Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.
39,590 vulnerabilities found (page 194 of 1584)
| CVE ID | Plugin / Theme | Severity | CVSS | Description | Fixed In | Source |
|---|---|---|---|---|---|---|
| 2ef3c7fb-27f5-4829-8cb6-d3a52778a689 | < 5.9.0 |
HIGH | 8.8 | The ProfileGrid β User Profiles, Groups and Communities plugin for WordPress is vulnerable to privilege escalation in … | — | wordfence |
| 2ee331d9-32b3-4be4-8f25-d65c1192ff6b | HIGH | 8.8 | The Convert Docx2post plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation i… | — | wordfence | |
| 2edb574d-74b7-4f72-91a1-bb6632709b7a | < 3.6.5 |
HIGH | 8.8 | The WooCommerce plugin for WordPress is vulnerable to Cross-Site Request forgery in versions up to, and including 3.6.4,… | — | wordfence |
| 2ec6cf42-291b-452d-ad14-80ae1cd5ec5c | < 1.7.1 |
HIGH | 8.8 | The FundEngine plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 1.7.0. T… | — | wordfence |
| 2eac991e-fc34-456c-a9a6-d30fde39fd42 | HIGH | 8.8 | The HTML5 MP3 Player with Playlist Free plugin for WordPress is vulnerable to PHP Object Injection in all versions up to… | — | wordfence | |
| 2ea89c44-8ed0-4ab7-a049-4d1b03a898c7 | < 5.00 |
HIGH | 8.8 | The Content Visibility for Divi Builder plugin for WordPress is vulnerable to Remote Code Execution in all versions up t… | — | wordfence |
| 2e9142b2-2935-4644-8c56-00789948202b | HIGH | 8.8 | The HQ Rental Software plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and inclu… | — | wordfence | |
| 2e840f76-1b46-452e-bd63-507cbab779b9 | < 3.2.0 |
HIGH | 8.8 | The Time Tracker plugin for WordPress is vulnerable to unauthorized modification and loss of data due to a missing capab… | — | wordfence |
| 2e61942e-15ea-468c-b71a-50396d5b2730 | < 2.2 |
HIGH | 8.8 | An issue was discovered in the read-and-understood plugin 2.1 for WordPress. CSRF exists via wp-admin/options-general.ph… | — | wordfence |
| 2e329432-c404-4312-969b-42cac345637d | < 1.23.3 |
HIGH | 8.8 | The UpdraftPlus plugin for WordPress is vulnerable to Privilege Escalation due to missing authorization on the 'updraft_… | — | wordfence |
| 2e29a67b-2b67-4cd5-a5ae-a931900c75cd | < 1.3.9 |
HIGH | 8.8 | The LA-Studio Element Kit for Elementor plugin for WordPress is vulnerable to Local File Inclusion in all versions up to… | — | wordfence |
| 2e1a68fb-51c6-4567-9a50-78ed44ccac21 | HIGH | 8.8 | The Sermon Browser WordPress plugin through 0.45.22 does not have CSRF checks in place when uploading Sermon files, and … | — | wordfence | |
| 2dc616d6-489a-426b-bb52-a0449f907152 | < 3.0.0 |
HIGH | 8.8 | The Forms plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in all versio… | — | wordfence |
| 2da019d3-4aca-485a-aa0c-73728dc1e7c1 | HIGH | 8.8 | The WordPress Video Robot - The Ultimate Video Importer plugin for WordPress is vulnerable to privilege escalation due t… | — | wordfence | |
| 2d7feea5-965f-4a07-90f8-39ccdba7b50f | < 3.5.0 |
HIGH | 8.8 | A Cross-Site Request Forgery (CSRF) issue in the NextGEN Gallery plugin before 3.5.0 for WordPress allows File Upload. (… | — | wordfence |
| 2d7bc556-cdaf-42a7-8801-ad2e4945a137 | < 4.0.5 |
HIGH | 8.8 | The Photo Gallery, Sliders, Proofing and Themes β NextGEN Gallery plugin for WordPress is vulnerable to Local File Inc… | — | wordfence |
| 2d70b9b6-a1f0-4449-8d1a-ae16dbcc844d | < 2.0.2 |
HIGH | 8.8 | The Better Font Awesome plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and includin… | — | wordfence |
| 2d29f77c-b86d-4058-b528-27631e8a1f2e | < 7.0.8 |
HIGH | 8.8 | The Ecwid by Lightspeed Ecommerce Shopping Cart plugin for WordPress is vulnerable to Privilege Escalation in all versio… | — | wordfence |
| 2d20e8c9-975d-4e8c-8bea-50935853c7d4 | < 2.20.2 |
HIGH | 8.8 | The GutenBee β Gutenberg Blocks plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and… | — | wordfence |
| 2d07880b-9af1-4b1e-aa70-b95ef10a6e33 | < 3.6 |
HIGH | 8.8 | The Real Spaces - WordPress Properties Directory Theme theme for WordPress is vulnerable to privilege escalation via the… | — | wordfence |
| 2ce1a40f-1489-42be-963e-052274a56e47 | < 2.0.6 |
HIGH | 8.8 | The wpForo Forum plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.0.… | — | wordfence |
| 2cb275d5-ec4b-419f-84e1-84172d381411 | < 3.2.5 |
HIGH | 8.8 | The Redirection for Contact Form 7 plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and… | — | wordfence |
| 2caed42f-fb5b-488a-af15-f5ad3d82a68c | < 2.4.1 |
HIGH | 8.8 | The Profile Builder plugin for WordPress is vulnerable to Privilege Escalation in versions up to, and including, 2.4.0. … | — | wordfence |
| 2c994021-d429-4652-ada5-34ec0517cb19 | < 2.3 |
HIGH | 8.8 | The myCred WordPress plugin before 2.3 does not validate or escape the fields parameter before using it in a SQL stateme… | — | wordfence |
| 2c69dec6-4988-4760-8dc0-a11044dde406 | HIGH | 8.8 | The WP User Profiles plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 2.… | — | wordfence |
EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.
Scan My Website →