Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.
39,409 vulnerabilities found (page 113 of 1577)
| CVE ID | Plugin / Theme | Severity | CVSS | Description | Fixed In | Source |
|---|---|---|---|---|---|---|
| f9cee379-79f8-4a60-b1bb-ccab1e954512 | < 2.6.2 |
HIGH | 8.8 | The Tutor LMS β eLearning and online course solution plugin for WordPress is vulnerable to time-based SQL Injection vi… | — | wordfence |
| f9ce0ae8-4729-4236-b4e8-e5726f4d3101 | < 2.8.6 |
HIGH | 8.8 | Unrestricted file upload vulnerability in the wp_check_filetype function in wp-includes/functions.php in WordPress befor… | — | wordfence |
| f9bfa726-40e1-4417-9d59-289dbb3a17ff | < 3.7.35 |
HIGH | 8.8 | WordPress before 5.5.2 allows attackers to gain privileges via XML-RPC. | — | wordfence |
| f9b90e03-cdaa-4bd3-9afd-5d5c91a17962 | < 17.0.5 |
HIGH | 8.8 | The Contest Gallery plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 17.0.4 due to… | — | wordfence |
| f9a2d45c-397f-4a2b-9d7f-760b7d561c2a | < 1.0.8 |
HIGH | 8.8 | SQL injection vulnerability in the editgallery function in admin/gallery_func.php in the Huge-IT Image Gallery plugin <=… | — | wordfence |
| f98bb2a2-6525-4e0b-8bbd-968cf5b122dc | HIGH | 8.8 | The Superior FAQ plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.0.… | — | wordfence | |
| f970ce63-da48-44ad-935c-e75f9791103c | HIGH | 8.8 | The Pet World theme for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 2.8 via deseri… | — | wordfence | |
| f938a446-ae0b-4e06-9d55-26e2fea4d1e8 | HIGH | 8.8 | The Stock in & out WordPress plugin for WordPress is vulnerable to SQL Injection via the product_id parameter in version… | — | wordfence | |
| f90b6cdb-d929-493e-b078-4762b7e2f76d | < 1.2.36 |
HIGH | 8.8 | The Slider by 10Web WordPress plugin, versions before 1.2.36, in the bulk_action, export_full and save_slider_db functio… | — | wordfence |
| f8f92355-e664-4aeb-9094-9c8aa49cd3e7 | < 22-05-2018 |
HIGH | 8.8 | Mojoomla Hospital Management System for WordPress allows SQL Injection via the id parameter. | — | wordfence |
| f8f31d01-7bbc-4ef8-a099-b957f3d20118 | < 5.4.2 |
HIGH | 8.8 | The WPify Woo β Withdrawal, CRN/VAT, QR payments, Heureka and more for WooCommerce plugin for WordPress is vulnerable … | — | wordfence |
| f8ccf307-3bb8-45c5-91da-7d0f46e96694 | < 3.0.5 |
HIGH | 8.8 | The wp-better-permalinks plugin before 3.0.5 for WordPress has CSRF. | — | wordfence |
| f8c85f61-3e0a-4dbe-a5d6-ab01dea000a7 | < 0.9.8 |
HIGH | 8.8 | The Ecommerce Zone theme for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in al… | — | wordfence |
| f89e9c46-aca3-4b2f-b935-2976c510ed8b | < 3.5.6.9 |
HIGH | 8.8 | The 3DPrint plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and excluding, 3.5.6.9. … | — | wordfence |
| f89ba641-6c78-48d3-8826-96576198274f | < 3.2.1 |
HIGH | 8.8 | The Simple JWT Login WordPress plugin before 3.2.1 does not have nonce checks when saving its settings, allowing attacke… | — | wordfence |
| f89718f2-e25b-4393-986a-34ef3076a59c | < 2.3.10 |
HIGH | 8.8 | The WP Google Map plugin before 2.3.10 for WordPress has CSRF in the add/edit map feature. | — | wordfence |
| f8953c5c-0711-4c29-8055-62b3a168b369 | < 1.4.5 |
HIGH | 8.8 | The Logo Showcase Ultimate plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, … | — | wordfence |
| f87e78c5-e7f4-4af6-b64f-444fef23e890 | < 4.8.4 |
HIGH | 8.8 | The Slimstat Analytics plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including… | — | wordfence |
| f87b6987-8896-4edf-9b14-8582426adeb0 | < 1.3.2 |
HIGH | 8.8 | The My Account Page Editor plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validat… | — | wordfence |
| f8758fd2-9f43-4e31-b496-50b77180bc07 | < 2.1 |
HIGH | 8.8 | Cross-site request forgery (CSRF) vulnerability in the retrospam component in wp-admin/options-discussion.php in WordPre… | — | wordfence |
| f861ece5-21e4-4c7f-8701-bd9492b1b8bf | HIGH | 8.8 | The Game Users Share Buttons plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path… | — | wordfence | |
| f8615422-5db7-495d-9956-7d6f658f42bf | < 2.1.20 |
HIGH | 8.8 | The Blocksy Companion plugin for WordPress is vulnerable to authenticated arbitrary file upload in all versions up to, a… | — | wordfence |
| f8470662-2247-4159-9dac-f13677c94bdf | < 10.9.0 |
HIGH | 8.8 | The AcyMailing β An Ultimate Newsletter Plugin and Marketing Automation Solution for WordPress plugin for WordPress is… | — | wordfence |
| f8375ecf-e64b-4649-9341-fa45bf5556c3 | HIGH | 8.8 | The Resideo Plugin for Resideo - Real Estate WordPress Theme plugin for WordPress is vulnerable to privilege escalation … | — | wordfence | |
| f8297149-2de3-4e49-80f9-6ea59dea6bce | < 3.0.5 |
HIGH | 8.8 | The Recently plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the fet… | — | wordfence |
EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.
Scan My Website →