Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.
40,117 vulnerabilities found (page 989 of 1605)
| CVE ID | Plugin / Theme | Severity | CVSS | Description | Fixed In | Source |
|---|---|---|---|---|---|---|
| 174c4050-8eed-4641-85d2-4b66702e03a6 | < 4.8.73 |
MEDIUM | 6.1 | In the miniOrange SAML SP Single Sign On plugin before 4.8.73 for WordPress, the SAML Login Endpoint is vulnerable to XS… | — | wordfence |
| 17422c79-494a-4c90-a48c-1aad9e0fa4c2 | < 4.3.1 |
MEDIUM | 6.1 | The wp-database-backup plugin before 4.3.1 for WordPress has XSS. | — | wordfence |
| 172a8c2c-dbfe-425a-9091-c9f20290cf03 | MEDIUM | 6.1 | The Simple Auto Tag plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and includin… | — | wordfence | |
| 1723a465-75ca-4fea-ad9c-d96ffb5625a8 | < 3.1.29 |
MEDIUM | 6.1 | The Ultimate Addons for Contact Form 7 plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 's' … | — | wordfence |
| 171fe5db-0b43-47ba-b215-87ce9d7b5095 | MEDIUM | 6.1 | The YANewsflash plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1… | — | wordfence | |
| 171faddd-c60c-4d07-834e-d8149703513b | < 1.4.7 |
MEDIUM | 6.1 | The Testimonial WordPress Plugin WordPress plugin before 1.4.7 does not sanitise and escape the id parameter before outp… | — | wordfence |
| 16e7a7c5-b845-4f28-bee6-fde54d003e13 | MEDIUM | 6.1 | The WP SEO Tags WordPress plugin is vulnerable to Reflected Cross-Site Scripting via the saq_txt_the_filter parameter in… | — | wordfence | |
| 16e2c051-6ec6-4b09-8802-adb537fa9af0 | < 2.8.3 |
MEDIUM | 6.1 | The Visual Form Builder plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘s’ parameter i… | — | wordfence |
| 16d41531-5250-421e-93d6-29176e1f252d | MEDIUM | 6.1 | The Import Users to MailChimp plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, an… | — | wordfence | |
| 16c9ed4a-9e9f-4f10-b3fd-7f0db2c86112 | < 4.0.0 |
MEDIUM | 6.1 | The WP Social Ninja – Embed Social Feeds, Customer Reviews, Chat Widgets plugin for WordPress is vulnerable to Stored … | — | wordfence |
| 16bd14a1-e69b-4b7d-8c0e-a294e120d2a6 | < 3.0.2 |
MEDIUM | 6.1 | The XML for Google Merchant Center plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'page’… | — | wordfence |
| 16b8851c-171b-43cc-85ef-28c01d7e090f | MEDIUM | 6.1 | The Blighty Explorer plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and includi… | — | wordfence | |
| 16b5ad20-a264-49fa-aafc-e137ac0d81fa | MEDIUM | 6.1 | The WP Headmaster plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including,… | — | wordfence | |
| 16a70662-d32c-4dfd-a1b2-0876ba4671ab | MEDIUM | 6.1 | The Section Widget plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including… | — | wordfence | |
| 16a4ebde-7c92-4ad2-9c8d-3bef0a8c600b | < 1.2.2 |
MEDIUM | 6.1 | Cross-site scripting (XSS) vulnerability in the Welcart plugin before 1.2.2 for WordPress allows remote attackers to inj… | — | wordfence |
| 169f2767-da20-4199-9997-438a62f6aee4 | < 1.28 |
MEDIUM | 6.1 | The reCaptcha by BestWebSoft plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘category’… | — | wordfence |
| 16919724-e495-492e-8cc7-639e6d8473c2 | < 4.0.3 |
MEDIUM | 6.1 | The WebP Converter for Media WordPress plugin before 4.0.3 contains a file (passthru.php) which does not validate the sr… | — | wordfence |
| 163f120e-533a-4054-b5d1-331950ad02a7 | MEDIUM | 6.1 | The Windows Live Writer plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and incl… | — | wordfence | |
| 1638145c-2bc8-45d4-904e-b1aba124a0e3 | < 1.4.1 |
MEDIUM | 6.1 | includes/options.php in the motors-car-dealership-classified-listings (aka Motors - Car Dealer & Classified Ads) plugin … | — | wordfence |
| 162afd58-3534-401b-9119-c1c26e15cd0f | < 2.9.5 |
MEDIUM | 6.1 | The Welcart e-Commerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'upload_mode' parame… | — | wordfence |
| 15fbfb20-50c7-4390-afa3-e6b9c95a2551 | < 3.1.7 |
MEDIUM | 6.1 | The Quick Interest Slider plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and in… | — | wordfence |
| 15f3ca33-50b8-4cd3-bcd1-5a73a3a06fc3 | < 4.5.3.1 |
MEDIUM | 6.1 | The CKEditor plugin before 4.5.3.1 for WordPress has reflected XSS in the built-in (old) file browser. | — | wordfence |
| 15f2c277-45ba-40a8-8123-17e23afbf68b | MEDIUM | 6.1 | The Tantyyellow theme for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 1.… | — | wordfence | |
| 15f1a14e-7536-4f6e-ad6d-a3bcb09efec6 | < 7.1.7 |
MEDIUM | 6.1 | The Nomupay Payment Processing Gateway plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions … | — | wordfence |
| 15f00b65-8304-4132-a2cf-8145444ecfb1 | < 4.4.3 |
MEDIUM | 6.1 | The NextScripts plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘code’ parameter in ver… | — | wordfence |
EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.
Scan My Website →