Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.
40,117 vulnerabilities found (page 930 of 1605)
| CVE ID | Plugin / Theme | Severity | CVSS | Description | Fixed In | Source |
|---|---|---|---|---|---|---|
| 5570b8ef-6fb9-4f9e-be39-d8c615d1abab | < 1.2 |
MEDIUM | 6.1 | The SendPress Newsletters plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'listID' & 'subsc… | — | wordfence |
| 556f6e7d-dbb4-4030-b6f9-8709135ae660 | MEDIUM | 6.1 | The 4 author cheer up donate plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to,… | — | wordfence | |
| 5569ec0f-eeb6-433f-bb49-336abae2a29a | MEDIUM | 6.1 | The Velvet Theme for WordPress is vulnerable to Reflected Cross-Site Scripting via an unknown parameter in all versions … | — | wordfence | |
| 5537c46d-1df3-4d24-b1c0-851c22c6ae79 | MEDIUM | 6.1 | The SingSong plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.2.… | — | wordfence | |
| 55367b9b-8ae1-4282-bf9f-8fb3848eb579 | MEDIUM | 6.1 | The Admission AppManager plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'q' parameter in v… | — | wordfence | |
| 552d2d0d-1f4a-4557-ba8e-9f63acbfffba | < 2.4.3 |
MEDIUM | 6.1 | The Wyzi Theme was affected by reflected XSS vulnerabilities in the business search feature | — | wordfence |
| 550a8107-f639-4edc-9aad-1943d032cc26 | MEDIUM | 6.1 | The Custom Website Data WordPress plugin is vulnerable to Reflected Cross-Site Scripting via the id parameter found in t… | — | wordfence | |
| 54fff686-3c5a-4e75-af04-05700db4f3f0 | MEDIUM | 6.1 | The Thebe theme for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 1.3.0 du… | — | wordfence | |
| 54e7ccaf-2b16-4e36-a8ec-8f1f61193ffd | < 0.810 |
MEDIUM | 6.1 | Cross-site scripting (XSS) vulnerability in the church_admin plugin before 0.810 for WordPress allows remote attackers t… | — | wordfence |
| 54e330e7-d305-4254-a9e9-4d7f2c54c51c | MEDIUM | 6.1 | The Forms Ada plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the βpβ ($page_nav) parameter… | — | wordfence | |
| 54def910-b934-4a48-b7fe-7165917b01ca | MEDIUM | 6.1 | The Studiocart plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 2.… | — | wordfence | |
| 54c79532-588d-4afd-ad01-199b5c4ce4d0 | < 4.1.6 |
MEDIUM | 6.1 | The Enable Media Replace plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and inc… | — | wordfence |
| 54c563fb-efc2-44f2-9b1d-7c4a377a2565 | MEDIUM | 6.1 | The Vice Versa plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 2.… | — | wordfence | |
| 54c38be0-ffe7-4fa4-b5c9-cb717c11aed5 | < 118 |
MEDIUM | 6.1 | The Simple URLs plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'post_id' parameter in vers… | — | wordfence |
| 54c1809d-cff3-4800-8945-bffad7f03d33 | MEDIUM | 6.1 | The JSON Structuring Markup plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and … | — | wordfence | |
| 54c154a9-e751-4e8f-a26e-7eb208fa7ffe | < 0.7.1.6 |
MEDIUM | 6.1 | The Connections plugin for WordPress is vulnerable to authorization bypass in versions up to, and including, 0.7.1.5 due… | — | wordfence |
| 54c0146d-3193-4fde-9082-600ab97160e6 | MEDIUM | 6.1 | The Twispay Credit Card Payments plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to,… | — | wordfence | |
| 54b88702-ec41-414b-87f1-1859b130a713 | MEDIUM | 6.1 | The CloudNet360 plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via an unknown parameter in all ver… | — | wordfence | |
| 54ac4a5a-b0f4-458e-b2c7-9884c7a2138d | MEDIUM | 6.1 | The Theme Blvd Sliders plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and inclu… | — | wordfence | |
| 54a5146e-53f8-455e-a80a-b9c60cb46984 | MEDIUM | 6.1 | The Block Collection for You β WP Block Pack plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in a… | — | wordfence | |
| 549d4aa4-9f34-4453-93ec-1561278f7959 | MEDIUM | 6.1 | The Accordion Slider PRO plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and inc… | — | wordfence | |
| 54904fb0-4737-414c-bc9a-f5b040b59286 | MEDIUM | 6.1 | The Automotive Car Dealership Business WordPress Theme theme for WordPress is vulnerable to Reflected Cross-Site Scripti… | — | wordfence | |
| 5486d50c-8544-4368-b58b-66024a8ae86d | < 8.6.01.005 |
MEDIUM | 6.1 | The WP Photo Album Plus plugin for WordPress is vulnerable to Cross-Site Scripting in versions up to, and including, 8.5… | — | wordfence |
| 547e5814-0201-4dbf-9d2d-8028ca055402 | < 5.0.1.9 |
MEDIUM | 6.1 | The RegistrationMagic WordPress plugin before 5.0.1.9 does not sanitise and escape the rm_search_value parameter before … | — | wordfence |
| 547008fe-2585-4089-a710-71a83ae3d829 | < 6.2.9 |
MEDIUM | 6.1 | The Fluent Forms β Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder plugin for WordPress is vul… | — | wordfence |
EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.
Scan My Website →