Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.
39,403 vulnerabilities found (page 44 of 1577)
| CVE ID | Plugin / Theme | Severity | CVSS | Description | Fixed In | Source |
|---|---|---|---|---|---|---|
| 9d979d09-a019-420e-b46e-b1d1f5e430ae | < 5.5.0 |
CRITICAL | 9.8 | The miniOrange OTP Login, Verification and SMS Notifications plugin for WordPress is vulnerable to Privilege Escalation … | — | wordfence |
| 9d8551b8-67b9-45a8-9357-9e42fb451606 | CRITICAL | 9.8 | The Ya'aburnee and Dignitas themes for WordPress are vulnerable to Privilege Escalation in versions up to, and including… | — | wordfence | |
| 9d4bbf48-6525-4569-98a6-412f2bfe7628 | CRITICAL | 9.8 | The mail-masta plugin 1.0 for WordPress has local file inclusion in count_of_send.php and csvexport.php. | — | wordfence | |
| 9cd87da6-1f4c-4a15-8ebb-6e0f8ef72513 | < 1.25.0 |
CRITICAL | 9.8 | The Forminator plugin for WordPress is vulnerable to arbitrary file uploads due to file type validation occurring after … | — | wordfence |
| 9c7d2321-735a-4b5f-a36d-16375c994d2d | < 2.9.8 |
CRITICAL | 9.8 | The Paid Memberships Pro plugin for WordPress is vulnerable to SQL injection in versions before 2.9.8 via the 'code' par… | — | wordfence |
| 9c78e0b6-bf24-4a23-8501-b26e681a7a4a | < 2.0.0 |
CRITICAL | 9.8 | The Author Char plugin for WordPress is vulnerable to generic SQL Injection in versions up to, and including, 1.9.0 due … | — | wordfence |
| 9c3df12d-e526-4a23-89d3-bfdcea9f7b2d | < 3.6.1 |
CRITICAL | 9.8 | The Miniorange OTP Verification with Firebase plugin for WordPress is vulnerable to Arbitrary User Password Change in ve… | — | wordfence |
| 9c35ca72-6ce9-40de-a413-12455bfb610e | CRITICAL | 9.8 | The Meta Keywords & Description plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and includ… | — | wordfence | |
| 9c269233-f2dc-42ef-98be-78600f90e87d | CRITICAL | 9.8 | The MainWP Links Manager Extension plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and inc… | — | wordfence | |
| 9c14d918-daf9-46e8-9f96-4215e4645c62 | CRITICAL | 9.8 | The GNUCommerce plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 1.5.4 via d… | — | wordfence | |
| 9c101fca-037c-4bed-9dc7-baa021a8b59c | < 1.8.5 |
CRITICAL | 9.8 | The Hunk Companion plugin for WordPress is vulnerable to unauthorized plugin installation/activation due to a missing ca… | — | wordfence |
| 9bfcc607-9fbc-4d36-858d-a0f763597a3b | CRITICAL | 9.8 | The ZoomSounds plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 6.91 via des… | — | wordfence | |
| 9be94d63-f027-4988-ab41-673658c1fa5f | < 18.0 |
CRITICAL | 9.8 | The WooCommerce Checkout Field Manager plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient … | — | wordfence |
| 9be4ad83-14da-499e-b216-e5f26016fa35 | < 3.6.8 RC1 |
CRITICAL | 9.8 | Unrestricted file upload vulnerability in image_processing.php in the e-Commerce Plugin 3.4 and earlier for Wordpress al… | — | wordfence |
| 9bd9c9db-d279-4de2-b5e4-ac7d8c919f2a | CRITICAL | 9.8 | The Piotnet Forms plugin for WordPress is vulnerable to arbitrary file upload due to missing file type validation in the… | — | wordfence | |
| 9bd3b7d6-7ad1-44f4-b28d-fdcb81692a8f | < 1.2.4 |
CRITICAL | 9.8 | The User Toolkit plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.2.3.… | — | wordfence |
| 9bb430e6-0c30-4c23-874a-f91e25622857 | < 1.110 |
CRITICAL | 9.8 | The MailCWP plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'mai… | — | wordfence |
| 9bb2ae16-7886-4e66-83e0-59806dd67450 | < 3.1.4 |
CRITICAL | 9.8 | A vulnerability in the user profile update component found in the ~/src/Classes/EditUserProfile.php file of the ProfileP… | — | wordfence |
| 9ba74e58-0647-4283-9fa3-428976c54474 | < 3.7.40 |
CRITICAL | 9.8 | … | — | wordfence |
| 9b5c2fb2-4274-460e-bb2b-567a0c3a7865 | CRITICAL | 9.8 | The Navayan CSV Export plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 1.0.9 due t… | — | wordfence | |
| 9b5bdeb8-d5ee-4e30-8aaf-88893abf4145 | < 2.0.2 |
CRITICAL | 9.8 | The Woocommerce Wordpress Auctions plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type… | — | wordfence |
| 9b458323-5fca-4fed-8c98-dfe69fd7a997 | CRITICAL | 9.8 | The Downloads Manager plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation o… | — | wordfence | |
| 9b3201e0-df2a-471e-875b-4ca2c3a659f3 | < 3.0 |
CRITICAL | 9.8 | The memphis-documents-library plugin before 3.0 for WordPress has Remote File Inclusion. | — | wordfence |
| 9ae9c422-8f5b-4ee4-ac3a-828c8230bf7b | CRITICAL | 9.8 | The Docpro plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 2.0.1. This make… | — | wordfence | |
| 9ae7b6fc-2120-4573-8b1b-d5422d435fa5 | < 1.3.6.6 |
CRITICAL | 9.8 | The HUSKY β Products Filter Professional for WooCommerce plugin for WordPress is vulnerable to Local File Inclusion in… | — | wordfence |
EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.
Scan My Website →