Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.
40,117 vulnerabilities found (page 972 of 1605)
| CVE ID | Plugin / Theme | Severity | CVSS | Description | Fixed In | Source |
|---|---|---|---|---|---|---|
| 28fd9f64-4451-46fd-bdeb-cc5a538ea563 | < 1.12.05 |
MEDIUM | 6.1 | The xili-tidy-tags plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'action' parameter in al… | — | wordfence |
| 28f77d5a-fc17-4e17-85b9-4e6f66dbf2c7 | < 2.1.20 |
MEDIUM | 6.1 | The GTM Server Side plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg… | — | wordfence |
| 28f08640-cd63-4f2a-a785-1956dc051991 | MEDIUM | 6.1 | Cross-site scripting (XSS) vulnerability in index.php in the Sirius 1.0 theme for WordPress allows remote attackers to i… | — | wordfence | |
| 28d8ebf9-2841-4a54-8537-959c43ca88e4 | < 2.6.4 |
MEDIUM | 6.1 | The Perfmatters plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 2… | — | wordfence |
| 28d41721-c538-4043-a411-3234ff1074bc | < 0.9.2 |
MEDIUM | 6.1 | The Send PDF for Contact Form 7 plugin for WordPress is vulnerable to Cross-Site Scripting in versions up to, and includ… | — | wordfence |
| 28c8abf2-09e2-43a2-8666-ca2a896bdbbe | < 1.6.8 |
MEDIUM | 6.1 | The Advanced Booking Calendar WordPress plugin before 1.6.8 does not sanitise the license error message when output in t… | — | wordfence |
| 28a9c2ba-7667-4601-8808-7258af69a432 | < 3.6.19 |
MEDIUM | 6.1 | The My auctions allegro plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and incl… | — | wordfence |
| 28928a78-24c2-44d2-a9e4-33c2f352d089 | < 1.3.8 |
MEDIUM | 6.1 | Themify WordPress plugin before 1.3.8 does not sanitise and escape the page parameter before outputting it back in an at… | — | wordfence |
| 2890a126-2752-4695-9eb6-a360c9bf69bb | MEDIUM | 6.1 | The TinyMCE Advanced qTranslate fix editor problems plugin for WordPress is vulnerable to Cross-Site Request Forgery in … | — | wordfence | |
| 288fdb71-1dae-4897-b5af-95c628fce288 | < 1.0.31 |
MEDIUM | 6.1 | The plugin in versions up to 1.0.30 does not sanitise or escape its tab parameter in the Settings page before outputting… | — | wordfence |
| 288db6ba-5d6c-448d-85c5-f9a19a9391c0 | MEDIUM | 6.1 | The Login Screen Manager plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and inc… | — | wordfence | |
| 2889ac63-6644-436d-9805-1efc9048d69c | MEDIUM | 6.1 | The School Management plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and includ… | — | wordfence | |
| 287d02ba-9cf0-446a-9393-036bd42b7aef | < 1.2 |
MEDIUM | 6.1 | The Tock Widget plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1… | — | wordfence |
| 286e52b4-2694-4f3b-9d1d-fd1ebf1d1e50 | < 2.1.0 |
MEDIUM | 6.1 | The Tiger Forms plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the use of PHP_SELF in versions… | — | wordfence |
| 28524702-3428-4fca-afe8-71b3f2dd983d | < 4.2.9 |
MEDIUM | 6.1 | The Contact Form by BestWebSoft plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘cntctfrm… | — | wordfence |
| 28456329-03f3-4c33-92f5-e4076aa15345 | < 1.5 |
MEDIUM | 6.1 | The Comment Reply Email plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and incl… | — | wordfence |
| 282ef0bb-4db5-4b07-9aad-b128e8fdb915 | MEDIUM | 6.1 | The User Email Verification for WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in vers… | — | wordfence | |
| 28267144-a709-4631-8925-69c6e0aca77c | < 1.6.1 |
MEDIUM | 6.1 | The Additional Custom Order Status for WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting … | — | wordfence |
| 2822114a-ffc2-43dd-bbf1-e4504aababfb | < 2.2.2 |
MEDIUM | 6.1 | WordPress before 2.2.2 allows remote attackers to redirect visitors to other websites and potentially obtain sensitive i… | — | wordfence |
| 281c49d3-078a-4fdc-9720-dac6b3a32892 | < 1.5.3 |
MEDIUM | 6.1 | The Shortlink by BestWebSoft plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘category’… | — | wordfence |
| 2809d55f-14f8-4916-800f-4d4fb9ee88c0 | MEDIUM | 6.1 | The WP Songbook WordPress plugin is vulnerable to Reflected Cross-Site Scripting via the url parameter found in the ~/in… | — | wordfence | |
| 28066511-a1e3-498d-a462-5e868334bfe1 | MEDIUM | 6.1 | The International Sms For Contact Form 7 Integration plugin for WordPress is vulnerable to Reflected Cross-Site Scriptin… | — | wordfence | |
| 2805267e-fd07-4bb2-b2e5-7c90c667097e | MEDIUM | 6.1 | The Simple Image Gallery WordPress plugin is vulnerable to Reflected Cross-Site Scripting via the msg parameter found in… | — | wordfence | |
| 27ec8f97-9b34-4737-bb45-37baf59598f1 | < 2.2.4.1 |
MEDIUM | 6.1 | Cross-site scripting vulnerability in Open Graph for Facebook, Google+ and Twitter Card Tags plugin prior to version 2.2… | — | wordfence |
| 27e0b9e8-b6b7-45fe-8c9e-5e49c4feccac | < 3.1.2 |
MEDIUM | 6.1 | The Sunshine Photo Cart plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and incl… | — | wordfence |
EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.
Scan My Website →