Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.
40,117 vulnerabilities found (page 871 of 1605)
| CVE ID | Plugin / Theme | Severity | CVSS | Description | Fixed In | Source |
|---|---|---|---|---|---|---|
| 96084352-cc53-45fc-a33f-2ebf470f81a7 | < 4.51 |
MEDIUM | 6.1 | The Webcam Video Conference plugin for WordPress is vulnerable to Cross-Site Scripting in versions up to, and including,… | — | wordfence |
| 960249b2-61e7-4105-a946-e3aea8d0ab16 | MEDIUM | 6.1 | The NS Simple Intro Loader plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and i… | — | wordfence | |
| 95f9066c-e0dd-4909-a57b-c52070b135d1 | < 1.1.5 |
MEDIUM | 6.1 | The Pricing Table Builder WordPress plugin before 1.1.5 does not sanitize and escape the postid parameter before outputt… | — | wordfence |
| 95ebb2ad-91a8-4a0d-ba91-f417943545b4 | < 2.5.8 |
MEDIUM | 6.1 | The Campaign Monitor Forms by Optin Cat plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the … | — | wordfence |
| 95c59e71-b755-4b39-bd5f-b2b2ac99f934 | < 4.2.0 |
MEDIUM | 6.1 | The all-in-one-wp-security-and-firewall plugin before 4.2.0 for WordPress has multiple XSS issues via the 'tab' paramete… | — | wordfence |
| 95c2038f-c4f9-472a-92ab-59ee395bda3d | < 3.2.9 |
MEDIUM | 6.1 | The Simple Membership plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘page’ parameter … | — | wordfence |
| 95bae3f2-313b-4b6c-a81c-8af6f169151b | < 2.4.6 |
MEDIUM | 6.1 | The Woody code snippets plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query… | — | wordfence |
| 959775d4-1c03-454a-b13b-670c726fec91 | MEDIUM | 6.1 | The WP doodlez plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 1… | — | wordfence | |
| 956f86c5-05af-41c3-a779-5b25f62122dd | < 4.9.3 |
MEDIUM | 6.1 | The Gwolle Guestbook plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘gwolle_gb_content’ p… | — | wordfence |
| 95579b81-857a-4ebb-9943-3761a2e5b3d9 | < 3.2.2.0 |
MEDIUM | 6.1 | The Universal Video Player - Addon for WPBakery Page Builder plugin for WordPress is vulnerable to Reflected Cross-Site … | — | wordfence |
| 953be831-d688-4ae1-b8c1-d863eded945b | < 5.9.5 |
MEDIUM | 6.1 | The Contact Form 7 plugin for WordPress is vulnerable to Open Redirect in all versions up to, and including, 5.9.4. This… | — | wordfence |
| 95265186-ff13-464b-adb9-3cf1753487d5 | < 1.2.7.6 |
MEDIUM | 6.1 | The Alpine PhotoTile for Instagram plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the client_i… | — | wordfence |
| 952293ff-ff17-4e35-8afb-88638265ec8d | MEDIUM | 6.1 | The Triss - Beauty Cosmetics Shop WordPress Theme theme for WordPress is vulnerable to Reflected Cross-Site Scripting in… | — | wordfence | |
| 94f803f4-0a06-4b77-9483-5c63f6dfd2f0 | < 3.1.2 |
MEDIUM | 6.1 | The wp-google-map-plugin plugin before 3.1.2 for WordPress has XSS. | — | wordfence |
| 94f6b24e-2c53-45c7-a19a-c37486838183 | < 3.1 |
MEDIUM | 6.1 | The Addon Jobsearch Chat plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and inc… | — | wordfence |
| 94f03821-eb33-4eb6-b7ff-b32a74facdd2 | < 3.4.3 |
MEDIUM | 6.1 | The "Schedule Name" input in the Weekly Schedule WordPress plugin before 3.4.3 general options did not properly sanitize… | — | wordfence |
| 94e9a982-a46d-4dda-9145-e7f74cf09820 | < 3.4.24 |
MEDIUM | 6.1 | The WP-Filebase plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘page’ parameter in ver… | — | wordfence |
| 94e859ea-3f90-49d1-9e66-fe3ab749c872 | < 1.6.0 |
MEDIUM | 6.1 | The Language Switcher for Transposh plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions… | — | wordfence |
| 94dd90ef-d801-4fd6-ade7-e1e7ad2e5fec | < 1.0.4 |
MEDIUM | 6.1 | Cross-site scripting (XSS) vulnerability in the Elegant Grunge theme before 1.0.4 for WordPress allows remote attackers … | — | wordfence |
| 94dc8fc6-8212-4f83-a844-f08174531d3b | < 1.0.3 |
MEDIUM | 6.1 | The Simple Login Registration plugin for WordPress is vulnerable to Cross-Site Scripting in versions up to, and includin… | — | wordfence |
| 94d522bc-9808-435d-804d-e979a6c8be66 | < 1.10.9 |
MEDIUM | 6.1 | Cross-site scripting (XSS) vulnerability exists in the Wordpress admin panel when the Broken Link Checker plugin before … | — | wordfence |
| 94c2dab9-40b3-4863-a5f3-fcaba10d2e20 | < 5.1.10 |
MEDIUM | 6.1 | CDI – Collect and Deliver Interface for Woocommerce plugin for WordPress is vulnerable to Cross-Site Scripting via mul… | — | wordfence |
| 94c1e520-efd7-479f-8cfc-bc75a00a610f | MEDIUM | 6.1 | The Universal Video Player plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and i… | — | wordfence | |
| 94c118a2-b0af-488f-bbb7-e2575c2c9523 | MEDIUM | 6.1 | The AlphaOmega Captcha & Anti-Spam Filter plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versio… | — | wordfence | |
| 94bd2229-0dfa-4f8b-9aa8-e2ee1bb7bc27 | MEDIUM | 6.1 | The No Future Posts WordPress plugin through 1.4 does not escape its settings, which could allow high privilege users su… | — | wordfence |
EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.
Scan My Website →