Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.
40,117 vulnerabilities found (page 884 of 1605)
| CVE ID | Plugin / Theme | Severity | CVSS | Description | Fixed In | Source |
|---|---|---|---|---|---|---|
| 88290419-2086-4b43-b2b9-5d8128b208e2 | MEDIUM | 6.1 | The Allure Real Estate Theme for WordPress is vulnerable to Cross-Site Scripting via ZeroCliboard.swf in versions up to,… | — | wordfence | |
| 882639e3-615f-48df-9ddc-afbe0788d55f | MEDIUM | 6.1 | The MM-Breaking News plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and includi… | — | wordfence | |
| 882631ab-ef16-4158-adbc-60ad177ae6b8 | < 1.11.27 |
MEDIUM | 6.1 | The Memberpress plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘message’ and 'error' p… | — | wordfence |
| 87efa10d-d359-4258-9db2-811d5ae75c60 | MEDIUM | 6.1 | The LinkedIn Resume plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and includin… | — | wordfence | |
| 87ee0da1-3a95-4e09-a070-4c8aa336ffe8 | MEDIUM | 6.1 | The WP MediaTagger plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and inclu… | — | wordfence | |
| 87eb4569-bfde-4bd8-95ef-561ec04158c8 | MEDIUM | 6.1 | The Userbase Access Control plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, … | — | wordfence | |
| 87e76cf7-cfaf-499d-8929-db7efd6ec284 | < 2.1.5 |
MEDIUM | 6.1 | The Product Table by WBW plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and inc… | — | wordfence |
| 87d064fc-923a-41f1-a14f-09ff91b2aaee | < 2.8.0 |
MEDIUM | 6.1 | The CM Download Manager plugin for WordPress is vulnerable to Cross-Site Scripting in versions up to, and including, 2.7… | — | wordfence |
| 87ca4c05-b9fc-4932-be4b-beb57ca3bb7e | MEDIUM | 6.1 | The WordPress Content Slide plugin for WordPress is vulnerable to Cross-Site Scripting via the 'wpcs_options[slide_image… | — | wordfence | |
| 87bb2aa8-9554-493b-931f-bef80dc5404a | MEDIUM | 6.1 | The One Backend Language plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and… | — | wordfence | |
| 87b8386e-863e-4a33-8beb-aab3e704ecb6 | < 1.06 |
MEDIUM | 6.1 | The Built-in Widgets Query extend plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to… | — | wordfence |
| 879bd819-5513-4253-b6e0-a34dbebae287 | < 1.2.9 |
MEDIUM | 6.1 | The Better Find and Replace WordPress plugin before 1.2.9 does not escape the 's' GET parameter before outputting back i… | — | wordfence |
| 878ec7b7-356a-4e14-8c48-3e217f5f51a1 | < 1.1.2 |
MEDIUM | 6.1 | The MemberPress Discord Addon plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, an… | — | wordfence |
| 87870d48-05ff-4f51-9ad9-091ce2ffaf01 | < 3.9.002 |
MEDIUM | 6.1 | Multiple cross-site scripting (XSS) vulnerabilities in the iMember360 plugin 3.8.012 through 3.9.001 for WordPress allow… | — | wordfence |
| 878671d2-572c-43f9-8fba-f2e2e955b7a6 | < 3.8 |
MEDIUM | 6.1 | The Protect WP Admin plugin for WordPress is vulnerable to Cross-Site Scripting in versions up to, and including, 3.7 du… | — | wordfence |
| 8782aefa-6fb6-4b42-b697-cee3e1713e9c | < 3.0.5 |
MEDIUM | 6.1 | The Verowa Connect plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including… | — | wordfence |
| 875fbe6e-436c-445c-bd0c-0e6beae3fbf2 | MEDIUM | 6.1 | The WordPress Gallery Plugin plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and… | — | wordfence | |
| 875c6474-5bf3-4556-b529-299cd2f65afe | < 5.0.5 |
MEDIUM | 6.1 | The Slimstat Analytics plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and inclu… | — | wordfence |
| 8759bb88-2c19-4875-99c1-f83a2abaffa2 | < 2.3.2 |
MEDIUM | 6.1 | The Paytm Payment Donation plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, a… | — | wordfence |
| 87418933-53a6-41d4-af7b-f1d2408ff4cd | MEDIUM | 6.1 | The Like in Vk.com plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including… | — | wordfence | |
| 873b6ace-0377-42d8-a6c5-3fe0226cebc5 | < 6.8.6 |
MEDIUM | 6.1 | The Easy Forms for Mailchimp WordPress plugin before 6.8.6 does not sanitise and escape the field_name and field_type pa… | — | wordfence |
| 872a6264-f0e2-4936-a942-172a99892672 | < 2.6.2 |
MEDIUM | 6.1 | The google-document-embedder plugin before 2.6.2 for WordPress has XSS. | — | wordfence |
| 8721b15f-cb17-48d2-bd8f-20125452d621 | MEDIUM | 6.1 | The Redux Converter plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and incl… | — | wordfence | |
| 871bef47-a151-4c5b-bffa-bc0abb53e191 | < 1.7.6 |
MEDIUM | 6.1 | The Integration for WooCommerce and Salesforce plugin for WordPress is vulnerable to Open Redirect in all versions up to… | — | wordfence |
| 87135f68-8010-40ff-8507-3111cf8e86e2 | MEDIUM | 6.1 | The Smooth Dynamic Slider plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, an… | — | wordfence |
EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.
Scan My Website →