Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.
40,117 vulnerabilities found (page 921 of 1605)
| CVE ID | Plugin / Theme | Severity | CVSS | Description | Fixed In | Source |
|---|---|---|---|---|---|---|
| 5eba6825-9a3a-4af5-8d8a-9439ab374cc7 | < 3.0.39 |
MEDIUM | 6.1 | The eCommerce Product Catalog Plugin for WordPress plugin before 3.0.39 does not escape the ic-settings-search parameter… | — | wordfence |
| 5eb66ca3-768e-4d8c-a0fa-74e78250aee3 | < 4.2.9 |
MEDIUM | 6.1 | The Contact Form by BestWebSoft plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘cntctfrm… | — | wordfence |
| 5eab077f-0aeb-4dec-9ed2-8a09c4450d06 | MEDIUM | 6.1 | The WP Lyrics plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 0.4… | — | wordfence | |
| 5e9ba1cb-62f5-4d6a-9727-ae62bb0edb98 | < 1.2.6.2 |
MEDIUM | 6.1 | Unauthenticated Stored Cross-Site Scripting (XSS) vulnerability discovered in Contact Form 7 Database Addon – CFDB7 Wo… | — | wordfence |
| 5e95ded5-ebf7-4ed3-a194-7e7e494d0c40 | MEDIUM | 6.1 | The Qards plugin through 2017-10-11 for WordPress has XSS via a remote document specified in the url parameter to html2c… | — | wordfence | |
| 5e959ac0-e5ac-4d28-8161-311d952b993c | < 3.9.6 |
MEDIUM | 6.1 | The Essential Real Estate plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and in… | — | wordfence |
| 5e74ee0d-f03d-4139-a192-2a45d5f619dc | MEDIUM | 6.1 | The ShopConstruct – Product Catalog, Shopping Cart and eCommerce solution for Store plugin for WordPress is vulnerable… | — | wordfence | |
| 5e69c365-65fd-4001-93c3-5df023e8e05b | MEDIUM | 6.1 | The Dezdy plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and including, 1.0… | — | wordfence | |
| 5e618864-e862-4d4f-aa28-3e2fb78882fc | < 1.6.22 |
MEDIUM | 6.1 | The iPanorama 360 WordPress Virtual Tour Builder plugin for WordPress is vulnerable to Reflected Cross-Site Scripting vi… | — | wordfence |
| 5e600744-7f5a-483a-9df9-cf90b22b3a9e | MEDIUM | 6.1 | The WP Compare Tables plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and includ… | — | wordfence | |
| 5e5bdc92-e682-4121-9ba5-167742f61138 | < 3.7.3 |
MEDIUM | 6.1 | The Custom 404 Pro plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘s’ parameter in ver… | — | wordfence |
| 5e45b5d3-0f55-45b2-a289-42d37af266c1 | MEDIUM | 6.1 | The Swift Calendar Online Appointment Scheduling plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in… | — | wordfence | |
| 5e3e6ca7-83fb-4558-aa90-0a10432af2d8 | MEDIUM | 6.1 | The Lime Developer Login plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and… | — | wordfence | |
| 5e36b6bd-20d9-433f-beb7-82077b09beee | MEDIUM | 6.1 | The Videos plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and including, 1.… | — | wordfence | |
| 5e364f0c-17ea-4962-92d3-35bf5eb666ad | < 1.4.15 |
MEDIUM | 6.1 | The PropertyHive plugin before 1.4.15 for WordPress has XSS via the body parameter to includes/admin/views/html-preview-… | — | wordfence |
| 5e3593e8-3840-4db0-8269-61bbcb50d569 | < 1.4.5 |
MEDIUM | 6.1 | The amCharts: Charts and Maps plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'amcharts_jav… | — | wordfence |
| 5e21524e-2470-49e1-983a-a62a0ae478f6 | < 4.0.38 |
MEDIUM | 6.1 | The Fast Secure Contact Form plugin before 4.0.38 for WordPress allows fs_contact_form1[welcome] XSS. | — | wordfence |
| 5e043348-c0aa-418f-9120-dcf470f92123 | MEDIUM | 6.1 | The Yahoo! WebPlayer plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and includi… | — | wordfence | |
| 5dfb8937-848d-4ce6-a90c-03b75f7951a1 | MEDIUM | 6.1 | The WordPress Filter plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and includi… | — | wordfence | |
| 5df2dfcd-2fda-4f09-bd77-f437422d20bb | < 1.5.12 |
MEDIUM | 6.1 | The LoginPress | Custom Login Page Customizer WordPress plugin before 1.5.12 does not escape the redirect-page parameter… | — | wordfence |
| 5df238dd-6269-4ee0-a0f4-12bdb74f74e8 | < 6.2.8 |
MEDIUM | 6.1 | In the YOP Poll WordPress plugin before 6.2.8, when a pool is created with the options "Allow other answers", "Display o… | — | wordfence |
| 5dea4293-0496-4cee-9d8a-c15beaa51b14 | MEDIUM | 6.1 | The WHMpress plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 6.2-… | — | wordfence | |
| 5de8bc53-612f-4cee-b10c-bc24fc67bcf0 | MEDIUM | 6.1 | The Feedpress Generator plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and incl… | — | wordfence | |
| 5dd270c6-31e5-4005-9c5f-d29e1f2f5faa | MEDIUM | 6.1 | The Conversion Helper plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and includ… | — | wordfence | |
| 5dbebce4-599b-4241-aa9a-3d2486a57d52 | MEDIUM | 6.1 | Cross-site scripting (XSS) vulnerability in js/window.php in the Wikipop plugin 2.0 and earlier for WordPress allows rem… | — | wordfence |
EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.
Scan My Website →