Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.
40,117 vulnerabilities found (page 977 of 1605)
| CVE ID | Plugin / Theme | Severity | CVSS | Description | Fixed In | Source |
|---|---|---|---|---|---|---|
| 23518a21-7b76-4edb-9a35-b6f623ed50a7 | < 3.4.7 |
MEDIUM | 6.1 | The Gutenverse plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 's' parameter in all version… | — | wordfence |
| 234df0e5-d1be-4354-8bfc-761bed1e9aa9 | < 2.7.5 |
MEDIUM | 6.1 | The Gravity Forms plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via URLs in versions up to, and i… | — | wordfence |
| 234a847b-3ffa-4c5c-9bba-39df227de0bc | < 1.9.13 |
MEDIUM | 6.1 | The Tutor LMS plugin for WordPress is vulnerable to reflected Cross-Site Scripting in versions up to, and including 1.9.… | — | wordfence |
| 2345c972-9fd4-4709-8bde-315ab54f60e2 | < 4.10.6 |
MEDIUM | 6.1 | The Contact Form and Calls To Action by vcita plugin for WordPress is vulnerable to Cross-Site Request Forgery in versio… | — | wordfence |
| 233df260-be3f-4d4b-9af8-a31a3577df1a | < 2.2 |
MEDIUM | 6.1 | The Catch Duplicate Switcher plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to,… | — | wordfence |
| 2339c392-49bc-4744-b82a-d40f3bb4a81e | < 1.1.10 |
MEDIUM | 6.1 | Etoile Web Design Ultimate Appointment Booking & Scheduling WordPress Plugin v1.1.9 and lower does not sanitize the valu… | — | wordfence |
| 23311ce1-0e94-4bff-8d92-388ccc600506 | < 2.6.5 |
MEDIUM | 6.1 | The football-pool plugin before 2.6.5 for WordPress has multiple XSS issues. | — | wordfence |
| 2326984b-8f2b-4922-8141-2fed0548101b | MEDIUM | 6.1 | The wpSOL plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.2.0. … | — | wordfence | |
| 231dbf87-2e17-4b4b-9eac-34a8b4a791ba | < 2.0 |
MEDIUM | 6.1 | The Elements For Elementor plugin for WordPress is vulnerable to Cross-Site Scripting via several parameters in versions… | — | wordfence |
| 2314cfeb-52e4-40c5-91e9-ebd7d7eab809 | < 4.8.2 |
MEDIUM | 6.1 | The Events Calendar plugin before 4.8.2 for WordPress has XSS via the tribe_paged URL parameter. | — | wordfence |
| 23132298-f1de-4085-a76f-f007b8b7de15 | < 7.13.12 |
MEDIUM | 6.1 | The WordPress Geolocation Plugin – CF Geo Plugin Plugin for WordPress is vulnerable to Reflected Cross-Site Scripting … | — | wordfence |
| 22fd58a6-2bcb-4190-8440-a7df7848ad9e | < 2.6.2 |
MEDIUM | 6.1 | The PowerPack Addons for Elementor WordPress plugin before 2.6.2 does not escape the tab parameter before outputting it … | — | wordfence |
| 22faab6d-a63f-4052-b7c6-92e11e4ca723 | < 3.5.1 |
MEDIUM | 6.1 | The Securimage-WP plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘PHP_SELF’ parameter … | — | wordfence |
| 22fa10c0-4efd-4b4d-84a6-cc6db647f6dc | < 3.5.0 |
MEDIUM | 6.1 | The Team Members Showcase plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and in… | — | wordfence |
| 22dcdd92-75d1-44aa-aaae-434ec4bdc20f | < 1.4.5 |
MEDIUM | 6.1 | The Auberge theme before 1.4.5 for WordPress has XSS via the genericons/example.html anchor identifier. | — | wordfence |
| 22dbd787-2b9a-4883-9203-c79fc241596d | < 1.0.3 |
MEDIUM | 6.1 | The WordPress Importer plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and inclu… | — | wordfence |
| 22d50526-e21f-412d-9eed-b9b1f48c3358 | < 3.2.41 |
MEDIUM | 6.1 | The Zephyr Project Manager plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘project’ pa… | — | wordfence |
| 22cfbaa1-5412-4944-899c-7ae41d017384 | MEDIUM | 6.1 | The Arya Multipurpose Pro theme for WordPress is vulnerable to Reflected Cross-Site Scripting via an unknown parameter i… | — | wordfence | |
| 22c03ddb-befe-4ac5-86b1-46d95d313b5e | MEDIUM | 6.1 | The WPMovieLibrary plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and inclu… | — | wordfence | |
| 22bf5b65-8ec4-477c-a6bd-c90b99f560a8 | < 1.5.2 |
MEDIUM | 6.1 | Cross-site scripting (XSS) vulnerability in xml/media-rss.php in the NextGEN Gallery plugin before 1.5.2 for WordPress a… | — | wordfence |
| 22b33944-443e-48fe-9fd0-4d48fe03072b | MEDIUM | 6.1 | The New Year Firework plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'text' parameter in t… | — | wordfence | |
| 22b16275-f46b-4338-b95f-1939ec85316d | MEDIUM | 6.1 | The Coupon Tab for DirectoryPress (pp-coupon-tab) plugin for WordPress is vulnerable to Reflected Cross-Site Scripting v… | — | wordfence | |
| 22ab3baa-34a3-4554-9c05-ebd5c9e5279b | MEDIUM | 6.1 | The WP_DEBUG Toggle plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and includin… | — | wordfence | |
| 22a9c0f6-7a20-4ed1-9afa-887adc790c80 | MEDIUM | 6.1 | The pageMash > Page Management plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, a… | — | wordfence | |
| 22a0f10f-0a67-4f4a-99db-a625bec20bdc | < 1.7.1 |
MEDIUM | 6.1 | The Image Gallery - Responsive Photo Gallery plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via th… | — | wordfence |
EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.
Scan My Website →