Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.
40,383 vulnerabilities found (page 1213 of 1616)
| CVE ID | Plugin / Theme | Severity | CVSS | Description | Fixed In | Source |
|---|---|---|---|---|---|---|
| 2ffd6393-6604-48d9-ba22-7d989305e9ed | MEDIUM | 5.3 | The Riaxe Product Customizer plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to,… | — | wordfence | |
| 2ff9570f-fca5-4e10-80ae-822608b6dd9d | < 1.2.168 |
MEDIUM | 5.3 | The Extra Product Options Builder for WooCommerce plugin for WordPress is vulnerable to unauthorized access due to a mis… | — | wordfence |
| 2ff30e1f-bb02-441c-bda7-af3fe9d4b5d8 | MEDIUM | 5.3 | The Responsive Posts Carousel WordPress Plugin plugin for WordPress is vulnerable to unauthorized access due to a missin… | — | wordfence | |
| 2fd8c981-081c-4671-ad1e-3caf004669dd | < 1.8.0 |
MEDIUM | 5.3 | The g-FFL Cockpit plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and includ… | — | wordfence |
| 2fd7d6af-a938-4106-aed2-12b9a5454da9 | < 1.2 |
MEDIUM | 5.3 | The secure-files plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 1.1 via… | — | wordfence |
| 2f91a7c3-ee0e-48e9-aa5f-dfc1160bbc09 | < 4.7.6 |
MEDIUM | 5.3 | The Simple Membership plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 4… | — | wordfence |
| 2f6eb792-aa01-4118-a7b3-e4ef50d6bcaf | < 7.2.7 |
MEDIUM | 5.3 | The WooCommerce Anti-Fraud plugin for WordPress is vulnerable to unauthorized access due to a missing capability check o… | — | wordfence |
| 2f51c73c-0eea-43b1-afae-ee8e8708a3d3 | < 4.9.3 |
MEDIUM | 5.3 | The YITH WooCommerce Product Add-Ons plugin for WordPress is vulnerable to Content Injection in all versions up to, and … | — | wordfence |
| 2f499d5e-eb27-4611-af27-ac9fd6a9f044 | < 2.0.80 |
MEDIUM | 5.3 | The Accept Stripe Payments plugin for WordPress is vulnerable to Content Injection in all versions up to, and including,… | — | wordfence |
| 2f32bf1e-acc7-4fbc-a448-75227dcced1d | < 3.5.0 |
MEDIUM | 5.3 | The Payoneer Checkout plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a f… | — | wordfence |
| 2f2ab0ba-6212-4466-835f-763ea01336b9 | < 2.11.1 |
MEDIUM | 5.3 | The SureForms β Contact Form Builder, AI Forms, Payment Form, Survey & Quiz plugin for WordPress is vulnerable to Paym… | — | wordfence |
| 2f12fa00-6108-4bd4-9310-8558211f4d0f | < 1.2.3 |
MEDIUM | 5.3 | The Campay Woocommerce Payment Gateway plugin for WordPress is vulnerable to Unauthenticated Payment Bypass in all versi… | — | wordfence |
| 2f127fe5-67b8-40e1-a916-c607410b08b3 | < 1.0.34 |
MEDIUM | 5.3 | The Product Designer plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check o… | — | wordfence |
| 2edbcf13-4cf8-46dd-a21e-1e5898ed4e50 | < 1.2.19 |
MEDIUM | 5.3 | The Better Chat Support for Messenger plugin for WordPress is vulnerable to unauthorized access due to a missing capabil… | — | wordfence |
| 2ecec7d7-d1b2-4ccf-ade6-1f78224968c6 | < 1.7.1057 |
MEDIUM | 5.3 | The Royal Addons for Elementor plugin for WordPress is vulnerable to unauthorized modification of data due to a missing … | — | wordfence |
| 2eae7c33-2347-4b34-8b5f-7f4a6ee3e9c1 | < 3.0 |
MEDIUM | 5.3 | The Sunshine Photo Cart plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions up to, and in… | — | wordfence |
| 2ea32997-9fe3-4f31-9c3a-28bc14af3713 | < 4.1.23 |
MEDIUM | 5.3 | The Google XML Sitemaps plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a… | — | wordfence |
| 2e933356-1faf-4766-9554-aad618052d83 | < 1.2.48 |
MEDIUM | 5.3 | The UsersWP β Front-end login form, User Registration, User Profile & Members Directory plugin for WP plugin for WordP… | — | wordfence |
| 2e90f61b-a74b-4f9f-a8ba-ea9ba3fa9987 | < 2.5.0 |
MEDIUM | 5.3 | The Easy Post Submission β Frontend Posting, Guest Publishing & Submit Content for WordPress plugin for WordPress is v… | — | wordfence |
| 2e69d666-50de-4c82-9ad4-9ed40fcc7218 | < 6.4.6.1 |
MEDIUM | 5.3 | The Community by PeepSo β Social Network, Membership, Registration, User Profiles plugin for WordPress is vulnerable t… | — | wordfence |
| 2e56e810-3884-4d2c-85c5-7d4ec8e27652 | < 6.0.2 |
MEDIUM | 5.3 | The Food Menu β Restaurant Menu & Online Ordering for WooCommerce plugin for WordPress is vulnerable to unauthorized a… | — | wordfence |
| 2e25557d-577b-4ac6-a006-43079ab4b77d | < 2.8.169 |
MEDIUM | 5.3 | The GeoDirectory plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and including, … | — | wordfence |
| 2e093d1f-9c5a-44f8-bc27-9c320e220358 | < 5.38.2 |
MEDIUM | 5.3 | The Customer Reviews for WooCommerce plugin for WordPress is vulnerable to unauthorized modification of data due to a mi… | — | wordfence |
| 2df8570b-c1a2-4a1b-b4d4-fe7a75eb05b6 | < 1.1.4.4 |
MEDIUM | 5.3 | The BEAR plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on th… | — | wordfence |
| 2dea1bcb-14c2-4ec9-8a4d-087bac2db486 | < 7.5.0 |
MEDIUM | 5.3 | The Blog2Social: Social Media Auto Post & Scheduler plugin for WordPress is vulnerable to Sensitive Information Exposure… | — | wordfence |
EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.
Scan My Website →