Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.
39,652 vulnerabilities found (page 297 of 1587)
| CVE ID | Plugin / Theme | Severity | CVSS | Description | Fixed In | Source |
|---|---|---|---|---|---|---|
| 9a47e6ff-a1d2-40f0-b4d2-8ee8394ce603 | < 1.1.17 |
HIGH | 7.5 | The wiseCampaign – WooCommerce Conversions Made Easy plugin for WordPress is vulnerable to unauthorized modification a… | — | wordfence |
| 9a455340-4d07-4f02-9dcb-835fcd43985d | HIGH | 7.5 | The Productive Commerce plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 1.1.22 due… | — | wordfence | |
| 9a09425f-f18d-40c3-888d-0845e4ebdc77 | < 1.2.9 |
HIGH | 7.5 | The Quentn WP plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 1.2.8 due to insuffi… | — | wordfence |
| 9a047577-d5eb-425b-9318-4473d052a223 | < 2.8.1 |
HIGH | 7.5 | The YITH WooCommerce Ajax Search plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 2… | — | wordfence |
| 99fa7f41-f3ac-435c-af1b-4a965291de37 | < 1.9 |
HIGH | 7.5 | The RokIntroScroller plugin for WordPress is vulnerable to Denial of Service via the 'src' parameter in the 'thumb.php' … | — | wordfence |
| 99e34600-7eba-473f-91c0-82e45a48c419 | < 1.2.9 |
HIGH | 7.5 | The Vex theme for WordPress is vulnerable to PHP Object Injection in versions up to 1.2.9 via deserialization of untrust… | — | wordfence |
| 99a9d844-305d-445d-947d-060920e8a229 | < 1.3 |
HIGH | 7.5 | The Multiple Shipping And Billing Address For Woocommerce plugin for WordPress is vulnerable to SQL Injection in version… | — | wordfence |
| 999b2249-5bfb-4add-b955-e82ab0308d2f | < 3.15.4 |
HIGH | 7.5 | The Avada theme for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 3.15.3 via deseria… | — | wordfence |
| 997918b9-2ccd-413e-9df2-d24bc3820ba1 | < 2.7.0 |
HIGH | 7.5 | The Better Messages – Live Chat for WordPress, BuddyPress, PeepSo, Ultimate Member, BuddyBoss plugin for WordPress is … | — | wordfence |
| 996697c7-39a9-411e-a1cf-c9bb7c34b258 | HIGH | 7.5 | The RealPress – Real Estate Plugin plugin for WordPress is vulnerable to SQL Injection in versions up to, and includin… | — | wordfence | |
| 99433521-721b-41c3-8736-fd2943901b4f | < 4.2 |
HIGH | 7.5 | The wp-support-plus-responsive-ticket-system plugin before 4.2 for WordPress has directory traversal. | — | wordfence |
| 99418bd5-041a-4210-9571-fee6842fb692 | < 1.11.5 |
HIGH | 7.5 | The Tracking Code Manager for WordPress is vulnerable to Denial of Service attacks in versions up to, and including, 1.1… | — | wordfence |
| 992a91da-724f-40cc-b552-113d62fe20c1 | < 1.1.0 |
HIGH | 7.5 | Multiple directory traversal vulnerabilities in the Vitamin plugin before 1.1.0 for WordPress allow remote attackers to … | — | wordfence |
| 9909b7e3-4c6b-478e-8775-99779b21b0c1 | < 2.2.2 |
HIGH | 7.5 | The Gyan Elements plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 2.2.1. Th… | — | wordfence |
| 98f16e3a-4ef3-43f9-86b2-2cf8e26f9c80 | < 6.0.5 |
HIGH | 7.5 | The WP Ticket plugin for WordPress is vulnerable to SQL Injection via the WordPress search query parameter (`s`) in vers… | — | wordfence |
| 98c263b5-8de6-4a75-9f4c-9756d6f3a050 | HIGH | 7.5 | The Valenti theme for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 5.6.3.5 via dese… | — | wordfence | |
| 98ab264f-b210-41d0-bb6f-b4f31d933f80 | < 5.4.0 |
HIGH | 7.5 | The Jetpack CRM plugin for WordPress is vulnerable to PHAR deserialization via the ‘zbscrmcsvimpf’ parameter in the … | — | wordfence |
| 982817f8-c85c-4e25-a33a-6fbf3ab06808 | < 2.5.4 |
HIGH | 7.5 | Directory traversal vulnerability in the Google Doc Embedder plugin before 2.5.4 for WordPress allows remote attackers t… | — | wordfence |
| 97fdd2f9-02ad-492c-88d1-1e7bd9c404a5 | < 3.9.7 |
HIGH | 7.5 | The Tutor LMS Pro plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 3.9.6 due to ins… | — | wordfence |
| 97da8e3d-0e29-423a-bd59-dbcff1eb1249 | < 3.1.3 |
HIGH | 7.5 | The MailerLite – WooCommerce integration plugin for WordPress is vulnerable to SQL Injection in versions up to, and in… | — | wordfence |
| 97677968-9231-4a6b-ad81-ddb9eb9791dd | < 2.0.4 |
HIGH | 7.5 | The Activity Log plugin for WordPress is vulnerable to Sensitive Data Exposure in versions up to, and including, 2.0.3 v… | — | wordfence |
| 975f7c66-033d-47b2-9e7a-b33b8fe06b17 | HIGH | 7.5 | The UDesign Core plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 4.14.0. Th… | — | wordfence | |
| 973ebafc-85c0-4cc5-b307-2fdb0a4a7577 | < 3.14.2 |
HIGH | 7.5 | The Ninja Forms – The Contact Form Builder That Grows With You plugin for WordPress is vulnerable to unauthorized acce… | — | wordfence |
| 970c7495-e43c-4606-8154-e2ac7d1c4816 | < 1.2.3 |
HIGH | 7.5 | The TAX SERVICE Electronic HDM plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 1.1… | — | wordfence |
| 96c77102-3293-476c-93bd-5bbbe39f3a5e | < 3.5.6 |
HIGH | 7.5 | The eCommerce Product Catalog Plugin for WordPress plugin for WordPress is vulnerable to SQL Injection in versions up to… | — | wordfence |
EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.
Scan My Website →