Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.
40,402 vulnerabilities found (page 1299 of 1617)
| CVE ID | Plugin / Theme | Severity | CVSS | Description | Fixed In | Source |
|---|---|---|---|---|---|---|
| a02ec9a2-6449-4975-9a68-2c8df5e28b31 | MEDIUM | 4.4 | The Stellissimo Text Box plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all ver… | — | wordfence | |
| 9fcdc458-783b-4ad5-8484-fdef4d814d71 | < 5.0.3 |
MEDIUM | 4.4 | The Robo Gallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 5.0… | — | wordfence |
| 9fcb65a0-4218-4728-9c29-0d1a03f438a6 | < 1.3 |
MEDIUM | 4.4 | The Visual Footer Credit Remover plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'selector' pa… | — | wordfence |
| 9fc46de4-af1c-4e38-9caa-55b7b18a69ae | MEDIUM | 4.4 | The WP Not Login Hide (WPNLH) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in al… | — | wordfence | |
| 9fc18fee-5813-4134-8c4d-44710665857a | < 1.7.7 |
MEDIUM | 4.4 | The My Content Management plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in versio… | — | wordfence |
| 9f93ee42-c21d-47cf-b140-65809da75653 | MEDIUM | 4.4 | The Squirrels Auto Inventory plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all… | — | wordfence | |
| 9f79fe15-65a1-44ab-a43e-1410ce1f1d77 | < 1.1.11 |
MEDIUM | 4.4 | The WordPress Affiliates Plugin β SliceWP Affiliates plugin for WordPress is vulnerable to Stored Cross-Site Scripting… | — | wordfence |
| 9ef9b22f-a0dc-43e5-9597-5dcc6ca3fc23 | MEDIUM | 4.4 | The Exifography plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.3.… | — | wordfence | |
| 9eb1c2b3-527c-45b6-a1bd-dc9c553b8aa8 | < 3.25 |
MEDIUM | 4.4 | The Media Library Assistant plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and inc… | — | wordfence |
| 9ea21bf9-9e2a-45d1-8cb7-db821ca13e70 | < 1.6.3 |
MEDIUM | 4.4 | The DN Footer Contacts plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versi… | — | wordfence |
| 9e9e0214-b88e-4125-8c10-850ca736e920 | < 20240216 |
MEDIUM | 4.4 | The Simple Ajax Chat β Add a Fast, Secure Chat Box plugin for WordPress is vulnerable to Stored Cross-Site Scripting v… | — | wordfence |
| 9e8346a4-4077-469f-9182-d6cf12f60776 | MEDIUM | 4.4 | The EC Stars Rating plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, … | — | wordfence | |
| 9e1a2de1-f153-40fb-81b6-4b7c1c374839 | MEDIUM | 4.4 | The DP ALTerminator - Missing ALT manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions … | — | wordfence | |
| 9df97805-b425-49b1-86c1-e66213dacd2b | < 4.5.6 |
MEDIUM | 4.4 | The AI ChatBot plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in versions up to, a… | — | wordfence |
| 9dd75955-3c9e-4cac-b952-f705a2129707 | MEDIUM | 4.4 | The Real WP Shop Lite Ajax eCommerce Shopping Cart plugin for WordPress is vulnerable to Stored Cross-Site Scripting via… | — | wordfence | |
| 9dc640c8-3740-4770-b729-fb45ecec2b45 | MEDIUM | 4.4 | The Column-Matic plugin for WordPress is vulnerable to Stored Cross-Site Scripting via an unknown parameter in versions … | — | wordfence | |
| 9dc3c8e7-464e-4742-bc96-5a1dc8b27ae3 | < 4.5.14 |
MEDIUM | 4.4 | The WP Meta SEO plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 4.5.… | — | wordfence |
| 9d8e0ad2-3cfb-443f-9958-9639d0745dd7 | < 1.2 |
MEDIUM | 4.4 | The Peadig's Like & Share Button plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in… | — | wordfence |
| 9d79ce22-33ef-4dfb-a842-591cd7cedc94 | < 1.16 |
MEDIUM | 4.4 | The Web Accessibility By accessiBe plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings … | — | wordfence |
| 9d70294c-e2a4-4a34-8341-fb2361cb0819 | < 4.7.5 |
MEDIUM | 4.4 | The WP ULike β All-in-One Engagement Toolkit plugin for WordPress is vulnerable to Stored Cross-Site Scripting via adm… | — | wordfence |
| 9d431b21-10df-485b-9d6d-b72363681fd5 | < 1.12.17 |
MEDIUM | 4.4 | The Giveaways and Contests by RafflePress β Get More Website Traffic, Email Subscribers, and Social Followers plugin f… | — | wordfence |
| 9d21191c-32ef-4de6-8e95-ad66779e42f9 | < 1.2.5 |
MEDIUM | 4.4 | The Serious Slider plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and includin… | — | wordfence |
| 9d0b1e05-0e28-4cf5-a278-ea91b6c9d253 | < 1.1.1 |
MEDIUM | 4.4 | The CPO Content Types plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in versions u… | — | wordfence |
| 9cb6384a-f9dc-454c-be39-c2c681e57d36 | < 2.2.0 |
MEDIUM | 4.4 | The Contact Form Builder by Bit Form plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin setting… | — | wordfence |
| 9c657ea2-ff7b-4ef2-a7dd-a330484dd821 | MEDIUM | 4.4 | The Sailthru Triggermail plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all ver… | — | wordfence |
EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.
Scan My Website →