Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.
40,117 vulnerabilities found (page 974 of 1605)
| CVE ID | Plugin / Theme | Severity | CVSS | Description | Fixed In | Source |
|---|---|---|---|---|---|---|
| 26c75a0a-8590-4ac7-814e-29e0c2d0822e | MEDIUM | 6.1 | The Custom Post Type and Taxonomy GUI Manager for WordPress is vulnerable to Cross-Site Request Forgery in versions up t… | — | wordfence | |
| 26ab8551-ec47-40ab-8beb-2625cc20e735 | MEDIUM | 6.1 | The Homey theme for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 2.4.5 du… | — | wordfence | |
| 26a2a20e-f200-4cb1-aa15-db12c86dd351 | MEDIUM | 6.1 | The FS Product Inquiry plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and incl… | — | wordfence | |
| 269e3b47-3775-41c1-9ed1-70c4177cbe8b | < 0.52 |
MEDIUM | 6.1 | The WP Log Action plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'log_time_start' and 'log… | — | wordfence |
| 2694747e-9423-475c-a3a8-d0afed9758ee | MEDIUM | 6.1 | The MediCenter - Health Medical Clinic WordPress Theme theme for WordPress is vulnerable to Reflected Cross-Site Scripti… | — | wordfence | |
| 2678d2c6-055e-462e-99da-bdc81bcc3662 | < 2.3.0 |
MEDIUM | 6.1 | The Affiliate Power – Sales Tracking for Affiliate Marketers plugin for WordPress is vulnerable to Reflected Cross-Sit… | — | wordfence |
| 26766830-c772-46a3-a045-7bfbb530b50a | < 1.5.13 |
MEDIUM | 6.1 | The Gallery Manager plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘delete’ parameter … | — | wordfence |
| 26753b92-3ec5-4b65-8fc7-2d6488f12974 | < 3.7.14 |
MEDIUM | 6.1 | Cross-site scripting (XSS) vulnerability in plupload.flash.swf in Plupload before 2.1.9, as used in WordPress before 4.5… | — | wordfence |
| 2668ad2e-d7ae-47f2-90b1-5f9c31c8fee2 | MEDIUM | 6.1 | Multiple themes for WordPress by Themify Themes are vulnerable to Reflected Cross-Site Scripting in various versions due… | — | wordfence | |
| 26624f19-c943-417a-abb2-c05646b192cf | MEDIUM | 6.1 | The Parsian Bank Gateway for Woocommerce WordPress plugin is vulnerable to Reflected Cross-Site Scripting via and parame… | — | wordfence | |
| 262b5326-a5e6-4063-a345-59dedd14c3c2 | MEDIUM | 6.1 | The Viable blog theme for WordPress is vulnerable to Cross-Site Scripting in versions up to, and including, 1.1.4 due to… | — | wordfence | |
| 2628b02e-5685-4e25-a786-4542ecbe874a | < 2.0.0 |
MEDIUM | 6.1 | The Gallery – Image and Video Gallery with Thumbnails plugin for WordPress is vulnerable to Reflected Cross-Site Scrip… | — | wordfence |
| 2627ac2b-25a8-480d-ac83-ee0ca323b3a1 | < 1.0.18 |
MEDIUM | 6.1 | The Team Circle Image Slider With Lightbox plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the … | — | wordfence |
| 261b5905-9194-40d3-99cb-1c7a832218dc | < 0.6.0.7 |
MEDIUM | 6.1 | The WP Accessibility Helper (WAH) WordPress plugin before 0.6.0.7 does not sanitise and escape the wahi parameter before… | — | wordfence |
| 2614ca26-6efc-49f5-8cee-5b078721acc1 | < 1.3.8.1 |
MEDIUM | 6.1 | The JetBlocks for Elementor plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and … | — | wordfence |
| 2608f894-88ed-4f34-a382-8eab7eaab2e7 | < 7.5.4 |
MEDIUM | 6.1 | The Visual CSS Style Editor WordPress plugin before 7.5.4 does not sanitise and escape the wyp_page_type parameter befor… | — | wordfence |
| 25e4ed00-a9f2-402f-8a46-3cb911ab5497 | < 1.5.3 |
MEDIUM | 6.1 | The Loan Comparison plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via a shortcode, in versions up… | — | wordfence |
| 25dfa483-26c6-43d1-9a24-9ea245b54f4c | MEDIUM | 6.1 | The Like DisLike Voting plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the `$_SERVER['PHP_SELF… | — | wordfence | |
| 25deb040-1338-40bd-b83e-be3a302e635c | MEDIUM | 6.1 | The While Loading plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including,… | — | wordfence | |
| 25de953d-e8c4-4ac7-ae6c-d8262bb083cd | < 5.3.3 |
MEDIUM | 6.1 | The Slimstat Analytics plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and inclu… | — | wordfence |
| 25cde35e-ba76-4651-8828-71ddd4c8a164 | < 12 |
MEDIUM | 6.1 | The Newspaper theme for WordPress is vulnerable to Reflected Cross-Site Scripting via an AJAX action in versions up to, … | — | wordfence |
| 25c44a00-da56-41f8-bd4f-c15bede6da58 | < 4.8.3 |
MEDIUM | 6.1 | The email-users plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘page’ parameter in ver… | — | wordfence |
| 25ba4be3-0bcd-41ff-8a7a-fd6ae848afb8 | MEDIUM | 6.1 | Multiple cross-site scripting (XSS) vulnerabilities in xencarousel-admin.js.php in the XEN Carousel plugin 0.12.2 and ea… | — | wordfence | |
| 25b32ad8-db0f-4391-a644-2759e35824ff | MEDIUM | 6.1 | The Naver Syndication V2 plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and inc… | — | wordfence | |
| 25b13322-d305-45db-8ac7-20762398dc21 | < 2.4.6 |
MEDIUM | 6.1 | The Update Image Tag Alt Attribute plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via 'posts_index… | — | wordfence |
EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.
Scan My Website →