Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.
39,942 vulnerabilities found (page 709 of 1598)
| CVE ID | Plugin / Theme | Severity | CVSS | Description | Fixed In | Source |
|---|---|---|---|---|---|---|
| 2c251bf5-f6c0-4d2e-a240-95b0f1fce3f5 | MEDIUM | 6.4 | The GMAPS for WPBakery Page Builder Free plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions u… | — | wordfence | |
| 2c1ecd71-57ed-44ba-a007-3b96b98d3bf7 | < 1.5.3 |
MEDIUM | 6.4 | The CM Business Directory plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'cmbd_featu… | — | wordfence |
| 2c07b5c8-7fae-499d-9f6c-9392166f74b8 | < 3.8.3 |
MEDIUM | 6.4 | The WPBakery Page Builder Addons by Livemesh plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the p… | — | wordfence |
| 2bffed25-d7f0-40de-a55d-42653aff0673 | < 1.3.2 |
MEDIUM | 6.4 | The WP-WebAuthn plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.3.… | — | wordfence |
| 2bf70203-61c0-406a-9110-b60761b4a513 | < 1.0.6 |
MEDIUM | 6.4 | The pdfl.io plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'pdflio' shortcode in all versions… | — | wordfence |
| 2bf511b6-1b62-43e0-9df5-674a423f6ae2 | < 1.6.2 |
MEDIUM | 6.4 | The Testimonial Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘blockip’ paramete… | — | wordfence |
| 2bed4818-70c5-40b7-8d8d-f43f3baa0f3d | < 2.3.5 |
MEDIUM | 6.4 | The LightPress Lightbox plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `group` attribute in t… | — | wordfence |
| 2be1fbfc-a809-4a42-9be4-24c8274c1e71 | < 1.8.15 |
MEDIUM | 6.4 | The BA Book Everything plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's babe-search-fo… | — | wordfence |
| 2be16ee8-6bae-44d9-bde7-8e893293c3f9 | < 1.0.7 |
MEDIUM | 6.4 | The WOLF plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the wpbe_update_page_field parameter in v… | — | wordfence |
| 2be089a0-d4d5-4d64-8fb7-8c42286ebbcd | < 3.7.30 |
MEDIUM | 6.4 | WordPress before 5.2.3 allows XSS in media uploads because wp_ajax_upload_attachment is mishandled. | — | wordfence |
| 2be06087-4616-47bb-8a33-3bba97c47cb2 | < 3.5.37 |
MEDIUM | 6.4 | The Ultra Addons for Contact Form 7 plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to,… | — | wordfence |
| 2bde5862-1b7c-4e58-b13f-c8f347593c51 | < 2.26.9 |
MEDIUM | 6.4 | The IP2Location Country Blocker plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multiple parameter… | — | wordfence |
| 2bd989c7-b7dc-4243-83ae-23621d100052 | < 7.4.0 |
MEDIUM | 6.4 | The Booster for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and inc… | — | wordfence |
| 2bd6b66d-f33e-4287-850b-a199de72f6ad | < 5.4.1 |
MEDIUM | 6.4 | The tagDiv Composer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multiple shortcodes in all ver… | — | wordfence |
| 2bd53172-ddfa-481a-818d-626b9db6fe41 | < 2.6.9.3 |
MEDIUM | 6.4 | The Exclusive Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Post Grid W… | — | wordfence |
| 2bcc2783-1c47-47e4-ba63-822012aba0a6 | < 1.4.46 |
MEDIUM | 6.4 | The Open User Map – Interactive Leaflet Maps plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Sho… | — | wordfence |
| 2bc8a3fb-176e-4bf0-b96e-6ccb9688254b | < 1.1.9 |
MEDIUM | 6.4 | The WP Google Street View (with 360° virtual tour) & Google maps + Local SEO plugin for WordPress is vulnerable to Stor… | — | wordfence |
| 2bc0b654-5174-41bc-9e8a-40257ceb7ded | < 1.2.2 |
MEDIUM | 6.4 | The Rife Elementor Extensions & Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'tag… | — | wordfence |
| 2bbe86c8-d568-49e2-bf3f-830c1dd53dec | < 5.0.18 |
MEDIUM | 6.4 | The Ninja Tables Pro plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including,… | — | wordfence |
| 2bb15304-1e46-44c6-b21b-e6768b79240a | < 2.2.100 |
MEDIUM | 6.4 | The Accordion plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.2.99… | — | wordfence |
| 2ba55591-f4f3-4e90-9358-ca9c7ca01b09 | < 4.0.0 |
MEDIUM | 6.4 | The MapifyLite and MapifyPro plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and in… | — | wordfence |
| 2b9c4ca8-e5cd-4c4f-8d81-b06367c89fd7 | < 2026.2 |
MEDIUM | 6.4 | The Advanced iFrame plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'additional' parameter in … | — | wordfence |
| 2b9b501e-2ce7-43d8-bad2-6c3176eed8e2 | MEDIUM | 6.4 | The PayMaster for WooCommerce plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, a… | — | wordfence | |
| 2b9999f4-6bff-4658-ad58-7707e0d22ccc | MEDIUM | 6.4 | The WordPress Events Calendar Plugin – connectDaily plugin for WordPress is vulnerable to Stored Cross-Site Scripting … | — | wordfence | |
| 2b95b72e-b986-4492-9537-74fecf5e93a8 | < 1.3.7 |
MEDIUM | 6.4 | The Black Widgets For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and… | — | wordfence |
EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.
Scan My Website →