Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.
39,942 vulnerabilities found (page 761 of 1598)
| CVE ID | Plugin / Theme | Severity | CVSS | Description | Fixed In | Source |
|---|---|---|---|---|---|---|
| 9fd38e86-6448-47fd-a8a7-f571158e3599 | < 2.9.14 |
MEDIUM | 6.3 | The Sunshine Photo Cart plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on … | — | wordfence |
| 9ea2964f-9e3a-450b-9724-5a520c73d306 | < 0.9.97.20 |
MEDIUM | 6.3 | TheAMP for WP plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the ampfor… | — | wordfence |
| 9e9823e6-bcd4-4c1e-bf86-caf472748b12 | < 2.3.4 |
MEDIUM | 6.3 | In the Redirection for Contact Form 7 WordPress plugin before 2.3.4, any authenticated user, such as a subscriber, could… | — | wordfence |
| 9d49e28b-8b5e-4c67-a36d-c78ee33ffc6e | < 1.5.66 |
MEDIUM | 6.3 | The Unlimited Elements For Elementor (Free Widgets, Addons, Templates) plugin for WordPress is vulnerable to unauthorize… | — | wordfence |
| 9764d402-b8a2-43d5-882a-bc3886078b7f | < 11.17 |
MEDIUM | 6.3 | The Media from FTP plugin for WordPress is vulnerable to improper privilege management due to an insufficient capability… | — | wordfence |
| 962af7eb-b2eb-4190-bf0d-cb05cb28f10b | < 2.7.8 |
MEDIUM | 6.3 | The "JS Help Desk β Best Help Desk & Support Plugin" plugin for WordPress is vulnerable to Insecure Direct Object Refe… | — | wordfence |
| 9251afbb-1a6d-40c6-b62e-a8866742f669 | < 12.1.21 |
MEDIUM | 6.3 | The SEO Plugin by Squirrly SEO plugin for WordPress is vulnerable to unauthorized access/modification or loss of data du… | — | wordfence |
| 9071acdf-8d40-4e8b-8d1f-be2cabf3d66e | < 4.900 |
MEDIUM | 6.3 | The WPLMS theme for WordPress is vulnerable to Cross-Site Request Forgery in versions up to 4.900. This is due to missi… | — | wordfence |
| 8f9ee168-82b1-4d13-a84e-379f16dcb283 | < 1.7.2 |
MEDIUM | 6.3 | The RapidLoad Power-Up for Autoptimize plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up t… | — | wordfence |
| 8eee3809-133e-4fd9-ad49-cc6fe3822457 | < 1.0.3 |
MEDIUM | 6.3 | The Themehunk Login Registration plugin for WordPress is vulnerable to privilege escalation in versions up to, and inclu… | — | wordfence |
| 8b32c517-ef6b-4cc9-8316-6289676d8222 | < 3.8.6 |
MEDIUM | 6.3 | The WooCommerce Ship to Multiple Addresses plugin for WordPress is vulnerable to unauthorized use of functionality due t… | — | wordfence |
| 89dab433-91e9-4500-ab40-f4b500e66983 | < 6.11 |
MEDIUM | 6.3 | The Spam protection, AntiSpam, FireWall by CleanTalk plugin for WordPress is vulnerable to unauthorized access and modif… | — | wordfence |
| 893500ba-cc16-4429-bbe1-725aa65589c9 | < 3.1.2.1 |
MEDIUM | 6.3 | Multiple plugins by Crocoblock for WordPress are vulnerable to unauthorized access due to a missing capability check on … | — | wordfence |
| 88d16ce2-a1cf-4402-b140-3cab17f8c638 | < 2.4.1.9 |
MEDIUM | 6.3 | The Oliver POS β A WooCommerce Point of Sale (POS) plugin for WordPress is vulnerable to Cross-Site Request Forgery in… | — | wordfence |
| 88907f28-7b1d-4a5a-b846-67dfd21d6488 | < 4.0.23 |
MEDIUM | 6.3 | The ARMember plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 4.0.22. … | — | wordfence |
| 87e3d9bc-a14c-4134-91ed-9de5177942ca | < 3.1.6 |
MEDIUM | 6.3 | The Templately plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check… | — | wordfence |
| 85af2186-0807-4926-9285-f8ac93f76b93 | < 4.9.1 |
MEDIUM | 6.3 | Insecure Direct Object References (IDOR) vulnerability in Spiffy Plugins Spiffy Calendar <= 4.9.0 at WordPress allows an… | — | wordfence |
| 7ffba592-6d0d-408f-89fa-079066750b0a | MEDIUM | 6.3 | The Waiting: One-click countdowns plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, an… | — | wordfence | |
| 7e697e7f-8d5b-4a9f-9148-f2dc5fb1ba38 | < 1.4.4.2 |
MEDIUM | 6.3 | The Web and WooCommerce Addons for WPBakery Builder plugin for WordPress is vulnerable to authorization bypass in versio… | — | wordfence |
| 7bfabeb4-c57d-412a-b27b-a6387d30081f | < 1.8.2 |
MEDIUM | 6.3 | The HappyFiles Pro plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability c… | — | wordfence |
| 7ae1d155-deb4-4847-858b-37b5cd9ac1c5 | < 1.08 |
MEDIUM | 6.3 | The FormBuilder plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions before 1.08. This is due to… | — | wordfence |
| 7a5da306-c798-4f2b-8875-8ae54c83ccd8 | MEDIUM | 6.3 | The radSLIDE plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function i… | — | wordfence | |
| 79b5883b-a3be-497e-b911-7dc39e7fb418 | < 2.9.61 |
MEDIUM | 6.3 | The WordPress Download Manager plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and i… | — | wordfence |
| 798b57ad-0922-435c-8b4d-8a96b388b314 | < 6.6.0 |
MEDIUM | 6.3 | The WCFM Frontend Manager plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and includ… | — | wordfence |
| 75f0bc5a-f588-4aeb-9e55-72e180d39ddf | < 1.0.22 |
MEDIUM | 6.3 | The ALD Dropping and Fulfillment for AliExpress and WooCommerce plugin for WordPress is vulnerable to unauthorized acces… | — | wordfence |
EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.
Scan My Website →