Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.
40,117 vulnerabilities found (page 851 of 1605)
| CVE ID | Plugin / Theme | Severity | CVSS | Description | Fixed In | Source |
|---|---|---|---|---|---|---|
| aa178e13-b4a5-4847-ac0e-9f14f8c9b446 | MEDIUM | 6.1 | Cross-site scripting (XSS) vulnerability in wp-plugins-net/index.php in the WP Plugin Manager (wppm) plugin 1.6.4.b and … | — | wordfence | |
| aa16cbeb-b3ba-4ef4-83ef-69d8ebd3738f | MEDIUM | 6.1 | The Simple Flash Video plugin for WordPress is vulnerable to Cross-Site Scripting in versions up to, and including, 1.7 … | — | wordfence | |
| aa105250-7d19-49c9-af20-6d5e033314e6 | < 2.73.1 |
MEDIUM | 6.1 | The wp-polls plugin before 2.73.1 for WordPress has XSS via the Poll bar option. | — | wordfence |
| a9eed9ee-2a84-4500-8ec9-86036c257659 | MEDIUM | 6.1 | The xili-tidy-tags plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including… | — | wordfence | |
| a9ca2bc8-8ec3-4fd2-a1ab-ee0982182623 | MEDIUM | 6.1 | The Google Transliteration plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, a… | — | wordfence | |
| a9b3b5ae-b086-4068-aa05-a732f1a8f508 | MEDIUM | 6.1 | The Social Links plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, … | — | wordfence | |
| a97f74bf-c3a5-4bb3-a7fd-d3f43af6ec42 | < 3.10.6 |
MEDIUM | 6.1 | The Visualizer plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 3.… | — | wordfence |
| a97df03d-a927-4745-b7ed-3a8402a21298 | MEDIUM | 6.1 | The WP Login Control plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'order' parameter in a… | — | wordfence | |
| a96da08b-f43d-4432-8c47-c86a1a1299ae | < 4.27.4 |
MEDIUM | 6.1 | Cross-site scripting (XSS) vulnerability in ls/vv_login.php in the VideoWhisper Live Streaming Integration plugin 4.27.2… | — | wordfence |
| a961d30e-f2cb-458d-8f1a-18f6e769efbc | < 2.5.1 |
MEDIUM | 6.1 | The WP Discord Invite plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘webhook’ paramet… | — | wordfence |
| a95f16ae-286d-474c-b85e-8d47a14d7533 | < 1.7.9 |
MEDIUM | 6.1 | The Landing Page Cat plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and includi… | — | wordfence |
| a95e1164-2c48-4265-818d-4ee4e894532b | MEDIUM | 6.1 | The Gigaom Sphinx plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and includ… | — | wordfence | |
| a95cbc9e-146a-4b6d-bfb7-9f7ea5ec394e | < 2.0.0 |
MEDIUM | 6.1 | The Wr Age Verification plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘PHP_SELF’ para… | — | wordfence |
| a946cca6-670b-4baf-a941-43d0a0261c0d | < 2.4.2 |
MEDIUM | 6.1 | Multiple cross-site scripting (XSS) vulnerabilities in the Zingiri Web Shop plugin 2.4.1 for WordPress allow remote atta… | — | wordfence |
| a93f6dce-56e0-4131-ba26-65a0c6b2e9c5 | < 1.0.4 |
MEDIUM | 6.1 | The Yampi Checkout plugin for WordPress is vulnerable to reflected Cross-Site Scripting in versions up to, and including… | — | wordfence |
| a93c0dd4-8341-438d-8730-470e9a230d97 | < 2.1.77 |
MEDIUM | 6.1 | The WooCommerce Product Vendors plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, … | — | wordfence |
| a931436c-102e-414a-9c1d-64c768be7b93 | MEDIUM | 6.1 | The bloggie theme for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 2.0.8… | — | wordfence | |
| a923c84e-3641-45ec-970e-faea803897bf | MEDIUM | 6.1 | The ECOBIZ <= 3.3, Ebiz <= 1.2, Avanix <= 1.2, and Ovum (unknown version) themes for WordPress are vulnerable to Cross-… | — | wordfence | |
| a922c2ad-77ec-4fa8-b997-fa7e85d96590 | MEDIUM | 6.1 | The Comment Genius plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the `$_SERVER['PHP_SELF']` p… | — | wordfence | |
| a9113601-7833-4d7a-8567-97e99b54200a | MEDIUM | 6.1 | The SrcSet Responsive Images for WordPress plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versi… | — | wordfence | |
| a90e1628-3490-4aac-9e82-b3b9692813f0 | < 1.1.1 |
MEDIUM | 6.1 | The shortcode-factory plugin before 1.1.1 for WordPress has XSS via add_query_arg. | — | wordfence |
| a8ea0559-dec7-4c20-956d-dbfe7bc67634 | < 4.4.3 |
MEDIUM | 6.1 | The Online Booking & Scheduling Calendar for WordPress by vcita plugin for WordPress is vulnerable to Reflected Cross-Si… | — | wordfence |
| a8e34c05-7431-4acd-91f3-aab5e66f61ad | < 1.7.1007 |
MEDIUM | 6.1 | The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to Cross-Site Request Forgery in all version… | — | wordfence |
| a8d67bc0-8c21-43e8-bdcc-1235eca94fa7 | < 2.1.1 |
MEDIUM | 6.1 | Cross-site scripting (XSS) vulnerability in client-assist.php in the dsIDXpress IDX plugin before 2.1.1 for WordPress al… | — | wordfence |
| a8d4dc12-ae17-477f-a8d2-da9747672a26 | < 1.3.40 |
MEDIUM | 6.1 | The ultimate-member plugin before 1.3.40 for WordPress has XSS on the login form. | — | wordfence |
EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.
Scan My Website →