Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.
40,369 vulnerabilities found (page 998 of 1615)
| CVE ID | Plugin / Theme | Severity | CVSS | Description | Fixed In | Source |
|---|---|---|---|---|---|---|
| 149c1da7-9da8-4e3f-8d34-39ce464847b1 | MEDIUM | 6.1 | The Latest Custom Post Type Updates plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up … | — | wordfence | |
| 147ad116-04fa-4dfa-9b96-26f361e19256 | MEDIUM | 6.1 | The BabelZ – Google Translate Widget plugin for WordPress is vulnerable to Cross-Site Request Forgery in [version]. Th… | — | wordfence | |
| 14667d93-4fba-4c50-8228-737ae91f2789 | < 2.7 |
MEDIUM | 6.1 | The MailPoet Newsletters plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘wysija-key’ p… | — | wordfence |
| 1460dc44-dd64-4fd6-952b-1f5d4285bfa4 | < 3.6.26 |
MEDIUM | 6.1 | The Ninja Forms plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘data’ parameter in ver… | — | wordfence |
| 145a2ba1-67c1-4446-9269-cdbfdce77ef9 | MEDIUM | 6.1 | The Cookie Scanner plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.… | — | wordfence | |
| 1454af30-319a-44b7-a83e-2d774cfbc8d1 | MEDIUM | 6.1 | The PDF Image Generator plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query… | — | wordfence | |
| 1448f0d2-6b1f-45de-8e3a-81b9445cb16d | MEDIUM | 6.1 | The Wizard Cloak plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, … | — | wordfence | |
| 143e28b0-56cf-4d8d-9147-60a85a595290 | < 10.3.9 |
MEDIUM | 6.1 | The WooCommerce and WP eMember Integration plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the … | — | wordfence |
| 1426bebe-d3c4-4f83-9b50-fae8c2373209 | < 4.5.11.1 |
MEDIUM | 6.1 | The Duplicator Pro plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including… | — | wordfence |
| 140f633c-c2e4-4b3c-befc-d870e06be970 | MEDIUM | 6.1 | The Easy Custom Admin Bar plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘msg’ paramet… | — | wordfence | |
| 140c0d22-dc26-4100-a5c0-a2f8a6f98d97 | < 4.2.9 |
MEDIUM | 6.1 | The Maximum Products per User for WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due t… | — | wordfence |
| 140b1f50-7c04-4396-ab0a-098bd06c80a8 | < 7.3.5 |
MEDIUM | 6.1 | The Zotpress plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via 'PHP_SELF' in versions up to, and … | — | wordfence |
| 1405e58a-0783-46f7-bbf0-9645777ed64e | MEDIUM | 6.1 | The polka dots theme for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 1.2… | — | wordfence | |
| 14039d7d-bd5a-4c6b-96b0-46f86536e085 | < 2.0.20 |
MEDIUM | 6.1 | Cross-site scripting (XSS) vulnerability in the Contact Bank plugin before 2.0.20 for WordPress allows remote attackers … | — | wordfence |
| 140262fc-23d0-4c30-9ce8-da9ccf2159df | MEDIUM | 6.1 | The InLocation plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.… | — | wordfence | |
| 13fb725f-cb16-49e3-b545-14266538c604 | < 1.9 |
MEDIUM | 6.1 | The RokIntroScroller plugin for WordPress is vulnerable to Cross-Site Scripting via the 'src' parameter in the 'thumb.ph… | — | wordfence |
| 13e9deb0-73e1-44ea-820b-6cffe924b74b | MEDIUM | 6.1 | The WP Colorful Tag Cloud plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and in… | — | wordfence | |
| 13e8f16b-b5a3-4be1-9557-e11cd9ffaea7 | < 1.16 |
MEDIUM | 6.1 | The Enhanced Admin Plugin for WordPress is vulnerable to Cross-Site Scripting via the 'REQUEST_URI' variable in versions… | — | wordfence |
| 13e77d77-8f09-4fb9-8ff9-a8e66afe0393 | < 2.1.6 |
MEDIUM | 6.1 | Cross-site scripting (XSS) vulnerability in services/diagnostics.php in the WordPress Social Login plugin 2.1.5 and earl… | — | wordfence |
| 13d53257-9dc7-4b7c-9472-72769099386c | MEDIUM | 6.1 | The Custom Dashboard Widget plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and … | — | wordfence | |
| 13cfcc7a-8529-4bd5-9842-b9ad8eb5f4b3 | < 1.8.22 |
MEDIUM | 6.1 | The Photo Gallery by 10Web – Mobile-Friendly Image Gallery plugin for WordPress is vulnerable to Reflected Cross-Site … | — | wordfence |
| 13cb5c62-34fb-4bbc-b42a-cc8a16d51258 | MEDIUM | 6.1 | The Email Artillery (MASS EMAIL) plugin for WordPress is vulnerable to various Reflected Cross-Site Scripting via the 'c… | — | wordfence | |
| 13ba9152-b9a0-4201-ba91-c41686b4d953 | < 3.4.34 |
MEDIUM | 6.1 | In the Ninja Forms Contact Form WordPress plugin before 3.4.34, the wp_ajax_nf_oauth_connect AJAX action was vulnerable … | — | wordfence |
| 13a1e293-f539-4d19-8fe8-392c126fd1c4 | MEDIUM | 6.1 | The intouch plugin for WordPress is vulnerable to Cross-Site Scripting via the 'intouch_failure' parameter in versions u… | — | wordfence | |
| 1394b739-9d3a-4162-a7ca-3d20025eba52 | < 1.4 |
MEDIUM | 6.1 | The GeoFlickr plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 1.3… | — | wordfence |
EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.
Scan My Website →