Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.
39,409 vulnerabilities found (page 150 of 1577)
| CVE ID | Plugin / Theme | Severity | CVSS | Description | Fixed In | Source |
|---|---|---|---|---|---|---|
| 9be6c569-4832-4b57-9123-0b2a26dac3a6 | HIGH | 8.8 | Multiple themes for WordPress by Themify Themes are vulnerable to arbitrary file uploads due to missing file type valida… | — | wordfence | |
| 9be6089f-a4ca-447c-b3fa-6917b1383512 | HIGH | 8.8 | The Maan Addons For Elementor plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and includin… | — | wordfence | |
| 9bc3039c-8e96-42e9-a28d-d3204f3e84f7 | < 3.0.4 |
HIGH | 8.8 | The wp_ajax_save_fbe_settings and wp_ajax_delete_fbe_settings AJAX actions of the Facebook for WordPress plugin before 3… | — | wordfence |
| 9bbb3c65-f02c-4d6d-bd4e-b3232af5e21b | < 2.7.1 |
HIGH | 8.8 | The Tutor LMS plugin for WordPress is vulnerable to time-based SQL Injection via the ‘question_id’ parameter in vers… | — | wordfence |
| 9bb520df-e838-4335-bd4f-97026082a204 | < 4.16.19 |
HIGH | 8.8 | The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePr… | — | wordfence |
| 9bb22acd-ffdb-4897-a657-538969aa6f41 | < 1.1.1 |
HIGH | 8.8 | The Video & Photo Gallery for Ultimate Member plugin for WordPress is vulnerable to arbitrary file uploads due to missin… | — | wordfence |
| 9baf0a14-600b-4c0e-9121-71c28653e530 | < 1.8.17.0 |
HIGH | 8.8 | The WP Mailster plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 1.8.16.0 due to in… | — | wordfence |
| 9b95fe0e-4677-4667-9a84-96801b547088 | < 1.7.6 |
HIGH | 8.8 | The AutomatorWP WordPress plugin before 1.7.6 does not perform capability checks which allows users with Subscriber role… | — | wordfence |
| 9b888f0c-5547-4ff7-9721-50166e3f0117 | < 1.14.15 |
HIGH | 8.8 | The MultiParcels Shipping plugin for WordPress is vulnerable to SQL Injection via the ‘id’ parameter in versions up … | — | wordfence |
| 9b4eba78-29f2-4357-ab3c-7bc3c20e0e75 | < 0.9.108 |
HIGH | 8.8 | The Migration, Backup, Staging – WPvivid plugin for WordPress is vulnerable to PHP Object Injection in all versions up… | — | wordfence |
| 9b4ea9ae-6a76-4dcb-ae3a-329bfb1ba547 | HIGH | 8.8 | The WP-Recall plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 16.26.14. Thi… | — | wordfence | |
| 9b4de243-d337-4f29-a766-bcafb3848d1c | < 2.2.5 |
HIGH | 8.8 | The Review Schema plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 2.2.4… | — | wordfence |
| 9aff7b03-4f03-434c-be87-b10ceeb4e625 | < 2.12.0 |
HIGH | 8.8 | The Ultimate Member plugin for WordPress is vulnerable to Account Takeover via Password Reset Link Disclosure in all ver… | — | wordfence |
| 9af8267f-48b1-4537-8985-6af1245ceed5 | < 4.8 |
HIGH | 8.8 | The FoodBakery | Delivery Restaurant Directory WordPress Theme theme for WordPress is vulnerable to unauthorized access … | — | wordfence |
| 9aeeb92f-26f8-44b5-a523-abc33043efff | HIGH | 8.8 | The multisite-post-duplicator plugin for WordPress has wp-admin/tools.php?page=mpd CSRF. | — | wordfence | |
| 9ae8de00-ba4c-48d2-a566-13dac0bc4312 | < 1.4.0 |
HIGH | 8.8 | The JetBackup – WP Backup, Migrate & Restore plugin for WordPress is vulnerable to Cross-Site Request Forgery in versi… | — | wordfence |
| 9adc6f3e-2360-480c-9f91-f47474e66c78 | < 1.1.2 |
HIGH | 8.8 | An issue was discovered in the weblizar-pinterest-feeds plugin 1.1.1 for WordPress. CSRF exists via wp-admin/admin-ajax.… | — | wordfence |
| 9acdbd48-8d38-4d75-b2b1-c993e25cf92a | HIGH | 8.8 | The Levo Slideshow plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient file type validation… | — | wordfence | |
| 9ac6817e-5794-4ecb-ab3c-58b09a4e52c0 | HIGH | 8.8 | The Estatik Mortgage Calculator plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and includ… | — | wordfence | |
| 9ab28410-76c5-43cb-b87a-c99f8867167c | < 2.9.3 |
HIGH | 8.8 | The Folders plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the hand… | — | wordfence |
| 9a9c8c4f-ce07-4fe5-a573-ece675d51441 | < 1.8.9 |
HIGH | 8.8 | … | — | wordfence |
| 9a5bbbc9-7e69-45fd-a0dd-9b4faa026f95 | < 1.7.8 |
HIGH | 8.8 | The WPCOM Member plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.7.7. Thi… | — | wordfence |
| 9a4f28bb-7669-483a-b93a-276b7a10826a | < 3.8.1.2 |
HIGH | 8.8 | The JetEngine plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 3.7.2. T… | — | wordfence |
| 9a485314-cd68-400c-b398-2f8529c6a3ab | < 2.2.33.34 |
HIGH | 8.8 | The Product Enquiry for WooCommerce, WooCommerce product catalog plugin for WordPress is vulnerable to PHP Object Inject… | — | wordfence |
| 9a446fe7-c97a-436e-b494-b924e6518297 | < 3.19 |
HIGH | 8.8 | The Media Library Assistant plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type valida… | — | wordfence |
EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.
Scan My Website →