Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.
40,117 vulnerabilities found (page 955 of 1605)
| CVE ID | Plugin / Theme | Severity | CVSS | Description | Fixed In | Source |
|---|---|---|---|---|---|---|
| 3ae9392a-591c-4be0-9f90-aa6ec81d3a10 | < 1.8.4.7 |
MEDIUM | 6.1 | The Gallery Plugin for WordPress – Envira Photo Gallery plugin for WordPress is vulnerable to Reflected Cross-Site Scr… | — | wordfence |
| 3adfbfcc-5d52-4a01-805d-c3273757aba1 | MEDIUM | 6.1 | The WP-Recall – Registration, Profile, Commerce & More plugin for WordPress is vulnerable to Reflected Cross-Site Scri… | — | wordfence | |
| 3ad2e495-5181-44a7-932f-520620146be7 | MEDIUM | 6.1 | The World Prayer Time plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and includ… | — | wordfence | |
| 3acc1464-18cf-4085-8cb4-946563d70b16 | < 2.8 |
MEDIUM | 6.1 | The WP Page Widget plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘taxonomy’ parameter… | — | wordfence |
| 3ac577f4-2e61-4b72-881e-6fbbfd268f7b | MEDIUM | 6.1 | The Elementor Forms Google Sheet Connector plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the … | — | wordfence | |
| 3abde27c-8234-4146-9e55-ea20b275ca48 | < 2.5.2 |
MEDIUM | 6.1 | The New User Approve plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and includi… | — | wordfence |
| 3aa73be6-0836-4540-8a80-e1da34c0ee0d | MEDIUM | 6.1 | The Shabat Keeper plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the $_SERVER['PHP_SELF'] para… | — | wordfence | |
| 3aa56fc7-8d48-4149-afa7-8f9885de0674 | < 1.4.2 |
MEDIUM | 6.1 | The WP Pipes plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘x1’ parameter in all vers… | — | wordfence |
| 3aa14f56-85b7-4f8d-bc62-a1e99977e510 | < 1.1.14 |
MEDIUM | 6.1 | The Travelpayouts: All Travel Brands in One Place plugin for WordPress is vulnerable to Reflected Cross-Site Scripting i… | — | wordfence |
| 3a92926f-c8d2-49c4-b50e-2544fd66fe01 | < 1.8.3 |
MEDIUM | 6.1 | The Amazon Affiliate Link Localizer plugin for WordPress is vulnerable to Cross-Site Scripting in versions up to, and in… | — | wordfence |
| 3a9045e5-ee8b-45f6-8e08-b1bf6b6f7159 | < 1.3.15 |
MEDIUM | 6.1 | The Free Booking Plugin for Hotels, Restaurants and Car Rentals – eaSYNC Booking plugin for WordPress is vulnerable to… | — | wordfence |
| 3a8998db-ffc2-40b2-a191-09380984adac | < 2.8.4 |
MEDIUM | 6.1 | The Social Media & Share Icons plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via an unknown param… | — | wordfence |
| 3a849ef2-ad0a-45ea-8827-9a7233b1ca30 | < 1.0.99 |
MEDIUM | 6.1 | The Booking for Appointments and Events Calendar – Amelia plugin for WordPress is vulnerable to Reflected Cross-Site S… | — | wordfence |
| 3a7afe2c-13ca-4df4-89c9-1544db016cdc | < 4.2 |
MEDIUM | 6.1 | The Export All URLs WordPress plugin before 4.2 does not sanitise and escape the CSV filename before outputting it back … | — | wordfence |
| 3a7aac7d-225f-45d5-86ac-183c56e76326 | < 5.4.31 |
MEDIUM | 6.1 | The Woffice theme for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 5.4.30… | — | wordfence |
| 3a6eac3b-823a-4a26-acb7-339357c10a07 | < 1.7.6 |
MEDIUM | 6.1 | The "Htaccess by BestWebSoft – WordPress Website Access Control Plugin" plugin for WordPress is vulnerable to Reflecte… | — | wordfence |
| 3a69bb27-dc93-4515-90e1-08a1fa5fdaa0 | < 2.0.9 |
MEDIUM | 6.1 | The Magee Shortcodes plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via several parameters in vers… | — | wordfence |
| 3a66d49d-eb3a-4ba3-bf2e-deeb7f5c197b | < 1.1.3 |
MEDIUM | 6.1 | The Analytics Cat plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including,… | — | wordfence |
| 3a5e8af3-fa65-4703-8f34-a48b102ec084 | MEDIUM | 6.1 | The ECT Home Page Products plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, a… | — | wordfence | |
| 3a503925-7fbf-42e8-9cee-604858c8ec0c | MEDIUM | 6.1 | Multiple cross-site scripting (XSS) vulnerabilities in forms/search.php in the WP-Business Directory (wp-ttisbdir) plugi… | — | wordfence | |
| 3a4f0c06-db88-4950-b1f5-b2aab480c974 | < 8.8.07.004 |
MEDIUM | 6.1 | The WP Photo Album Plus plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'wppa-tab' paramete… | — | wordfence |
| 3a48c501-6fa6-4767-b3f0-6b15e56807d9 | MEDIUM | 6.1 | The AppReview plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 0.2… | — | wordfence | |
| 3a468814-ecb7-4414-9472-6c2aaa5f5c2c | < 9.0.28 |
MEDIUM | 6.1 | The WP Go Maps (formerly WP Google Maps) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the REST … | — | wordfence |
| 3a2c96a1-bbab-41ed-aafd-6a6f569242f3 | < 2.19.2 |
MEDIUM | 6.1 | The Smash Balloon Social Post Feed WordPress plugin before 2.19.2 does not sanitise or escape the feedID POST parameter … | — | wordfence |
| 3a28f29e-7831-4a61-b5d1-d34d09b0e830 | < 1.0.61 |
MEDIUM | 6.1 | The Captcha.eu plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and including… | — | wordfence |
EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.
Scan My Website →