Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.
40,383 vulnerabilities found (page 1214 of 1616)
| CVE ID | Plugin / Theme | Severity | CVSS | Description | Fixed In | Source |
|---|---|---|---|---|---|---|
| 2db29c12-bf8a-4d5a-b12a-6c74b816d5f0 | < 3.5.4.9 |
MEDIUM | 5.3 | The Tickera β WordPress Event Ticketing plugin for WordPress is vulnerable to Information Exposure in all versions up … | — | wordfence |
| 2da883bf-5741-4eda-8a93-3b7feb90f4c6 | < 1.4.2 |
MEDIUM | 5.3 | The RomethemeKit For Elementor plugin for WordPress is vulnerable to unauthorized modification of data due to a missing … | — | wordfence |
| 2d9f9774-e45d-4b69-80e0-dce1e7c0ea78 | < 3.5.0 |
MEDIUM | 5.3 | The Slider & Popup Builder by Depicter β Add Image Slider, Carousel Slider, Exit Intent Popup, Popup Modal, Coupon Pop… | — | wordfence |
| 2d9d3588-9c71-485a-9183-3d1d4a936e03 | < 2.11.33 |
MEDIUM | 5.3 | The Welcart e-Commerce plugin for WordPress is vulnerable to Payment Bypass in all versions up to 2.11.33 (exclusive). T… | — | wordfence |
| 2d8cbc6e-cb75-4d7b-94a5-876c57cf3329 | MEDIUM | 5.3 | The Social Share Buttons for WordPress plugin for WordPress is vulnerable to unauthorized access due to a missing capabi… | — | wordfence | |
| 2d8ae431-04cd-49e4-a5ea-ea7b1263c836 | MEDIUM | 5.3 | The Caulk theme for WordPress is vulnerable to Sensitive Data Exposure in all versions. This could allow unauthenticated… | — | wordfence | |
| 2d7d83f6-92d1-43a8-821c-7b9470ead493 | < 3.4.27.1 |
MEDIUM | 5.3 | The Ninja Forms plugin before 3.4.27.1 for WordPress allows attackers to bypass validation via the email field. | — | wordfence |
| 2d790b52-bb2e-4bfa-bca1-34c0df721571 | < 6.1.1 |
MEDIUM | 5.3 | The Course Booking System plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on… | — | wordfence |
| 2d7330ac-22c6-48a7-91ab-66e2ec639964 | < 9.2.07.002 |
MEDIUM | 5.3 | The WP Photo Album Plus plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a… | — | wordfence |
| 2d5e247c-ec80-4d25-9fb3-dd17a3724a70 | MEDIUM | 5.3 | The Printeers Print & Ship plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 1.… | — | wordfence | |
| 2d532ffc-c6f1-41e3-9a59-0706802ab8e2 | MEDIUM | 5.3 | The App Builder β Create Native Android & iOS Apps On The Flight plugin for WordPress is vulnerable to Insecure Direct… | — | wordfence | |
| 2d36c088-d512-4c9a-a1bc-47a4ee597d63 | MEDIUM | 5.3 | The Aardvark plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function i… | — | wordfence | |
| 2d24aa7e-bbf1-4a54-b53b-7a37e613e0e6 | < 3.4.3 |
MEDIUM | 5.3 | The Rate my Post β WP Rating System plugin for WordPress is vulnerable to IP Address Spoofing in all versions up to, a… | — | wordfence |
| 2d1302c4-7aeb-49f4-aa11-2c0e08bd9c71 | < 3.8.7.2 |
MEDIUM | 5.3 | Cross-site scripting (XSS) vulnerability in wpsc-admin/display-sales-logs.php in WP e-Commerce plugin 3.8.7.1 and possib… | — | wordfence |
| 2ce8da99-a150-473f-9136-50e42833bb9a | MEDIUM | 5.3 | The Arcane theme for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in v… | — | wordfence | |
| 2cdacd01-0eae-4f38-9ecc-170a1a6e7d56 | MEDIUM | 5.3 | The Final User plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function… | — | wordfence | |
| 2cd92497-25ac-4560-82ed-e21a117d8c64 | < 1.3.3 |
MEDIUM | 5.3 | The Newsmatic theme for WordPress is vulnerable to unauthorized access due to a missing capability check on a function i… | — | wordfence |
| 2cc9f75d-f1a6-486b-b924-76ec618c5314 | < 2.0.74 |
MEDIUM | 5.3 | The Radio Player plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability che… | — | wordfence |
| 2cc27239-1464-4dba-99a2-4784e230ca48 | < 4.4.6 |
MEDIUM | 5.3 | The sailing theme for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in … | — | wordfence |
| 2cbc0b70-c8a4-4924-a67f-cea81ab19cdc | < 1.1.1 |
MEDIUM | 5.3 | The Branded Social Images plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capab… | — | wordfence |
| 2cb276a2-131b-4ce2-9968-2007ce9cdc93 | MEDIUM | 5.3 | The LA-Studio Element Kit for Elementor plugin for WordPress is vulnerable to unauthorized access due to a missing capab… | — | wordfence | |
| 2caff643-77a5-4951-80ac-177671c30fba | < 1.1.9 |
MEDIUM | 5.3 | The Internal Linking of Related Contents plugin for WordPress is vulnerable to unauthorized access due to a missing capa… | — | wordfence |
| 2ca879be-ac35-4bc6-b3f4-a6e8fdf02875 | MEDIUM | 5.3 | The Under Construction / Maintenance Mode from Acurax plugin for WordPress is vulnerable to IP Address Spoofing in all v… | — | wordfence | |
| 2c9cf461-572c-4be8-96e6-659acf3208f3 | < 4.0.12 |
MEDIUM | 5.3 | The Podlove Podcast Publisher plugin for WordPress is vulnerable to unauthorized modification of data due to a missing c… | — | wordfence |
| 2c931bd2-8c19-4211-9378-f32a1302defd | MEDIUM | 5.3 | The User Activity Log plugin for WordPress is vulnerable to unauthorized modification of data that can lead to a denial … | — | wordfence |
EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.
Scan My Website →