Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.
39,652 vulnerabilities found (page 321 of 1587)
| CVE ID | Plugin / Theme | Severity | CVSS | Description | Fixed In | Source |
|---|---|---|---|---|---|---|
| 2e5eee1d-4e0a-4ec2-93ff-86f0b3942ae2 | < 2.7.8 |
HIGH | 7.5 | The Multi Step for Contact Form plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 2.… | — | wordfence |
| 2e41eaf6-bb59-41a5-9c19-c119528287e9 | < 3.8.16 |
HIGH | 7.5 | The Easy Form Builder plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 3.8.15 due t… | — | wordfence |
| 2e3e3b0d-21cb-4b19-ba14-580b3d2802ab | HIGH | 7.5 | The Testimonial Slider plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 3.5.… | — | wordfence | |
| 2dfeeff5-5fcf-445b-af66-33ec873b7e44 | < 2.9.0 |
HIGH | 7.5 | The Email Verification for WooCommerce plugin for WordPress is vulnerable to SQL Injection in versions up to, and includ… | — | wordfence |
| 2db0b8c9-7908-484d-9a02-1c50f88efdd0 | < 2.2.4 |
HIGH | 7.5 | The LTL Freight Quotes β Purolator Edition plugin for WordPress is vulnerable to SQL Injection via the 'dropship_edit_… | — | wordfence |
| 2d6e3a66-4c25-485b-ad49-7ab083a59dd2 | HIGH | 7.5 | The Constant Contact for WordPress plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and… | — | wordfence | |
| 2d49fa2d-0625-40a4-b3dd-13679b806bc1 | < 1.1 |
HIGH | 7.5 | The AntiVirus plugin for WordPress is vulnerable to Sensitive Data Exposure in versions up to, and including, 1.0 via th… | — | wordfence |
| 2d044e0a-a956-4319-985d-6a9a276daf49 | HIGH | 7.5 | The WP-DB-Table-Editor plugin for WordPress is vulnerable to unauthorized access of data, modification of data, and loss… | — | wordfence | |
| 2cde1f4d-0212-48b1-a0ef-ba923c37ab50 | < 3.1.25 |
HIGH | 7.5 | Authenticated File Upload in WordPress Download Manager <= 3.1.24 allows authenticated (Author+) users to upload files w… | — | wordfence |
| 2cd53590-ded1-4e68-a9a3-aa1d2d880b80 | HIGH | 7.5 | The WP Forms Connector plugin for WordPress is vulnerable to SQL Injection via the 'order' parameter of the /wp-json/wp/… | — | wordfence | |
| 2cc737b3-4072-4dd4-8e50-ec94dc2a17d5 | < 2.6 |
HIGH | 7.5 | Directory traversal vulnerability in the WP e-Commerce Shop Styling plugin before 2.6 for WordPress allows remote attack… | — | wordfence |
| 2ca30fef-a014-4d19-b9f8-c51db512795b | HIGH | 7.5 | The "WP Intercom - Slack for WordPress" plugin for WordPress is vulnerable to Sensitive Data Exposure in versions up to,… | — | wordfence | |
| 2c0082ff-2a33-44e9-b0d0-8b9a404ab648 | < 2.6.5 |
HIGH | 7.5 | The Perfmatters plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 2.6.4 vi… | — | wordfence |
| 2bc5451c-c43e-4286-8a72-5bb41cfdc064 | HIGH | 7.5 | The Slider Responsive Slideshow β Image slider, Gallery slideshow plugin for WordPress is vulnerable to PHP Object Inj… | — | wordfence | |
| 2bb1aadd-5a7d-4a0c-8e5e-9ba7024e9c55 | < 3.2.6 |
HIGH | 7.5 | The Shopper plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 3.2.5 due to insuffici… | — | wordfence |
| 2ba4a8bb-c67c-42c5-8c4e-229756babc5f | < 1.2.0 |
HIGH | 7.5 | The Multi Plugin Installer plugin for WordPress is vulnerable to Arbitrary File Read in versions before 1.2.0. This is d… | — | wordfence |
| 2b8da4db-65f4-4c94-91c9-186d3abb7d51 | < 2.0.0 |
HIGH | 7.5 | The HieCOR Payment Gateway Plugin plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, … | — | wordfence |
| 2affce7c-6c59-4a50-ab26-5da2e18120d7 | < 1.4.7 |
HIGH | 7.5 | The Medilazar Core plugin for WordPress is vulnerable to Local File Inclusion in versions up to 1.4.7. This makes it pos… | — | wordfence |
| 2afe77cc-88f5-4778-893a-26517bd520cb | < 4.0.7 |
HIGH | 7.5 | The Easy Form Builder by WhiteStudio β Drag & Drop Form Builder plugin for WordPress is vulnerable to SQL Injection in… | — | wordfence |
| 2ad47937-8125-405c-9fd3-9b3b210942fa | HIGH | 7.5 | The ThemeMakers GamesTheme Premium theme through 2015-05-15 for WordPress allows remote attackers to obtain sensitive in… | — | wordfence | |
| 2ac3ffcf-50e0-42fc-a88d-cd7a51fbe1a9 | < 1.5.7 |
HIGH | 7.5 | The eRoom β Webinar & Meeting Plugin for Zoom, Google Meet, Microsoft Teams plugin for WordPress is vulnerable to Sens… | — | wordfence |
| 2a99a21c-d4f1-4cdb-b1f1-31b3cf666b80 | < 5.6.1 |
HIGH | 7.5 | The WP STAGING Pro WordPress Backup Plugin plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versi… | — | wordfence |
| 2a06dc0d-f002-4f82-b380-0e329b022dc9 | HIGH | 7.5 | An issue was discovered in the JSmol2WP plugin 1.07 for WordPress. There is an arbitrary file read vulnerability via ../… | — | wordfence | |
| 29a5701f-92f7-4a02-a990-b189a381cff5 | < 3.8.6.2 |
HIGH | 7.5 | The JetEngine plugin for WordPress is vulnerable to SQL Injection via the Custom Content Type (CCT) REST API search endp… | — | wordfence |
| 2959c04a-70bd-4f5c-a61a-1eab2609f8ef | < 3.0.5 |
HIGH | 7.5 | The JS Help Desk β AI-Powered Support & Ticketing System plugin for WordPress is vulnerable to SQL Injection via the `… | — | wordfence |
EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.
Scan My Website →