Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.
40,117 vulnerabilities found (page 948 of 1605)
| CVE ID | Plugin / Theme | Severity | CVSS | Description | Fixed In | Source |
|---|---|---|---|---|---|---|
| 41fadee9-ced6-4743-898f-d02d0b6f7f39 | < 5.8.0 |
MEDIUM | 6.1 | The wProject theme for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to 5.8.0 due to insuffic… | — | wordfence |
| 41f8b229-dada-4460-b394-04502f62a75f | < 2.1.3 |
MEDIUM | 6.1 | The Hesabfa Accounting plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and inclu… | — | wordfence |
| 41ef545a-7de1-406c-8686-57216e697a1b | < 5.4 |
MEDIUM | 6.1 | The tagDiv Composer plugin for WordPress, used by the Newspaper theme, is vulnerable to Reflected Cross-Site Scripting v… | — | wordfence |
| 41edf49a-18a2-4cf0-b498-738e77287b90 | < 3.9.2 |
MEDIUM | 6.1 | The EmbedPress – Embed PDF, YouTube, Google Docs, Vimeo, Wistia Videos, Audios, Maps & Any Documents in Gutenberg & El… | — | wordfence |
| 41c2edae-9788-47ad-bf0b-aa944893c4e2 | < 4.14.3 |
MEDIUM | 6.1 | The GiveWP – Donation Plugin and Fundraising Platform plugin for WordPress is vulnerable to Reflected Cross-Site Scrip… | — | wordfence |
| 41bbb772-9a2c-4c69-bdac-a5ce4f50d3ec | MEDIUM | 6.1 | The WP Stacker plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.… | — | wordfence | |
| 419df0c4-1e78-47da-b28d-5ab1cb66729a | < 1.3.6 |
MEDIUM | 6.1 | The Maps by BestWebSoft plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and inc… | — | wordfence |
| 4197dd30-bfd8-4d6c-80f5-b13e3844adf8 | < 1.2.11 |
MEDIUM | 6.1 | The Favicon Rotator plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and incl… | — | wordfence |
| 4196b8d1-23a7-4b90-8e6b-f51849d44f9c | MEDIUM | 6.1 | The Featured Posts Scroll plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and in… | — | wordfence | |
| 4187f559-87ba-46ab-9b45-7a36dd98d71d | < 2.2 |
MEDIUM | 6.1 | Cross-site scripting (XSS) vulnerability in js/wp-seo-metabox.js in the WordPress SEO by Yoast plugin before 2.2 for Wor… | — | wordfence |
| 4186fe8d-ca09-4b82-9500-7b16bd10b044 | < 4.1.0 |
MEDIUM | 6.1 | The WP MAPS – Easiest & Most Advanced WordPress Plugin for Google Maps plugin for WordPress is vulnerable to Reflected… | — | wordfence |
| 4186a609-84f1-4852-8ed9-e8ba6263b635 | < 1.6.2 |
MEDIUM | 6.1 | The Robokassa payment gateway for Woocommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in ve… | — | wordfence |
| 417ff4fd-e514-4366-b9a6-c04d7434eac1 | MEDIUM | 6.1 | The AMP+ Plus plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and including,… | — | wordfence | |
| 417fb507-a414-4bc2-ab01-d6f2fc554350 | MEDIUM | 6.1 | The Custom Admin-Bar Favorites plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'menuObject'… | — | wordfence | |
| 416fc00d-2e72-41aa-9023-0c098ca32192 | < 3.0.4.1 |
MEDIUM | 6.1 | Cross-site scripting (XSS) vulnerability in login-with-ajax.php in the Login With Ajax (aka login-with-ajax) plugin befo… | — | wordfence |
| 4148b37e-c5dd-43a1-aecf-085ce4fb2473 | < 2.4.0 |
MEDIUM | 6.1 | The Portfolio by BestWebSoft plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘category’… | — | wordfence |
| 414013e9-5baa-4f4f-bf67-f0e821ece807 | < 5.7.0 |
MEDIUM | 6.1 | … | — | wordfence |
| 41307a48-d49d-402f-bd3f-96b99afe6a42 | < 2.4.2 |
MEDIUM | 6.1 | A Cross-site scripting (XSS) vulnerability in /inc/class-search.php in the Sell Media plugin v2.4.1 for WordPress allows… | — | wordfence |
| 41219c9d-a10d-4006-9edc-1387dfdc8b8d | < 2.6 |
MEDIUM | 6.1 | The yolink Search for WordPress plugin for WordPress is vulnerable to Cross-Site Scripting via the 's' parameter in vers… | — | wordfence |
| 410cc5f0-265a-46c1-a334-115142318d10 | MEDIUM | 6.1 | The Hot Linked Image Cacher plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via an several paramete… | — | wordfence | |
| 410ae0f1-a4ed-4631-9f80-86b7a403ce0d | < 1.7.6 |
MEDIUM | 6.1 | The Loginizer plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘name’ parameter in versi… | — | wordfence |
| 40f79195-23e7-4091-9dcb-8b787f0606f4 | < 0.8.5 |
MEDIUM | 6.1 | The GiveWP – Donation Plugin and Fundraising Platform plugin for WordPress is vulnerable to Cross-Site Scripting in ve… | — | wordfence |
| 40ec1b62-5eff-4a93-9730-9a5602b7e00f | < 1.7 |
MEDIUM | 6.1 | The Reservation plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 1… | — | wordfence |
| 40dc5db4-0907-48bf-a483-0da40589107d | < 1.4 |
MEDIUM | 6.1 | The LeadBoxer plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and including,… | — | wordfence |
| 40c20b9d-9a7d-46ca-81d1-c58150dae2cf | < 2.4.2 |
MEDIUM | 6.1 | The Discount Rules for WooCommerce WordPress plugin before 2.4.2 does not escape a parameter before outputting it back i… | — | wordfence |
EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.
Scan My Website →