Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.
40,407 vulnerabilities found (page 1434 of 1617)
| CVE ID | Plugin / Theme | Severity | CVSS | Description | Fixed In | Source |
|---|---|---|---|---|---|---|
| 9f35a407-a7dd-4b6b-8c77-9a20ba797429 | < 4.0.11 |
MEDIUM | 4.3 | The ARMember β Membership Plugin, Content Restriction, Member Levels, User Profile & User signup plugin for WordPress … | — | wordfence |
| 9f34a917-1c96-4f2a-b496-8ff848cdc314 | < 4.1.4 |
MEDIUM | 4.3 | The Elementor Website Builder β more than just a page builder plugin for WordPress is vulnerable to Sensitive Informat… | — | wordfence |
| 9f19030c-bee2-4d04-a45f-517783cece5e | < 4.0.1 |
MEDIUM | 4.3 | The JCH Optimize plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a functi… | — | wordfence |
| 9f1902e7-66e9-417f-97ba-4db766cf29f1 | MEDIUM | 4.3 | The Sunny Search plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.0.… | — | wordfence | |
| 9f1078b8-f458-46a6-9982-e8d2d1d1b73b | < 3.12.3 |
MEDIUM | 4.3 | The Happy Addons for Elementor plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up t… | — | wordfence |
| 9f0cc8da-5377-4e1a-85d0-d8b6f314818f | < 2.2.0 |
MEDIUM | 4.3 | The Term Order plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.1.0.… | — | wordfence |
| 9effc186-c225-4b3b-9b8c-c453505a41de | < 1.3.7.3 |
MEDIUM | 4.3 | The HUSKY β Products Filter Professional for WooCommerce plugin for WordPress is vulnerable to Insecure Direct Object … | — | wordfence |
| 9efea864-544d-4c13-a5a8-68d21ce6f762 | MEDIUM | 4.3 | The Litho Addons plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a functi… | — | wordfence | |
| 9efc782a-ec61-4741-81fd-a263a2739e16 | < 4.0.7 |
MEDIUM | 4.3 | The Essential Blocks plugin for WordPress is vulnerable to unauthorized use of functionality due to a missing capability… | — | wordfence |
| 9efb88e2-381f-4e26-80bb-1b034ffc1c91 | < 1.0.26 |
MEDIUM | 4.3 | The Table & Contact Form 7 Database β Tablesome plugin for WordPress is vulnerable to Cross-Site Request Forgery in ve… | — | wordfence |
| 9efa43c6-1ec9-4380-9c53-eca47cdc9ec9 | MEDIUM | 4.3 | The User Profile Meta Manager plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and in… | — | wordfence | |
| 9eef053c-16a1-4624-8393-08e78b221d4f | < 9.18 |
MEDIUM | 4.3 | The WP Spell Check plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including… | — | wordfence |
| 9ee26828-fa3c-4014-bcf0-8e262c39a5dc | MEDIUM | 4.3 | The Raychat plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.2.1. Th… | — | wordfence | |
| 9ed9c59c-191f-4219-8701-ce2f088b3b6d | < 2.6.94 |
MEDIUM | 4.3 | The Smart Forms plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2… | — | wordfence |
| 9ed24d24-e899-4850-8552-4f6cf45fa467 | < 3.1.0 |
MEDIUM | 4.3 | The Notifima β WooCommerce Stock Manager, Inventory Management, Waitlist plugin for WordPress is vulnerable to Sensiti… | — | wordfence |
| 9ed0d4b6-f553-4aa5-9dfa-49df78f4269d | < 3.6.16 |
MEDIUM | 4.3 | The PrettyLinks β Affiliate Links, Link Branding, Link Tracking, Marketing and Stripe Payments Plugin plugin for WordP… | — | wordfence |
| 9ecd4231-d1b7-420e-a8af-1508fed11d1f | < 8.5.5 |
MEDIUM | 4.3 | The WP VR plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in v… | — | wordfence |
| 9ebeba9e-bda9-4cdd-bb59-fd7265f49c50 | < 1.3.4 |
MEDIUM | 4.3 | The Thim Kit for Elementor β Pre-built Templates & Widgets for Elementor plugin for WordPress is vulnerable to Insecur… | — | wordfence |
| 9ea49a07-022e-4c9a-b1d3-ff900b337067 | < 1.1.6 |
MEDIUM | 4.3 | The AffiEasy plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.1.4. T… | — | wordfence |
| 9ea2dfc5-0dcc-4ea1-9ade-d59021e078fa | < 1.3.7.4 |
MEDIUM | 4.3 | The HUSKY β Products Filter Professional for WooCommerce plugin for WordPress is vulnerable to Insecure Direct Object … | — | wordfence |
| 9e9a5b7e-db74-4c66-a659-85b2509fded4 | < 2.9.12 |
MEDIUM | 4.3 | The WP User Manager β User Profile Builder & Membership plugin for WordPress is vulnerable to unauthorized access of d… | — | wordfence |
| 9e932f7a-7012-499c-922f-29ed567d4bc4 | < 2.6.6 |
MEDIUM | 4.3 | The WPSpeed plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.6.5… | — | wordfence |
| 9e6eec31-0603-40ab-9ed1-eedb163de1d6 | MEDIUM | 4.3 | The Misiek Photo Album plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and inclu… | — | wordfence | |
| 9e4a1671-56aa-4003-bed7-b793d14522d7 | < 17.6 |
MEDIUM | 4.3 | The WP Google Review Slider plugin for WordPress is vulnerable to unauthorized access due to a missing capability check … | — | wordfence |
| 9e45feb6-5ffa-4ad3-9549-4414988f040e | < 3.2 |
MEDIUM | 4.3 | The Library Management System plugin for WordPress is vulnerable to unauthorized modification of data due to a missing c… | — | wordfence |
EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.
Scan My Website →