Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.
39,409 vulnerabilities found (page 154 of 1577)
| CVE ID | Plugin / Theme | Severity | CVSS | Description | Fixed In | Source |
|---|---|---|---|---|---|---|
| 91e61664-3b98-4a97-b35c-1ec88034d05b | < 3.7.17 |
HIGH | 8.8 | Cross-site request forgery (CSRF) vulnerability in the widget-editing accessibility-mode feature in WordPress before 4.7… | — | wordfence |
| 91c147f9-8179-4ce0-8d17-87ea47cf08fe | < 3.0.21 |
HIGH | 8.8 | The ec_ajax_update_option and ec_ajax_clear_all_taxrates functions in inc/admin/admin_ajax_functions.php in the WP EasyC… | — | wordfence |
| 91aa1f4c-ace7-43a4-a9e6-82c15e00d0eb | HIGH | 8.8 | The Inline Google Maps WordPress plugin through 5.11 does not have CSRF check in place when updating its settings, which… | — | wordfence | |
| 91998552-bf97-40e0-b5b2-be35a8d58b54 | < 2.4 |
HIGH | 8.8 | pixabay-images.php in the Pixabay Images plugin before 2.4 for WordPress does not validate hostnames, which allows remot… | — | wordfence |
| 916e6f8b-cb29-4062-9a05-0337cfdb382a | < 4.1 |
HIGH | 8.8 | The WP Replicate Post plugin for WordPress is vulnerable to SQL Injection via the post_id parameter in versions up to, a… | — | wordfence |
| 914e17ce-ab09-4e9f-9466-0ed21712cf66 | < 1.5.50 |
HIGH | 8.8 | The Events Made Easy plugin for WordPress is vulnerable to Cross-Site Request Forgery to Stored Cross-Site Scripting in … | — | wordfence |
| 91417d83-b645-4072-92f5-e0f3a398ac95 | HIGH | 8.8 | The Eximius theme for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in all versi… | — | wordfence | |
| 9133fa10-036b-4f42-9d0c-8e15d2625f5e | < 3.0.0 |
HIGH | 8.8 | The a3 Lazy Load, a3 Portfolio, Contact Us Page β Contact People, Dynamic Product Gallery for WooCommerce, a3 Responsi… | — | wordfence |
| 910c3d74-63ed-476d-b014-659d7780260f | < 1.1.19 |
HIGH | 8.8 | An issue was discovered in the responsive-coming-soon-page plugin 1.1.18 for WordPress. CSRF exists via wp-admin/admin.p… | — | wordfence |
| 90bab2a1-7c19-45d2-909f-05014fb24740 | < 1.09 |
HIGH | 8.8 | Cross-site request forgery (CSRF) vulnerability in the underConstruction plugin before 1.09 for WordPress allows remote … | — | wordfence |
| 90783d75-a255-4133-ac7b-32e0a70c8c69 | < 3.1.2 |
HIGH | 8.8 | The Firebase Support & Chat Management plugin for WordPress is vulnerable to privilege escalation in all versions up to,… | — | wordfence |
| 9077bdce-31c9-4877-8bb5-db87046125cc | < 5.2 |
HIGH | 8.8 | The Discy WordPress theme before 5.2 lacks CSRF checks in some AJAX actions, allowing an attacker to make a logged in ad… | — | wordfence |
| 90752679-4b21-4db7-89f4-19a1b2adb914 | < 4.2.4 |
HIGH | 8.8 | The Widget Options β Advanced Conditional Visibility for Gutenberg Blocks & Classic Widgets plugin for WordPress is vu… | — | wordfence |
| 90465354-0174-4f85-a66b-589d9408c3c8 | HIGH | 8.8 | The Delhivery Logistics Courier plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 1.… | — | wordfence | |
| 8fd1de2b-bb88-4f7c-b9eb-784eb7af17a6 | HIGH | 8.8 | Cross-site request forgery (CSRF) vulnerability in the qTranslate plugin 2.5.34 and earlier for WordPress allows remote … | — | wordfence | |
| 8fc28132-eae6-4082-988c-2d9e56ff1283 | < 9.5 |
HIGH | 8.8 | The Easy Social Share Buttons for WordPress plugin for WordPress is vulnerable to Local File Inclusion in all versions u… | — | wordfence |
| 8fb7dc15-45e6-4209-a4c6-34c9c268e17b | < 1.3.1 |
HIGH | 8.8 | The Subscribe to Unlock Lite plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including… | — | wordfence |
| 8f9db3b8-dd37-4d8b-b041-50b453858a39 | < 5.6.4 |
HIGH | 8.8 | The LatePoint β Calendar Booking Plugin for Appointments and Events plugin for WordPress is vulnerable to Privilege Es… | — | wordfence |
| 8f64361a-e5b5-4481-b25c-bdffeb80c198 | < 5.0.6 |
HIGH | 8.8 | The Genolve β AI image AI video generation plugin for WordPress is vulnerable to unauthorized modification of data due… | — | wordfence |
| 8f5722b0-0d54-4c44-b168-a886da1077cb | HIGH | 8.8 | The Browse As plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 0.2. This is… | — | wordfence | |
| 8f53a8d1-e7d6-4085-a1e6-f4263ec341b6 | < 1.8.1 |
HIGH | 8.8 | The Progress Planner plugin for WordPress is vulnerable to unauthorized modification of data that can lead to privilege … | — | wordfence |
| 8f4a9f9f-a342-4053-b4e0-cbaa9796e4ba | < 2.3.9 |
HIGH | 8.8 | Multiple SQL injection vulnerabilities in admin/handlers.php in the GigPress plugin before 2.3.9 for WordPress allow rem… | — | wordfence |
| 8efa8e86-6260-484a-a6da-18574bf41ed9 | HIGH | 8.8 | The Dynamic Elementor Addons plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including… | — | wordfence | |
| 8e926708-3c7f-4d7b-a64b-209f696984f9 | < 3.1.17 |
HIGH | 8.8 | The Classified Listing plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 3.1.… | — | wordfence |
| 8e50c519-7d79-4270-92e8-75e54bb08cff | < 7.1.2 |
HIGH | 8.8 | The Custom Login Page Styler β Login Protected Private Site , Change wp-admin login url , WordPress login logo , Tempo… | — | wordfence |
EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.
Scan My Website →