Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.
40,117 vulnerabilities found (page 915 of 1605)
| CVE ID | Plugin / Theme | Severity | CVSS | Description | Fixed In | Source |
|---|---|---|---|---|---|---|
| 65647429-8c76-4538-9725-91fda7fd7d4e | MEDIUM | 6.1 | The Better User Shortcodes plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and i… | — | wordfence | |
| 65644477-263d-493d-99df-80fc558aad51 | < 1.0.5 |
MEDIUM | 6.1 | The Cleanup – Directory Listing & Classifieds WordPress Plugin plugin for WordPress is vulnerable to Reflected Cross-S… | — | wordfence |
| 655729e1-9002-4ca5-be08-9fb601fb53ad | MEDIUM | 6.1 | The Magic Slider plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, … | — | wordfence | |
| 65402225-99ba-49ff-807b-b8e4cf474ffb | < 1.5.68 |
MEDIUM | 6.1 | The Photo Gallery by 10Web WordPress plugin before 1.5.68 is vulnerable to Reflected Cross-Site Scripting (XSS) issues v… | — | wordfence |
| 653fbe5d-3388-4227-8a0a-46764b6be4d2 | < 2.1.16 |
MEDIUM | 6.1 | The Post Grid WordPress plugin before 2.1.16 does not escape the keyword parameter before outputting it back in an attri… | — | wordfence |
| 65329e2c-0ce2-4033-93a8-ba52ae3774c1 | MEDIUM | 6.1 | The Audio plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 0.6.1 d… | — | wordfence | |
| 651df16c-2472-4124-90a3-69b98e478ed3 | < 3.37.30 |
MEDIUM | 6.1 | The WP Fusion Lite WordPress plugin is vulnerable to Reflected Cross-Site Scripting via the startdate parameter found in… | — | wordfence |
| 651572c7-83e0-4651-aa43-9177fbf9d91e | MEDIUM | 6.1 | The LeanPress plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 1.0… | — | wordfence | |
| 650dfc4c-d851-481c-af8f-4dfe1e128a1d | < 2.0.4 |
MEDIUM | 6.1 | The XML Sitemap Generator for Google WordPress plugin before 2.0.4 does not validate a parameter which can be set to an … | — | wordfence |
| 650dbbaa-4348-42a6-973c-487f53430955 | < 3.3.40 |
MEDIUM | 6.1 | The Social Sharing Plugin WordPress plugin before 3.3.40 does not escape the viewed post URL before outputting it back i… | — | wordfence |
| 64e14944-db83-413f-82a3-cda594398c7e | < 1.34.1 |
MEDIUM | 6.1 | The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is vulnerable to Reflecte… | — | wordfence |
| 64de1220-52f5-46a9-b8ba-cf808d5d2e29 | < 4.9.9 |
MEDIUM | 6.1 | The Newsletters plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and includin… | — | wordfence |
| 64d2174e-ee69-4e71-b8cb-ff7a1ba0f52f | < 3.9.24 |
MEDIUM | 6.1 | The Locatoraid Store Locator plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'lpr-search' p… | — | wordfence |
| 64cf73fa-cdb9-4703-869e-343ee6f8178e | < 1.2.9 |
MEDIUM | 6.1 | The TinyChat Room Spy plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'room' parameter in v… | — | wordfence |
| 64ccf609-5cdf-4f05-ad83-4fb7aa475ba5 | < 1.2.8 |
MEDIUM | 6.1 | iThemes Mobile before 1.2.8 for WordPress has XSS via add_query_arg() and remove_query_arg(). | — | wordfence |
| 64abe00c-05b7-4661-b560-bae3957ad3e2 | MEDIUM | 6.1 | The Bulk Creator WordPress plugin through 1.0.1 does not sanitize and escape the post_type parameter before outputting i… | — | wordfence | |
| 64aa76c3-a70a-4939-ad46-b2e67a556124 | < 2.7.10 |
MEDIUM | 6.1 | The Video Share VOD plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and includin… | — | wordfence |
| 64aa45bd-7bf8-4fe9-85e7-ace226e09f34 | < 3.1.15 |
MEDIUM | 6.1 | WebAppick WooCommerce Product Feed 3.1.14 and earlier is affected by: Cross Site Scripting (XSS). The impact is: XSS to … | — | wordfence |
| 64a7a4db-8b28-4085-91b0-4ea5343c5643 | < 1.1 |
MEDIUM | 6.1 | The Import WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'alertmsg’ paramet… | — | wordfence |
| 64827b61-42ea-454a-b41d-85ce8d6ad866 | < 3.0.0.5 |
MEDIUM | 6.1 | The LoginWP (Formerly Peter's Login Redirect) WordPress plugin before 3.0.0.5 does not sanitise and escape the rul_login… | — | wordfence |
| 64729dfb-adfe-4eb8-ad3e-03a5784f19a1 | MEDIUM | 6.1 | The Privacy Policy Genius plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, an… | — | wordfence | |
| 646e3a57-92e1-4502-a0dd-8921e99cfe2d | < 3.0.3 |
MEDIUM | 6.1 | The FancyBox for WordPress plugin before 3.0.3 for WordPress does not properly restrict access, which allows remote atta… | — | wordfence |
| 646ba700-28d5-455f-88de-2864ef8f202c | < 1.4.18 |
MEDIUM | 6.1 | The ViewMedica 9 plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, … | — | wordfence |
| 646af494-5348-484a-80d8-0f9a11ed310e | < 5.8.2 |
MEDIUM | 6.1 | The DeBounce Email Validator plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and… | — | wordfence |
| 645ec67e-f0a3-4273-970c-2073d9a80b4f | MEDIUM | 6.1 | The WP Query Creator plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and inc… | — | wordfence |
EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.
Scan My Website →