Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.
39,652 vulnerabilities found (page 296 of 1587)
| CVE ID | Plugin / Theme | Severity | CVSS | Description | Fixed In | Source |
|---|---|---|---|---|---|---|
| 9d4ff5ed-8857-46b8-942b-ac0f47880a95 | < 5.2.5 |
HIGH | 7.5 | The Advanced File Manager plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, an… | — | wordfence |
| 9d4f47af-294a-4c3a-accd-9ae674916a38 | < 2.5.4 |
HIGH | 7.5 | The LearnDash LMS WordPress plugin before 2.5.4 does not have any authorisation and validation of the file to be uploade… | — | wordfence |
| 9d17f26b-e8b7-480d-bf03-2cfdb261fa28 | < 3.0.0 |
HIGH | 7.5 | An unprivileged user could use the functionality of the NS WooCommerce Watermark WordPress plugin through 2.11.3 to load… | — | wordfence |
| 9cecce4d-5d4a-4286-97dc-88a379e21b60 | < 1.9.1 |
HIGH | 7.5 | The Elegance Menu plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1.9 v… | — | wordfence |
| 9cec4d7a-81e0-489a-b549-5848ed9a8449 | < 3.1.1 |
HIGH | 7.5 | Directory traversal vulnerability in the file_get_contents function in downloadfiles/download.php in the WP Content Sour… | — | wordfence |
| 9cbba523-8f9f-421d-9305-4b52e8eef726 | HIGH | 7.5 | The Paid Downloads plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 3.15 due to ins… | — | wordfence | |
| 9cb96b56-82cb-4429-b645-dfe8a14931e5 | < 5.0.7 |
HIGH | 7.5 | The Plus Addons for Elementor - Pro WordPress plugin before 5.0.7 does not validate the qvquery parameter of the tp_get_… | — | wordfence |
| 9c92dbe9-faeb-4ea9-9657-ed7accf63cc1 | < 2.3.3 |
HIGH | 7.5 | The WP Job Portal β A Complete Recruitment System for Company or Job Board website plugin for WordPress is vulnerable … | — | wordfence |
| 9c8ab916-240d-43c3-92d4-7efd75862a5e | < 4.9.58 |
HIGH | 7.5 | The ShiftController Employee Shift Scheduling plugin is vulnerable to PHP Object Injection via deserialization of untrus… | — | wordfence |
| 9c2e8932-f207-40f2-85c9-5d1f28f859f2 | HIGH | 7.5 | The WordPress Auction Plugin plugin for WordPress is vulnerable to SQL Injection in all versions up to, and including, 3… | — | wordfence | |
| 9c226d83-2886-4b7c-978c-ad723709145f | < 2.5.4 |
HIGH | 7.5 | Directory traversal vulnerability in the dp_img_resize function in php/dp-functions.php in the DukaPress plugin before 2… | — | wordfence |
| 9bfd6ec9-51e1-41a3-9db1-3b44d6eba958 | HIGH | 7.5 | The Responsive Posts Carousel Pro plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and incl… | — | wordfence | |
| 9bf472f1-5980-48ee-aa10-aad19b6f2456 | < 2.7.10 |
HIGH | 7.5 | The Groundhogg plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.7.9.… | — | wordfence |
| 9bd873e5-fd65-48c3-a71d-aaf6d8372606 | < 21.8.0.100 |
HIGH | 7.5 | The Quiz Maker Business, Developer, and Agency plugins for WordPress is vulnerable to SQL Injection via the βidβ par… | — | wordfence |
| 9bcd18bd-032e-4a97-83aa-a377f9b1f435 | < 1.5.5 |
HIGH | 7.5 | The Order Tip for WooCommerce plugin for WordPress is vulnerable to Unauthenticated Improper Input Validation in all ver… | — | wordfence |
| 9b871957-a2b3-492f-b461-7040d9098b2b | < 2.2.14 |
HIGH | 7.5 | The Everest Backup β WordPress Cloud Backup, Migration, Restore & Cloning Plugin plugin for WordPress is vulnerable to… | — | wordfence |
| 9b1dc818-75c6-45b7-9f0f-88275cc6e946 | < 6.9.1 |
HIGH | 7.5 | The iThemes Security plugin before 6.9.1 for WordPress does not properly perform data escaping for the logs page. | — | wordfence |
| 9b0f6653-471b-4cee-9c92-f24dbe2c2dbd | < 6.2.0 |
HIGH | 7.5 | The JS Archive List plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 6.1… | — | wordfence |
| 9b0e973b-f0bf-44d1-b964-e259f68291aa | < 1.2.3 |
HIGH | 7.5 | The TrueBooker β Appointment Booking and Scheduler System plugin for WordPress is vulnerable to generic SQL Injection … | — | wordfence |
| 9b0d1174-b94f-4b44-8b88-bc4355f0d165 | < 1.9.2 |
HIGH | 7.5 | The WeMusic theme for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 1.9.1 via deseri… | — | wordfence |
| 9b09bf42-a85d-4a5b-9acc-609e0a5d7748 | < 2.2.50 |
HIGH | 7.5 | In the nextgen-gallery plugin before 2.2.50 for WordPress, gallery paths are not secured. | — | wordfence |
| 9b00da60-7d2d-467e-ab58-0bb4af0cbda5 | < 2.9.1 |
HIGH | 7.5 | The Bit integrations β Form Integration, Webhook, Spreadsheets, CRM, LMS & Email Automation plugin for WordPress is vu… | — | wordfence |
| 9abfd0f5-f665-4745-9756-8445ddbdc29d | < 0.6.4 |
HIGH | 7.5 | The WPNakama plugin for WordPress is vulnerable to time-based SQL Injection via the 'order_by' parameter in all versions… | — | wordfence |
| 9aad7539-071e-474b-a2db-0f496aac2995 | < 11.15.11 |
HIGH | 7.5 | The PowerPress Podcasting plugin by Blubrry plugin for WordPress is vulnerable to PHP Object Injection in all versions u… | — | wordfence |
| 9a7ad642-ace5-41c9-bd33-44e532326f25 | HIGH | 7.5 | The WP Pipes plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 1.4.3 due to insuffic… | — | wordfence |
EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.
Scan My Website →