Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.
39,891 vulnerabilities found (page 452 of 1596)
| CVE ID | Plugin / Theme | Severity | CVSS | Description | Fixed In | Source |
|---|---|---|---|---|---|---|
| 9309b8bf-f581-4a56-a1ed-3941ebb36127 | < 4.16.5 |
MEDIUM | 6.5 | The The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content β Profi… | — | wordfence |
| 92e444db-72d5-444f-811e-ade0bc097769 | < 3.0.7 |
MEDIUM | 6.5 | The License Manager for WooCommerce plugin for WordPress is vulnerable to unauthorized access of data due to a missing c… | — | wordfence |
| 92c37a5e-7896-44f6-807d-61e06bfbda99 | MEDIUM | 6.5 | The AppExperts plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 1.4.5 due to insuff… | — | wordfence | |
| 92b8829e-a8eb-4fdb-a772-9efbb5aaeb6c | < 1.6.1 |
MEDIUM | 6.5 | The BetterLinks plugin for WordPress is vulnerable to unauthorized access and modification due to insufficient capabilit… | — | wordfence |
| 9283f6ea-8bc4-4fdd-a0b9-05de127f34e4 | < 4.0.3 |
MEDIUM | 6.5 | The WebPurify Profanity Filter plugin for WordPress is vulnerable to unauthorized modification of data due to a missing … | — | wordfence |
| 927076bc-bafa-43d6-bf3b-5861844c932a | < 3.8.3 |
MEDIUM | 6.5 | The Advanced Floating Content plugin for WordPress is vulnerable to SQL Injection via the 'floating_content_duplicate_po… | — | wordfence |
| 926e7bbf-7e19-4bc3-b976-5003399cdcdc | < 1.3 |
MEDIUM | 6.5 | The Accordion Slider PRO plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 1.2 due t… | — | wordfence |
| 926b0a28-17b8-4d28-b911-03c75c2e64c9 | < 4.5.2 |
MEDIUM | 6.5 | The KiviCare plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 4.5.1 due to insuffic… | — | wordfence |
| 9242cebe-3394-4df9-9c60-8d8d6297d791 | < 2.2.4.2 |
MEDIUM | 6.5 | The Open Graph and Twitter Card Tags plugin for WordPress is vulnerable to Cross-Site Scripting via the βimgβ parame… | — | wordfence |
| 921c2486-42cb-42f2-a326-e951c20bd7ea | MEDIUM | 6.5 | The Multi-Scheduler plugin 1.0.0 for WordPress has a Cross-Site Request Forgery (CSRF) vulnerability in the forms it pre… | — | wordfence | |
| 91f9235e-f578-475f-92c3-34062d6d1e3d | MEDIUM | 6.5 | The Subscribe To Comments Reloaded plugin for WordPress is vulnerable to unauthorized modification of data due to a leak… | — | wordfence | |
| 91ebe8cb-99ec-4380-a77e-17e17144a17e | < 1.6.2 |
MEDIUM | 6.5 | The EmailKit plugin for WordPress is vulnerable to Arbitrary File Read via Path Traversal in all versions up to, and inc… | — | wordfence |
| 91ebde99-3383-4179-a72b-2709c1db9e53 | < 11.8.2 |
MEDIUM | 6.5 | CSRF in YouTube (WordPress plugin) could allow unauthenticated attacker to change any setting within the plugin | — | wordfence |
| 91c9fb05-e853-4d59-95ec-a0c2ff06565b | MEDIUM | 6.5 | The Envato Sales By Item plugin for WordPress fails to sanitize user input that is subsequently used in an SQL. It also … | — | wordfence | |
| 915cce97-8305-4249-b2d3-c4da2f59a95a | MEDIUM | 6.5 | The ACF Flexible Layouts Manager plugin for WordPress is vulnerable to unauthorized modification of data due to a missin… | — | wordfence | |
| 912523ae-f619-46af-83b9-e9fca81bd5b0 | < 1.22.22 |
MEDIUM | 6.5 | The Backup and Staging by WP Time Capsule plugin for WordPress is vulnerable to SQL Injection in versions up to, and inc… | — | wordfence |
| 9118acb5-65d7-4058-82f0-0989d33ea44c | < 5.9.4.9 |
MEDIUM | 6.5 | The ProfileGrid plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 5.9.4.8 due to in… | — | wordfence |
| 9102fe7e-7baa-4bc0-879f-cc7df1ea13d2 | < 2.4.0 |
MEDIUM | 6.5 | The MediaCommander β Bring Folders to Media, Posts, and Pages plugin for WordPress is vulnerable to unauthorized data … | — | wordfence |
| 900d09e8-ded5-49b9-81bf-ddfc85d3cf2b | MEDIUM | 6.5 | The WP01 plugin for WordPress is vulnerable to Arbitrary File Download in all versions up to, and including, 2.6.2 due t… | — | wordfence | |
| 900cfb6d-61c8-4696-9a5d-1ff03cd76a22 | < 1.8.17.0 |
MEDIUM | 6.5 | The WP Mailster plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a functio… | — | wordfence |
| 8ff1ca68-7c71-4442-b27f-12743fc39b37 | < 4.0 |
MEDIUM | 6.5 | The Get Custom Field Values WordPress plugin before 4.0 allows users with a role as low as Contributor to access other p… | — | wordfence |
| 8fcc8b94-6ed3-4784-93f3-ec1654d197bd | MEDIUM | 6.5 | The Author Discussion plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 0.2.2 due to… | — | wordfence | |
| 8f9863b2-177d-4b72-8337-90fbedfd5b54 | < 2.11.2 |
MEDIUM | 6.5 | An issue was discovered in the Currency Switcher addon before 2.11.2 for WooCommerce if a user provides a currency that … | — | wordfence |
| 8f7b0a1c-16d7-45db-b419-569ed5c4a5e4 | < 1.5.3 |
MEDIUM | 6.5 | The Make plugin for WordPress is vulnerable to authorization bypass due to a missing capability check and nonce verifica… | — | wordfence |
| 8f411d17-5b0d-4a4a-afa8-7efebf6965f2 | < 1.4.8 |
MEDIUM | 6.5 | The Sparkle Demo Importer plugin for WordPress is vulnerable to unauthorized database reset and demo data import due to … | — | wordfence |
EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.
Scan My Website →