Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.
39,403 vulnerabilities found (page 43 of 1577)
| CVE ID | Plugin / Theme | Severity | CVSS | Description | Fixed In | Source |
|---|---|---|---|---|---|---|
| a0998721-7b5e-4657-894c-52dfadde5d4a | < 1.1.33 |
CRITICAL | 9.8 | The Hydra Booking — Appointment Scheduling & Booking Calendar plugin for WordPress is vulnerable to Privilege Escalati… | — | wordfence |
| a08fa649-3092-4c26-a009-2dd576b9b1ac | < 2.6.1 |
CRITICAL | 9.8 | The ListingPro - WordPress Directory & Listing Theme for WordPress is vulnerable to Arbitrary Plugin Installation, Activ… | — | wordfence |
| a0695f66-5932-4ca4-86d3-ef53f1a669b5 | CRITICAL | 9.8 | The Oberliga Theme for WordPress is vulnerable to generic SQL Injection via the ‘team’ parameter in all versions due… | — | wordfence | |
| a042b1be-d39f-4d28-8566-d9974becdd40 | CRITICAL | 9.8 | The Project Source Code Download WordPress plugin through 1.0.0 does not protect its backup generation and download func… | — | wordfence | |
| a0146f17-35bd-45cf-b9c6-c4fce688efc2 | < 1.1.2 |
CRITICAL | 9.8 | The Integration for Google Sheets and Contact Form 7, WPForms, Elementor, Ninja Forms plugin for WordPress is vulnerable… | — | wordfence |
| a003e922-d6c6-4f99-9b94-a3232d311677 | < 5.4.02 |
CRITICAL | 9.8 | The Hide My WP Ghost plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 5.4.01… | — | wordfence |
| a00222f4-6f41-4a88-a50a-1e25b11a2ffc | < 1.2.9 |
CRITICAL | 9.8 | The Nika theme for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.2.8. This makes i… | — | wordfence |
| 9fdb6e4d-a94d-448c-aaea-0f38eeafd033 | < 2.5.4 |
CRITICAL | 9.8 | The WooLentor plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 2.5.3 via des… | — | wordfence |
| 9fb4c58d-321d-453f-92b9-ae409541911b | < 9.3.9 |
CRITICAL | 9.8 | The XStore theme for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 9.3.8. This m… | — | wordfence |
| 9fb09a77-aba1-422c-961b-dc2c7ce82320 | < 1.7.5.7 |
CRITICAL | 9.8 | The Cooked Pro plugin for WordPress is vulnerable to PHP Object Injection in versions up to, but not including, 1.7.5.7 … | — | wordfence |
| 9fa30fa2-6c42-4e5f-a0b5-8711ce5d8121 | < 2.150 |
CRITICAL | 9.8 | The Security & Malware scan by CleanTalk plugin for WordPress is vulnerable to arbitrary file uploads due to the plugin … | — | wordfence |
| 9f9fd9e1-c4b8-420e-a4d3-30c934853a98 | < 12.6.7 |
CRITICAL | 9.8 | An issue was discovered in the VeronaLabs wp-statistics plugin before 12.6.7 for WordPress. The v1/hit endpoint of the A… | — | wordfence |
| 9f5cdb47-205a-4c03-a8a9-f39d1b4fc769 | < 1.0.24 |
CRITICAL | 9.8 | The Agency Toolkit plugin for WordPress is vulnerable to unauthorized modification of data that can lead to privilege es… | — | wordfence |
| 9f4fe2b2-c7a6-4e88-ac2e-2201072c4dac | CRITICAL | 9.8 | The Advanced Online Ordering and Delivery Platform plugin for WordPress is vulnerable to Local File Inclusion in version… | — | wordfence | |
| 9f301908-d491-492f-9347-432c462de286 | < 7.3.15.727 |
CRITICAL | 9.8 | The FV Flowplayer Video Player plugin before 7.3.15.727 for WordPress allows email subscription SQL injection. | — | wordfence |
| 9f130158-8c68-4a39-a94b-1f0ce81b1799 | CRITICAL | 9.8 | The Custom Field List Widget plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including… | — | wordfence | |
| 9ef3e6c7-b75a-4afc-b1c7-6e74b0c894a9 | < 5.0.3 |
CRITICAL | 9.8 | The Paytium: Mollie payment forms & donations plugin for WordPress is vulnerable to Privilege Escalation in all versions… | — | wordfence |
| 9eb835fd-6ebf-4162-856c-0366b663a07e | < 4.2.3 |
CRITICAL | 9.8 | The Simple-File-List Plugin for WordPress is vulnerable to Remote Code Execution in versions up to, and including, 4.2.2… | — | wordfence |
| 9eb34cb2-ebf8-4913-b8e0-152a436963ee | < 3.2.2 |
CRITICAL | 9.8 | The Booking calendar, Appointment Booking System plugin for WordPress is vulnerable to arbitrary file uploads due to mis… | — | wordfence |
| 9e7a1116-2bf1-4d36-a091-e0d4a9d6e1c9 | < 1.3.8 |
CRITICAL | 9.8 | The InfiniteWP Client plugin for WordPress is vulnerable to Privilege Escalation in versions up to, and including, 1.3.7… | — | wordfence |
| 9e4d84ad-ab02-45b1-aecb-dc2c08c097fe | < 3.7.6 |
CRITICAL | 9.8 | The Dokan plugin for WordPress is vulnerable to SQL Injection via the ‘user_ids’ parameter in versions up to, and in… | — | wordfence |
| 9dfee325-9001-4483-b3eb-846da0314529 | < 2.2.0 |
CRITICAL | 9.8 | The Tutor LMS plugin for WordPress is vulnerable to SQL Injection via many parameters in versions up to, and including, … | — | wordfence |
| 9dfa4679-79d6-4444-9372-0753509ae93f | < 3.7 |
CRITICAL | 9.8 | The Hotel Booking plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 3.6. This… | — | wordfence |
| 9dda0b0a-234c-46bb-950a-2b7a5ef3227b | CRITICAL | 9.8 | The Grace Mag theme for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.1.5. This ma… | — | wordfence | |
| 9db30856-7541-4647-9e10-3855230b7efe | < 1.3.9 |
CRITICAL | 9.8 | The Zota theme for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.3.8. This makes i… | — | wordfence |
EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.
Scan My Website →