Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.
40,369 vulnerabilities found (page 918 of 1615)
| CVE ID | Plugin / Theme | Severity | CVSS | Description | Fixed In | Source |
|---|---|---|---|---|---|---|
| 696960f4-ed10-4b61-8292-ef407544ba69 | MEDIUM | 6.1 | The Canvasflow for WordPress plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to,… | — | wordfence | |
| 6966cf31-721b-4759-a4c2-4b20c6a7053d | < 3.2.2.0 |
MEDIUM | 6.1 | The Universal Video Player - Addon for WPBakery Page Builder plugin for WordPress is vulnerable to Reflected Cross-Site … | — | wordfence |
| 69435cb6-9591-45bb-86e3-eaf1a9bc46f9 | < 2.9.19 |
MEDIUM | 6.1 | The Ninja Forms Contact Form plugin for WordPress is vulnerable to Cross-Site Scripting in versions up to, and including… | — | wordfence |
| 691c0f3b-b723-4310-b4df-ed3e1db9d548 | < 2.3.7 |
MEDIUM | 6.1 | The WP Plugin Info Card plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘slug’ paramete… | — | wordfence |
| 691b080c-052a-4967-a251-98a17038448d | MEDIUM | 6.1 | Multiple cross-site scripting (XSS) vulnerabilities in test-plugin.php in the Swipe Checkout for WP e-Commerce plugin 3.… | — | wordfence | |
| 6918bbc2-ad9d-4d3b-8cdf-bf906bae180c | MEDIUM | 6.1 | The Save & Import Image from URL plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up… | — | wordfence | |
| 69150437-dfd6-436a-b100-99f5001c7fe7 | < 1.12.0 |
MEDIUM | 6.1 | iThemes Exchange before 1.12.0 for WordPress has XSS via add_query_arg() and remove_query_arg(). | — | wordfence |
| 6913a08d-c997-4f58-bec1-eeae08a5b6c9 | MEDIUM | 6.1 | The WPOptin – AI-Powered Top Bars, PopUps & Lead Generation plugin for WordPress is vulnerable to Stored Cross-Site Sc… | — | wordfence | |
| 6903e37e-5251-47bb-8023-755821af4689 | < 1.4.12 |
MEDIUM | 6.1 | The User Avatar plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'uid' parameter in versions… | — | wordfence |
| 69025975-9fb7-47a7-9dea-68f4c01d5fdc | < 2.1.2 |
MEDIUM | 6.1 | The Email Encoder – Protect Email Addresses WordPress plugin before 2.1.2 has an endpoint that requires no authenticat… | — | wordfence |
| 6902180a-dd74-4c50-bce2-75cef88241e9 | MEDIUM | 6.1 | The Advance WP Query Search Filter plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up t… | — | wordfence | |
| 6901648a-b54f-4d20-bc22-65731fab13b9 | MEDIUM | 6.1 | The WordPress Hashtags plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and inclu… | — | wordfence | |
| 68fe0f74-96d7-4d5b-99a2-dff4f1c9d30b | MEDIUM | 6.1 | The Plugmatter Pricing Table Lite WordPress plugin is vulnerable to Reflected Cross-Site Scripting via the `email` param… | — | wordfence | |
| 68f2e124-73c5-4ab2-ae0f-b4ca29d8312e | MEDIUM | 6.1 | The Extensions for Elementor plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and… | — | wordfence | |
| 68d9b56b-2460-48d5-95ca-b64e65592b16 | < 2.0.24 |
MEDIUM | 6.1 | The Polldaddy Polls & Rating for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘polldaddy-ratings-… | — | wordfence |
| 68d71bd0-176c-4eee-99c2-9b591d6f70d3 | < 1.3.1910240 |
MEDIUM | 6.1 | The ECPay Logistics for WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'CVSSto… | — | wordfence |
| 68aba88f-e7f9-42d7-9dea-045e7fef7056 | < 5.0.06 |
MEDIUM | 6.1 | The google-language-translator plugin before 5.0.06 for WordPress has XSS. | — | wordfence |
| 68a87e74-597d-4d2c-9900-9c46dffe334f | < 1.2 |
MEDIUM | 6.1 | The Dynamic URL SEO plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and includin… | — | wordfence |
| 688d30ac-9b30-4298-a935-316e5503a31b | MEDIUM | 6.1 | The SpiderFAQ plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and including,… | — | wordfence | |
| 688353c9-e4e5-4717-9651-15d05248554f | MEDIUM | 6.1 | The Footer Putter plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via an unknown parameter in all v… | — | wordfence | |
| 6870e237-2c2f-46c7-bf00-b3f1bedb8d8d | MEDIUM | 6.1 | The Ad-minister plugin for WordPress is vulnerable to Cross-Site Scripting in versions up to, and including, 0.6 via the… | — | wordfence | |
| 686430ed-8b26-4c6a-9e49-4a2cc5f1f7dd | < 1.22.24 |
MEDIUM | 6.1 | The Backup and Staging by WP Time Capsule plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versio… | — | wordfence |
| 6857b90e-7570-4c1c-836e-08f367bb485b | < 4.9.5 |
MEDIUM | 6.1 | The DotLife theme for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to 4.9.5 due to insuffici… | — | wordfence |
| 6845b506-3d38-47f6-9348-d7931e65707a | < 6.3.2 |
MEDIUM | 6.1 | The WooCommerce PensoPay plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'pensopay_action' … | — | wordfence |
| 6840add4-62db-4b99-b48b-0b51aa2451b8 | < 3.2 |
MEDIUM | 6.1 | The Product Enquiry for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘name’… | — | wordfence |
EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.
Scan My Website →