Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.
40,117 vulnerabilities found (page 975 of 1605)
| CVE ID | Plugin / Theme | Severity | CVSS | Description | Fixed In | Source |
|---|---|---|---|---|---|---|
| 25a9fd76-15aa-43f9-bb11-9825b847a4e3 | < 2.3.1 |
MEDIUM | 6.1 | The Contact Form 7 β PayPal & Stripe Add-on plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in ve… | — | wordfence |
| 259f9ea3-ac24-4bea-8d0d-c635a68d9c98 | < 2.35.20 |
MEDIUM | 6.1 | The 404 Solution plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via URLs in all versions up to, an… | — | wordfence |
| 259f2e45-23df-442a-abb5-d37aadf7f045 | < 4.2.6 |
MEDIUM | 6.1 | The Contact Form With Shortcode plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up … | — | wordfence |
| 2598ae85-5e91-47e6-b3f5-0d977fe80dd5 | < 2021.9 |
MEDIUM | 6.1 | The Stop Spammers WordPress plugin before 2021.9 did not escape user input when blocking requests (such as matching a sp… | — | wordfence |
| 2598076e-85d6-40a7-a975-36c3f7320c4f | MEDIUM | 6.1 | The WS Audio Player plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and includin… | — | wordfence | |
| 25838724-42b6-41e1-9546-78e6da2e95e1 | < 2.1.8 |
MEDIUM | 6.1 | The slider import search feature and tab parameter of the Post Grid WordPress plugin before 2.1.8 settings are not prope… | — | wordfence |
| 257aba03-bb41-4798-b62c-b51310d70264 | < 0.8.21 |
MEDIUM | 6.1 | The Chatbot with IBM Watson plugin before 0.8.21 for WordPress has a DOM-based XSS vulnerability that is executed when a… | — | wordfence |
| 2578a863-4129-4f56-8b18-65b2d2b972e3 | < 4.9.9.8 |
MEDIUM | 6.1 | The Newsletters plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the "to" parameter in all versi… | — | wordfence |
| 25762427-8d31-4fef-8b93-1065d15cd918 | < 2.1.13 |
MEDIUM | 6.1 | The Slideshow plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via several parameters in versions up… | — | wordfence |
| 256be233-e950-4a93-8153-83a297b0d4ca | MEDIUM | 6.1 | The Block Controller plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and includi… | — | wordfence | |
| 2568d209-a89d-495d-adc1-c44aef75d337 | MEDIUM | 6.1 | The Push Envoy Notifications plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to,… | — | wordfence | |
| 255f0fc4-5023-4039-9418-2f28363dbfc4 | < 0.9.56 |
MEDIUM | 6.1 | The Migration, Backup, Staging β WPvivid plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the … | — | wordfence |
| 255e7322-641a-4b05-ae2d-0ec90d133e8e | < 1.1.5.6 |
MEDIUM | 6.1 | The Hostel plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 1.1.5.… | — | wordfence |
| 255a50f0-0213-4de5-92f1-d71dbb5caeff | < 3.2.2 |
MEDIUM | 6.1 | The Nimble Page Builder WordPress plugin before 3.2.2 does not sanitise and escape the preview-level-guid parameter befo… | — | wordfence |
| 25595c99-87e2-408d-9931-c864af1cedd8 | MEDIUM | 6.1 | The MHR-Custom-Anti-Copy plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and inc… | — | wordfence | |
| 2549394c-2f2f-4d90-a11c-ba6f28c3ea39 | MEDIUM | 6.1 | The Video Blogster Lite plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and incl… | — | wordfence | |
| 2546ea7e-133a-44b8-9cdb-1b345a45d583 | < 2.1.9 |
MEDIUM | 6.1 | The WP Crowdfunding plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 's' parameter in all ve… | — | wordfence |
| 253dcecb-b88d-423c-8e74-1d59581e2893 | < 5.9 |
MEDIUM | 6.1 | The Library Bookshelves plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query… | — | wordfence |
| 252c616f-2198-43d7-8767-3704f192a391 | < 25.0513 |
MEDIUM | 6.1 | The ReDi Restaurant Reservation plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, … | — | wordfence |
| 25250755-0d22-44f4-8930-3a60efd61e32 | MEDIUM | 6.1 | The Truemag theme 2016 Q2 for WordPress has XSS via the s parameter. | — | wordfence | |
| 2523f85d-be90-4334-b8d5-8021ec05283d | < 3.2.9 |
MEDIUM | 6.1 | The Poll Maker WordPress plugin is vulnerable to Reflected Cross-Site Scripting via the mcount parameter found in the ~/… | — | wordfence |
| 2514c343-3a34-4580-abe8-fc0192408860 | MEDIUM | 6.1 | The CloudFlare(R) Cache Purge plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to… | — | wordfence | |
| 250d1bea-793d-4c13-976b-bfc3ff7d9160 | MEDIUM | 6.1 | The Advanced Search by My Solr Server plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions u… | — | wordfence | |
| 24f2eafc-c8eb-4d78-af5e-1a589d7e4d21 | < 5.3.2.1 |
MEDIUM | 6.1 | The RegistrationMagic β User Registration Plugin with Custom Registration Forms plugin for WordPress is vulnerable to … | — | wordfence |
| 24e8513c-f8d4-4e32-8212-191f5b5893b5 | < 0.1.2 |
MEDIUM | 6.1 | The Contact Form 7 Captcha WordPress plugin before 0.1.2 does not escape the $_SERVER['REQUEST_URI'] parameter before ou… | — | wordfence |
EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.
Scan My Website →