Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.
40,369 vulnerabilities found (page 1033 of 1615)
| CVE ID | Plugin / Theme | Severity | CVSS | Description | Fixed In | Source |
|---|---|---|---|---|---|---|
| a07ca145-9349-4961-9e66-4c59ea9b5069 | MEDIUM | 5.5 | The Ad Injection WordPress plugin through 1.2.0.19 does not properly sanitize the body of the adverts injected into the … | — | wordfence | |
| a07bd233-902c-402c-9055-f3085246da78 | < 4.2.2 |
MEDIUM | 5.5 | The WP OAuth Server plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the client ID parameter in ver… | — | wordfence |
| a03f0780-796c-41a3-8f06-04f76e0da2da | < 4.8.2 |
MEDIUM | 5.5 | The Download Monitor plugin for WordPress is vulnerable to Server-Side Request Forgery in versions up to, and including,… | — | wordfence |
| a018ba2b-8188-41f9-bdab-64cae3362e0e | < 3.4.0 |
MEDIUM | 5.5 | The Easy Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including… | — | wordfence |
| 9fe2a19a-b6ed-409f-a496-a005f87d06e6 | < 1.0.12 |
MEDIUM | 5.5 | The Simplified Plugin plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and inclu… | — | wordfence |
| 9fae8288-898a-4acd-bbdf-c2fd4f1be1c6 | < 7.2.4 |
MEDIUM | 5.5 | The AGCA β Custom Dashboard & Login Page plugin for WordPress is vulnerable to Server-Side Request Forgery in all vers… | — | wordfence |
| 9f76e294-1b17-4125-b85c-af7957de1c13 | < 1.3.8 |
MEDIUM | 5.5 | The Login with phone number WordPress plugin through 1.3.7 do not sanitise and escape plugin settings which could allow … | — | wordfence |
| 9f6fd068-3f72-4015-b2d8-a47cd86df073 | < 1.1.23 |
MEDIUM | 5.5 | The MJM Clinic plugin for WordPress is vulnerable to Stored Cross-Site Scripting via settings in all versions up to, and… | — | wordfence |
| 9f699d49-738f-49f0-ab1a-f43645a32c90 | < 2.0.7 |
MEDIUM | 5.5 | The Social Slider Feed plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the hashtag parameter in ve… | — | wordfence |
| 9f5a77d1-b575-4e7c-bf27-fc78260de302 | MEDIUM | 5.5 | The Reaction Buttons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all version… | — | wordfence | |
| 9ec83425-c756-450e-ac46-c897ad72714c | MEDIUM | 5.5 | The Woocommerce Tip/Donation plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin settings i… | — | wordfence | |
| 9eb829f2-c05f-4f81-85d0-2429fb515d33 | < 1.1.19 |
MEDIUM | 5.5 | An issue was discovered in the responsive-coming-soon-page plugin 1.1.18 for WordPress. XSS exists via the wp-admin/admi… | — | wordfence |
| 9e9fcaf5-d531-4b14-b8b1-d8090243cf0c | < 2.3.20 |
MEDIUM | 5.5 | The SVG Support WordPress plugin before 2.3.20 does not escape the "CSS Class to target" setting before outputting it in… | — | wordfence |
| 9e6434fb-390d-439d-bf3e-9afe8644fd58 | < 5.4.7 |
MEDIUM | 5.5 | The Poll Maker β Versus Polls, Anonymous Polls, Image Polls plugin for WordPress is vulnerable to Stored Cross-Site Sc… | — | wordfence |
| 9e2214d8-b22d-4e51-a0cf-cca1af8e761c | < 2.6.9 |
MEDIUM | 5.5 | The Responsive Starter Templates β Elementor & WordPress Templates plugin for WordPress is vulnerable to stored cross-… | — | wordfence |
| 9e1ae8f2-dd2e-46f9-bef1-aaaee26435a1 | < 2411.1 |
MEDIUM | 5.5 | The Table of Contents Plus plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all v… | — | wordfence |
| 9d879fc6-97ec-4ecb-99c8-7fc0b91692ef | MEDIUM | 5.5 | The Category and Taxonomy Meta Fields plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'new_met… | — | wordfence | |
| 9d5ed6cf-ae12-4da5-809f-6a8c61eeb4f6 | < 1.4.4 |
MEDIUM | 5.5 | The Assistant plugin for WordPress is vulnerable to Server-Side Request Forgery in versions up to, and including, 1.4.3 … | — | wordfence |
| 9d389098-d428-48f2-b012-207b55497b0b | < 4.3.7 |
MEDIUM | 5.5 | The Paytium plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'paytium_live_api_key' option and … | — | wordfence |
| 9d1fcdb9-215c-415b-bd47-4cbf9258685b | < 1.32.0 |
MEDIUM | 5.5 | The Advanced Ads plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the title parameter in versions u… | — | wordfence |
| 9c3dc5fe-b1c8-4581-8100-68d313c3ac20 | < 4.8.7 |
MEDIUM | 5.5 | The MC4WP: Mailchimp for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several paramet… | — | wordfence |
| 9bbcd280-25c3-4bc3-88bf-d109cfd1e855 | MEDIUM | 5.5 | The Hotjar Connecticator WordPress plugin through 1.1.1 is vulnerable to Stored Cross-Site Scripting (XSS) in the 'hotja… | — | wordfence | |
| 9b8042b0-83d3-417f-a5e0-43ff4f7648fb | < 0.4.6 |
MEDIUM | 5.5 | The reSmush.it plugin for WordPress is vulnerable to Stored Cross-Site Scripting via some of its settings parameters in … | — | wordfence |
| 9b0cc3a0-5a80-4a56-abeb-13046d9eaf3f | < 1.4.10 |
MEDIUM | 5.5 | The Slideshow CK WordPress plugin before 1.4.10 does not sanitize and escape Slide's descriptions, which could allow hig… | — | wordfence |
| 9ae9b5c7-0d76-4772-973b-be48e520c837 | < 1.6.0 |
MEDIUM | 5.5 | The Testimonial WordPress plugin before 1.6.0 does not escape some testimonial fields which could allow high privilege u… | — | wordfence |
EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.
Scan My Website →