Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.
40,434 vulnerabilities found (page 1541 of 1618)
| CVE ID | Plugin / Theme | Severity | CVSS | Description | Fixed In | Source |
|---|---|---|---|---|---|---|
| 2c883c96-3d7f-47b9-ba90-d464024b62fc | < 1.3 |
MEDIUM | 4.3 | The AIO Performance Profiler, Monitor, Optimize, Compress & Debug plugin for WordPress is vulnerable to unauthorized acc… | — | wordfence |
| 2c657483-204c-4117-ac7c-c0522d9c3816 | MEDIUM | 4.3 | The WooHoo Newspaper Magazine Theme theme for WordPress is vulnerable to Cross-Site Request Forgery in all versions up t… | — | wordfence | |
| 2c5ad2d5-3786-4bc0-aba0-f77bb5319ef9 | MEDIUM | 4.3 | The Site Offline Or Coming Soon Or Maintenance Mode plugin for WordPress is vulnerable to unauthorized access due to a m… | — | wordfence | |
| 2c4faf5b-70bf-4682-89bb-aa3fc19b29e8 | MEDIUM | 4.3 | The Import external attachments plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, … | — | wordfence | |
| 2c3d9fa7-8ea2-4213-8b28-2ca9191a8223 | < 3.5.8 |
MEDIUM | 4.3 | The MultiVendorX plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 3.5.… | — | wordfence |
| 2c3b1b88-227a-4d0b-bd78-a1088c17a91e | MEDIUM | 4.3 | The User Roles and Capabilities plugin for WordPress is vulnerable to unauthorized access due to a missing capability ch… | — | wordfence | |
| 2c368677-e436-412a-9a88-89d128d72aa0 | MEDIUM | 4.3 | The Ultimate Classified Listings plugin for WordPress is vulnerable to unauthorized modification of data due to a missin… | — | wordfence | |
| 2c2d9569-a551-46f5-8581-464b9f35b71c | < 5.0 |
MEDIUM | 4.3 | The MainWP Dashboard β WordPress Manager for Multiple Websites Maintenance plugin for WordPress is vulnerable to Cros… | — | wordfence |
| 2c1dd87c-cc28-43b3-8378-4583dc6de195 | < 15 |
MEDIUM | 4.3 | The Admin and Customer Messages After Order for WooCommerce: OrderConvo plugin for WordPress is vulnerable to Missing Au… | — | wordfence |
| 2c16048a-6b05-48ef-92c3-6e3a42909adb | < 19.12.1 |
MEDIUM | 4.3 | The Poll, Survey & Quiz Maker Plugin by Opinion Stage plugin for WordPress is vulnerable to Cross-Site Request Forgery i… | — | wordfence |
| 2c148123-9da3-4384-8aec-4ee71cb05e01 | < 1.3.6 |
MEDIUM | 4.3 | The Responsive Image Slider, Photo Gallery And Carousel plugin for WordPress is vulnerable to arbitrary post access due … | — | wordfence |
| 2c02b9b2-b41e-4a30-b69a-9cdae86dd7a7 | MEDIUM | 4.3 | The Chronoforms plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 7.0.9… | — | wordfence | |
| 2bed7fc8-a961-4141-80a1-9c23a6504fbd | < 1.1.7 |
MEDIUM | 4.3 | The Subscriptions & Memberships for PayPal plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versi… | — | wordfence |
| 2be578d9-27c3-4a16-a634-1514ed97a1a2 | < 4.0.7.4 |
MEDIUM | 4.3 | The EventPrime β Events Calendar, Bookings and Tickets plugin for WordPress is vulnerable to unauthorized access of da… | — | wordfence |
| 2bc82c22-8fac-409d-9331-b5cc3bd29c43 | < 6.2.5 |
MEDIUM | 4.3 | The Broadcast Live Video β Live Streaming : WebRTC, HLS, RTSP, RTMP plugin for WordPress is vulnerable to Cross-Site R… | — | wordfence |
| 2bc2c2f8-fb1c-4c37-83d1-d05abd17fbeb | < 3.5.5 |
MEDIUM | 4.3 | The AI Engine β The Chatbot, AI Framework & MCP for WordPress plugin for WordPress is vulnerable to Insecure Direct Ob… | — | wordfence |
| 2bbf9526-1a82-496e-b762-6fa114ba8d46 | < 1.1.7 |
MEDIUM | 4.3 | The Comments Ratings plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, … | — | wordfence |
| 2ba56b4c-0573-4911-97a4-a51e867daa75 | < 1.4.13 |
MEDIUM | 4.3 | The Blog Floating Button plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and includi… | — | wordfence |
| 2b9ea2a2-34af-408c-91ee-6d5fd9431529 | < 4.7.1 |
MEDIUM | 4.3 | The AnnunciFunebri Impresa plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capa… | — | wordfence |
| 2b732bce-29a5-4b1f-99a2-b3153c0e82ed | < 2.6.0 |
MEDIUM | 4.3 | The TS Poll plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in… | — | wordfence |
| 2b70032d-cfd5-4415-a5d6-d594ed265a5b | < 2.16.9 |
MEDIUM | 4.3 | The Paid Membership Subscriptions β Effortless Memberships, Recurring Payments & Content Restriction plugin for WordPr… | — | wordfence |
| 2b6b4953-a264-4668-9cc3-1578109f6592 | < 1.0.4 |
MEDIUM | 4.3 | The Preview Link Generator plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and inclu… | — | wordfence |
| 2b670550-cf04-4db1-95e7-0330b5793c58 | < 1.6.2 |
MEDIUM | 4.3 | The VikBooking Hotel Booking Engine & PMS plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions u… | — | wordfence |
| 2b5eecb3-b001-4a07-806d-5d4a39622853 | < 3.3.1 |
MEDIUM | 4.3 | The GS Testimonial Slider plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on… | — | wordfence |
| 2b5d0d8f-fee6-4bee-9b01-c23ce1f27dfe | MEDIUM | 4.3 | The WP No-Bot Question plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and inclu… | — | wordfence |
EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.
Scan My Website →