Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.
40,117 vulnerabilities found (page 958 of 1605)
| CVE ID | Plugin / Theme | Severity | CVSS | Description | Fixed In | Source |
|---|---|---|---|---|---|---|
| 38191721-8d5d-4a13-8271-c7ca96c3f6b8 | < 2.2.9 |
MEDIUM | 6.1 | The Countdown, Coming Soon, Maintenance WordPress plugin before 2.2.9 does not sanitize and escape the post parameter be… | — | wordfence |
| 38145ad1-f441-40a4-9e92-6837cfeba656 | < 2.3.6 |
MEDIUM | 6.1 | The EazyDocs plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘edit_doc_one_page’ parameter… | — | wordfence |
| 3807d162-d62a-4370-b521-fba960a770ca | MEDIUM | 6.1 | The WP-HideThat plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1… | — | wordfence | |
| 38039171-f2cc-47d5-9b7b-d2c4a347a839 | MEDIUM | 6.1 | The Tiger theme for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 2.0 due … | — | wordfence | |
| 3802cbf7-6725-4f93-a178-2af02bb022a1 | < 3.7.30 |
MEDIUM | 6.1 | WordPress before 5.2.3 allows reflected XSS in the dashboard. | — | wordfence |
| 37f7edb2-4fc0-4785-a49d-6bae9aa57d42 | < 1.3 |
MEDIUM | 6.1 | Cross-site scripting (XSS) vulnerability in wp-live.php in the WP Live.php module 1.2.1 for WordPress allows remote atta… | — | wordfence |
| 37f47ce1-0657-414d-a491-99f2722a44f5 | < 1.3.25 |
MEDIUM | 6.1 | The BA Book Everything plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘date_from’ and … | — | wordfence |
| 37ea39bd-58c5-49f6-9956-8e0089e8192d | < 3.4.0 |
MEDIUM | 6.1 | The Official Integration for Billingo plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the us… | — | wordfence |
| 37e707ef-fe66-4c21-9c37-7b65fb7690db | MEDIUM | 6.1 | The Easy Google Analytics for WordPress plugin is vulnerable to Cross-Site Request Forgery in versions up to, and includ… | — | wordfence | |
| 37d9171d-4722-4ebc-a773-9fd497bc12cf | MEDIUM | 6.1 | The Social Share, Social Login and Social Comments Plugin – Super Socializer plugin for WordPress is vulnerable to Ref… | — | wordfence | |
| 37cc54a9-a780-42b5-b64d-c47470f17db7 | < 1.2.4 |
MEDIUM | 6.1 | The Artificial Intelligence theme before 1.2.4 for WordPress has XSS because Genericons HTML files are unnecessarily pla… | — | wordfence |
| 3798fb5d-f7d6-4a93-8908-c9b1f93bb05a | < 2.7.10 |
MEDIUM | 6.1 | The Ad Inserter WordPress plugin before 2.7.10, Ad Inserter Pro WordPress plugin before 2.7.10 do not sanitise and escap… | — | wordfence |
| 378bc737-6547-4dc2-8123-3a33d7d2e122 | MEDIUM | 6.1 | The Coronavirus (COVID-19) Outbreak Data Widgets plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in… | — | wordfence | |
| 377afb95-02d9-46b9-936d-3d58257dd928 | < 2.2.0 |
MEDIUM | 6.1 | The Deliver via Shipos for WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘d… | — | wordfence |
| 3779826a-90a4-4d6d-8387-2c8253985c64 | MEDIUM | 6.1 | The SW Plus plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and including, 2… | — | wordfence | |
| 37563f9c-658c-4806-9bd8-a8413e7934fb | < 1.0.2 |
MEDIUM | 6.1 | The Workio theme for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘filter-title’ parameter in v… | — | wordfence |
| 3742f2c5-55be-426c-8445-bf58eeebc74b | < 1.6.2 |
MEDIUM | 6.1 | Cross-site scripting (XSS) vulnerability in the Cakifo theme 1.x before 1.6.2 for WordPress allows remote authenticated … | — | wordfence |
| 3737d7a0-76d6-4292-aa31-6ee2cb0e9575 | < 2.2.0 |
MEDIUM | 6.1 | The YITH WooCommerce Wishlist plugin for WordPress is vulnerable to SQL Injection via the 'limit' variable in versions u… | — | wordfence |
| 372f4908-8796-4a52-8346-bd0eb1e41adc | < 4.0 |
MEDIUM | 6.1 | The tagDiv Composer plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘td_video_url’ para… | — | wordfence |
| 372d1ff2-b56f-43ea-b4e6-fa09ddbbb1a9 | MEDIUM | 6.1 | The Site Launcher plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and includ… | — | wordfence | |
| 370e816c-920a-4e53-a2f8-afe2806c9df3 | < 1.2.12 |
MEDIUM | 6.1 | The Fast Flow WordPress plugin is vulnerable to reflected Cross-Site scripting in versions up to, and including, 1.2.11,… | — | wordfence |
| 3708ce44-987f-4e73-b1cb-899349c8e0d4 | < 1.0.9 |
MEDIUM | 6.1 | The Connector to CiviCRM with CiviMcRestFace plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in ver… | — | wordfence |
| 3704b365-cbdf-4c74-9619-59f0a10e3c6a | MEDIUM | 6.1 | The Edit WooCommerce Templates plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘page’ p… | — | wordfence | |
| 36f4e51d-d613-4db6-8d79-d26398c3e5df | MEDIUM | 6.1 | Reflected XSS in wordpress plugin tidio-gallery v1.1 via galleryId parameter. | — | wordfence | |
| 36ef164e-33cc-41b1-8e28-d2af89739f04 | < 3.3.8.2 |
MEDIUM | 6.1 | The Watu Quiz for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'quiz_word_plural' parameter in vers… | — | wordfence |
EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.
Scan My Website →