Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.
39,942 vulnerabilities found (page 711 of 1598)
| CVE ID | Plugin / Theme | Severity | CVSS | Description | Fixed In | Source |
|---|---|---|---|---|---|---|
| 2ac1168e-51a9-43a2-9086-6b75627bedbf | MEDIUM | 6.4 | The Bg Church Memos plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, … | — | wordfence | |
| 2abe953c-dd50-413c-8424-7cd9dbf92d67 | < 7.0.0.21 |
MEDIUM | 6.4 | The Xagio SEO plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 7.0.0.… | — | wordfence |
| 2ab4ac58-ea16-4b3b-8646-afe10f331f0c | < 5.4.2 |
MEDIUM | 6.4 | The tagDiv Composer plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, … | — | wordfence |
| 2aaca776-03ce-43bb-9553-f455f57124a3 | < 10.2.2 |
MEDIUM | 6.4 | The WP Booking Calendar plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'type' attribute withi… | — | wordfence |
| 2aa5b7e8-3030-47d3-9440-3b1b5c94b5ec | < 24.0.4 |
MEDIUM | 6.4 | The Contest Gallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, … | — | wordfence |
| 2a90678a-6f40-4f76-9ffb-576827005ec9 | < 5.10.0 |
MEDIUM | 6.4 | The Event post plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 5.9.1… | — | wordfence |
| 2a804605-c079-4310-a57f-81c3eb216dee | MEDIUM | 6.4 | The NOTICE BOARD plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.1… | — | wordfence | |
| 2a7f070a-b67c-4e65-a928-a6116266c54d | < 2.11.2 |
MEDIUM | 6.4 | The Ultimate Member β User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin plu… | — | wordfence |
| 2a6e37c1-aaac-4642-bace-234bbc4f6c38 | MEDIUM | 6.4 | The WP Meta SEO plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, … | — | wordfence | |
| 2a6bfc87-6135-4d49-baa2-e8e6291148dc | < 5.9.3 |
MEDIUM | 6.4 | The Meta Box β WordPress Custom Fields Framework plugin for WordPress is vulnerable to Stored Cross-Site Scripting via… | — | wordfence |
| 2a5eeae6-313a-4244-9d6a-583828521a3b | MEDIUM | 6.4 | The Shortcode Buddy plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Shortcode Attributes in all ve… | — | wordfence | |
| 2a5ccc0b-a80a-41df-991c-5c356eb10512 | < 6.2.1.1 |
MEDIUM | 6.4 | The WPJAM Basic plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in versi… | — | wordfence |
| 2a56b6f1-d3f1-4c6b-9657-a25ebc083b9e | < 3.0.8 |
MEDIUM | 6.4 | The Edwiser Bridge plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 3… | — | wordfence |
| 2a52f6ae-7cb2-493b-aa99-1d0e1e3cf567 | MEDIUM | 6.4 | The Card flip image slideshow plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, a… | — | wordfence | |
| 2a521be2-b3ce-47de-8a28-aeff94942d85 | < 3.0.4 |
MEDIUM | 6.4 | Multiple cross-site scripting (XSS) vulnerabilities in KSES, as used in WordPress before 3.0.4, allow remote attackers t… | — | wordfence |
| 2a4af494-ef5a-4bcb-916b-d4184d3df9b5 | < 3.1.45 |
MEDIUM | 6.4 | The Ditty β Responsive News Tickers, Sliders, and Lists plugin for WordPress is vulnerable to Stored Cross-Site Script… | — | wordfence |
| 2a49eb7f-971e-4039-ab2f-5844bf4f2775 | < 2.7.11 |
MEDIUM | 6.4 | The Job Postings plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including,… | — | wordfence |
| 2a295969-454a-47fb-bc35-4e84db38c887 | < 2.3.0 |
MEDIUM | 6.4 | The Garden Gnome Package plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's ggpkg shortc… | — | wordfence |
| 2a275deb-a0e3-491a-bed6-9f6112918061 | MEDIUM | 6.4 | The Social Feed Gallery Portfolio plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'id' paramet… | — | wordfence | |
| 2a225ccb-a7dc-4437-bd97-b309d6ae6a47 | < 5.9.10 |
MEDIUM | 6.4 | WordPress Core is vulnerable to Stored Cross-Site Scripting via the Template Part Block in various versions up to 6.5.5 … | — | wordfence |
| 2a203577-0ced-4e1e-a7db-e4ca53a5bade | MEDIUM | 6.4 | The Unique theme for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 0.3.0 … | — | wordfence | |
| 2a090167-0ea9-47f9-be8f-fe392da9ec38 | < 2.2.1 |
MEDIUM | 6.4 | The Embed Google Photos album plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, a… | — | wordfence |
| 29ef6956-aeb7-4a72-9f51-b5c5b05c1425 | MEDIUM | 6.4 | The YouTube Playlists with Schema plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'yt… | — | wordfence | |
| 29e9ad80-6a02-494a-9d53-0f14728952aa | MEDIUM | 6.4 | The Outgrow plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'id' attribute of the 'outgrow' sh… | — | wordfence | |
| 29de27d3-e9f5-4e73-8b6d-4491d2151d7f | < 1.1.0 |
MEDIUM | 6.4 | The Awesome Progress Bar plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and includ… | — | wordfence |
EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.
Scan My Website →