Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.
40,117 vulnerabilities found (page 943 of 1605)
| CVE ID | Plugin / Theme | Severity | CVSS | Description | Fixed In | Source |
|---|---|---|---|---|---|---|
| 472b523f-b987-4da0-8533-54ae076d7a6b | MEDIUM | 6.1 | The Email Artillery (MASS EMAIL) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Cross-Site Reques… | — | wordfence | |
| 47122866-8e40-42bc-84ed-60fc81247320 | MEDIUM | 6.1 | The Advanced Schedule Posts plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via an unknown paramete… | — | wordfence | |
| 46fd4e5d-e1d7-4de6-ae24-66e260a1b288 | < 1.0.4.3 |
MEDIUM | 6.1 | The TableOn plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 1.0.4… | — | wordfence |
| 46f5d1fa-dba7-4882-be29-39dc281d7278 | < 2.1.9 |
MEDIUM | 6.1 | The CodeBard's Patron Button and Widgets for Patreon plugin for WordPress is vulnerable to Reflected Cross-Site Scriptin… | — | wordfence |
| 46e2693a-809f-43f9-b189-35a0c73bf34e | MEDIUM | 6.1 | The search feature of the Mediumish WordPress theme through 1.0.60 does not properly sanitise it's 's' GET parameter bef… | — | wordfence | |
| 46c9dae7-d811-4b59-94c1-71a83652a14d | < 3.1.9 |
MEDIUM | 6.1 | The Traveler theme for WordPress is vulnerable to Reflected Cross-Site Scripting via multiple parameters in all versions… | — | wordfence |
| 46b9ca33-e140-48de-88bc-3dc1dc338c70 | MEDIUM | 6.1 | The WP Post Category Notifications plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions … | — | wordfence | |
| 46a16b7b-6de4-49a6-83e3-309f8ab43505 | < 1.3.9 |
MEDIUM | 6.1 | search.php in the Nova Lite theme before 1.3.9 for WordPress allows Reflected XSS. | — | wordfence |
| 46a022ff-7ec8-48bc-b0ae-8e925ea3f361 | MEDIUM | 6.1 | The Magic Post Voice WordPress plugin is vulnerable to Reflected Cross-Site Scripting via the ids parameter found in the… | — | wordfence | |
| 467e0946-cfbb-4ea3-b2d9-db21d0f182cd | < 1.3.5 |
MEDIUM | 6.1 | PageLayer before 1.3.5 allows reflected XSS via the font-size parameter. | — | wordfence |
| 4671556c-d902-4294-9e25-47e3d0e2ca98 | < 0.45.16 |
MEDIUM | 6.1 | The Sermon Browser plugin for WordPress is vulnerable to multiple Cross-Site Scripting in versions up to, and including,… | — | wordfence |
| 466d6087-1e4d-4010-b3c7-87e9e2d64f06 | < 1.2.7 |
MEDIUM | 6.1 | The Christmas Greetings plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the code parameter in a… | — | wordfence |
| 466171e7-575d-4fc1-8005-8704904b7725 | < 12.4.0 |
MEDIUM | 6.1 | The Order Delivery Date for WP e-Commerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the '… | — | wordfence |
| 464fda21-5efe-4565-9b21-85d6c458a6a1 | MEDIUM | 6.1 | The Dooodl plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 2.3.0 … | — | wordfence | |
| 463fd745-92ea-4e55-b470-a5f08884169f | < 1.1.47 |
MEDIUM | 6.1 | The Backup Guard plugin before 1.1.47 for WordPress has multiple XSS issues. | — | wordfence |
| 463c11ba-f307-4ab5-8de7-09f3a113cddd | < 2.8.1 |
MEDIUM | 6.1 | The Brizy Pro plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 2.8… | — | wordfence |
| 462ea9c3-ed33-46f2-8d60-ba024f369561 | MEDIUM | 6.1 | The LinkLaunder SEO plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and includin… | — | wordfence | |
| 4625d217-99d4-47d8-b093-fe55a3018348 | < 2.21 |
MEDIUM | 6.1 | The Sticky Menu & Sticky Header plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the tab paramet… | — | wordfence |
| 4618c39d-219e-4fc3-be98-15303bc8483f | MEDIUM | 6.1 | The WP Ajax Contact Form plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'eid' parameter in… | — | wordfence | |
| 45f581dc-d424-4cda-aa03-016e9b5ee1e5 | MEDIUM | 6.1 | The OSD Subscribe WordPress plugin is vulnerable to Reflected Cross-Site Scripting via the osd_subscribe_message paramet… | — | wordfence | |
| 45f3568c-b6d9-4d00-a8cd-571443d80fd3 | < 2.44 |
MEDIUM | 6.1 | The Memory Usage, Memory Limit, PHP and Server Memory Health Check plugin for WordPress is vulnerable to Stored Cross-Si… | — | wordfence |
| 45ee8b10-6758-45c8-835e-197ad6a9284a | MEDIUM | 6.1 | The Post Carousel & Slider plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and i… | — | wordfence | |
| 45dd22d4-9a51-4569-a756-1f1a5f8626c1 | < 1.1.21 |
MEDIUM | 6.1 | The WordPress Affiliates Plugin β SliceWP Affiliates plugin for WordPress is vulnerable to Reflected Cross-Site Script… | — | wordfence |
| 45d5a677-9b8b-4258-9cfb-101b0f0e6f6f | < 1.82.6 |
MEDIUM | 6.1 | The Advanced Form Integration β Connect WooCommerce and Contact Form 7 to Google Sheets and other platforms plugin for… | — | wordfence |
| 45d3cff1-3a86-4b79-bf43-1623d41ac821 | < 3.4.1 |
MEDIUM | 6.1 | The total-security plugin before 3.4.1 for WordPress has XSS via several parameters. | — | wordfence |
EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.
Scan My Website →