM | 6.1 | Cross-site scripting (XSS) vulnerability in the Tweet Blender plugin before 4.0.2 for WordPress allows remote attackers … | — | wordfence |
| af7f5e86-3e88-4fb1-942d-f755ae60f088 | < 2.7.2.5 |
MEDIUM | 6.1 | The Arigato Autoresponder and Newsletter plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in version… | — | wordfence |
| af71ca13-781d-49ca-948c-03d52d91d11b | < 0.8.1 |
MEDIUM | 6.1 | The Debug Bar plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg witho… | — | wordfence |
| af59102e-f029-4c7d-95ee-16b9dcef4827 | MEDIUM | 6.1 | The Broadscope theme for WordPress is vulnerable to Cross-Site Scripting due to insufficient input sanitization and outp… | — | wordfence | |
| af568eea-59ce-467e-ba03-625d04d3db6e | < 1.25.1 |
MEDIUM | 6.1 | The UpdraftPlus: WP Backup & Migration Plugin plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via t… | — | wordfence |
| af48906b-f7b2-45ec-b0c1-1ac521106759 | < 2.1.6 |
MEDIUM | 6.1 | The WP Matterport Shortcode plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the use of PHP_SELF… | — | wordfence |
| af4058cd-79bc-433c-96e1-fb0aad12969c | < 0.9.1 |
MEDIUM | 6.1 | The WP OER plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via several parameters in versions up to… | — | wordfence |
EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.
Scan My Website →