Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.
40,369 vulnerabilities found (page 1034 of 1615)
| CVE ID | Plugin / Theme | Severity | CVSS | Description | Fixed In | Source |
|---|---|---|---|---|---|---|
| 9acf80aa-8354-4430-9836-18fa17854521 | < 4.10.1 |
MEDIUM | 5.5 | The Schedule Post Changes With PublishPress Future plugin for WordPress is vulnerable to Stored Cross-Site Scripting via… | — | wordfence |
| 9a7f738e-21f3-42f3-bf33-1d93ff0d1364 | < 3.27.9 |
MEDIUM | 5.5 | The "Slider, Gallery, and Carousel by MetaSlider – Responsive WordPress Plugin" plugin for WordPress is vulnerable to … | — | wordfence |
| 9a4488c8-7138-4046-88ea-84f9462eec93 | < 2.2.24 |
MEDIUM | 5.5 | The Events Made Easy WordPress plugin before 2.2.24 does not sanitise and escape Custom Field Names, allowing high privi… | — | wordfence |
| 99e61ed1-df56-4e95-b4f9-3027ee7b7793 | < 5.7.26 |
MEDIUM | 5.5 | The Quick Paypal Payments plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings through s… | — | wordfence |
| 999cf54e-2ea8-474d-984c-1c4f729198aa | < 2.2 |
MEDIUM | 5.5 | An issue was discovered in the read-and-understood plugin 2.1 for WordPress. XSS exists via the wp-admin/options-general… | — | wordfence |
| 9985627d-9ba4-4a5b-94fb-06bcc769acfd | < 2.1.6 |
MEDIUM | 5.5 | The Notibar – Notification Bar for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via adm… | — | wordfence |
| 994a044d-db69-4f2d-9027-cf3665446ed3 | < 1.8.22 |
MEDIUM | 5.5 | The Photo Gallery by 10Web – Mobile-Friendly Image Gallery plugin for WordPress is vulnerable to Stored Cross-Site Scr… | — | wordfence |
| 993f6505-918c-45fd-8afa-4d567cc79e9e | < 3.0.6 |
MEDIUM | 5.5 | The ImageBoss WordPress plugin before 3.0.6 does not sanitise and escape its Source Name setting, which could allow high… | — | wordfence |
| 990b3318-e3e1-4a19-875c-80d5d639ca4a | < 1.2.8 |
MEDIUM | 5.5 | The Meks Easy Social Share plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several of its paramete… | — | wordfence |
| 98c2d04d-c401-411f-8bf0-4aebb1779e8d | < 1.1.0 |
MEDIUM | 5.5 | The Analytics Cat – Google Analytics Made Easy plugin for WordPress is vulnerable to Stored Cross-Site Scripting via t… | — | wordfence |
| 988f102e-08b6-4436-be03-fc37a4084ca1 | < 2.4.4 |
MEDIUM | 5.5 | The All-in-One Addons for Elementor - WidgetKit plugin for WordPress is vulnerable to Stored Cross-Site Scripting via th… | — | wordfence |
| 986f158e-1960-4105-b477-9587850aa0aa | MEDIUM | 5.5 | The Message ticker plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 9… | — | wordfence | |
| 98553e47-f121-4300-b6d9-ab309516cf1d | < 4.4.0 |
MEDIUM | 5.5 | The WP MAPS plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcodes in versions up… | — | wordfence |
| 97c7b0bc-4c73-4330-851a-2d6d6d0b62c9 | < 3.1.4 |
MEDIUM | 5.5 | The Easy Social Icons WordPress plugin before 3.1.4 does not sanitize the selected_icons attribute to the cnss_widget be… | — | wordfence |
| 97b10f88-1911-4416-a5cd-83b4c991e6c9 | < 1.0.83 |
MEDIUM | 5.5 | The Loading Page with Loading Screen WordPress plugin before 1.0.83 does not escape its settings, allowing high privileg… | — | wordfence |
| 978c13e5-d30c-4caa-ab6d-256f2517fd79 | MEDIUM | 5.5 | The Auto Attachments plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all version… | — | wordfence | |
| 978159d3-39b2-49b7-a59a-2da72f1792fd | MEDIUM | 5.5 | The CPO Shortcodes plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1… | — | wordfence | |
| 9694c8b6-3e2f-499f-bdac-eed78d89e08a | < 1.6.6 |
MEDIUM | 5.5 | The WP Last Modified Info plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘Custom Message to… | — | wordfence |
| 9642be85-2817-4a3b-831b-0f1535106897 | < 3.0.0 |
MEDIUM | 5.5 | The Page Loading Effects plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in version… | — | wordfence |
| 961b2b60-2026-42fc-be55-e7023e8ef3df | MEDIUM | 5.5 | The Event Geek WordPress plugin through 2.5.2 does not sanitise or escape its "Use your own " setting before outputting … | — | wordfence | |
| 95f1e3eb-da87-417e-8e8c-e5035e072950 | < 3.62 |
MEDIUM | 5.5 | The Qwizcards – online quizzes and flashcards WordPress plugin before 3.62 does not properly sanitize and escape some … | — | wordfence |
| 94d682bb-ed94-40fc-98b4-2f404d6cd8ea | < 6.6.0 |
MEDIUM | 5.5 | The WooCommerce plugin for WordPress is vulnerable to Stored HTML Injection via payment gateway titles in versions up to… | — | wordfence |
| 94cbd525-de3b-448a-b65b-21c63208b8b8 | < 1.4.6 |
MEDIUM | 5.5 | The Business Manager WordPress plugin is vulnerable to Stored Cross-Site Scripting due to insufficient input validation … | — | wordfence |
| 94384812-fa6e-48db-a84a-b1769e62ca58 | < 3.9.31 |
MEDIUM | 5.5 | The WP Import Export Lite plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to and in… | — | wordfence |
| 93a07f4e-8359-4ca2-a1cc-ca0ba2b7c0de | < 2.0.4 |
MEDIUM | 5.5 | The Seed Social plugin for WordPress is vulnerable to Stored Cross-Site Scripting via some of the plugin's settings in v… | — | wordfence |
EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.
Scan My Website →