Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.
40,117 vulnerabilities found (page 931 of 1605)
| CVE ID | Plugin / Theme | Severity | CVSS | Description | Fixed In | Source |
|---|---|---|---|---|---|---|
| 546c6222-6ffa-41cb-8fff-d2c3cd37ed1f | MEDIUM | 6.1 | The OrangeBox plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.0… | — | wordfence | |
| 5463a730-a8cf-40c9-83fc-3e451e4db1c9 | < 3.1.4 |
MEDIUM | 6.1 | The CM Tooltip Glossary β Better SEO and UEX for your WP site plugin for WordPress is vulnerable to reflected Cross-Si… | — | wordfence |
| 545d5a0f-2f7d-4d2e-9584-cea6449fe045 | MEDIUM | 6.1 | The My Login Logout Plugin plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and i… | — | wordfence | |
| 54560426-a9c9-4a60-9690-8e797e0e7e8d | MEDIUM | 6.1 | Multiple cross-site scripting (XSS) vulnerabilities in the WP GuestMap plugin 1.8 and earlier for WordPress allow remote… | — | wordfence | |
| 54516240-7f2e-4bb8-a252-bb4259b724d7 | MEDIUM | 6.1 | The Related Posts via Categories plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to,… | — | wordfence | |
| 54285c08-c9c8-4576-b1e8-e3b1c584c4bb | < 2.0.2 |
MEDIUM | 6.1 | Cross-site scripting (XSS) vulnerability in wp-register.php in WordPress 2.0 and 2.0.1 allows remote attackers to inject… | — | wordfence |
| 54245c83-a0ae-454f-af80-25383b90948d | MEDIUM | 6.1 | The Terms Dictionary plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and inc… | — | wordfence | |
| 54212d4d-5ff7-4ca4-82f5-10ade4c4a1c0 | < 11.49 |
MEDIUM | 6.1 | The WPMobile.App β Android and iOS Mobile Application plugin for WordPress is vulnerable to Reflected Cross-Site Scrip… | — | wordfence |
| 54140e73-0eb0-4ef3-a8e2-8e7a0d321ca5 | MEDIUM | 6.1 | The Explara Events plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including… | — | wordfence | |
| 541012b2-5d52-452b-85ec-62d3c56d2bc4 | < 2.0.19 |
MEDIUM | 6.1 | The Listeo Core plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to 2.0.19 due to ins… | — | wordfence |
| 540d2495-7ad4-428c-b86e-9af73d0ebe51 | < 1.2.7 |
MEDIUM | 6.1 | The Ad Invalid Click Protector (AICP) WordPress plugin is vulnerable to Reflected Cross-Site Scripting via the page par… | — | wordfence |
| 5409a9c0-df17-4663-96c7-aced7b0f8c70 | < 3.5.9 |
MEDIUM | 6.1 | The Responsive HTML5 Audio Player PRO With Playlist plugin for WordPress is vulnerable to Reflected Cross-Site Scripting… | — | wordfence |
| 54044b8c-52f2-4887-b67c-ed78023da3ff | < 2.6.7 |
MEDIUM | 6.1 | The Search Atlas SEO β Premier SEO Plugin for One-Click WP Publishing & Integrated AI Optimization plugin for WordPres… | — | wordfence |
| 540236b8-ff7a-4171-812b-29d3c88a881a | MEDIUM | 6.1 | The Boot Store theme for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'tcp_register_error' paramete… | — | wordfence | |
| 53ef1383-55a7-40ea-b382-6804e10efa84 | MEDIUM | 6.1 | The hpb seo plugin for WordPress plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to,… | — | wordfence | |
| 53e01cb5-f8c2-4151-b0d6-13422382fd13 | < 5.1.4 |
MEDIUM | 6.1 | The WordPress Internal Link Optimiser plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions u… | — | wordfence |
| 53d2f416-4b0f-49b7-af14-fbb225aac34d | MEDIUM | 6.1 | The Purity Of Soul theme for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and includ… | — | wordfence | |
| 53ac7001-e381-4bfb-8749-6f9df10dcab5 | MEDIUM | 6.1 | The WordPress Activity-o-meter plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up t… | — | wordfence | |
| 53a58c45-b7fd-469e-8c67-4f20707f2363 | MEDIUM | 6.1 | Multiple cross-site scripting (XSS) vulnerabilities in the WP SimpleMail plugin 1.0.6 for WordPress allow remote attacke… | — | wordfence | |
| 5394623b-e9ee-4047-bfe3-d7f6374993cd | < 0.85 |
MEDIUM | 6.1 | The Google Forms plugin for WordPress is vulnerable to Cross-Site Scripting via the 'page' parameter in versions before … | — | wordfence |
| 539300b9-3e8e-4c20-93a6-b6eb1588cc6c | MEDIUM | 6.1 | The Saragna plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 1.0 d… | — | wordfence | |
| 538616b8-0c23-42b7-a694-dde69af9e3b9 | MEDIUM | 6.1 | The Tuaug4 theme for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 1.4 due… | — | wordfence | |
| 537b6f36-ae45-465a-b139-6753d50d8e10 | MEDIUM | 6.1 | Cross-site scripting (XSS) vulnerability in index.php in the (1) Blix 0.9.1 and (2) Blix 0.9.1 Rus themes for WordPress … | — | wordfence | |
| 537acaf7-8d44-484d-9516-774a3de5573f | < 3.6 |
MEDIUM | 6.1 | Stored XSS was discovered in the Easy Testimonials plugin 3.5.2 for WordPress. Three wp-admin/post.php parameters (_ikcf… | — | wordfence |
| 53686d01-b60c-4324-895e-2fae3ccfa3c9 | < 1.8.12 |
MEDIUM | 6.1 | The MP3-jPlayer plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the βmp3β parameter in vers… | — | wordfence |
EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.
Scan My Website →