Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.
39,409 vulnerabilities found (page 149 of 1577)
| CVE ID | Plugin / Theme | Severity | CVSS | Description | Fixed In | Source |
|---|---|---|---|---|---|---|
| 9e9cfb9b-6951-4246-9cd6-dd64fee3a1bc | HIGH | 8.8 | The Account Switcher plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.… | — | wordfence | |
| 9e991342-b0d1-486c-a24d-e4d3f2be9b91 | < 6.4.4 |
HIGH | 8.8 | The Nasa Core plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and excluding, 6.4.4. This m… | — | wordfence |
| 9e3e996b-6988-42ab-9766-ddc070243c1f | < 1.0.4 |
HIGH | 8.8 | The Easy Username Updater plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and includ… | — | wordfence |
| 9e15727a-35c4-42c0-9997-cdcd40ac8e5f | HIGH | 8.8 | A WordPress plugin and several WordPress themes developed by AccessPress Themes are vulnerable to unauthorized plugin de… | — | wordfence | |
| 9e0d441d-1da5-45e7-8a14-ce178099c0cc | < 4.0.35 |
HIGH | 8.8 | The Eventin plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and i… | — | wordfence |
| 9e0cba5b-5833-4c02-ac17-830994b0f207 | < 1.9.31 |
HIGH | 8.8 | The Vikinger theme for WordPress is vulnerable to privilege in all versions up to, and including, 1.9.30. This is due to… | — | wordfence |
| 9df24b5e-109e-43ae-b55b-8514281a631f | < 2.1 |
HIGH | 8.8 | The Favicon Generator plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including,… | — | wordfence |
| 9dd1e52c-83b7-4b3e-a791-a2c0ccd856bc | < 7.6.6 |
HIGH | 8.8 | The wpDiscuz plugin for WordPress is vulnerable to SQL Injection via the 'visibleCommentIds' parameter in versions up to… | — | wordfence |
| 9dbaafbb-ab7b-41d8-a8f7-178b9d42b4c5 | < 9.2 |
HIGH | 8.8 | The Amelia Booking plugin for WordPress is vulnerable to Insecure Direct Object References in versions 8.3 to 9.1.2. Thi… | — | wordfence |
| 9d979950-d365-4750-a4f1-df9335d3452d | < 1.6.4 |
HIGH | 8.8 | The Qi Addons For Elementor plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and includ… | — | wordfence |
| 9d866870-dff4-44c0-b1ee-781370f7e8ae | < 2.4.2 |
HIGH | 8.8 | The EventON plugin for WordPress is vulnerable to Local File Inclusion via the evo_block_render_callback() function in v… | — | wordfence |
| 9d72a965-5d81-4619-ad8b-46960a89bf1b | < 3.1.2 |
HIGH | 8.8 | The Survey Maker plugin for WordPress is vulnerable to SQL injection in versions before 3.1.2 via the 'ays_surveys_expor… | — | wordfence |
| 9d47df99-cff5-4be7-ab8e-ef333cf3755b | < 3.0.9 |
HIGH | 8.8 | The The Ultimate WordPress Toolkit β WP Extended plugin for WordPress is vulnerable to unauthorized modification of da… | — | wordfence |
| 9d387a5c-717c-4383-af7d-5a5f48628cb7 | < 2.4 |
HIGH | 8.8 | Low privileged users can use the AJAX action 'cp_plugins_do_button_job_later_callback' in the Captchinoo, Google recaptc… | — | wordfence |
| 9d2dde9f-c3c3-4e6e-a7e2-a0e511bff010 | < 57.0 |
HIGH | 8.8 | The School Management System for Wordpress plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions … | — | wordfence |
| 9d15e418-36bb-4f53-ac67-8f6122591dd2 | < 4.0.2 |
HIGH | 8.8 | The Stream plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 4.0.1.… | — | wordfence |
| 9cfd5cfa-9075-4408-bfb1-fb0c3494f61e | < 1.4.5 |
HIGH | 8.8 | The Hero Banner Ultimate plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.… | — | wordfence |
| 9cd2ca03-e644-4bcd-b4b1-a547494fed7d | < 2.2.6 |
HIGH | 8.8 | The Booked plugin for WordPress is vulnerable to authorization bypass due to missing capability checks on several functi… | — | wordfence |
| 9ccdf08b-8b74-4b58-8779-3b07ef2d7b2f | < 2.1.7 |
HIGH | 8.8 | The LightSync Pro plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in th… | — | wordfence |
| 9cae7702-e531-45b9-9131-42edbc073a07 | < 6.5.6 |
HIGH | 8.8 | The Bit File Manager β 100% Free & Open Source File Manager and Code Editor for WordPress plugin for WordPress is vuln… | — | wordfence |
| 9c97283b-404d-4138-b8a1-057f068e3564 | < 3.5.29 |
HIGH | 8.8 | The MasterStudy LMS plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 3.5.28.… | — | wordfence |
| 9c7cf6f9-6fd0-487f-93cf-516b52736512 | < 1.1 |
HIGH | 8.8 | The wps-hide-login plugin before 1.1 for WordPress has CSRF that affects saving an option value. | — | wordfence |
| 9c32fcaf-afc3-4493-8cd8-6f49bbe40c7b | < 1.5.9 |
HIGH | 8.8 | The Simple Registration for WooCommerce plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions… | — | wordfence |
| 9c17d18a-090f-4b35-a257-cfc0a16d5459 | HIGH | 8.8 | The Social Media Share Buttons plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and inc… | — | wordfence | |
| 9bed2e86-1cc0-4fed-a44f-0c495c423e22 | < 2.3.5 |
HIGH | 8.8 | The BuddyPress plugin for WordPress is vulnerable to Privilege Escalation in versions up to, and including, 2.3.4. This … | — | wordfence |
EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.
Scan My Website →