Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.
40,117 vulnerabilities found (page 867 of 1605)
| CVE ID | Plugin / Theme | Severity | CVSS | Description | Fixed In | Source |
|---|---|---|---|---|---|---|
| 99d73781-d0e8-4730-9ec1-ff2151982006 | < 10.6.6 |
MEDIUM | 6.1 | The Wp EMember plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'login_pwd' parameter in all… | — | wordfence |
| 99d62147-f1bf-4146-a22d-d7d8486ed9e7 | MEDIUM | 6.1 | The Book a Place plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, … | — | wordfence | |
| 99c89e29-a21d-4c32-9459-18c7b08b9ff0 | < 1.5.69 |
MEDIUM | 6.1 | The Photo Gallery by 10Web plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the β bwg_search_X… | — | wordfence |
| 99c13de3-e040-4c11-b9c0-bd6a337c4769 | < 1.3.5 |
MEDIUM | 6.1 | PageLayer before 1.3.5 allows reflected XSS via color settings. | — | wordfence |
| 99be8703-b462-4589-9918-76c0ebbb3bcf | < 2.1 |
MEDIUM | 6.1 | The Contact Form 7 β PayPal & Stripe Add-on plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in ve… | — | wordfence |
| 99afde73-3f2b-4ba4-a82b-a6df42462384 | MEDIUM | 6.1 | Multiple cross-site scripting (XSS) vulnerabilities in views/notify.php in the Uploader plugin 1.0.4 for WordPress allow… | — | wordfence | |
| 99a51d1f-35eb-4fe9-967e-c723b47393ea | MEDIUM | 6.1 | The Author Showcase plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and incl… | — | wordfence | |
| 999d8168-b4be-492e-8f25-9df104711341 | < 2.0.15 |
MEDIUM | 6.1 | The J&T Express Malaysia plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and inc… | — | wordfence |
| 999692ee-8bd4-4e7c-89a8-fba9d6f88bc2 | MEDIUM | 6.1 | The Firework Shoppable Live Video plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to… | — | wordfence | |
| 9980ec20-60ae-42eb-a2cd-146e57435398 | < 1.1.15 |
MEDIUM | 6.1 | The Premmerce WooCommerce Customers Manager plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the… | — | wordfence |
| 99711f41-d21b-4725-acc8-9542283daf12 | < 1.1.10 |
MEDIUM | 6.1 | The Thumbnail carousel slider plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, an… | — | wordfence |
| 99555021-68f4-4395-978d-ff1bbae9ebd4 | < 1.3.2.1 |
MEDIUM | 6.1 | The Chained Quiz plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'ipf' parameter on the 'ch… | — | wordfence |
| 9954c283-4dd5-4b78-8c86-97b93a1880b4 | MEDIUM | 6.1 | WordPress Xorbin Digital Flash Clock 1.0 has XSS via 'widgetUrl' parameter. | — | wordfence | |
| 993670b7-a3ea-497d-ad46-881bd47b9346 | < 2.8.18 |
MEDIUM | 6.1 | The System Dashboard plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the Filename parameter in … | — | wordfence |
| 9933ca13-32fd-4481-a18f-21e9a11c423c | < 4.9.3 |
MEDIUM | 6.1 | The Slimstat Analytics plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the β$_SERVER['REQUEST… | — | wordfence |
| 992f9f08-82c1-4bbd-bbd2-543ad8affe53 | < 2.3.22 |
MEDIUM | 6.1 | The WP Dynamic Keywords Injector plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up… | — | wordfence |
| 992d3ed0-2df9-44f4-a36b-434bd89aa4ea | MEDIUM | 6.1 | The Woocommerce Notify Updated Product plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions … | — | wordfence | |
| 99258980-2be8-4590-bf47-576bd1ae4535 | MEDIUM | 6.1 | The Social Analytics plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and includi… | — | wordfence | |
| 991a9271-f6cb-4d33-b853-21b927ac4ad1 | MEDIUM | 6.1 | The ShareBang, Ultimate Social Share Buttons for WordPress plugin for WordPress is vulnerable to Reflected Cross-Site Sc… | — | wordfence | |
| 9918ffe1-5911-48d7-84ba-8e6568d6f50c | < 5.0 |
MEDIUM | 6.1 | The Newsmag WordPress theme before 5.0 does not sanitise the td_block_id parameter in its td_ajax_block AJAX action, lea… | — | wordfence |
| 99140d47-88bb-48a1-863a-93a558541800 | < 3.5.15 |
MEDIUM | 6.1 | The Modal Dialog plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the modal config id in version… | — | wordfence |
| 9911e99e-0b3b-4be1-b8cd-28593b6d12ad | < 1.09 |
MEDIUM | 6.1 | The LH Copy Media File plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_… | — | wordfence |
| 98f71c32-9453-4598-acb5-242818508c74 | < 7.6 |
MEDIUM | 6.1 | The LiteSpeed Cache plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via URLs in all versions up to,… | — | wordfence |
| 98e47920-fb99-478d-9d6c-1612e8b4aca1 | < 1.5.7 |
MEDIUM | 6.1 | The Contact Form to DB plugin for WordPress is vulnerable to Cross-Site Scripting in versions up to, and including, 1.5.… | — | wordfence |
| 98c9c9cb-ca35-461e-9ca6-733012332fd6 | < 2.6.5 |
MEDIUM | 6.1 | The MakeStories (for Web Stories) plugin for WordPress is vulnerable to Cross-Site Scripting in versions up to, and incl… | — | wordfence |
EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.
Scan My Website →