Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.
40,117 vulnerabilities found (page 937 of 1605)
| CVE ID | Plugin / Theme | Severity | CVSS | Description | Fixed In | Source |
|---|---|---|---|---|---|---|
| 4e54613a-24c7-4e2d-a14b-07912acfb69a | MEDIUM | 6.1 | Cross-site scripting (XSS) vulnerability in admin/admin_show_dialogs.php in the WP Consultant plugin 1.0 and earlier for… | — | wordfence | |
| 4e4dab1c-357f-440f-b3c7-598834a16599 | < 6.2.6 |
MEDIUM | 6.1 | The wp-file-download plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and inc… | — | wordfence |
| 4e3cb44c-ed14-42d5-9e26-0904978bd2a4 | MEDIUM | 6.1 | The Media Category Library plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, a… | — | wordfence | |
| 4e383235-8f61-46f2-bd54-cc41e3ec189e | < 1.5.4 |
MEDIUM | 6.1 | The MailerLite WordPress plugin before 1.5.4 does not sanitise and escape a parameter before outputting it back in the p… | — | wordfence |
| 4e376fce-48a7-4b33-8a5a-9402625d24c0 | MEDIUM | 6.1 | The MapFig Studio plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including,… | — | wordfence | |
| 4e30c4fd-91fd-4f05-85fa-73e445de3c6e | < 5.9.12.30 |
MEDIUM | 6.1 | The link-library plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘'successimportcount’ … | — | wordfence |
| 4e262772-06b7-4490-a342-5b1abc421b67 | MEDIUM | 6.1 | The BMI BMR Calculator WordPress plugin through 1.3 does not sanitise and escape arbitrary POST data before outputting i… | — | wordfence | |
| 4e054485-71cc-47c2-9bd6-4f060dc76738 | MEDIUM | 6.1 | The WPB Show Core plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘fileList’ parameter … | — | wordfence | |
| 4e04b161-3cd0-454d-869c-56f42bd8afb0 | < 22.6 |
MEDIUM | 6.1 | The Yoast SEO plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via URLs in all versions up to, and i… | — | wordfence |
| 4e018ce5-ec78-42a9-ab70-4fb3eaa347b9 | MEDIUM | 6.1 | The pushBIZ – Push Notification plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions u… | — | wordfence | |
| 4dee07a1-9f48-4e8f-89dc-99270f55f17c | < 2.3 |
MEDIUM | 6.1 | The EnvíaloSimple: Email Marketing y Newsletters plugin for WordPress is vulnerable to Reflected Cross-Site Scripting i… | — | wordfence |
| 4deca6fe-561e-41a9-aaf6-308fde0b0d1b | MEDIUM | 6.1 | The CF7 Spreadsheets plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and includi… | — | wordfence | |
| 4dea175f-3728-4aee-9296-1bb595c83925 | < 5 alpha 3 |
MEDIUM | 6.1 | Multiple cross-site scripting (XSS) vulnerabilities in ui_stats.php in the bSuite plugin before 5 alpha 3 for WordPress … | — | wordfence |
| 4db5d4ec-0f49-40fb-97b3-f0146cbbbe52 | < 3.1.8 |
MEDIUM | 6.1 | The WP-Members plugin for WordPress is vulnerable to Cross-Site Scripting in versions before 3.1.8 due to insufficient i… | — | wordfence |
| 4d902dfe-f16d-4795-9fcf-ee454b3d8c56 | < 9.7.1 |
MEDIUM | 6.1 | The Image Hover Effects Ultimate (Image Gallery, Effects, Lightbox, Comparison or Magnifier) WordPress plugin before 9.7… | — | wordfence |
| 4d8056cb-58e5-468b-9316-c862c6d8c930 | < 1.0.2 |
MEDIUM | 6.1 | The WooFramework Tweaks plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via a URL in versions up to… | — | wordfence |
| 4d7f4d17-8318-4ab3-b4a2-81d7a017c397 | < 3.1.42 |
MEDIUM | 6.1 | The WP Event Manager – Events Calendar, Registrations, Sell Tickets with WooCommerce plugin for WordPress is vulnerabl… | — | wordfence |
| 4d63c11c-edf8-4b37-9701-e21d5f7b5a9b | MEDIUM | 6.1 | The Google Map With Fancybox plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to,… | — | wordfence | |
| 4d5ed607-4ab4-4e98-975b-e3043014d847 | MEDIUM | 6.1 | The Site PIN plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 1.3 … | — | wordfence | |
| 4d5a7f60-0850-4322-a7d8-8e5c144efe51 | < 5.4.18 |
MEDIUM | 6.1 | The WP Photo Album Plus plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘walbum’ parame… | — | wordfence |
| 4d4ce8ce-2630-4f8b-9438-38c6b7b0caa9 | < 3.9 |
MEDIUM | 6.1 | The BSK Forms Blacklist plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and incl… | — | wordfence |
| 4d3e6c49-e686-463c-bc50-b0ce94702075 | < 1.1.0 |
MEDIUM | 6.1 | Authorize.net Add-on for iThemes Exchange before 1.1.0 for WordPress has XSS via add_query_arg() and remove_query_arg(). | — | wordfence |
| 4d32eae6-f49f-403b-b295-c72b1486c71c | < 2.5.2 |
MEDIUM | 6.1 | The Greenmart theme for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'callback' parameter in the 'a… | — | wordfence |
| 4d2b8bc2-68c2-40aa-b8b0-a0584549f303 | < 3.4 |
MEDIUM | 6.1 | The Secure HTML5 Video Player plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the flowplayer-3.… | — | wordfence |
| 4d1e9de3-da94-4f90-b72a-b38d5d131246 | < 1.1.7 |
MEDIUM | 6.1 | Cross-site scripting (XSS) vulnerability in the Floating Social Bar plugin before 1.1.7 for WordPress allows remote atta… | — | wordfence |
EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.
Scan My Website →