Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.
40,117 vulnerabilities found (page 990 of 1605)
| CVE ID | Plugin / Theme | Severity | CVSS | Description | Fixed In | Source |
|---|---|---|---|---|---|---|
| 15e65a86-db8e-4a4a-b9c6-c688021a514f | MEDIUM | 6.1 | The Testimonial Master plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the `$_SERVER['PHP_SELF'… | — | wordfence | |
| 15e06f6e-2a13-490e-8e41-d9f7db8e78e0 | MEDIUM | 6.1 | Multiple cross-site scripting (XSS) vulnerabilities in the wp-football plugin 1.1 and earlier for WordPress allow remote… | — | wordfence | |
| 15d6cdb5-5259-46d5-8649-a3abcde4fb47 | MEDIUM | 6.1 | The Unique UX plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 0.9… | — | wordfence | |
| 15d66474-e215-4d28-b6fb-259c90053212 | < 3.2 |
MEDIUM | 6.1 | The Portrait-Archiv.com Photostore plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘pDeta… | — | wordfence |
| 15ce5666-f020-4264-989d-713e4520e012 | < 0.9.69 |
MEDIUM | 6.1 | The Migration, Backup, Staging – WPvivid plugin before 0.9.69 does not have authorisation when adding remote storages,… | — | wordfence |
| 15b57809-6062-48ca-8572-26032928cd16 | < 3.4.7 |
MEDIUM | 6.1 | The Survey Maker plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘page’ parameter in ve… | — | wordfence |
| 15967a0f-2512-4418-b503-b9d53032d40f | < 1.7.0 |
MEDIUM | 6.1 | The wpForo plugin 1.6.5 for WordPress allows XSS via the wp-admin/admin.php?page=wpforo-phrases langid parameter. | — | wordfence |
| 157b3095-b662-465e-a975-5b71b5d4ba2a | < 3.3.5 |
MEDIUM | 6.1 | … | — | wordfence |
| 156b9e3f-0a99-4fbc-88a4-1ed5e5e6b896 | < 1.5.1.9 |
MEDIUM | 6.1 | The Landing Page Builder – Coming Soon page, Maintenance Mode, Lead Page, WordPress Landing Pages plugin for WordPress… | — | wordfence |
| 15672f90-3192-452c-a4f2-be6db00b7888 | MEDIUM | 6.1 | The Custom Add User plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'dmsg' parameter in ver… | — | wordfence | |
| 15655362-b77f-4ba4-a823-17085de55f85 | MEDIUM | 6.1 | The Simple Popup Newsletter WordPress plugin is vulnerable to Reflected Cross-Site Scripting due to the use of $_SERVER[… | — | wordfence | |
| 1564429b-0fb7-4c97-9802-8360e6ff3568 | MEDIUM | 6.1 | The QR Master plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 1.0… | — | wordfence | |
| 15517a81-0913-4922-be2b-aaf9abc52a84 | < 1.6.9 |
MEDIUM | 6.1 | XSS exists in the Tribulant Slideshow Gallery plugin 1.6.8 for WordPress via the wp-admin/admin.php?page=slideshow-galle… | — | wordfence |
| 154b3a1a-7246-42de-a555-2c655778d59e | MEDIUM | 6.1 | The WP URL Shortener plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and includi… | — | wordfence | |
| 15416268-c040-46be-bf4d-252dc9a1ffad | MEDIUM | 6.1 | The WP Profitshare plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including… | — | wordfence | |
| 153a9a08-66b3-40fd-963d-93058c863a80 | < 1.1.2 |
MEDIUM | 6.1 | … | — | wordfence |
| 1535a174-ab59-4c6e-8080-ef818e00b070 | MEDIUM | 6.1 | The Add User Meta plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including,… | — | wordfence | |
| 15357b2b-acc4-45a2-9183-fd0e910ee943 | MEDIUM | 6.1 | The Plestar Directory Listing plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to… | — | wordfence | |
| 153213ee-d1c6-4cc7-a297-e25266b705a8 | MEDIUM | 6.1 | The Dyn Business Panel plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and incl… | — | wordfence | |
| 15253d0c-3425-4065-94d2-969939e858ca | < 1.8.22 |
MEDIUM | 6.1 | The Photo Gallery by 10Web – Mobile-Friendly Image Gallery plugin for WordPress is vulnerable to Reflected Cross-Site … | — | wordfence |
| 1522d23b-7655-4fde-a18b-b46c6625185f | < 1.2.2.29 |
MEDIUM | 6.1 | The UsersWP – User Registration & User Profile plugin for WordPress is vulnerable to Reflected Cross-Site Scripting vi… | — | wordfence |
| 1507628c-4a81-47de-a06f-a5d573eebffb | < 1.1.0 |
MEDIUM | 6.1 | PayPal Pro Add-on for iThemes Exchange before 1.1.0 for WordPress has XSS via add_query_arg() and remove_query_arg(). | — | wordfence |
| 14ffe10e-e1a6-4752-9ff9-d2b01a49521e | < 1.2.20 |
MEDIUM | 6.1 | The Email Subscription Popup plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'queueemails' … | — | wordfence |
| 14fdd10e-283e-4978-9efa-73bc02c9c297 | MEDIUM | 6.1 | The Posts Date Ranges plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and includ… | — | wordfence | |
| 14fb6cde-3ab5-4360-add2-c0b0fa4ca114 | < 2.1.2 |
MEDIUM | 6.1 | Cross-site scripting (XSS) vulnerability in Social Sharing Toolkit plugin before 2.1.2 for WordPress allows remote attac… | — | wordfence |
EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.
Scan My Website →