Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.
40,117 vulnerabilities found (page 898 of 1605)
| CVE ID | Plugin / Theme | Severity | CVSS | Description | Fixed In | Source |
|---|---|---|---|---|---|---|
| 7849addf-cdee-4de2-9b6c-bb1c92a472fd | < 5.20.1 |
MEDIUM | 6.1 | The Event Tickets plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including,… | — | wordfence |
| 7848e904-b521-479b-bf7e-d695ad0163b0 | < 2.6.6 |
MEDIUM | 6.1 | The Paid Memberships Pro WordPress plugin before 2.6.6 does not escape the s parameter before outputting it back in an a… | — | wordfence |
| 78393d56-5e83-4eac-bee7-a194aaaa8f5e | MEDIUM | 6.1 | The Category Custom Fields plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and i… | — | wordfence | |
| 78391643-6625-4f5b-a08d-3d8462292a1e | MEDIUM | 6.1 | The iContact for Gravity Forms plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, a… | — | wordfence | |
| 78376368-4883-48ce-aad0-e1d5a993cd74 | < 9.7.2 |
MEDIUM | 6.1 | Authenticated (admin or higher user role) Reflected Cross-Site Scripting (XSS) vulnerability in Biplob Adhikari's Image … | — | wordfence |
| 7831b324-7016-4a5e-85bb-89de773cde0e | MEDIUM | 6.1 | The The Loops plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and including,… | — | wordfence | |
| 782e30a7-6813-47b4-b447-d5f03dcb9dc4 | < 4.1.6 |
MEDIUM | 6.1 | The LearnPress WordPress plugin before 4.1.6 does not sanitise and escape the lp-dismiss-notice before outputting it bac… | — | wordfence |
| 7821b17a-7da7-434f-8e3f-540e7d7cf6bb | < 3.9.48 |
MEDIUM | 6.1 | The Locatoraid Store Locator plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via $_POST keys in all… | — | wordfence |
| 7817f343-1ed6-4b76-afbe-1054de892422 | < 6.8.7 |
MEDIUM | 6.1 | The Blog2Social: Social Media Auto Post & Scheduler WordPress plugin before 6.8.7 does not sanitise and escape the b2sSh… | — | wordfence |
| 7809697d-367a-4051-9865-440ba8ce7ad5 | < 3.0.9 |
MEDIUM | 6.1 | The The Ultimate WordPress Toolkit – WP Extended plugin for WordPress is vulnerable to Reflected Cross-Site Scripting … | — | wordfence |
| 77ff6195-e2e6-49bd-a96e-d2f60b309368 | < 2.14.3 |
MEDIUM | 6.1 | The Code Snippets WordPress plugin before 2.14.3 does not escape the snippets-safe-mode parameter before outputting it b… | — | wordfence |
| 77fdfb42-6540-43be-be5c-63dd6e1a34d7 | < 3.8.9 |
MEDIUM | 6.1 | The Headway theme before 3.8.9 for WordPress has XSS via the license key field. | — | wordfence |
| 77fd0714-ae9d-4136-beed-7f37b1266dc9 | < 1.4.3 |
MEDIUM | 6.1 | The iPages Flipbook plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘page’ parameter in… | — | wordfence |
| 77f3db0c-d575-48a8-872a-a64fd77486de | < 2.0.13 |
MEDIUM | 6.1 | The WooCommerce plugin for WordPress is vulnerable to Self-Reflected Cross-Site Scripting in versions up to, and includi… | — | wordfence |
| 77d66e98-9987-430d-8866-496debe8f65e | < 3.2.2 |
MEDIUM | 6.1 | The JobSearch WP Job Board plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and i… | — | wordfence |
| 77cf3e7c-bcb5-421d-a537-a0d28c36cd05 | MEDIUM | 6.1 | The price-calc plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 0.… | — | wordfence | |
| 77cc3871-664b-404c-b06c-b757374a777a | < 1.4.23.1 |
MEDIUM | 6.1 | The Shipment Tracker for Woocommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all version… | — | wordfence |
| 77b7cf5d-2dad-4a4f-ae48-f1ab86065c2d | < 4.3.0 |
MEDIUM | 6.1 | The Careerfy theme for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 4.2.0… | — | wordfence |
| 77ab3a4b-da39-454e-b223-56a36a7c9447 | MEDIUM | 6.1 | The MDR Webmaster Tools plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and incl… | — | wordfence | |
| 7794f043-0e0b-4ff3-b2dd-1caff8d7168d | < 1.7.1 |
MEDIUM | 6.1 | The Advanced Booking Calendar WordPress plugin before 1.7.1 does not sanitise and escape the room parameter before outpu… | — | wordfence |
| 778aa2be-ffcb-4d28-9efe-c29c8d5391bd | MEDIUM | 6.1 | The HDW Player Plugin (Video Player & Video Gallery) plugin for WordPress is vulnerable to Cross-Site Scripting in versi… | — | wordfence | |
| 77838bf8-7809-4dd6-87f1-a9bda40275a6 | < 2.6.4 |
MEDIUM | 6.1 | The Otter Blocks – Gutenberg Blocks, Page Builder for Gutenberg Editor & FSE PRO plugin for WordPress is vulnerable to… | — | wordfence |
| 777e2e60-46c3-496c-8263-f2e253014ba5 | < 1.5.4 |
MEDIUM | 6.1 | The Get Use APIs – JSON Content Importer plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the … | — | wordfence |
| 776a0059-9e9a-454a-a325-2e3a0e133000 | MEDIUM | 6.1 | The SpiderVPlayer for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘s_v_player_id’ parameter in… | — | wordfence | |
| 7769f3d4-041d-445f-a5fc-d5bc9e45ed58 | < 1.5.4.1 |
MEDIUM | 6.1 | The WPCOM Member plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'login_redirect' parameter… | — | wordfence |
EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.
Scan My Website →