Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.
39,836 vulnerabilities found (page 370 of 1594)
| CVE ID | Plugin / Theme | Severity | CVSS | Description | Fixed In | Source |
|---|---|---|---|---|---|---|
| 9c44b6e5-7fb2-402e-8c8c-79d811ff0e9a | < 3.2.7 |
HIGH | 7.2 | The Booking calendar, Appointment Booking System plugin for WordPress is vulnerable to generic SQL Injection via the mul… | — | wordfence |
| 9c40773d-3a2f-46b6-861e-608d662250da | < 5.4 |
HIGH | 7.2 | The MonsterInsights β Google Analytics Dashboard for WordPress plugin is vulnerable to Cross-Site Scripting via the a… | — | wordfence |
| 9c2d97c4-b166-4d1f-8042-d0362e650c62 | HIGH | 7.2 | The Add custom page template plugin for WordPress is vulnerable to PHP Code Injection leading to Remote Code Execution i… | — | wordfence | |
| 9bd63003-d1d6-480a-8df7-878bcc89f1ee | < 3.31 |
HIGH | 7.2 | The Visual Website Collaboration, Feedback & Project Management β Atarim plugin for WordPress is vulnerable to Stored … | — | wordfence |
| 9bb5e60d-f7c9-4b47-ba6f-0f2d1d060263 | < 6.7 |
HIGH | 7.2 | The Simple User Registration plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'wpr_admin_msg' p… | — | wordfence |
| 9bac82ee-55bf-4381-b441-115a675e4834 | < 9.1.12 |
HIGH | 7.2 | The NEX-Forms β Ultimate Forms Plugin for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting … | — | wordfence |
| 9b821fb6-abc5-411f-ad6b-00b20954142c | < 3.1.5 |
HIGH | 7.2 | The menu delete functionality of the Side Menu β add fixed side buttons WordPress plugin before 3.1.5, available to Ad… | — | wordfence |
| 9b7be8e8-264c-4c28-a419-3bbfea744f3a | HIGH | 7.2 | The photography theme for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in all v… | — | wordfence | |
| 9b6cf4ab-9e4d-4fd7-9e9e-c678ccc4d810 | < 5.2.6 |
HIGH | 7.2 | The JoomSport β for Sports: Team & League, Football, Hockey & more plugin for WordPress is vulnerable to SQL Injection… | — | wordfence |
| 9b448712-b989-453f-9acb-5556e01e41a4 | HIGH | 7.2 | The WP App Bar plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'app-bar-features' parameter in… | — | wordfence | |
| 9b350b48-05ba-4054-895f-36d7ad71459d | < 14.16.5 |
HIGH | 7.2 | The WP Statistics plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'utm_source' parameter in al… | — | wordfence |
| 9afe4620-2d23-438e-9b8e-003a3c132c85 | < 2.3.20 |
HIGH | 7.2 | The Five Star Business Profile and Schema plugin for WordPress is vulnerable to Remote Code Execution in all versions up… | — | wordfence |
| 9ab883bf-d6b4-4b0e-b8f4-69e6c0f90c70 | < 1.7.1 |
HIGH | 7.2 | Unvalidated input in the Contact Form Submissions WordPress plugin before 1.7.1, could lead to SQL injection in the wpcf… | — | wordfence |
| 9a41bc0e-0ab9-4cee-b3ca-d730c828782c | < 1.1.14 |
HIGH | 7.2 | The Lucky Wheel for WooCommerce β Spin a Sale plugin for WordPress is vulnerable to PHP Code Injection in all versions… | — | wordfence |
| 9a371489-031e-483e-9fde-3901b55710c6 | < 1.6.0 |
HIGH | 7.2 | The Coming Soon Page plugin for WordPress is vulnerable to SQL Injection via the 'rem' parameter in versions up to, and … | — | wordfence |
| 9a353364-73a9-428c-b702-0183b29c7e3d | < 1.2.5 |
HIGH | 7.2 | The NewStatPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several parameters in versions up… | — | wordfence |
| 9a2ee9bb-ae20-47ae-b792-438bf7be6cc4 | < 3.1.2 |
HIGH | 7.2 | The BSK PDF Manager WordPress plugin before 3.1.2 does not validate and escape the orderby and order parameters before u… | — | wordfence |
| 9a09af8e-8da6-46e4-90e5-6ce1f8bfd36b | HIGH | 7.2 | The xtremelocator plugin 3.0.1 for WordPress has SQL injection via the id parameter for high-privilege (admin+) users. | — | wordfence | |
| 99fc02ea-5399-4ff2-a5f9-27878cadf40d | < 1.2.23 |
HIGH | 7.2 | The atec Debug plugin for WordPress is vulnerable to remote code execution in all versions up to, and including, 1.2.22 … | — | wordfence |
| 99e0a243-3e0e-4e2b-82fd-95c3cfde8a1b | < 3.7.4 |
HIGH | 7.2 | wp-includes/class-wp-customize-widgets.php in the widget implementation in WordPress 3.9.x before 3.9.2 might allow remo… | — | wordfence |
| 99dfce3b-2b47-41bf-8b20-b53fb9f061a7 | < 1.8.1 |
HIGH | 7.2 | The Login No Captcha reCAPTCHA plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `$_SERVER['PHP_… | — | wordfence |
| 99dfacb4-f784-4e8d-b411-7cab7683c7c8 | < 0.6.0 |
HIGH | 7.2 | The crazy-bone plugin before 0.6.0 for WordPress has XSS via the User-Agent HTTP header | — | wordfence |
| 99b2e3c3-b5e5-4648-81c8-da2f42ceec66 | < 1.8.1 |
HIGH | 7.2 | The File Manager Pro β Filester plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient permi… | — | wordfence |
| 993175b7-832d-4d08-8056-1ab2b0b0f3f6 | < 6.4.26 |
HIGH | 7.2 | The Business Directory plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and includin… | — | wordfence |
| 98d33b73-9c4b-477c-9a1c-17c792df3b1b | HIGH | 7.2 | The AI Bud β AI Content Generator, AI Chatbot, ChatGPT, Gemini, GPT-4o plugin for WordPress is vulnerable to arbitrary… | — | wordfence |
EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.
Scan My Website →