Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.
40,117 vulnerabilities found (page 949 of 1605)
| CVE ID | Plugin / Theme | Severity | CVSS | Description | Fixed In | Source |
|---|---|---|---|---|---|---|
| 40c134ed-c4b6-46f9-ba2a-9c3436d6accd | MEDIUM | 6.1 | The Sticky Social Bar plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and includ… | — | wordfence | |
| 40b5d7e4-97a0-4a1c-8000-f2cfd1e751a3 | < 0.34 |
MEDIUM | 6.1 | Multiple cross-site scripting (XSS) vulnerabilities in the 2 Click Social Media Buttons plugin before 0.34 for WordPress… | — | wordfence |
| 409f3a27-e94a-4298-88f4-69f69fb56ce8 | MEDIUM | 6.1 | The Cart66 Cloud plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, … | — | wordfence | |
| 4096367c-3141-4e75-97a8-6f35d15d229d | MEDIUM | 6.1 | The Search engine keywords highlighter plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions … | — | wordfence | |
| 408e14e7-5034-4f56-90b1-76f5637938df | MEDIUM | 6.1 | The AB Google Map Travel (AB-MAP) plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to… | — | wordfence | |
| 40766e17-8134-44ed-888f-f725848baf00 | < 1.0.1 |
MEDIUM | 6.1 | The Notify Odoo plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1… | — | wordfence |
| 406fe34a-0991-4653-9924-b6586091d7df | < 3.4.6 |
MEDIUM | 6.1 | Cross-site scripting vulnerability in WP All Import plugin prior to version 3.4.6 for WordPress allows an attacker to in… | — | wordfence |
| 4052adde-8d3f-409c-8cd3-a0170206c3fe | MEDIUM | 6.1 | The Bet WC 2018 Russia plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and inclu… | — | wordfence | |
| 404aabc5-1ff4-492d-8cab-4b83eb68157a | < 4.1.1 |
MEDIUM | 6.1 | The WP All Import Pro plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via an unknown parameter in v… | — | wordfence |
| 40494f1e-d5df-4ed0-b107-aa52cb28bc0e | < 5.4.5 |
MEDIUM | 6.1 | The Jannah WordPress theme before 5.4.5 did not properly sanitize the 'query' POST parameter in its tie_ajax_search AJAX… | — | wordfence |
| 40371178-b04f-4360-8805-268028629755 | MEDIUM | 6.1 | The Simple Redirect plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and includin… | — | wordfence | |
| 401f5d57-ce3d-46c1-bfa9-c8fab99a7e31 | < 2.1.7 |
MEDIUM | 6.1 | The Wysija Newsletters plugin for WordPress is vulnerable to Cross-Site Scripting via the swfupload.swf applet in versio… | — | wordfence |
| 401e2201-9c82-4f21-aa71-b68dc84c93f4 | MEDIUM | 6.1 | The Nature FlipBook WordPress Plugin plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all version… | — | wordfence | |
| 401da94d-6538-478a-bfcd-f9c91f84a3c6 | MEDIUM | 6.1 | The Simple Finance Calculator plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, an… | — | wordfence | |
| 4013a22a-701b-43ef-90fb-f8eddf65acf2 | < 3.3.1 |
MEDIUM | 6.1 | The EELV Newsletter plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'email' parameter in ve… | — | wordfence |
| 400d31ba-2cef-4558-8983-6689f7e4b93c | < 8.0.6 |
MEDIUM | 6.1 | The JNews WordPress theme before 8.0.6 did not sanitise the cat_id parameter in the POST request /?ajax-request=jnews (w… | — | wordfence |
| 4007814b-7e01-4188-8a42-9564444af95f | < 2.1.3 |
MEDIUM | 6.1 | The Easy Digital Downloads (EDD) Stripe extension for WordPress, as used with EDD 1.8.x before 1.8.7, 1.9.x before 1.9.1… | — | wordfence |
| 3fffe8f2-9241-4a4f-8e8a-647a9e41d769 | MEDIUM | 6.1 | The VKontakte Wall Post plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and includin… | — | wordfence | |
| 3ffd63ca-5ea4-451c-aa97-092a754ca79f | < 2.7.3 |
MEDIUM | 6.1 | The archive-tainacan-collection theme for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of ad… | — | wordfence |
| 3fe91c7e-e4d4-4308-a8ca-22d7985ddb61 | < 2.6.2 |
MEDIUM | 6.1 | The Payflex Payment Gateway plugin for WordPress is vulnerable to Open Redirect in all versions up to, and including, 2.… | — | wordfence |
| 3fddf493-246b-4e39-99a7-503c9fab3652 | MEDIUM | 6.1 | The WP Simple Slideshow plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and incl… | — | wordfence | |
| 3fc962d7-2301-436e-ac1f-6309cd958ecd | MEDIUM | 6.1 | The LambertGroup - AllInOne - Content Slider plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in ver… | — | wordfence | |
| 3fc752bb-3f1d-4106-9df1-361564905a55 | MEDIUM | 6.1 | The Sandbox plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'debug' parameter in all versio… | — | wordfence | |
| 3fc04d8a-f551-4e91-b920-f2a8efcf61de | < 2.4.30 |
MEDIUM | 6.1 | The FooGallery β Responsive Photo Gallery, Image Viewer, Justified, Masonry & Carousel plugin for WordPress is vulnera… | — | wordfence |
| 3fb46633-50c5-4adf-8097-50e6aecefb5d | MEDIUM | 6.1 | The Woocommerce Line Notify plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, … | — | wordfence |
EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.
Scan My Website →