Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.
41,761 vulnerabilities found (page 108 of 1671)
| CVE ID | Plugin / Theme | Severity | CVSS | Description | Fixed In | Source |
|---|---|---|---|---|---|---|
| 9affd2b9-9576-435e-931d-f60816af0b91 | < 1.7.21 |
CRITICAL | 9.1 | The CBX Bookmark & Favorite plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 1.7.20… | — | wordfence |
| 9addaa26-46b3-4fbf-8986-0b8c8f2dd286 | CRITICAL | 9.1 | The Shortcode Addons- with Visual Composer, Divi, Beaver Builder and Elementor Extension plugin for WordPress is vulnera… | — | wordfence | |
| 9a5ce873-e90b-4bdc-b428-426818ff9a86 | < 3.6.8 |
CRITICAL | 9.1 | The WP All Import plugin for WordPress is vulnerable to arbitrary code execution in versions up to, and including, 3.6.7… | — | wordfence |
| 9a29aea7-9e22-4edb-80d9-266843a416a5 | < 3.15 |
CRITICAL | 9.1 | The WordPress plugin, WP Database Reset through 3.1, contains a flaw that allowed any unauthenticated user to reset any … | — | wordfence |
| 98a274eb-036f-44f1-861d-1cfea0b34d7f | < 4.0.4 |
CRITICAL | 9.1 | The LearnPress Export Import plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 4.0.3… | — | wordfence |
| 97416640-c076-4f5e-9119-adbca2fcc495 | CRITICAL | 9.1 | Open proxy in Wordpress plugin google-adsense-and-hotel-booking v1.05 | — | wordfence | |
| 9715d1b2-1d82-4f48-89c3-9a389ab31360 | < 2.2.70 |
CRITICAL | 9.1 | The AI Engine plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in all ve… | — | wordfence |
| 96e2ba3d-4e6d-42b8-832c-03ef4915cadb | < 2.4.2 |
CRITICAL | 9.1 | SQL injection vulnerability in fim_rss.php in the fGallery 2.4.1 plugin for WordPress allows remote attackers to execute… | — | wordfence |
| 93d00b7e-cad1-4521-8acf-94818258a9d9 | < 1.5.16 |
CRITICAL | 9.1 | The Scape - Multipurpose WordPress theme theme for WordPress is vulnerable to arbitrary file deletion due to insufficien… | — | wordfence |
| 901e85b9-0948-4a00-a29f-a726b53ba51b | < 2.35.8 |
CRITICAL | 9.1 | The 404 Solution plugin for WordPress is vulnerable to SQL Injection in all versions up to, and including, 2.35.7 due to… | — | wordfence |
| 8ebb1072-ea05-4914-961d-0d8f20248078 | < 3.5.0 |
CRITICAL | 9.1 | The WP STAGING WordPress Backup Plugin β Migration Backup Restore plugin for WordPress is vulnerable to arbitrary file… | — | wordfence |
| 8cf1889b-c249-4bd7-ae23-2db66ca9d873 | CRITICAL | 9.1 | The FormGent β Next-Gen AI Form Builder for WordPress with Multi-Step, Quizzes, Payments & More plugin for WordPress i… | — | wordfence | |
| 8b7e1da1-8e40-4119-894d-43e82e188608 | < 1.8.11 |
CRITICAL | 9.1 | The VikBooking Hotel Booking Engine & PMS plugin for WordPress is vulnerable to arbitrary file deletion due to insuffici… | — | wordfence |
| 8b0f58b8-46d6-4deb-bfcc-806bb635b060 | < 5.3.4 |
CRITICAL | 9.1 | The WooCommerce Multilingual & Multicurrency with WPML plugin for WordPress is vulnerable to SQL Injection in all versio… | — | wordfence |
| 8aa0fffa-475e-4227-9ab1-17ca6fcce529 | < 2.1.1 |
CRITICAL | 9.1 | In Firebase PHP-JWT before 6.0.0, an algorithm-confusion issue (e.g., RS256 / HS256) exists via the kid (aka Key ID) hea… | — | wordfence |
| 8a24e409-8aa9-4d18-b428-b202407fdbfe | CRITICAL | 9.1 | The PluginPass β WordPress PRO Plugin/Theme Licensing (Public Alpha) plugin for WordPress is vulnerable to arbitrary f… | — | wordfence | |
| 88b8a93b-f34f-4188-8153-ce36b03b6a4c | < 4.9.12 |
CRITICAL | 9.1 | The Spiffy Calendar plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 4.9.11 due to … | — | wordfence |
| 885dd550-4c80-4e36-8dae-cb47c1500ea5 | CRITICAL | 9.1 | The WP Travel Pro plugin for WordPress is vulnerable to arbitrary user deletion via the /wp-json/wp-travel/v1/travel-gui… | — | wordfence | |
| 8834d017-04e8-4748-9acc-3f2213fc8592 | CRITICAL | 9.1 | The CarZone - A Complete Car Dealer HTML Wire-Frame theme for WordPress is vulnerable to arbitrary file deletion due to … | — | wordfence | |
| 86d5af9f-ffe9-4d22-885d-e117da7687de | < 3.4.5 |
CRITICAL | 9.1 | The Advanced Order Export For WooCommerce plugin for WordPress is vulnerable to Remote Code Execution in all versions up… | — | wordfence |
| 86218eaa-916b-4197-8fa4-62b527bd29a4 | CRITICAL | 9.1 | The Anona - Pest Control WordPress Theme theme for WordPress is vulnerable to arbitrary file deletion due to insufficien… | — | wordfence | |
| 84ed666c-3154-4f26-beae-aba190f7a2f4 | < 10.1.5 |
CRITICAL | 9.1 | The Import Spreadsheets from Microsoft Excel plugin for WordPress is vulnerable to arbitrary file uploads due to missing… | — | wordfence |
| 813532fd-0613-47df-a4d0-54d6b33f37b3 | CRITICAL | 9.1 | The Zynith SEO plugin for WordPress is vulnerable to unauthorized modification of data that can lead to a denial of serv… | — | wordfence | |
| 80303684-5e10-474b-b6be-a63327015826 | CRITICAL | 9.1 | The Forms to Zapier, Integromat, IFTTT, Workato, Automate.io, elastic.io, Built.io, APIANT, Webhook plugin for WordPress… | — | wordfence | |
| 80067f73-53df-4014-b171-8435061a5cc7 | < 2.7.8.5 |
CRITICAL | 9.1 | The Participants Database plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path va… | — | wordfence |
EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.
Scan My Website →