Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.
40,117 vulnerabilities found (page 860 of 1605)
| CVE ID | Plugin / Theme | Severity | CVSS | Description | Fixed In | Source |
|---|---|---|---|---|---|---|
| a12ccd08-ee29-4fb9-9075-cf71dc488ffc | MEDIUM | 6.1 | The Footer Text plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.0.3… | — | wordfence | |
| a1211a41-3ab5-4ae9-84eb-0079ac54b28d | MEDIUM | 6.1 | The Texteller plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and including,… | — | wordfence | |
| a10da173-9b88-4599-928d-71fc42b35c50 | < 3.5.7 |
MEDIUM | 6.1 | The WPify Woo Czech plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of '$_SERVER['PH… | — | wordfence |
| a0fa6d9f-7243-4349-9c79-00199ee84c25 | < 4.9.4 |
MEDIUM | 6.1 | The Verge3D Publishing and E-Commerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versio… | — | wordfence |
| a0eed0fd-8841-41d1-80fb-dd02f2a1edf3 | < 1.1.10 |
MEDIUM | 6.1 | The Orders Tracking for WooCommerce WordPress plugin before 1.1.10 does not sanitise and escape the file_url before outp… | — | wordfence |
| a0d8ec3e-b16c-416f-ac18-93ecb5a63313 | < 8.0.1 |
MEDIUM | 6.1 | The LifterLMS – WP LMS for eLearning, Online Courses, & Quizzes plugin for WordPress is vulnerable to Reflected Cross-… | — | wordfence |
| a0cd4441-7e25-46dd-82ff-91d10b8eacd8 | < 1.7.4 |
MEDIUM | 6.1 | The I Plant A Tree plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including… | — | wordfence |
| a0c4ef62-1274-4cf3-88fc-ccabedbbe26c | < 2.8.12 |
MEDIUM | 6.1 | The Yellow Yard Searchbar plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_que… | — | wordfence |
| a0b14d91-f8f9-41df-b2eb-12792fb3a197 | < 1.9.6 |
MEDIUM | 6.1 | The Tutor LMS plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘page’ parameter in versi… | — | wordfence |
| a0af6cea-a667-4339-bc9f-e4c0d0e36848 | MEDIUM | 6.1 | The bbPress Move Topics plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and … | — | wordfence | |
| a0aa2a10-da05-41e4-bbfa-938341919b5d | < 2.10.4 |
MEDIUM | 6.1 | The Easy Digital Downloads plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘code’ param… | — | wordfence |
| a0a43e7c-f1c1-4b29-86d9-64d4c2e8b8aa | < 5.3.5 |
MEDIUM | 6.1 | The Tour Master - Tour Booking, Travel, Hotel plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due t… | — | wordfence |
| a09771da-a423-42ba-8f59-5c3bd189d9d3 | < 5.9.1 |
MEDIUM | 6.1 | The Advanced Custom Fields Pro WordPress plugin before 5.9.1 did not properly escape the generated update URL when outpu… | — | wordfence |
| a0831971-3862-4774-8375-fe5870ef82d9 | < 7.0 |
MEDIUM | 6.1 | The WP User WordPress plugin before 7.0 does not sanitise and escape some parameters in pages where the [wp_user] shortc… | — | wordfence |
| a082a8bc-1dcc-4a5c-9a12-26a020c344ce | MEDIUM | 6.1 | The Pages Order plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 1… | — | wordfence | |
| a08046a5-69ac-430d-af0a-592305543ffb | MEDIUM | 6.1 | The WordPress连接微博 plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and in… | — | wordfence | |
| a07ebb3a-d670-4339-a0a8-82ce661e2552 | < 0.3.0 |
MEDIUM | 6.1 | The tarteaucitron-wp plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and excludi… | — | wordfence |
| a073c2f1-88d3-4410-b9f5-45b04becbfcb | < 1.12.4 |
MEDIUM | 6.1 | The WP ERP plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'employee_name' parameter in ver… | — | wordfence |
| a068e411-d81f-4162-84e9-f1e9868963f9 | < 1.1.9 |
MEDIUM | 6.1 | The Supreme Directory plugin for WordPress is vulnerable to Cross-Site Scripting via the 's' parameter in versions befor… | — | wordfence |
| a06812c5-43db-4c32-a9fb-f7b86900a741 | < 2.8.18 |
MEDIUM | 6.1 | The Contact Form DB plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'submit_time' and 'form… | — | wordfence |
| a05b1d00-386f-4914-80e6-92d3e9721dc5 | < 1.4.0 |
MEDIUM | 6.1 | init.php in the Loginizer plugin 1.3.8 through 1.3.9 for WordPress has Unauthenticated Stored Cross-Site Scripting (XSS)… | — | wordfence |
| a0598208-bfaf-40da-8e83-15c22a87fa06 | < 3.9.9 |
MEDIUM | 6.1 | The Eventer plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and including, 3… | — | wordfence |
| a0365d52-8817-4b69-9df3-ac4c5bb6f4f3 | MEDIUM | 6.1 | The HTML5 jQuery Audio Player plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, an… | — | wordfence | |
| a0297cab-8b6f-4e09-b552-4772c6f72c04 | < 1.6.4 |
MEDIUM | 6.1 | The Elementor Addon Elements plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the tab parameter … | — | wordfence |
| a0247ba6-d193-4b7d-969d-0cd239c57faa | < 2.2.25 |
MEDIUM | 6.1 | The Biteship plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'biteship_error' and 'biteship… | — | wordfence |
EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.
Scan My Website →