Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.
39,409 vulnerabilities found (page 82 of 1577)
| CVE ID | Plugin / Theme | Severity | CVSS | Description | Fixed In | Source |
|---|---|---|---|---|---|---|
| 2e88aa9e-6d1d-44ba-8d63-2f4d4161bc9e | < 3.4 |
CRITICAL | 9.8 | The NEX-Forms β Ultimate Form Builder β Contact forms and much more plugin for WordPress is vulnerable to time-based… | — | wordfence |
| 2e78cb46-7964-4ba5-b9bf-d47de865dbd2 | < 6.3.2 |
CRITICAL | 9.8 | The WP BASE Booking of Appointments, Services and Events plugin for WordPress is vulnerable to Privilege Escalation in a… | — | wordfence |
| 2e6c60bb-d7c9-4925-afbe-00ea847d1f0b | CRITICAL | 9.8 | The Alone β Charity Multipurpose Non-profit WordPress Theme theme for WordPress is vulnerable to Remote Code Execution… | — | wordfence | |
| 2e24da0c-13d2-4a3d-b918-0d28e3341d88 | CRITICAL | 9.8 | The Lifeline Donation plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 1.2.… | — | wordfence | |
| 2df89ab9-5cc2-46cb-99b2-bc864e960a35 | < 2.4.3 |
CRITICAL | 9.8 | The Wp-Insert plugin through 2.4.2 for WordPress allows upload of arbitrary PHP code because of the exposure and configu… | — | wordfence |
| 2df449b4-3f3b-4afc-b391-8d8d11710c07 | < 2.1.47 |
CRITICAL | 9.8 | The Blocksy Companion plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, … | — | wordfence |
| 2d6e9aea-6ccb-4c83-83bb-63c9c9f59005 | < 3.4.12 |
CRITICAL | 9.8 | The wcfm_ajax_controller AJAX action of the WCFM Marketplace WordPress plugin before 3.4.12, available to unauthenticate… | — | wordfence |
| 2d6cbfc8-1ced-4757-b090-39add17afc77 | < 5.3.0 |
CRITICAL | 9.8 | The Realtyna Organic IDX plugin + WPL Real Estate plugin for WordPress is vulnerable to arbitrary file uploads due to mi… | — | wordfence |
| 2d64e1c6-1e25-4438-974d-b7da0979cc40 | < 4.2.6.6 |
CRITICAL | 9.8 | The LearnPress β WordPress LMS Plugin plugin for WordPress is vulnerable to time-based SQL Injection via the βterm_i… | — | wordfence |
| 2d58322f-e24d-40fd-8dab-20752b386bb9 | CRITICAL | 9.8 | The WP REST API FNS Plugin plugin for WordPress is vulnerable to privilege escalation in all versions up to, and includi… | — | wordfence | |
| 2d35279d-299e-4ca2-8f84-165284e058c8 | < 5.9.9.6 |
CRITICAL | 9.8 | The ProfileGrid β User Profiles, Groups and Communities plugin for WordPress is vulnerable to privilege escalation via… | — | wordfence |
| 2d29c30c-bb42-4ed0-a78d-eeea5b256275 | < 1.71.0 |
CRITICAL | 9.8 | The ark-core plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 1.70.0. T… | — | wordfence |
| 2d23a2b9-8476-4564-a5de-5e6cfc38ce68 | < 1.6.6 |
CRITICAL | 9.8 | The WPBookit plugin for WordPress is vulnerable to Arbitrary User Password Change in versions up to, and including, 1.6.… | — | wordfence |
| 2d10f043-df2c-4e81-bd99-e478a2dca0cf | CRITICAL | 9.8 | The WordPress Shout Box Widget plugin is vulnerable to generic SQL Injection via the 'class_qshout.php' file in versions… | — | wordfence | |
| 2d048878-12ae-442a-921d-c02a4e1e3974 | < 34.06 |
CRITICAL | 9.8 | Multiple SQL injection vulnerabilities in CWPPoll.js in WordPress Poll Plugin 34.5 for WordPress allow attackers to exec… | — | wordfence |
| 2ceba97c-8dfe-4195-87f7-5835efa1cd1f | < 1.4.0 |
CRITICAL | 9.8 | The Checkout Field Visibility for WooCommerce plugin for WordPress is vulnerable to Local File Inclusion in versions up … | — | wordfence |
| 2cb40ada-03db-49ed-9f0d-84177238710b | CRITICAL | 9.8 | The Support Ticket Management System for WordPress plugin for WordPress is vulnerable to Privilege Escalation in all ver… | — | wordfence | |
| 2cb252c9-fd84-439a-9e7f-05a6000912eb | < 1.1.8 |
CRITICAL | 9.8 | The Meta News theme for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.1.7. This ma… | — | wordfence |
| 2c9fa6f9-a549-4629-862f-f9a47b13aa59 | < 3.11.9 |
CRITICAL | 9.8 | The User Profile Builder β Beautiful User Registration Forms, User Profiles & User Role Editor plugin for WordPress is… | — | wordfence |
| 2c8a2446-60c1-4641-9b5c-229327724333 | CRITICAL | 9.8 | The Goodlayers Hostel plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 3.1.2… | — | wordfence | |
| 2c7a0b51-6626-449f-95f5-74c4847909de | < 2.1.4.1 |
CRITICAL | 9.8 | The InPost Gallery Plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 2.1.4 vi… | — | wordfence |
| 2c5bb593-59b5-4760-8d54-14d7665c7e7f | < 6.03.01 |
CRITICAL | 9.8 | The Event Registration plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 6.02… | — | wordfence |
| 2c4615d4-92b4-45d3-9fb7-66c9f5d6bdd2 | CRITICAL | 9.8 | The GetShop ecommerce plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.3. … | — | wordfence | |
| 2c1e6298-f243-49a5-b1b7-52bd6a6c8858 | < 1.1 |
CRITICAL | 9.8 | The Frontend File Manager (versions < 4.0), N-Media Post Front-end Form (versions < 1.1) plugins for WordPress are vulne… | — | wordfence |
| 2be770c7-7aa2-430b-981d-5d81fe068bef | < 1.3.33 |
CRITICAL | 9.8 | The Tablesome Table β Contact Form DB β WPForms, CF7, Gravity, Forminator, Fluent plugin for WordPress is vulnerable… | — | wordfence |
EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.
Scan My Website →