Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.
41,761 vulnerabilities found (page 86 of 1671)
| CVE ID | Plugin / Theme | Severity | CVSS | Description | Fixed In | Source |
|---|---|---|---|---|---|---|
| 3045c9e5-4095-48e5-8d9d-16a091e69d54 | < 1.3 |
CRITICAL | 9.8 | The Copypress Rest API plugin for WordPress is vulnerable to Remote Code Execution via copyreap_handle_image() Function … | — | wordfence |
| 2fb44c6e-520e-4a9f-9987-8b770feb710d | < 2.5.2 |
CRITICAL | 9.8 | The Kubio AI Page Builder plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and includin… | — | wordfence |
| 2fa6d06d-7323-42d1-94ef-9dfda9c166c4 | < 7.8.0 |
CRITICAL | 9.8 | The miniOrange Social Login and Register (Discord, Google, Twitter, LinkedIn) Pro Addon plugin for WordPress is vulnerab… | — | wordfence |
| 2fa59f00-49f5-43ff-b3fe-0a62f52b0257 | < 5.5.4 |
CRITICAL | 9.8 | The iControlWP plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 5.5.3. T… | — | wordfence |
| 2f8f6ade-84a2-4a42-9208-a74f5ebe19b3 | < 1.8.3 |
CRITICAL | 9.8 | The Collne Welcart e-Commerce plugin before 1.8.3 for WordPress mishandles sessions, which allows remote attackers to ob… | — | wordfence |
| 2f7e7b03-e709-44b6-8ff9-f2f0b3836629 | < 1.3.8 |
CRITICAL | 9.8 | The AI Hub plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in all versi… | — | wordfence |
| 2f6822a9-94b2-47a8-9faa-5e1498e0dbde | CRITICAL | 9.8 | The Background Image Cropper plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and incl… | — | wordfence | |
| 2f52298b-344b-4561-b1bf-93bea95a3e53 | < 1.0.29 |
CRITICAL | 9.8 | The Piotnet Forms plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in th… | — | wordfence |
| 2f47a01d-b259-465e-bec1-9079987dc5a5 | < 2.0.11 |
CRITICAL | 9.8 | The Kiwi Social Share plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on th… | — | wordfence |
| 2f0a7d6f-9b95-4052-bab3-85aca01f6ab7 | < 1.1.11 |
CRITICAL | 9.8 | The Form Notify plugin for WordPress is vulnerable to Authentication Bypass in versions up to and including 1.1.10. This… | — | wordfence |
| 2ef5e73e-a627-4e9c-9784-493ace5c8614 | < 4.91.9 |
CRITICAL | 9.8 | The VideoWhisper videowhisper-video-conference-integration plugin 4.91.8 for WordPress allows remote attackers to execut… | — | wordfence |
| 2ef21a44-6d03-4197-b49c-d881f9831f46 | < 8.9.1 |
CRITICAL | 9.8 | The Admin and Site Enhancements (ASE) Pro plugin for WordPress is vulnerable to Remote Code Execution in all versions up… | — | wordfence |
| 2eeeb4b5-972b-471b-8f0f-a198640fc894 | < 3.0 |
CRITICAL | 9.8 | The Memphis Documents Library plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and includin… | — | wordfence |
| 2e88aa9e-6d1d-44ba-8d63-2f4d4161bc9e | < 3.4 |
CRITICAL | 9.8 | The NEX-Forms β Ultimate Form Builder β Contact forms and much more plugin for WordPress is vulnerable to time-based… | — | wordfence |
| 2e78cb46-7964-4ba5-b9bf-d47de865dbd2 | < 6.3.2 |
CRITICAL | 9.8 | The WP BASE Booking of Appointments, Services and Events plugin for WordPress is vulnerable to Privilege Escalation in a… | — | wordfence |
| 2e6c60bb-d7c9-4925-afbe-00ea847d1f0b | CRITICAL | 9.8 | The Alone β Charity Multipurpose Non-profit WordPress Theme theme for WordPress is vulnerable to Remote Code Execution… | — | wordfence | |
| 2e24da0c-13d2-4a3d-b918-0d28e3341d88 | CRITICAL | 9.8 | The Lifeline Donation plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 1.2.… | — | wordfence | |
| 2e1ab5a7-0be8-444d-8680-68b3b0be6edf | < 3.29.13 |
CRITICAL | 9.8 | The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and i… | — | wordfence |
| 2df89ab9-5cc2-46cb-99b2-bc864e960a35 | < 2.4.3 |
CRITICAL | 9.8 | The Wp-Insert plugin through 2.4.2 for WordPress allows upload of arbitrary PHP code because of the exposure and configu… | — | wordfence |
| 2df449b4-3f3b-4afc-b391-8d8d11710c07 | < 2.1.47 |
CRITICAL | 9.8 | The Blocksy Companion plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, … | — | wordfence |
| 2d6e9aea-6ccb-4c83-83bb-63c9c9f59005 | < 3.4.12 |
CRITICAL | 9.8 | The wcfm_ajax_controller AJAX action of the WCFM Marketplace WordPress plugin before 3.4.12, available to unauthenticate… | — | wordfence |
| 2d6cbfc8-1ced-4757-b090-39add17afc77 | < 5.3.0 |
CRITICAL | 9.8 | The Realtyna Organic IDX plugin + WPL Real Estate plugin for WordPress is vulnerable to arbitrary file uploads due to mi… | — | wordfence |
| 2d64e1c6-1e25-4438-974d-b7da0979cc40 | < 4.2.6.6 |
CRITICAL | 9.8 | The LearnPress β WordPress LMS Plugin plugin for WordPress is vulnerable to time-based SQL Injection via the βterm_i… | — | wordfence |
| 2d58322f-e24d-40fd-8dab-20752b386bb9 | CRITICAL | 9.8 | The WP REST API FNS Plugin plugin for WordPress is vulnerable to privilege escalation in all versions up to, and includi… | — | wordfence | |
| 2d35279d-299e-4ca2-8f84-165284e058c8 | < 5.9.9.6 |
CRITICAL | 9.8 | The ProfileGrid β User Profiles, Groups and Communities plugin for WordPress is vulnerable to privilege escalation via… | — | wordfence |
EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.
Scan My Website →