Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.
39,409 vulnerabilities found (page 153 of 1577)
| CVE ID | Plugin / Theme | Severity | CVSS | Description | Fixed In | Source |
|---|---|---|---|---|---|---|
| 947626b4-c640-4b45-8186-2ed4ff7c2c18 | < 19.6.2 |
HIGH | 8.8 | The REHub Framework plugin for WordPress is vulnerable to SQL Injection in versions prior to 19.6.2 due to insufficient … | — | wordfence |
| 94356695-d2b1-4144-a0ca-b638d4e70d8f | < 1.8.8 |
HIGH | 8.8 | The WpTravelly plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 1.8.7 via de… | — | wordfence |
| 942ae035-91b3-4330-800c-2dbe94a4b4b5 | < 2.2.5 |
HIGH | 8.8 | admin/includes/class.import.snippet.php in the "Woody ad snippets" plugin before 2.2.5 for WordPress allows unauthentica… | — | wordfence |
| 93ff1634-d520-4895-8822-2dbfa7b5e030 | < 1.13.3 |
HIGH | 8.8 | In the Form Maker plugin before 1.13.3 for WordPress, it's possible to achieve SQL injection in the function get_labels_… | — | wordfence |
| 93ef0a2c-2197-4c23-b5c4-5a94bd44130d | < 2.2.6 |
HIGH | 8.8 | The Side Menu Lite WordPress plugin before 2.2.6 does not sanitise user input from the List page in the admin dashboard … | — | wordfence |
| 93a4d653-a852-41c1-8942-8f059420aeb1 | < 8.4.4 |
HIGH | 8.8 | SQL injection vulnerability in Booking Calendar plugin 8.4.3 for WordPress allows remote attackers to execute arbitrary … | — | wordfence |
| 9391474f-8cf8-4e8b-b3e6-39b397b7b6b6 | < 2.5.2 |
HIGH | 8.8 | The Master Slider - Responsive Touch Slider plugin for WordPress is vulnerable to blind SQL Injection via the ‘orderby… | — | wordfence |
| 938be2d0-1e56-42d5-874e-574e78a44932 | < 2013.0.1.41 |
HIGH | 8.8 | The Developer Formatter plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to 2013.0.1.41. … | — | wordfence |
| 938b8a4f-96cf-488d-8fd9-116caa929ccf | < 14.1.8 |
HIGH | 8.8 | The AI ChatBot for WooCommerce with ChatGPT, Retargeting, Exit Intent plugin for WordPress is vulnerable to arbitrary fi… | — | wordfence |
| 9382d94c-3767-4d05-ada7-2857713b9e3a | < 3.0.0 |
HIGH | 8.8 | The Sahifa theme for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.4.0. This… | — | wordfence |
| 93495395-42cc-4787-be95-4691ff77d01b | < 1.2.3 |
HIGH | 8.8 | The GeekyBot — AI Copilot, Chatbot, WooCommerce Lead Gen & Zero-Prompt Content plugin for WordPress is vulnerable to a… | — | wordfence |
| 931e83b6-b05a-4f48-a159-e15cc99e0fe4 | < 2.0.4 |
HIGH | 8.8 | The export_data function of the Simple 301 Redirects by BetterLinks WordPress plugin before 2.0.4 had no capability or n… | — | wordfence |
| 93164941-effe-4363-811e-3161cff10c88 | < 2.0.7 |
HIGH | 8.8 | The WP Simple Booking Calendar WordPress plugin before 2.0.7 did not escape, validate or sanitise the orderby parameter … | — | wordfence |
| 93027dd1-f36a-4954-a8d2-b77bbbaef6fb | < 1.1.19 |
HIGH | 8.8 | The Hydra Booking plugin for WordPress is vulnerable to Privilege Escalation due to a missing capability check on the tf… | — | wordfence |
| 92f6f3f7-c49b-4290-806f-6add333159b9 | < 4.6.2 |
HIGH | 8.8 | The Conversios.io WordPress plugin before 4.6.2 does not sanitise, validate and escape the sync_progressive_data paramet… | — | wordfence |
| 92f02a92-9364-492e-a896-2f7e6f8b3b13 | < 1.6.0 |
HIGH | 8.8 | The WP Shopify plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.5.9. This … | — | wordfence |
| 92d048a2-3ecb-466d-9e0c-f1b654d2a944 | < 4.2.2 |
HIGH | 8.8 | The WordPress CRM, Email & Marketing Automation for WordPress | Award Winner — Groundhogg plugin for WordPress is vuln… | — | wordfence |
| 92c88e7f-9393-4e44-8a1d-314f6560bf63 | HIGH | 8.8 | The GoCodes plugin for WordPress is vulnerable to blind SQL Injection via the ‘gcid’ parameter in versions up to, an… | — | wordfence | |
| 9269d18d-8d83-43ff-b777-ba8f58321e9e | HIGH | 8.8 | The Offsprout Page Builder plugin for WordPress is vulnerable to Privilege Escalation due to improper authorization plac… | — | wordfence | |
| 92652339-ec86-4069-aeee-91c314ed2540 | < 5.39 |
HIGH | 8.8 | The WP Captcha PRO (the premium version of the Advanced Google reCAPTCHA plugin, both have the same slug) plugin for Wor… | — | wordfence |
| 925ca72b-3761-42e5-aace-b31d42bc9a73 | < 5.5.0 |
HIGH | 8.8 | The Content Egg plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 5.4.0… | — | wordfence |
| 925af22b-a728-496e-a63a-5966347ebe6c | < 7.29 |
HIGH | 8.8 | The WP Import – Ultimate CSV XML Importer for WordPress plugin for WordPress is vulnerable to Remote Code Execution in… | — | wordfence |
| 921795f5-0477-474b-a9c2-3f5955c6f131 | < 2.17 |
HIGH | 8.8 | The WC Affiliate plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 2.16 via d… | — | wordfence |
| 921489e9-a083-47b3-a20d-e2566b51d8d4 | < 1.5 |
HIGH | 8.8 | SQL injection vulnerability in the WP Jobs plugin before 1.5 for WordPress allows authenticated users to execute arbitra… | — | wordfence |
| 91f67907-9b42-4fa3-a333-2ac0d3afaaad | < 4.1.0 |
HIGH | 8.8 | The Post Snippets – Custom WordPress Code Snippets Customizer plugin for WordPress is vulnerable to Remote Code Execut… | — | wordfence |
EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.
Scan My Website →