Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.
39,409 vulnerabilities found (page 102 of 1577)
| CVE ID | Plugin / Theme | Severity | CVSS | Description | Fixed In | Source |
|---|---|---|---|---|---|---|
| a9f5eab2-09d9-4d8e-8024-abf02b0f6b86 | < 1.1.6 |
CRITICAL | 9.1 | The Movie Booking plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation… | — | wordfence |
| a8447fa0-f994-4de3-b6e7-2fe61e06bed1 | < 3.3.2 |
CRITICAL | 9.1 | The Blackhole for Bad Bots WordPress plugin before 3.3.2 uses headers such as CF-CONNECTING-IP, CLIENT-IP etc to determi… | — | wordfence |
| a555da8f-586a-4fb8-9230-9238df73cba4 | < 1.1.14 |
CRITICAL | 9.1 | The Music Store β WordPress eCommerce plugin for WordPress is vulnerable to SQL Injection in all versions up to, and i… | — | wordfence |
| a2248ba8-b7d7-4691-bf7c-8b23c24417f7 | < 3.2 |
CRITICAL | 9.1 | The WP Custom Cursors | WordPress Cursor Plugin plugin for WordPress is vulnerable to SQL Injection via the 'edit_row' p… | — | wordfence |
| a147956c-a4d8-4945-997a-9b7cea60f926 | < 11.2.0 |
CRITICAL | 9.1 | The PitchPrint plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in… | — | wordfence |
| a125bbf1-8ff6-4f3d-a4fb-caaaefe1df2a | < 1.7.14 |
CRITICAL | 9.1 | The Startklar Elementor Addons plugin for WordPress is vulnerable to arbitrary file deletion in all versions up to, and … | — | wordfence |
| 9e20afee-9336-458e-ab5c-b320c6887b83 | CRITICAL | 9.1 | The 10Web Map Builder for Google Maps plugin for WordPress is vulnerable to SQL Injection in versions up to, and includi… | — | wordfence | |
| 9cb7bc91-b2e9-4ede-80cf-6b961ac6dcb9 | < 0.3.0 |
CRITICAL | 9.1 | An issue was discovered in WPGraphQL up to 0.2.3 . By querying the 'users' RootQuery, it is possible, for an unauthentic… | — | wordfence |
| 9affd2b9-9576-435e-931d-f60816af0b91 | < 1.7.21 |
CRITICAL | 9.1 | The CBX Bookmark & Favorite plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 1.7.20… | — | wordfence |
| 9addaa26-46b3-4fbf-8986-0b8c8f2dd286 | CRITICAL | 9.1 | The Shortcode Addons- with Visual Composer, Divi, Beaver Builder and Elementor Extension plugin for WordPress is vulnera… | — | wordfence | |
| 9a5ce873-e90b-4bdc-b428-426818ff9a86 | < 3.6.8 |
CRITICAL | 9.1 | The WP All Import plugin for WordPress is vulnerable to arbitrary code execution in versions up to, and including, 3.6.7… | — | wordfence |
| 9a29aea7-9e22-4edb-80d9-266843a416a5 | < 3.15 |
CRITICAL | 9.1 | The WordPress plugin, WP Database Reset through 3.1, contains a flaw that allowed any unauthenticated user to reset any … | — | wordfence |
| 98a274eb-036f-44f1-861d-1cfea0b34d7f | < 4.0.4 |
CRITICAL | 9.1 | The LearnPress Export Import plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 4.0.3… | — | wordfence |
| 97416640-c076-4f5e-9119-adbca2fcc495 | CRITICAL | 9.1 | Open proxy in Wordpress plugin google-adsense-and-hotel-booking v1.05 | — | wordfence | |
| 9715d1b2-1d82-4f48-89c3-9a389ab31360 | < 2.2.70 |
CRITICAL | 9.1 | The AI Engine plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in all ve… | — | wordfence |
| 96e2ba3d-4e6d-42b8-832c-03ef4915cadb | < 2.4.2 |
CRITICAL | 9.1 | SQL injection vulnerability in fim_rss.php in the fGallery 2.4.1 plugin for WordPress allows remote attackers to execute… | — | wordfence |
| 93d00b7e-cad1-4521-8acf-94818258a9d9 | < 1.5.16 |
CRITICAL | 9.1 | The Scape - Multipurpose WordPress theme theme for WordPress is vulnerable to arbitrary file deletion due to insufficien… | — | wordfence |
| 901e85b9-0948-4a00-a29f-a726b53ba51b | < 2.35.8 |
CRITICAL | 9.1 | The 404 Solution plugin for WordPress is vulnerable to SQL Injection in all versions up to, and including, 2.35.7 due to… | — | wordfence |
| 8ebb1072-ea05-4914-961d-0d8f20248078 | < 3.5.0 |
CRITICAL | 9.1 | The WP STAGING WordPress Backup Plugin β Migration Backup Restore plugin for WordPress is vulnerable to arbitrary file… | — | wordfence |
| 8cf1889b-c249-4bd7-ae23-2db66ca9d873 | CRITICAL | 9.1 | The FormGent β Next-Gen AI Form Builder for WordPress with Multi-Step, Quizzes, Payments & More plugin for WordPress i… | — | wordfence | |
| 8b7e1da1-8e40-4119-894d-43e82e188608 | < 1.8.11 |
CRITICAL | 9.1 | The VikBooking Hotel Booking Engine & PMS plugin for WordPress is vulnerable to arbitrary file deletion due to insuffici… | — | wordfence |
| 8b0f58b8-46d6-4deb-bfcc-806bb635b060 | < 5.3.4 |
CRITICAL | 9.1 | The WooCommerce Multilingual & Multicurrency with WPML plugin for WordPress is vulnerable to SQL Injection in all versio… | — | wordfence |
| 8aa0fffa-475e-4227-9ab1-17ca6fcce529 | < 2.1.1 |
CRITICAL | 9.1 | In Firebase PHP-JWT before 6.0.0, an algorithm-confusion issue (e.g., RS256 / HS256) exists via the kid (aka Key ID) hea… | — | wordfence |
| 8a24e409-8aa9-4d18-b428-b202407fdbfe | CRITICAL | 9.1 | The PluginPass β WordPress PRO Plugin/Theme Licensing (Public Alpha) plugin for WordPress is vulnerable to arbitrary f… | — | wordfence | |
| 88b8a93b-f34f-4188-8153-ce36b03b6a4c | < 4.9.12 |
CRITICAL | 9.1 | The Spiffy Calendar plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 4.9.11 due to … | — | wordfence |
EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.
Scan My Website →