Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.
40,117 vulnerabilities found (page 847 of 1605)
| CVE ID | Plugin / Theme | Severity | CVSS | Description | Fixed In | Source |
|---|---|---|---|---|---|---|
| ae1820ab-6a24-45b3-801c-34c5515c8868 | < 1.4.2 |
MEDIUM | 6.1 | The Modern theme before 1.4.2 for WordPress has XSS via the genericons/example.html anchor identifier. | — | wordfence |
| adffa925-0d91-4c8a-b9ec-1af10cb882ca | MEDIUM | 6.1 | The Authentication and xmlrpc log writer plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in version… | — | wordfence | |
| adfe66d7-5402-447f-bca2-8de5b6447cbb | MEDIUM | 6.1 | The Push Monkey Pro – Web Push Notifications and WooCommerce Abandoned Cart plugin for WordPress is vulnerable to Cros… | — | wordfence | |
| adf8c50a-c657-4452-8c6b-23c2a56b7b78 | MEDIUM | 6.1 | The Word Freshener plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including… | — | wordfence | |
| adf5b377-f4b6-4859-a5a2-2cb8f61b7e81 | MEDIUM | 6.1 | The Forge – Front-End Page Builder plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up… | — | wordfence | |
| adee74ec-7a3c-4519-bea8-23c92e89d484 | MEDIUM | 6.1 | Multiple cross-site scripting (XSS) vulnerabilities in payper/payper.php in the Pay Per Media Player plugin 1.24 and ear… | — | wordfence | |
| ade7da50-49f3-4026-a2c0-5c23c9b0f0cb | MEDIUM | 6.1 | The Admin Menu Plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘role' GET parameter in ve… | — | wordfence | |
| addf264e-e23c-4bb6-a898-0fbb4ec28189 | < 5.9.5.5 |
MEDIUM | 6.1 | The ProfileGrid – User Profiles, Groups and Communities plugin for WordPress is vulnerable to Reflected Cross-Site Scr… | — | wordfence |
| add32c06-90d0-466f-b176-aaae55cf03fb | MEDIUM | 6.1 | The Sentence To SEO (keywords, description and tags) plugin for WordPress is vulnerable to Cross-Site Request Forgery in… | — | wordfence | |
| adcaf2db-2026-46bb-8fbc-0400d7c1e296 | < 2.4.1 |
MEDIUM | 6.1 | The Stock Sync for WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘page’ p… | — | wordfence |
| adc7e02f-aa95-417f-8778-d9a75beeaf13 | MEDIUM | 6.1 | An issue was discovered in the JSmol2WP plugin 1.07 for WordPress. A cross-site scripting (XSS) vulnerability allows rem… | — | wordfence | |
| adc2ce12-6be2-447d-a05d-da36ce7f5727 | < 0.9.8 |
MEDIUM | 6.1 | The Admin Options Pages plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and … | — | wordfence |
| adbf25c2-b572-4a83-811e-3a5dda1ad8cd | < 2.0 |
MEDIUM | 6.1 | The Pinfinity theme for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘s’ parameter in versions … | — | wordfence |
| adbebe61-3adc-4ba1-8767-863dc2310cad | MEDIUM | 6.1 | The Gift Certificate Creator plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘receip_addr… | — | wordfence | |
| adbc8d10-4088-4918-b01e-86554512c7a4 | MEDIUM | 6.1 | The Off Page SEO plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, … | — | wordfence | |
| ad8f8c41-a3b9-4287-b6b2-489fb77b7553 | < 4.6.1 |
MEDIUM | 6.1 | The Albo Pretorio Online plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘Errore’ param… | — | wordfence |
| ad8311d4-b07d-4e74-ab14-69faa3e409c8 | < 1.15.27 |
MEDIUM | 6.1 | The Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder plugin for WordPress is vulnerable to Refle… | — | wordfence |
| ad81c6b6-dbf5-40a3-894d-e2fbab69d38a | MEDIUM | 6.1 | The Domain Replace plugin for WordPress is vulnerable to Cross-Site Scripting via the msg parameter found in the ~/domai… | — | wordfence | |
| ad7eee97-332a-4f3c-bba1-d108a769599d | < 1.9.12 |
MEDIUM | 6.1 | The Tutor LMS WordPress plugin before 1.9.12 does not escape the search parameter before outputting it back in an attrib… | — | wordfence |
| ad7e3fe0-561e-40d8-b22c-bf8e7675b87f | < 2.17.3 |
MEDIUM | 6.1 | The GiveWP WordPress plugin before 2.17.3 does not escape the s parameter before outputting it back in an attribute in t… | — | wordfence |
| ad5ca2a1-06ac-4f26-9ecb-bb861c035f57 | MEDIUM | 6.1 | The Social Stickers WordPress plugin through 2.2.9 does not have CSRF checks in place when updating its Social Network s… | — | wordfence | |
| ad5c8eb8-8e58-4bed-a39c-b54e2cfd9cd3 | < 3.3.0 |
MEDIUM | 6.1 | The 15Zine WordPress theme before 3.3.0 does not sanitise and escape the cbi parameter before outputing it back in the r… | — | wordfence |
| ad40de6a-744c-4a78-912a-4fd76ae75dc1 | MEDIUM | 6.1 | The BruteGuard – Brute Force Login Protection plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in … | — | wordfence | |
| ad3644a7-3999-49f8-822c-9e3b22bf7b8f | MEDIUM | 6.1 | The ez Form Calculator - WordPress plugin plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versio… | — | wordfence | |
| ad306c2b-5fc7-49c2-9ee0-777c7e6014e5 | MEDIUM | 6.1 | The Full Circle plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 0… | — | wordfence |
EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.
Scan My Website →