Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.
40,117 vulnerabilities found (page 966 of 1605)
| CVE ID | Plugin / Theme | Severity | CVSS | Description | Fixed In | Source |
|---|---|---|---|---|---|---|
| 2f79778c-c11a-4d98-bc26-8113c3fef630 | < 2.1.2 |
MEDIUM | 6.1 | The Transporters.io plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and includin… | — | wordfence |
| 2f715a80-ec70-4f1e-8ec9-c6f70173e5d7 | < 4.3.21 |
MEDIUM | 6.1 | The NextScripts: Social Networks Auto-Poster <= 4.3.20 WordPress plugin is vulnerable to Reflected Cross-Site Scripting … | — | wordfence |
| 2f640ae4-b53b-4644-9c47-0d360057c01a | MEDIUM | 6.1 | The Events Planner plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including… | — | wordfence | |
| 2f621cfa-d02e-4414-bb1d-6e23da3c92b9 | < 1.4.4 |
MEDIUM | 6.1 | The Themify β WooCommerce Product Filter plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all v… | — | wordfence |
| 2f5d874a-d70e-4d3f-a9aa-d24707a3f7f4 | < 2.2.34 |
MEDIUM | 6.1 | The WooCommerce Bulk Stock Management plugin plugin for WordPress is vulnerable to Cross-Site Scripting in versions up t… | — | wordfence |
| 2f58d7e9-3764-4478-82ab-6d21990cd573 | MEDIUM | 6.1 | The Post Connector plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including… | — | wordfence | |
| 2f4a0b8d-0f3b-4ab1-929e-071b45781ca7 | < 1.8.3.1 |
MEDIUM | 6.1 | Cross-site scripting (XSS) vulnerability in wassup.php in the WassUp plugin before 1.8.3.1 for WordPress allows remote a… | — | wordfence |
| 2f438626-2984-49b8-878a-291887e81375 | < 3.1 |
MEDIUM | 6.1 | The Image Wall plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and including… | — | wordfence |
| 2f40b4fb-4e90-4a5a-9667-20e4087abe00 | < 9.2.07.002 |
MEDIUM | 6.1 | The Photo Album Plus plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and includi… | — | wordfence |
| 2f383a56-21e3-4f06-b4d4-47a269007cdc | < 1.6.1 |
MEDIUM | 6.1 | The Subaccounts for WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of a… | — | wordfence |
| 2f34854a-5ca1-48a3-81d5-80f80f3a85fc | MEDIUM | 6.1 | The WP Forms Puzzle Captcha plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and incl… | — | wordfence | |
| 2f340cfe-0829-444a-a67d-867ac8650b21 | MEDIUM | 6.1 | The kento-post-view-counter plugin through 2.8 for WordPress has stored XSS via kento_pvc_numbers_lang, kento_pvc_today_… | — | wordfence | |
| 2f280d50-196b-43a9-83f8-713d84ea1a00 | < 15.8 |
MEDIUM | 6.1 | The WP GoToWebinar plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including… | — | wordfence |
| 2f257c92-1529-49c8-a140-567ba5c36d04 | MEDIUM | 6.1 | Cross-site scripting (XSS) vulnerability in Peter's Random Anti-Spam Image 1.0.6 and earlier plugin for WordPress allows… | — | wordfence | |
| 2f14b0b9-6ccd-4f53-b015-e8537127b909 | < 1.1.4.3 |
MEDIUM | 6.1 | The BEAR β Bulk Editor and Products Manager Professional for WooCommerce by Pluginus.Net plugin for WordPress is vulne… | — | wordfence |
| 2f0e7f9f-cc9b-4e90-a768-776c927b6d83 | MEDIUM | 6.1 | The TRUSTist REVIEWer plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and includ… | — | wordfence | |
| 2f08961b-8da2-40bf-b197-aea76c4e79f9 | < 1.2.04.25 |
MEDIUM | 6.1 | The EZ Related Posts Footer Links and Widget plugin for WordPress is vulnerable to Cross-Site Request Forgery in all ver… | — | wordfence |
| 2efeffa2-b21a-4aa1-93b0-51c775758ab1 | MEDIUM | 6.1 | The Page Builder by AZEXO plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and includ… | — | wordfence | |
| 2ef6d5f4-fc29-4b9f-b3cc-834eff37b085 | MEDIUM | 6.1 | The Mobile Smart plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, … | — | wordfence | |
| 2ee837fd-a41e-44f2-81e8-258a7d8547bd | MEDIUM | 6.1 | The TheAgency theme for WordPress is vulnerable to Cross-Site Scripting due to insufficient input sanitization and outpu… | — | wordfence | |
| 2ee3d536-6d7b-41dc-9d63-52b9b4facf73 | < 1.3.3 |
MEDIUM | 6.1 | The Easy Digital Downloads (EDD) Digital Store theme for WordPress, as used with EDD 1.8.x before 1.8.7, 1.9.x before 1.… | — | wordfence |
| 2ec35484-8561-4a8c-bf67-0a880f915fb1 | MEDIUM | 6.1 | The Social Share With Floating Bar plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use o… | — | wordfence | |
| 2eb70d40-b1c1-456e-9207-66b6e91969eb | MEDIUM | 6.1 | The rognone plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'mode' parameter in versions up… | — | wordfence | |
| 2eb65c25-9400-4c5a-a4b2-b72628725500 | MEDIUM | 6.1 | The Starred Review plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the PHP_SELF variable in all… | — | wordfence | |
| 2e9291e8-b4f5-4fd1-aded-4690f82f6905 | < 3.3.2 |
MEDIUM | 6.1 | … | — | wordfence |
EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.
Scan My Website →