Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.
39,836 vulnerabilities found (page 372 of 1594)
| CVE ID | Plugin / Theme | Severity | CVSS | Description | Fixed In | Source |
|---|---|---|---|---|---|---|
| 9373c82d-15a8-495a-8290-1b85c096f7e5 | < 0.9.5 |
HIGH | 7.2 | The W3 Total Cache plugin for WordPress is vulnerable to weak validation of Amazon SNS push messages in versions up to, … | — | wordfence |
| 936e753b-b3e9-43c9-8686-c610faa8b20e | < 5.4.3 |
HIGH | 7.2 | The Shopping Cart & eCommerce Store plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and in… | — | wordfence |
| 9347dafb-1789-4855-b09e-2a1ef5f7f2c1 | < 1.13.36 |
HIGH | 7.2 | The Form Maker plugin for WordPress is vulnerable to generic SQL Injection via the 's' parameter in versions up to, and … | — | wordfence |
| 934545ff-8886-47c7-ad50-0e5ff513a26c | < 1.0.9 |
HIGH | 7.2 | The PWA for WP & AMP plugin for WordPress is vulnerable to Cross-Site Scripting via several parameters in versions up to… | — | wordfence |
| 931983c3-d704-4c95-8078-7db4d79e1e1c | HIGH | 7.2 | The Newsletter by Supsystic plugin for WordPress is vulnerable to time-based blind SQL Injection via the ‘sidx’ para… | — | wordfence | |
| 92e9af52-a9a8-4b68-8351-f1091855fedc | < 1.3.25 |
HIGH | 7.2 | The HTML Forms plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 1.3.24 due to insuf… | — | wordfence |
| 92d94f9a-150f-40ca-88e1-57cbd6e6880a | < 5.2 |
HIGH | 7.2 | The Extensions for Leaflet Map plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and … | — | wordfence |
| 9298820e-3753-41b3-8ba6-9fb494e215a8 | < 1.2.9.2 |
HIGH | 7.2 | The WP Editor plugin for WordPress is vulnerable to arbitrary file update due to missing file path validation in all ver… | — | wordfence |
| 928b4c4f-0614-410a-857b-90037770cfbf | < 2.56 |
HIGH | 7.2 | The Album and Image Gallery with Lightbox – Flagallery Photo Portfolio plugin for WordPress is vulnerable to SQL Injec… | — | wordfence |
| 922c029e-57a9-4c18-8598-9ea3bbc2ab69 | < 3.5.46 |
HIGH | 7.2 | The Ultimate Addons for Contact Form 7 plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up … | — | wordfence |
| 920e4111-ac5c-4562-8529-67b17ceeb506 | < 3.3.8 |
HIGH | 7.2 | The Oshine Modules plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to 3.3.8 (exclus… | — | wordfence |
| 91f86c22-94db-4c43-985a-2f3dd96ece21 | < 2.9.6 |
HIGH | 7.2 | The Welcart e-Commerce plugin for WordPress is vulnerable to PHP Object Injection in all versions up to 2.9.5 (inclusive… | — | wordfence |
| 91e0b45c-e73f-408a-94b8-fdbc5da64b20 | < 3.95.0 |
HIGH | 7.2 | The Slider, Gallery, and Carousel by MetaSlider – Image Slider, Video Slider plugin for WordPress is vulnerable to PHP… | — | wordfence |
| 91aa163b-ac5b-4737-afa7-be4b55cb1e90 | HIGH | 7.2 | The Canonical Attachments plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and i… | — | wordfence | |
| 91699d32-1768-4d87-a4f2-91969b3e3355 | < 5.3.0 |
HIGH | 7.2 | The WP Activity Log plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘message’ parameter in… | — | wordfence |
| 9124240d-e540-4a59-a4c5-c4279bb39399 | < 2.3.11 |
HIGH | 7.2 | The gigpress plugin before 2.3.11 for WordPress has SQL injection in the admin area, a different vulnerability than CVE-… | — | wordfence |
| 910d9b31-b63a-427e-830b-a4c6a7e77ade | < 1.10.14 |
HIGH | 7.2 | The WS Form LITE and PRO plugins for WordPress are vulnerable to Stored Cross-Site Scripting via the url parameter in al… | — | wordfence |
| 90ea5c51-e739-42c1-a276-851ad800ff00 | < 2.15.1 |
HIGH | 7.2 | The Independent Analytics plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 404 not_found_url tr… | — | wordfence |
| 90ea439b-48a6-4b21-a277-35db458e5a7a | < 10.11.1 |
HIGH | 7.2 | The AcyMailing – An Ultimate Newsletter Plugin and Marketing Automation Solution for WordPress plugin for WordPress is… | — | wordfence |
| 90e39398-19d7-435d-b23f-e93b8cdbcae4 | < 2.4.19 |
HIGH | 7.2 | The Kali Forms — Contact Form & Drag-and-Drop Builder plugin for WordPress is vulnerable to Stored Cross-Site Scriptin… | — | wordfence |
| 90d0b748-a56a-4932-8e43-751ca363725c | < 1.14.0 |
HIGH | 7.2 | The WPMasterToolKit (WPMTK) – All in one plugin plugin for WordPress is vulnerable to arbitrary file uploads due to mi… | — | wordfence |
| 90c4441e-3578-4bb0-befe-cfedcb5c1a71 | < 1.0.275 |
HIGH | 7.2 | The Rank Math SEO – AI SEO Tools to Dominate SEO Rankings plugin for WordPress is vulnerable to Stored Cross-Site Scri… | — | wordfence |
| 90920df9-1362-466b-b14b-4714087f556b | < 5.3.4 |
HIGH | 7.2 | The SlimStat Analytics plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `fh` (fingerprint) para… | — | wordfence |
| 9085b3b8-ee5e-455c-af39-1cb674a44f61 | < 94.3.6 |
HIGH | 7.2 | The Hostiko theme for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to 94.3.6 due to insufficien… | — | wordfence |
| 907329af-2ff0-475e-b4b2-3ac7ae4b9ced | < 2.6 |
HIGH | 7.2 | The WP Post Statistics (Visitors & Visits Counter) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via… | — | wordfence |
EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.
Scan My Website →