Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.
39,590 vulnerabilities found (page 195 of 1584)
| CVE ID | Plugin / Theme | Severity | CVSS | Description | Fixed In | Source |
|---|---|---|---|---|---|---|
| 2c643074-d57e-4878-b61d-2790ce9dadaa | HIGH | 8.8 | The OAuth Client by DigitialPixies plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, a… | — | wordfence | |
| 2c358cbe-7600-43a1-94a3-1530cdb5a9f3 | < 4.2.9 |
HIGH | 8.8 | The User Frontend: AI Powered Frontend Posting, User Directory, Profile, Membership & User Registration plugin for WordP… | — | wordfence |
| 2c25a344-4876-4ba8-bbc6-d1a32f4b1d08 | < 1.7.1 |
HIGH | 8.8 | The User Login History for WordPress is vulnerable to SQL Injection via the 'orderby' parameter in versions up to, and … | — | wordfence |
| 2c056904-5b2d-4ca6-8dcf-8ab5c1a7645b | < 2.5.2 |
HIGH | 8.8 | The Login/Signup Popup, Waitlist Woocommerce ( Back in stock notifier ), and Side Cart Woocommerce (Ajax) WordPress plug… | — | wordfence |
| 2bdb68bc-b773-4537-98dd-c54ffa5309c7 | < 1.16 |
HIGH | 8.8 | The ImageInject plugin 1.15 for WordPress has CSRF via wp-admin/options-general.php. | — | wordfence |
| 2bd2ce54-9ccb-4943-a01a-c9e8c1ff2d0d | < 3.1.9.2 |
HIGH | 8.8 | The WordPress Countdown Widget plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and i… | — | wordfence |
| 2bb4ead4-b2ad-42b4-92a0-fb7293f6df06 | < 6.30.16 |
HIGH | 8.8 | The WP Compress – Instant Performance & Speed Optimization plugin for WordPress is vulnerable to unauthorized access, … | — | wordfence |
| 2b881c73-2dfc-4b73-99f3-33432b750efd | < 2.5.6 |
HIGH | 8.8 | The Page View Count plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2… | — | wordfence |
| 2b84804d-cb60-4f83-a027-60455c9556c3 | HIGH | 8.8 | The Solar Energy theme for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 3.5 via des… | — | wordfence | |
| 2b8306b8-1f4c-48fb-8eb7-bf02a2f77e04 | < 1.62 |
HIGH | 8.8 | SQL injection vulnerability in wp-postratings.php in the WP-PostRatings plugin 1.50, 1.61, and probably other versions b… | — | wordfence |
| 2b5d27cc-c6eb-4c5c-8ee1-30483b91c6fd | < 4.3.2 |
HIGH | 8.8 | The User Frontend: AI Powered Frontend Posting, User Directory, Profile, Membership & User Registration plugin for WordP… | — | wordfence |
| 2b4df2b3-8d85-4e5c-8ead-92ed2259c84a | HIGH | 8.8 | In the Orange Form WordPress plugin through 1.0.1, the process_bulk_action() function in "admin/orange-form-email.php" p… | — | wordfence | |
| 2b39abc8-9281-4d58-a9ec-877c5bae805a | < 2.4 |
HIGH | 8.8 | The EnvíaloSimple: Email Marketing y Newsletters plugin for WordPress is vulnerable to Cross-Site Request Forgery in al… | — | wordfence |
| 2b38f102-e3ad-4715-99d0-ef8524e5c455 | HIGH | 8.8 | The Sage AI: Chatbots, OpenAI GPT-4 Bulk Articles, Dalle-3 Image Generation plugin for WordPress is vulnerable to arbitr… | — | wordfence | |
| 2b23b71d-1231-44ce-b992-5e74ddafb4bd | < 1.1.6 |
HIGH | 8.8 | The bbPress Move Topics plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 1.1… | — | wordfence |
| 2ae70225-3597-463b-907c-d2a3a7bcecb4 | < 1.0.8 |
HIGH | 8.8 | The WooCommerce Stock Manager plugin for WordPress is vulnerable to authorization bypass due to a missing capability che… | — | wordfence |
| 2ae0d83b-a444-4141-89da-b63ce216db17 | < 4.0 |
HIGH | 8.8 | The Ajax Search Pro plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 3… | — | wordfence |
| 2acd40d5-8a9c-4ca8-9c89-5bf639b1c66c | < 1.3 |
HIGH | 8.8 | The Process Steps Template Designer plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, … | — | wordfence |
| 2a691f92-9eff-4777-8198-b7cc5d9e73c0 | < 1.7.8.5 |
HIGH | 8.8 | The MDJM Event Management plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and includin… | — | wordfence |
| 2a681cef-649f-4342-beb6-914674bbf6d6 | < 0.1.0.9 |
HIGH | 8.8 | The InstaWP Connect – 1-click WP Staging & Migration plugin for WordPress is vulnerable to Remote Code Execution in al… | — | wordfence |
| 2a64b1ff-0d3f-42fa-bab2-4f31bb8f0476 | < 2.2.1 |
HIGH | 8.8 | The Tutor LMS plugin for WordPress is vulnerable to SQL Injection via many parameters in versions up to, and including, … | — | wordfence |
| 2a4e8dbe-9889-43b1-8e15-e96791b13093 | < 5.9 |
HIGH | 8.8 | Cross-Site Request Forgery (CSRF) vulnerability in KubiQ CPT base plugin <= 5.8 at WordPress allows an attacker to delet… | — | wordfence |
| 2a49db7f-62fc-472d-9edf-de5edbe48219 | < 9.6 |
HIGH | 8.8 | The XStore theme for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 9.5.4 via the… | — | wordfence |
| 2a296dd3-fbcb-4443-a905-9cbaa87faf7d | < 1.4.7 |
HIGH | 8.8 | The one-click-ssl plugin before 1.4.7 for WordPress has CSRF. | — | wordfence |
| 2a1ee053-18bc-4fcd-8bb9-d5295c503d20 | HIGH | 8.8 | The WooCommerce Registration Fields Plugin - Custom Signup Fields plugin for WordPress is vulnerable to Privilege Escala… | — | wordfence |
EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.
Scan My Website →