Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.
39,836 vulnerabilities found (page 399 of 1594)
| CVE ID | Plugin / Theme | Severity | CVSS | Description | Fixed In | Source |
|---|---|---|---|---|---|---|
| 2eb4608f-fa4f-444c-a857-c9059777a70b | < 2.9.1.1 |
HIGH | 7.2 | The Beaver Builder Plugin (Starter Version) plugin for WordPress is vulnerable to arbitrary file uploads due to missing … | — | wordfence |
| 2ea5c0e4-afee-4fbd-8b2e-9befd16c7935 | < 1.8.10 |
HIGH | 7.2 | The VikBooking Hotel Booking Engine & PMS plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions … | — | wordfence |
| 2e8f224c-cd22-4926-be24-9da2f22afa50 | < 3.2.6 |
HIGH | 7.2 | The WPML String Translation plugin for WordPress is vulnerable to SQL Injection via the ‘context’ parameter in versi… | — | wordfence |
| 2dfd592b-cbe9-460a-8b9a-148058d1bd58 | < 5.7.5 |
HIGH | 7.2 | The BackWPup plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 5.7.4 d… | — | wordfence |
| 2df059e6-a875-4e65-8cb4-bc409f450c09 | < 11.11 |
HIGH | 7.2 | The Visitor Traffic Real Time Statistics pro plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versio… | — | wordfence |
| 2db4eb1d-3a82-4f0f-b4ff-a291b0289b7f | < 6.5.0 |
HIGH | 7.2 | The Fancy Product Designer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all… | — | wordfence |
| 2d8e037e-c446-44ae-a5ee-bbba938e5edf | < 3.32.4 |
HIGH | 7.2 | The Age Verification & Identity Verification by Token of Trust plugin for WordPress is vulnerable to Stored Cross-Site S… | — | wordfence |
| 2d6a6159-5c8c-4d8f-9592-93b6ce74f082 | < 6.6.43 |
HIGH | 7.2 | The Product Feed Manager for WooCommerce – CTX Feed – Support 220+ Shopping & Social Channels plugin for WordPress i… | — | wordfence |
| 2d6304e5-7fbf-484d-b147-f2a6c2ee0658 | HIGH | 7.2 | The Cincopa video and media plug-in plugin for WordPress is vulnerable to Stored Cross-Site Scripting via cincopa Shortc… | — | wordfence | |
| 2d5c6566-a890-4b95-b349-3874eb57b45a | < 1.3.38 |
HIGH | 7.2 | The Contact Form Email plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'Message' field in vers… | — | wordfence |
| 2d32e6d1-67b4-44e1-b82a-78ce08aea1e6 | < 1.4.9 |
HIGH | 7.2 | The FOX – Currency Switcher Professional for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scrip… | — | wordfence |
| 2d0e5d24-5d65-4ed5-8086-347969cbd3ec | < 3.8.1 |
HIGH | 7.2 | The PDF Invoices & Packing Slips for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via s… | — | wordfence |
| 2c7c2b11-750a-48de-b48b-dcc6fbb8e917 | HIGH | 7.2 | The Note Press WordPress plugin through 0.1.10 does not sanitise and escape the ids from the bulk actions before using t… | — | wordfence | |
| 2c648ea4-7df6-4a77-9bc5-bd3c18979250 | < 2.53 |
HIGH | 7.2 | The Album and Image Gallery with Lightbox – Flagallery Photo Portfolio plugin for WordPress is vulnerable to generic S… | — | wordfence |
| 2c535cea-dad6-440f-b37f-6d196b469214 | < 1.69 |
HIGH | 7.2 | The WP-DownloadManager plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation … | — | wordfence |
| 2c314acf-d5bb-433a-8e2d-4ca333944bb6 | HIGH | 7.2 | The WordPress Database Administrator plugin for WordPress is vulnerable to SQL Injection via an AJAX action in versions … | — | wordfence | |
| 2c2f0e74-cdc0-4da9-bd79-8d09f5459be7 | HIGH | 7.2 | The Timeline Calendar WordPress plugin through 1.2 does not sanitise, validate or escape the edit GET parameter before u… | — | wordfence | |
| 2bf0832c-13ed-4e53-9847-d5d2110eb3f8 | < 10.6.1 |
HIGH | 7.2 | The WP Cost Estimation & Payment Forms Builder (E&P Forms) plugin for WordPress is vulnerable to Stored Cross-Site Scrip… | — | wordfence |
| 2baf528d-a24b-4cad-99c9-5fef9df3fe6d | HIGH | 7.2 | Vulnerability in wordpress plugin add-edit-delete-listing-for-member-module v1.0, The plugin author does not sanitize us… | — | wordfence | |
| 2b80fb3b-c874-468f-860b-ea0f93bb95bd | < 6.5.1.2 |
HIGH | 7.2 | The wpDataTables (Premium) plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and incl… | — | wordfence |
| 2b737a26-e4ae-4c9f-a98a-a22a31ac4f99 | < 1.6.7 |
HIGH | 7.2 | The Transbank Webpay REST plugin for WordPress is vulnerable to SQL Injection via the ‘oderby’ parameter in versions… | — | wordfence |
| 2b5d64b8-c339-4bbc-b91e-4805428f7296 | HIGH | 7.2 | The Newsletter Popup plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘nl_data’ parameter i… | — | wordfence | |
| 2b4aa268-a1c9-4ab0-8db4-483adae1d45e | < 3.8 |
HIGH | 7.2 | The WooCommerce Vehicle Parts Finder plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to… | — | wordfence |
| 2b1933a5-48f3-4707-8e3d-824b60ce2635 | < 2.0.9 |
HIGH | 7.2 | The My Sticky Elements plugin for WordPress is vulnerable to SQL Injection via the 'delete_message' parameter in version… | — | wordfence |
| 2b0f887c-b9e5-4d3c-b354-ebf5741dc3ba | < 1.3.8 |
HIGH | 7.2 | The Podcast Importer SecondLine WordPress plugin before 1.3.8 does not sanitise and properly escape some imported data, … | — | wordfence |
EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.
Scan My Website →