Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.
39,409 vulnerabilities found (page 83 of 1577)
| CVE ID | Plugin / Theme | Severity | CVSS | Description | Fixed In | Source |
|---|---|---|---|---|---|---|
| 2be3638e-3a0d-40e5-914e-9f20971abf9a | CRITICAL | 9.8 | SQL injection vulnerability in ahah/sf-profile.php in the Yellow Swordfish Simple Forum module for Wordpress allows remo… | — | wordfence | |
| 2bc8c04f-3764-473e-a216-7c5dc49abfa8 | CRITICAL | 9.8 | SQL injection vulnerability in settings.php in the Web Dorado Spider Video Player plugin 2.1 for WordPress allows remote… | — | wordfence | |
| 2b69f90a-1dd3-4184-aee3-9b0251b981cc | < 2.6.11 |
CRITICAL | 9.8 | The WP Migrate Pro plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 2.6.… | — | wordfence |
| 2b6489f8-061d-4fbd-81f2-9f508dd0e7f8 | < 3.3.1 |
CRITICAL | 9.8 | An arbitrary file upload vulnerability in the YITH WooCommerce Gift Cards Premium plugin before 3.3.1 for WordPress allo… | — | wordfence |
| 2b5a57d2-13bb-43d8-b495-e1d4d933b138 | < 4.0.19 |
CRITICAL | 9.8 | The Eyewear prescription form plugin for WordPress is vulnerable to unauthorized modification of data that can lead to p… | — | wordfence |
| 2b24693f-6b69-4dfb-a18c-e929db09d020 | < 1.4.6 |
CRITICAL | 9.8 | The Pagelines Theme for WordPress is vulnerable to authorization bypass due to a missing capability check on the pagelin… | — | wordfence |
| 2b0198c8-4be8-44e0-9728-d5d2aa376796 | < 2.0 |
CRITICAL | 9.8 | The WooCommerce PPOM plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in… | — | wordfence |
| 2ae44bcb-6149-4661-8890-23c867e9a918 | < 2.0.0 |
CRITICAL | 9.8 | The Ultimate Store Kit Elementor Addons, Woocommerce Builder, EDD Builder, Elementor Store Builder, Product Grid, Produc… | — | wordfence |
| 2ad674f7-aff6-432d-9c4c-95aebf8fcf6b | < 2.3.2 |
CRITICAL | 9.8 | SQL injection vulnerability in wp-includes/query.php in WordPress 2.3.1 and earlier allows remote attackers to execute a… | — | wordfence |
| 2ad1af69-61e1-4453-866e-1ae71f614f30 | < 2.1.7 |
CRITICAL | 9.8 | The Membership For WooCommerce plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type val… | — | wordfence |
| 2ab6e751-dc23-442f-b22e-ee41fd6651f6 | < 2.0.4 |
CRITICAL | 9.8 | Multiple unspecified vulnerabilities in WordPress before 2.0.4 have unknown impact and remote attack vectors. NOTE: due… | — | wordfence |
| 2a6c5610-ed84-4d7d-a28f-d3807230e119 | < 1.7.0 |
CRITICAL | 9.8 | The Web Directory Free plugin for WordPress is vulnerable to SQL Injection in all versions up to, and including, 1.6.9 d… | — | wordfence |
| 2a4caee4-f4fa-45a6-8fe8-d5445bb097bf | CRITICAL | 9.8 | The ListApp Mobile Manager plugin for WordPress is vulnerable to privilege escalation via account takeover in all versio… | — | wordfence | |
| 2a45fec7-cc69-4df6-98bb-ff70e5b6486c | CRITICAL | 9.8 | The LMS Elementor Pro plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1… | — | wordfence | |
| 2a3e8c29-2e97-48f0-bf72-303857b51511 | < 2.0.4 |
CRITICAL | 9.8 | The Enable CORS plugin contained a backdoor in all versions up to, and including, 2.0.3. This makes it possible for unau… | — | wordfence |
| 2a237492-0eb3-46fb-96dc-1959d8a87d1a | CRITICAL | 9.8 | The Stacks Mobile App Builder β The most powerful Mobile Applications Drag and Drop builder plugin for WordPress is vu… | — | wordfence | |
| 2a0671b1-1414-4315-8a2d-bd1aabe091a4 | < 6.2.0 |
CRITICAL | 9.8 | The WooCommerce Point of Sale plugin for WordPress is vulnerable to privilege escalation in all versions up to, and incl… | — | wordfence |
| 29e214fd-327b-45c4-a408-7ff56fd29876 | CRITICAL | 9.8 | The Boat Rental Plugin for WordPress plugin for WordPress is vulnerable to arbitrary file uploads due to missing file ty… | — | wordfence | |
| 29cbde71-772f-473c-9cad-0c5529b1aa97 | < 2.10.3 |
CRITICAL | 9.8 | The Backpack Traveler theme for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 2.10.2… | — | wordfence |
| 29cbcbc9-a2a3-4518-a430-969ca76f9bda | CRITICAL | 9.8 | The Homey Login Register plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including… | — | wordfence | |
| 29ca151b-ef37-4f68-b0ea-b199ad6a4fce | < 1.1.14 |
CRITICAL | 9.8 | The Booking Ultra Pro Appointments Booking Calendar Plugin plugin for WordPress is vulnerable to Local File Inclusion in… | — | wordfence |
| 29adf3d2-b3a4-43f3-9aaa-bd2cf6cd115b | CRITICAL | 9.8 | Vulnerability in wordpress plugin eventr v1.02.2, The edit.php form and event_form.php code do not sanitize input, this … | — | wordfence | |
| 2988bb1f-0a32-4e9b-8096-46476879317b | < 15.6.9 |
CRITICAL | 9.8 | The Simple Business Directory Pro plugin for WordPress is vulnerable to Privilege Escalation in all versions up to 15.6.… | — | wordfence |
| 2971547d-39da-46f1-b62c-1918042ae654 | < 3.4 |
CRITICAL | 9.8 | The Image News Slider plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation i… | — | wordfence |
| 2948d8f6-4b7b-49c3-a917-4306448416ff | < 2.6.4 |
CRITICAL | 9.8 | The Houzez Login Register plugin for WordPress is vulnerable to privilege escalation in versions up to, and including, 2… | — | wordfence |
EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.
Scan My Website →