Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.
41,758 vulnerabilities found (page 46 of 1671)
| CVE ID | Plugin / Theme | Severity | CVSS | Description | Fixed In | Source |
|---|---|---|---|---|---|---|
| 9f4fe2b2-c7a6-4e88-ac2e-2201072c4dac | CRITICAL | 9.8 | The Advanced Online Ordering and Delivery Platform plugin for WordPress is vulnerable to Local File Inclusion in version… | — | wordfence | |
| 9f301908-d491-492f-9347-432c462de286 | < 7.3.15.727 |
CRITICAL | 9.8 | The FV Flowplayer Video Player plugin before 7.3.15.727 for WordPress allows email subscription SQL injection. | — | wordfence |
| 9f130158-8c68-4a39-a94b-1f0ce81b1799 | CRITICAL | 9.8 | The Custom Field List Widget plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including… | — | wordfence | |
| 9ef3e6c7-b75a-4afc-b1c7-6e74b0c894a9 | < 5.0.3 |
CRITICAL | 9.8 | The Paytium: Mollie payment forms & donations plugin for WordPress is vulnerable to Privilege Escalation in all versions… | — | wordfence |
| 9eb835fd-6ebf-4162-856c-0366b663a07e | < 4.2.3 |
CRITICAL | 9.8 | The Simple-File-List Plugin for WordPress is vulnerable to Remote Code Execution in versions up to, and including, 4.2.2… | — | wordfence |
| 9eb34cb2-ebf8-4913-b8e0-152a436963ee | < 3.2.2 |
CRITICAL | 9.8 | The Booking calendar, Appointment Booking System plugin for WordPress is vulnerable to arbitrary file uploads due to mis… | — | wordfence |
| 9e7a1116-2bf1-4d36-a091-e0d4a9d6e1c9 | < 1.3.8 |
CRITICAL | 9.8 | The InfiniteWP Client plugin for WordPress is vulnerable to Privilege Escalation in versions up to, and including, 1.3.7… | — | wordfence |
| 9e4d84ad-ab02-45b1-aecb-dc2c08c097fe | < 3.7.6 |
CRITICAL | 9.8 | The Dokan plugin for WordPress is vulnerable to SQL Injection via the ‘user_ids’ parameter in versions up to, and in… | — | wordfence |
| 9dfee325-9001-4483-b3eb-846da0314529 | < 2.2.0 |
CRITICAL | 9.8 | The Tutor LMS plugin for WordPress is vulnerable to SQL Injection via many parameters in versions up to, and including, … | — | wordfence |
| 9dfa4679-79d6-4444-9372-0753509ae93f | < 3.7 |
CRITICAL | 9.8 | The Hotel Booking plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 3.6. This… | — | wordfence |
| 9dda0b0a-234c-46bb-950a-2b7a5ef3227b | CRITICAL | 9.8 | The Grace Mag theme for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.1.5. This ma… | — | wordfence | |
| 9db30856-7541-4647-9e10-3855230b7efe | < 1.3.9 |
CRITICAL | 9.8 | The Zota theme for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.3.8. This makes i… | — | wordfence |
| 9d979d09-a019-420e-b46e-b1d1f5e430ae | < 5.5.0 |
CRITICAL | 9.8 | The miniOrange OTP Login, Verification and SMS Notifications plugin for WordPress is vulnerable to Privilege Escalation … | — | wordfence |
| 9d8551b8-67b9-45a8-9357-9e42fb451606 | CRITICAL | 9.8 | The Ya'aburnee and Dignitas themes for WordPress are vulnerable to Privilege Escalation in versions up to, and including… | — | wordfence | |
| 9d4bbf48-6525-4569-98a6-412f2bfe7628 | CRITICAL | 9.8 | The mail-masta plugin 1.0 for WordPress has local file inclusion in count_of_send.php and csvexport.php. | — | wordfence | |
| 9cd87da6-1f4c-4a15-8ebb-6e0f8ef72513 | < 1.25.0 |
CRITICAL | 9.8 | The Forminator plugin for WordPress is vulnerable to arbitrary file uploads due to file type validation occurring after … | — | wordfence |
| 9c7d2321-735a-4b5f-a36d-16375c994d2d | < 2.9.8 |
CRITICAL | 9.8 | The Paid Memberships Pro plugin for WordPress is vulnerable to SQL injection in versions before 2.9.8 via the 'code' par… | — | wordfence |
| 9c78e0b6-bf24-4a23-8501-b26e681a7a4a | < 2.0.0 |
CRITICAL | 9.8 | The Author Char plugin for WordPress is vulnerable to generic SQL Injection in versions up to, and including, 1.9.0 due … | — | wordfence |
| 9c3df12d-e526-4a23-89d3-bfdcea9f7b2d | < 3.6.1 |
CRITICAL | 9.8 | The Miniorange OTP Verification with Firebase plugin for WordPress is vulnerable to Arbitrary User Password Change in ve… | — | wordfence |
| 9c35ca72-6ce9-40de-a413-12455bfb610e | CRITICAL | 9.8 | The Meta Keywords & Description plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and includ… | — | wordfence | |
| 9c269233-f2dc-42ef-98be-78600f90e87d | CRITICAL | 9.8 | The MainWP Links Manager Extension plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and inc… | — | wordfence | |
| 9c14d918-daf9-46e8-9f96-4215e4645c62 | CRITICAL | 9.8 | The GNUCommerce plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 1.5.4 via d… | — | wordfence | |
| 9c101fca-037c-4bed-9dc7-baa021a8b59c | < 1.8.5 |
CRITICAL | 9.8 | The Hunk Companion plugin for WordPress is vulnerable to unauthorized plugin installation/activation due to a missing ca… | — | wordfence |
| 9bfcc607-9fbc-4d36-858d-a0f763597a3b | CRITICAL | 9.8 | The ZoomSounds plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 6.91 via des… | — | wordfence | |
| 9be94d63-f027-4988-ab41-673658c1fa5f | < 18.0 |
CRITICAL | 9.8 | The WooCommerce Checkout Field Manager plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient … | — | wordfence |
EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.
Scan My Website →