Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.
40,383 vulnerabilities found (page 1093 of 1616)
| CVE ID | Plugin / Theme | Severity | CVSS | Description | Fixed In | Source |
|---|---|---|---|---|---|---|
| 2dca6c29-9f05-4d82-90e3-834f1dd8005a | < 3.14.0 |
MEDIUM | 5.4 | The GiveWP – Donation Plugin and Fundraising Platform plugin for WordPress is vulnerable to Insecure Direct Object Ref… | — | wordfence |
| 2dc9c744-6ffb-4d7a-94ce-ba576d7b6d47 | MEDIUM | 5.4 | The Category and Taxonomy Meta Fields plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to… | — | wordfence | |
| 2db39ae2-6c44-4a4c-84de-9b7041bece37 | < 4.8.9 |
MEDIUM | 5.4 | The Bold Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's "Separator" ele… | — | wordfence |
| 2d5a9a2d-63d3-411c-af22-2829fd79c72b | MEDIUM | 5.4 | The Buffer Button WordPress plugin through 1.0 was vulnerable to Authenticated Stored Cross Site Scripting (XSS) within … | — | wordfence | |
| 2d23541e-bb1c-4fcf-836b-28522a39b018 | MEDIUM | 5.4 | The All Users Messenger plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions up to, and in… | — | wordfence | |
| 2d0a822f-94b2-4875-b4b2-5c866555e3bd | < 3.1.7.1 |
MEDIUM | 5.4 | The WP Responsive Menu WordPress plugin before 3.1.7.1 does not have capability and CSRF checks in the wpr_live_update A… | — | wordfence |
| 2cfe69ae-2d42-484e-9c35-672394219ec2 | < 0.99 |
MEDIUM | 5.4 | An XSS vulnerability in the WP Lead Plus X plugin through 0.98 for WordPress allows logged-in users with minimal permiss… | — | wordfence |
| 2cfbee75-13ef-49ad-9edd-f3077a033c1b | MEDIUM | 5.4 | Multiple cross-site request forgery (CSRF) vulnerabilities in the Image Metadata Cruncher plugin for WordPress allow rem… | — | wordfence | |
| 2cf5879f-82ae-41de-b220-aaec45c96c87 | < 3.0.1 |
MEDIUM | 5.4 | The Feed Them Social plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘access_token’ param… | — | wordfence |
| 2cd509f7-100a-4f28-8d5a-b6b906456c52 | MEDIUM | 5.4 | The WP-Eggdrop plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 0.… | — | wordfence | |
| 2c5f2dc8-67f7-4dbf-8631-f434522f1b53 | < 4.1.8 |
MEDIUM | 5.4 | The Enable Media Replace plugin for WordPress is vulnerable to unauthorized modification of data due to an improper capa… | — | wordfence |
| 2c5cdc3f-eaa6-4d0b-9e75-5483c723e15a | < 2.6.9 |
MEDIUM | 5.4 | The Exclusive Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'Link To' u… | — | wordfence |
| 2c26d6de-5653-4be8-9526-39b30cb61625 | < 2.18.17 |
MEDIUM | 5.4 | The Wicked Folders plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the a… | — | wordfence |
| 2bff8dea-6971-47d4-bd2c-0821687033e5 | < 2.33.4 |
MEDIUM | 5.4 | The GiveWP plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.33.3. Th… | — | wordfence |
| 2b1f068f-6473-4875-a990-dd4bf337e7b7 | < 1.5.1 |
MEDIUM | 5.4 | The OpenPGP Form Encryption for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plug… | — | wordfence |
| 2a9bf519-bc55-411b-836a-fb394e317396 | < 1.5.5 |
MEDIUM | 5.4 | The Caldera Forms plugin for WordPress is vulnerable to Cross-Site Scripting via the "edit" parameter in versions up to,… | — | wordfence |
| 2a938325-45f5-455b-b2b7-e19e6e22cd0c | MEDIUM | 5.4 | The Post State Tags plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2… | — | wordfence | |
| 29b4c20b-486c-45d4-904f-561d6624d477 | MEDIUM | 5.4 | The CRM: Contact Management Simplified – UkuuPeople plugin for WordPress is vulnerable to Cross-Site Request Forgery i… | — | wordfence | |
| 29358ea9-21b7-4294-8fc9-0d38e689cf53 | < 2.18.17 |
MEDIUM | 5.4 | The Wicked Folders plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the a… | — | wordfence |
| 28fe3ec0-5e62-4a52-890d-e05b7d5bf531 | < 1.15.6 |
MEDIUM | 5.4 | Cross-Site Request Forgery (CSRF) vulnerability in Photo Gallery by Supsystic plugin <= 1.15.5 at WordPress allows chang… | — | wordfence |
| 28f0a927-a92e-45ab-8ef3-7a7c9368e1e4 | < 2.5.4.4 |
MEDIUM | 5.4 | The Beaver Builder plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the s… | — | wordfence |
| 28e16994-a03f-4b3a-9f45-e6b0a1334c98 | < 5.9.1 |
MEDIUM | 5.4 | The Events Tickets Plus plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and … | — | wordfence |
| 28aae3d4-c4c4-4cda-9f4b-7f2ea58629aa | < 3.6.0 |
MEDIUM | 5.4 | The Code Snippets plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to and including 3… | — | wordfence |
| 2821d32e-386b-4d6a-8079-b6b184d1d266 | < 1.0.02 |
MEDIUM | 5.4 | Multiple cross-site scripting (XSS) vulnerabilities in the scr_do_redirect function in scr.php in the Shortcode Redirect… | — | wordfence |
| 27d579d5-a4d2-45f7-a7bb-8f384d851d7a | < 1.2.1 |
MEDIUM | 5.4 | The Force First and Last Name as Display Name plugin for WordPress is vulnerable to Cross-Site Request Forgery in versio… | — | wordfence |
EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.
Scan My Website →