Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.
39,942 vulnerabilities found (page 722 of 1598)
| CVE ID | Plugin / Theme | Severity | CVSS | Description | Fixed In | Source |
|---|---|---|---|---|---|---|
| 2132d5b4-583d-46c0-be5e-6664bee9cad2 | < 2.1.0 |
MEDIUM | 6.4 | The DethemeKit For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, an… | — | wordfence |
| 21322495-a709-45a9-b8df-c3a3aeb1f260 | MEDIUM | 6.4 | The Responsive Image Gallery, Gallery Album plugin for WordPress is vulnerable to Stored Cross-Site Scripting in version… | — | wordfence | |
| 2130847a-b6c5-412e-8d90-ba42d3fb21f6 | < 3.8.0 |
MEDIUM | 6.4 | The WPFunnels β Easy Funnel Builder To Optimize Buyer Journeys And Get More Leads & Sales plugin for WordPress is vuln… | — | wordfence |
| 212e33f8-438b-4781-913f-a4f9f6d24a89 | < 0.9.2.1 |
MEDIUM | 6.4 | The Dropdown multisite selector plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's short… | — | wordfence |
| 211a104c-4311-4df9-9083-9cae92ea50b5 | MEDIUM | 6.4 | The Opal Service plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.9… | — | wordfence | |
| 210fa57c-7cf7-4ff1-84c4-5b3b6bd87a28 | < 4.0.3 |
MEDIUM | 6.4 | The Quantity Dynamic Pricing & Bulk Discounts for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Sc… | — | wordfence |
| 21065544-8a48-485b-88af-2e638b400de4 | < 5.0.5 |
MEDIUM | 6.4 | The Dokan: AI Powered WooCommerce Multivendor Marketplace Solution β Build Your Own Amazon, eBay, Etsy plugin for Word… | — | wordfence |
| 21019e1f-3d09-4727-8788-281c647d39dc | MEDIUM | 6.4 | The Photo Block β A Modern Image Block With Lightbox and Caption Support plugin for WordPress is vulnerable to Server-… | — | wordfence | |
| 2100d720-bfb4-451d-9907-e0b77ef507a5 | < 6.7.0 |
MEDIUM | 6.4 | The Essential Addons for Elementor β Popular Elementor Templates & Widgets plugin for WordPress is vulnerable to Store… | — | wordfence |
| 2100071c-aa66-445b-acef-7655e64f47e0 | < 1.15.8 |
MEDIUM | 6.4 | The Interactive Content β H5P plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads i… | — | wordfence |
| 20fc675c-08a4-4d77-9872-335d23146906 | < 1.2.3.36 |
MEDIUM | 6.4 | The Payment Button for PayPal plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'wp_pay… | — | wordfence |
| 20fb2c18-2502-4d2a-b329-da60070a42ea | < 1.3.7 |
MEDIUM | 6.4 | The Meks Flexible Shortcodes plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and in… | — | wordfence |
| 20e2454f-f49b-413f-ae45-8b628b30a780 | MEDIUM | 6.4 | The Embed Swagger UI plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'wpsgui' shortco… | — | wordfence | |
| 20daf751-176d-48f2-ac68-480fda89cee1 | < 1.6.2 |
MEDIUM | 6.4 | The WordPress Pinterest Plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'gs_pinterest' shortco… | — | wordfence |
| 20d16cc4-3bc2-4f1b-b7ba-17993199a997 | < 2.0.21 |
MEDIUM | 6.4 | The User profile plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.0… | — | wordfence |
| 20cd08ac-826f-40dd-804a-546b0c334b66 | < 1.4.15 |
MEDIUM | 6.4 | The WP Table Builder β WordPress Table Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via th… | — | wordfence |
| 20ba8f45-d101-46e1-b2c3-4f6a588a8fc9 | < 1.4.4 |
MEDIUM | 6.4 | The Norse Rune Oracle Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and in… | — | wordfence |
| 20b3c88f-a0df-4814-83b6-27440c5ad38e | MEDIUM | 6.4 | The Ultra Skype Button plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'btn_id' parameter of t… | — | wordfence | |
| 20b0a946-f429-4615-9d16-4a95a9120c3d | < 4.0.3 |
MEDIUM | 6.4 | The Payment Forms for Paystack plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortc… | — | wordfence |
| 20afddaa-5185-4224-a302-2d74461be648 | < 1.8.2 |
MEDIUM | 6.4 | The Termageddon: Cookie Consent & Privacy Compliance plugin for WordPress is vulnerable to Stored Cross-Site Scripting i… | — | wordfence |
| 20a67cde-612a-4c57-83d6-a5d8f3716a2d | < 2.8.2 |
MEDIUM | 6.4 | The HT Mega β Absolute Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the … | — | wordfence |
| 20793de1-468f-4b9d-8e1f-b05dc204c0fb | < 2.8.2 |
MEDIUM | 6.4 | The Post, Registration and Profile Form Builder β FrontEnd Editor BuddyForms β Easy WordPress Forms plugin for WordP… | — | wordfence |
| 2070c6e6-d830-4d1c-9408-5cb2254a00e5 | < 2.4.30 |
MEDIUM | 6.4 | The FooGallery β Responsive Photo Gallery, Image Viewer, Justified, Masonry & Carousel plugin for WordPress is vulnera… | — | wordfence |
| 206d343d-6ed6-461c-bf7d-cf5011ed956f | < 2.1.5 |
MEDIUM | 6.4 | The AI Engine plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 2.… | — | wordfence |
| 206c5736-d9d9-4029-afdf-d76251cc81ac | < 2.6.9.5 |
MEDIUM | 6.4 | The Exclusive Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Ca… | — | wordfence |
EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.
Scan My Website →