Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.
40,369 vulnerabilities found (page 1072 of 1615)
| CVE ID | Plugin / Theme | Severity | CVSS | Description | Fixed In | Source |
|---|---|---|---|---|---|---|
| 9d6dd532-008b-4ce9-beca-baf5b3678a0b | < 2.20.29 |
MEDIUM | 5.4 | The Seraphinite Accelerator plugin for WordPress is vulnerable to Open Redirect in all versions up to, and including, 2.… | — | wordfence |
| 9d3b4315-05cd-4349-8dd9-ea6792048a9d | < 3.0.3 |
MEDIUM | 5.4 | The Google Fonts Typography WordPress plugin before 3.0.3 does not escape and sanitize some of its block settings, allow… | — | wordfence |
| 9d1e498a-ddcb-4c67-bf0d-bb45b6fe0e9d | < 4.5.4 |
MEDIUM | 5.4 | The WP Meta SEO plugin for WordPress is vulnerable to unauthorized plugin settings update due to a missing capability ch… | — | wordfence |
| 9cf2d3bd-359c-4334-ad28-b6b9722edd1c | < 3.0.15 |
MEDIUM | 5.4 | The WPCafe β Restaurant Menu, Online Food Ordering & Table Booking System plugin for WordPress is vulnerable to author… | — | wordfence |
| 9cceca0e-5411-4b8c-a261-91098a8bc7fa | < 1.3.6 |
MEDIUM | 5.4 | The WP Reactions Lite WordPress plugin before 1.3.6 does not properly sanitize inputs within wp-admin pages, allowing us… | — | wordfence |
| 9c159237-1a3a-4d42-9a2e-fbd6ca98f38e | < 4.5.6 |
MEDIUM | 5.4 | The Return Refund and Exchange For WooCommerce plugin for WordPress is vulnerable to Insecure Direct Object Reference in… | — | wordfence |
| 9bd6c6f7-a535-4e3a-8d72-01007d00d6be | < 9.6.3 |
MEDIUM | 5.4 | The Salon booking system plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'Mobile Phone' parame… | — | wordfence |
| 9b5bc030-7739-4eb4-b85d-99e5d0f2643a | < 1.17 |
MEDIUM | 5.4 | The Enhanced Plugin Admin plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and includ… | — | wordfence |
| 9b26604b-2423-4130-b0ef-8f63a392c760 | < 2.18.17 |
MEDIUM | 5.4 | The Wicked Folders plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the a… | — | wordfence |
| 9b2083f9-79d0-43f6-b7ae-a5817dc561b0 | < 2.1.6 |
MEDIUM | 5.4 | The DethemeKit For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the URL parameter of … | — | wordfence |
| 9af929a3-6e17-40c7-9fce-1ce0eb72bc7b | < 3.3.10 |
MEDIUM | 5.4 | The Zephyr Project Manager plugin for WordPress is vulnerable to Open Redirect in versions up to, and including, 3.3.9. … | — | wordfence |
| 9aeb996c-723a-402a-a0f8-4212391c64eb | < 2.16.0 |
MEDIUM | 5.4 | The WooCommerce PDF Invoices & Packing Slips plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via th… | — | wordfence |
| 9a4c327c-f756-4f50-8121-363791c6bd8c | < 1.4.5 |
MEDIUM | 5.4 | The Donate With QRCode WordPress plugin before 1.4.5 does not sanitise or escape its QRCode Image setting, which result … | — | wordfence |
| 9a09ec65-32e4-4841-a365-f67c15b80bf9 | < 7.8.5.11 |
MEDIUM | 5.4 | The WP Encryption β One Click Free SSL Certificate & SSL / HTTPS Redirect, Security & SSL Scan plugin for WordPress is… | — | wordfence |
| 99e8017a-346e-42d8-b9c1-29ed15da1156 | < 1.30.0 |
MEDIUM | 5.4 | The Ultimate Addons for Elementor WordPress Plugin before 1.30.0 has several widgets that are vulnerable to stored Cross… | — | wordfence |
| 9945c85b-a97a-4ad0-9d0a-69faf157563a | < 2.0.8 |
MEDIUM | 5.4 | The Simple 301 Redirects plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and includi… | — | wordfence |
| 991327f0-8bb9-4fdf-9c2a-b266ead962a3 | < 4.1.13 |
MEDIUM | 5.4 | The The Registration, User Profile, Membership, Content Restriction, User Directory, and Frontend Post Submission β WP… | — | wordfence |
| 99051b12-5a24-4108-9ea4-81f37a1c1b35 | < 2.0.99 |
MEDIUM | 5.4 | The Quads Ads Manager for Google AdSense plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions u… | — | wordfence |
| 98f87769-d4e4-4e27-9acf-a4e52bdbf734 | < 5.10.2 |
MEDIUM | 5.4 | The Shortcodes Ultimate WordPress plugin before 5.10.2 allows users with Contributor roles to perform stored XSS via sho… | — | wordfence |
| 98361cfd-1277-43fd-b0da-db2549628383 | < 1.8.3.3 |
MEDIUM | 5.4 | Unvalidated input and lack of output encoding in the Envira Gallery Lite WordPress plugin, versions before 1.8.3.3, did … | — | wordfence |
| 9831d7d4-14ba-4db5-99ea-72f366eda4d5 | < 1.4.12 |
MEDIUM | 5.4 | The Custom Post Carousels with Owl plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up … | — | wordfence |
| 982be9d7-fe9f-40c6-a474-fcc2d6455839 | < 9.2.2 |
MEDIUM | 5.4 | The Booking Calendar plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, … | — | wordfence |
| 97985b75-6ac9-4aba-8f76-5633418e7907 | < 2025.7 |
MEDIUM | 5.4 | The Advanced iFrame plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'additional' parameter in … | — | wordfence |
| 97628ee2-f7d9-4be5-8230-c38e531d1974 | < 1.0.9 |
MEDIUM | 5.4 | The Polls CP plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0.… | — | wordfence |
| 97396207-4892-4d1a-8740-3000484f1317 | < 2.1.0 |
MEDIUM | 5.4 | The WPFront Notification Bar WordPress plugin before 2.1.0.08087 does not properly sanitise and escape its settings, whi… | — | wordfence |
EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.
Scan My Website →