Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.
40,117 vulnerabilities found (page 862 of 1605)
| CVE ID | Plugin / Theme | Severity | CVSS | Description | Fixed In | Source |
|---|---|---|---|---|---|---|
| 9f3ccf43-dad2-445b-8e65-7d972249dc0b | MEDIUM | 6.1 | The WP Front-end login and register plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions… | — | wordfence | |
| 9f397671-0b59-4049-95af-3087e07685f0 | MEDIUM | 6.1 | The Pet Manager plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and includin… | — | wordfence | |
| 9f395100-cf1f-4a3e-a353-1aec6b4e7448 | < 1.5.47 |
MEDIUM | 6.1 | The PropertyHive plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'merge_ids' parameter in v… | — | wordfence |
| 9f2e0427-c000-4536-8639-b5f0c8f2b19f | < 2.1.14 |
MEDIUM | 6.1 | The MemberSpace plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 2… | — | wordfence |
| 9f200526-890c-4a2a-9d8e-334443ef7e0b | MEDIUM | 6.1 | The WP-Strava plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to… | — | wordfence | |
| 9f0fa6a7-43d8-4fc9-a2a3-7586d2bd986b | MEDIUM | 6.1 | The Auto scroll for reading plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and … | — | wordfence | |
| 9f0c2d65-a9b1-4ac4-8518-b5ba7dea25c8 | < 4.19.1 |
MEDIUM | 6.1 | The eForm - WordPress Form Builder plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions … | — | wordfence |
| 9f00b763-1b8a-4a20-96c6-7a93adf806e4 | < 1.2.6 |
MEDIUM | 6.1 | The Contact Form 7 Summary and Print plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to,… | — | wordfence |
| 9ef8f39e-6e5d-4ef6-a81d-0b2be3506ec1 | < 6.4.5 |
MEDIUM | 6.1 | The Complianz - GDPR/CCPA Cookie Consent plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up… | — | wordfence |
| 9ee9b2e9-e3fe-43b2-9caf-7246a4201fe9 | < 1.2.0 |
MEDIUM | 6.1 | The MailUp Auto Subscription plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and… | — | wordfence |
| 9ee4e021-946f-42e2-bae1-d73fdd34749d | < 7.7.2 |
MEDIUM | 6.1 | The Link Library plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, … | — | wordfence |
| 9ee11e19-21a6-45df-a118-f6dec3b55bc1 | < 1.0.8 |
MEDIUM | 6.1 | The CBX 5 Star Rating & Review plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'page' param… | — | wordfence |
| 9ec52096-27c8-4c42-bc89-4aef8239ec6e | < 4.1 |
MEDIUM | 6.1 | The SyncFields plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and excluding, 4.… | — | wordfence |
| 9ec1d3e0-eb30-4f46-b533-f57fd9a8510f | MEDIUM | 6.1 | The 17TRACK for WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and … | — | wordfence | |
| 9ebc263e-ff60-4e6f-8d93-02d99583447d | MEDIUM | 6.1 | The Add custom content after post plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions u… | — | wordfence | |
| 9eb14563-7aa6-4703-96ef-95708f08beff | < 1.1.1 |
MEDIUM | 6.1 | The Analytics Tracker plugin for WordPress is vulnerable to Cross-Site Scripting in versions up to, and including, 1.1.0… | — | wordfence |
| 9ea32791-edd3-4495-893e-668f42dcf5e9 | MEDIUM | 6.1 | Cross-site scripting (XSS) vulnerability in test-plugin.php in the Swipe Checkout for WooCommerce plugin 2.7.1 and earli… | — | wordfence | |
| 9e9ef3dd-9055-4f9f-b3af-6bf34c06292a | < 4.20.96 |
MEDIUM | 6.1 | The Anti-Malware Security and Brute-Force Firewall WordPress plugin before 4.20.96 does not sanitise and escape the QUER… | — | wordfence |
| 9e9a8383-7044-484d-8e4a-e9e4171da385 | < 1.27 |
MEDIUM | 6.1 | The Prolisting - Directory Listing theme for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to… | — | wordfence |
| 9e860c60-b330-4a6c-8d15-947451af62fc | < 1.7.1002 |
MEDIUM | 6.1 | The Royal Elementor Addons plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and i… | — | wordfence |
| 9e3899d8-170e-481f-8c80-90addc66eb41 | MEDIUM | 6.1 | The Woocommerce Custom Checkout Fields Editor With Drag & Drop plugin for WordPress is vulnerable to Reflected Cross-Sit… | — | wordfence | |
| 9e283a5a-98b7-464e-9426-cb414f3e3abf | < 3.96 |
MEDIUM | 6.1 | The Contact Form by BestWebSoft plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, … | — | wordfence |
| 9e2543be-e84f-424f-92cc-3a5d7e0a33b9 | MEDIUM | 6.1 | The Naver Blog plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.… | — | wordfence | |
| 9e169776-0475-45b8-8e8f-ac98cee558a3 | < 4.1.0 |
MEDIUM | 6.1 | The LearnPress Export Import plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and… | — | wordfence |
| 9e104e84-5b2c-4111-8950-54030950a790 | MEDIUM | 6.1 | The The Visitor Counter Plugin plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, a… | — | wordfence |
EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.
Scan My Website →