Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.
40,117 vulnerabilities found (page 935 of 1605)
| CVE ID | Plugin / Theme | Severity | CVSS | Description | Fixed In | Source |
|---|---|---|---|---|---|---|
| 4fe0df91-21f0-4eef-8064-2b283f38b181 | MEDIUM | 6.1 | The World Travel Information plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the β$_SERVER['P… | — | wordfence | |
| 4fd7af43-5b49-4c4c-a51c-0cce5529ea1b | < 3.12.0.1 |
MEDIUM | 6.1 | The FunnelKit plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 3.1… | — | wordfence |
| 4fd4d30b-f37f-4083-acfe-8e85c075da10 | < 7.13.30 |
MEDIUM | 6.1 | The Social Share, Social Login and Social Comments Plugin WordPress plugin before 7.13.30 does not sanitise and escape t… | — | wordfence |
| 4fcd03cd-87c9-4378-ae42-3715ca3a1cb8 | MEDIUM | 6.1 | The Social2Blog plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and includin… | — | wordfence | |
| 4fc8deda-9fb3-41e5-850b-5109d4018027 | < 1.44 |
MEDIUM | 6.1 | The AdPush plugin for WordPress is vulnerable to multiple Cross-Site Scripting in versions up to, and including, 1.43 du… | — | wordfence |
| 4fc82778-0493-456f-bc73-3d70e3a2b1bf | < 1.2.7 |
MEDIUM | 6.1 | The Popularis Extra plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg… | — | wordfence |
| 4fbfec7f-2e96-432c-ade4-c9b96adcaf88 | MEDIUM | 6.1 | The Social Media Links plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and inclu… | — | wordfence | |
| 4fbeee29-751a-48c9-a875-393441f62dde | < 1.1.9 |
MEDIUM | 6.1 | The Lingotek Translation plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the βsmβ parameter… | — | wordfence |
| 4fb06315-30ad-4d98-af75-b04933583be7 | MEDIUM | 6.1 | Multiple plugins for WordPress by KlbTheme are vulnerable to Reflected Cross-Site Scripting in various versions due to i… | — | wordfence | |
| 4faf5d1f-604d-4174-8b83-8779cc83ac4c | MEDIUM | 6.1 | The Post Carousel Slider plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and inc… | — | wordfence | |
| 4fa979e8-2569-4d6c-9eee-344972000aab | MEDIUM | 6.1 | The Trendy Travel theme for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, … | — | wordfence | |
| 4fa5f0a2-30e9-4e89-a509-25a7fe8a643b | MEDIUM | 6.1 | The Contact Form Builder, Contact Widget plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in version… | — | wordfence | |
| 4fa3de8b-3d51-46b4-92ef-fbebadd4e708 | MEDIUM | 6.1 | The CopyLink plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.1.… | — | wordfence | |
| 4f9e0328-6d38-4512-a233-82e37950eb80 | MEDIUM | 6.1 | The GB Gallery Slideshow plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and… | — | wordfence | |
| 4f98d50a-51cb-479b-be4c-566a72f0f221 | < 0.7 |
MEDIUM | 6.1 | The supportflow plugin before 0.7 for WordPress has XSS via a ticket excerpt. | — | wordfence |
| 4f856b92-a090-4974-a256-d1022b10014a | < 1.9.0 |
MEDIUM | 6.1 | The Cool Flipbox β Shortcode & Gutenberg Block plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in… | — | wordfence |
| 4f7fa392-e192-40db-9275-6da668d5a493 | < 4.8 |
MEDIUM | 6.1 | The Team Rosters plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, … | — | wordfence |
| 4f7bc717-8b6a-41f2-9587-33b44d51996a | MEDIUM | 6.1 | The ZenphotoPress plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including,… | — | wordfence | |
| 4f5b048d-3a00-4337-8a85-97740449f1a5 | MEDIUM | 6.1 | The Formatted post plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and inclu… | — | wordfence | |
| 4f5919eb-ac74-4926-9ede-e651bb4463b2 | < 3.13 |
MEDIUM | 6.1 | The Atarim plugin for WordPress is vulnerable to Cross-Site Scripting via the new_task parameter in versions up to, and … | — | wordfence |
| 4f510772-d1f6-4751-bfff-addb51bf27c6 | MEDIUM | 6.1 | The WP tarteaucitron.js Self Hosted plugin for WordPress is running a vulnerable dependency (version 20210310 of tarteau… | — | wordfence | |
| 4f49eaf0-1273-41e8-9087-4d4ed978fce4 | < 1.2.2 |
MEDIUM | 6.1 | The Sharebar plugin for WordPress is vulnerable to Cross-Site Scripting in versions up to, and including, 1.2.1 due to i… | — | wordfence |
| 4f4934be-db95-4b4d-92df-f0d493f56f25 | MEDIUM | 6.1 | The QMean β WordPress Did You Mean and Search Suggestion Like Google plugin for WordPress is vulnerable to Reflected C… | — | wordfence | |
| 4f406c82-14e7-468b-8bba-400aefe687b5 | MEDIUM | 6.1 | The Plugin plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.0.9.… | — | wordfence | |
| 4f3a01fe-8c84-4219-98fe-14e4ac74b7f7 | < 2.13.5 |
MEDIUM | 6.1 | The Infility Global plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and includin… | — | wordfence |
EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.
Scan My Website →