Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.
40,434 vulnerabilities found (page 1542 of 1618)
| CVE ID | Plugin / Theme | Severity | CVSS | Description | Fixed In | Source |
|---|---|---|---|---|---|---|
| 2b59d281-d5c8-455a-8aa8-b03847bdd45f | < 4.9.6 |
MEDIUM | 4.3 | The WP Links Page plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability ch… | — | wordfence |
| 2b49add4-a4ae-4527-95bd-c295200eeedd | < 6.5.1 |
MEDIUM | 4.3 | The LiteSpeed Cache plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 6.4.1. Th… | — | wordfence |
| 2b4035c9-1ffa-465e-84cb-1c30bb4fb95c | MEDIUM | 4.3 | The QR Code Tag for WC order emails, POS receipt emails, PDF invoices, PDF packing slips, Blog posts, Custom post types … | — | wordfence | |
| 2b365fb8-7a93-4306-b2b1-ce47dc19457a | < 1.15.79 |
MEDIUM | 4.3 | The WooCommerce Bookings plugin for WordPress is vulnerable to insecure direct object reference in versions up to, and i… | — | wordfence |
| 2b335807-f4d1-43b3-9e1b-2215eb00a3f8 | < 3.1.5 |
MEDIUM | 4.3 | The WP Meteor Page Speed Optimization Topping plugin for WordPress is vulnerable to unauthorized admin notice dismissal … | — | wordfence |
| 2b300f55-f1ee-4345-adc2-32cd3b081a30 | < 3.7.17 |
MEDIUM | 4.3 | wp-includes/rest-api/endpoints/class-wp-rest-users-controller.php in the REST API implementation in WordPress 4.7 before… | — | wordfence |
| 2b2b812d-b2bd-45d7-b712-482f41356764 | < 17.4.0 |
MEDIUM | 4.3 | The Salient | Creative Multipurpose & WooCommerce Theme theme for WordPress is vulnerable to unauthorized access due to … | — | wordfence |
| 2b2a10b6-e7dc-47c7-9f59-c4350d58b0d1 | < 0.1.0.25 |
MEDIUM | 4.3 | The InstaWP Connect plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on sever… | — | wordfence |
| 2b249842-c480-495a-8eec-6c7d0893ef1c | < 3.2 |
MEDIUM | 4.3 | The Rise Blocks β A Complete Gutenberg Page Builder plugin for WordPress is vulnerable to Cross-Site Request Forgery i… | — | wordfence |
| 2b229ea2-3a7d-42bd-a235-ffd18e206c8b | < 15.1 |
MEDIUM | 4.3 | The WP GoToWebinar plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on … | — | wordfence |
| 2af44b3e-62b4-4c27-8462-b2a82030a826 | < 1.0.67 |
MEDIUM | 4.3 | The Skrill Official plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and includin… | — | wordfence |
| 2ae3aaf6-457f-4b7f-b3bb-b4028980ef55 | MEDIUM | 4.3 | The Arabic Webfonts plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a fun… | — | wordfence | |
| 2ad0acd5-b5d8-481d-954e-a629bb0e11a8 | MEDIUM | 4.3 | The Progressive WordPress (PWA) plugin for WordPress is vulnerable to unauthorized access due to a missing capability ch… | — | wordfence | |
| 2ac7414c-8035-406a-ab1e-94d9f64e52fa | < 1.4.15 |
MEDIUM | 4.3 | The PixTypes plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.4.14. … | — | wordfence |
| 2ac3dd6c-6055-4a21-a4d2-e95ba5edc291 | < 1.4.6 |
MEDIUM | 4.3 | The Groovy Menu plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.4.5… | — | wordfence |
| 2abb66a3-67b9-48cb-acf1-18ee76eb3f70 | < 6.0.1 |
MEDIUM | 4.3 | The Export WordPress Pages to Static HTML & PDF β Static Site Export plugin for WordPress is vulnerable to Cross-Site … | — | wordfence |
| 2ab58add-ab81-4c84-b773-7daf382492b0 | < 3.2.3 |
MEDIUM | 4.3 | The Views for WPForms β Display & Edit WPForms Entries on your site frontend plugin for WordPress is vulnerable to una… | — | wordfence |
| 2a9ed6f2-3def-420c-b6d5-6343fcd7b147 | < 3.1.4 |
MEDIUM | 4.3 | The Wise Chat plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 3.1.3. … | — | wordfence |
| 2a8c62e6-f459-433a-b0c4-c79285ea7fe9 | < 11.3.33 |
MEDIUM | 4.3 | The HubSpot All-In-One Marketing - Forms, Popups, Live Chat plugin for WordPress is vulnerable to Sensitive Information … | — | wordfence |
| 2a7d6059-4cef-4bd1-a14d-ad544bfaeea3 | < 2.5.3 |
MEDIUM | 4.3 | The BetterDocs plugin for WordPress is vulnerable to unauthorized document modification due to a missing capability chec… | — | wordfence |
| 2a7b4c3c-a8a0-4f16-bfcb-5c2cd479fb9a | < 2.3.2 |
MEDIUM | 4.3 | The Fluent Support Pro plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a … | — | wordfence |
| 2a75f4eb-698b-4c92-9829-de6c55e21ecb | MEDIUM | 4.3 | The Under Construction / Maintenance Mode from Acurax plugin for WordPress is vulnerable to Sensitive Information Exposu… | — | wordfence | |
| 2a746ec6-c2fa-46ed-baf6-154659655235 | < 2.5.4 |
MEDIUM | 4.3 | The Request a Quote Form Plugin β Price Quote Request Management Made Easy plugin for WordPress is vulnerable to unaut… | — | wordfence |
| 2a60d27b-dfcc-464e-a927-eb6bb35f9932 | MEDIUM | 4.3 | The Frontend File Manager Plugin plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions … | — | wordfence | |
| 2a5f4a74-3974-4d08-8238-387e573a5655 | < 1.2.4 |
MEDIUM | 4.3 | The CM Table Of Contents β WordPress TOC Plugin plugin for WordPress is vulnerable to Cross-Site Request Forgery in al… | — | wordfence |
EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.
Scan My Website →