Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.
40,117 vulnerabilities found (page 967 of 1605)
| CVE ID | Plugin / Theme | Severity | CVSS | Description | Fixed In | Source |
|---|---|---|---|---|---|---|
| 2e8abe63-c11b-48e7-8867-3bc1ab940b1f | < 1.2.6 |
MEDIUM | 6.1 | Cross-site request forgery (CSRF) vulnerability in improved-user-search-in-backend.php in the backend in the Improved us… | — | wordfence |
| 2e895698-30dd-4703-b085-e9e7ad1ec1e1 | MEDIUM | 6.1 | The Master Bar plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 1.… | — | wordfence | |
| 2e8527c0-a4b0-436d-901a-c07f93c7ec5e | < 1.0.49.47 |
MEDIUM | 6.1 | The Store credit / Gift cards for woocommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via t… | — | wordfence |
| 2e7b6ef6-1238-4987-a7ad-dd19bb055b80 | MEDIUM | 6.1 | The History timeline plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and inc… | — | wordfence | |
| 2e7a78e1-8c1a-4fb4-9959-d8fb7f9ee917 | < 4.20 |
MEDIUM | 6.1 | The Flexi - Guest Submit WordPress plugin before 4.20 does not sanitise and escape various parameters before outputting … | — | wordfence |
| 2e79b6b2-b227-44a4-85e3-6859c4f6f972 | MEDIUM | 6.1 | The Tournamatch plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 4… | — | wordfence | |
| 2e78bcfd-9764-49ae-9cac-cbc5419a0aa5 | < 4.3.7 |
MEDIUM | 6.1 | The LearnPress β WordPress LMS Plugin for Create and Sell Online Courses plugin for WordPress is vulnerable to Reflect… | — | wordfence |
| 2e6bd1d4-25ba-4475-8840-06f3d614d6d7 | MEDIUM | 6.1 | The WP Smart Editor plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and incl… | — | wordfence | |
| 2e69254d-d9e4-4b9e-972e-30bb6de86776 | < 4.1.8 |
MEDIUM | 6.1 | The mailchimp-for-wp plugin before 4.1.8 for WordPress has XSS via the return value of add_query_arg. | — | wordfence |
| 2e680ed2-36a9-4ca4-8865-4ce58bf8f5d6 | < 2.0.226 |
MEDIUM | 6.1 | The Contact Bank plugin for WordPress is vulnerable to Cross-Site Scripting via the 'form_id' parameter in versions befo… | — | wordfence |
| 2e62781e-4e35-479b-ad2f-617a679f180f | < 7.1 |
MEDIUM | 6.1 | The Pressroom - News Magazine WordPress Theme theme for WordPress is vulnerable to Reflected Cross-Site Scripting in ver… | — | wordfence |
| 2e5b3595-932c-4a42-b340-f162b29f69ee | MEDIUM | 6.1 | The Breezing Forms plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including… | — | wordfence | |
| 2e43b327-c141-480e-a5b2-bba179b3e0a1 | < 7.2.9 |
MEDIUM | 6.1 | The Link Library WordPress plugin before 7.2.9 does not sanitise and escape the settingscopy parameter before outputting… | — | wordfence |
| 2e405c91-e382-45d0-b01f-37774beeaf8b | < 1.4 |
MEDIUM | 6.1 | The Ultimate Classified Listings plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up… | — | wordfence |
| 2e2d54eb-c176-49c4-a4fc-833e17189cad | < 5.0.1 |
MEDIUM | 6.1 | The Matomo Analytics β Ethical Stats. Powerful Insights. plugin for WordPress is vulnerable to Reflected Cross-Site Sc… | — | wordfence |
| 2e268dfa-7761-4e52-9e97-288c58d2e5c3 | < 1.5.4 |
MEDIUM | 6.1 | The Barcode Scanner with Inventory & Order Manager plugin for WordPress is vulnerable to Reflected Cross-Site Scripting … | — | wordfence |
| 2e1ca3b7-e402-40de-bed9-f443e3a7c952 | MEDIUM | 6.1 | The Call To Action Popup plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and… | — | wordfence | |
| 2e11227f-87b0-42b2-98a5-555e49d983ad | MEDIUM | 6.1 | The EmailShroud plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2… | — | wordfence | |
| 2e08e1b5-d388-46cf-a9e7-4bab2a09667f | < 1.5.35 |
MEDIUM | 6.1 | Cross site scripting (XSS) in the photo-gallery (10Web Photo Gallery) plugin before 1.5.35 for WordPress exists via admi… | — | wordfence |
| 2dee25f3-cbe2-4c30-97db-6cc90157c1a6 | MEDIUM | 6.1 | The Contact Us By Lord Linus plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and… | — | wordfence | |
| 2db4a67d-0b54-4aa7-8d3a-b72fb3ad7f64 | MEDIUM | 6.1 | The Schedule plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and including, … | — | wordfence | |
| 2db15abf-344c-45f1-927d-61ac2647f6be | MEDIUM | 6.1 | The Map Contact plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3… | — | wordfence | |
| 2da9c3d0-7efb-4c34-bf31-2f17a52c21f9 | MEDIUM | 6.1 | The ultimate-weather plugin 1.0 for WordPress has XSS via the url parameter. | — | wordfence | |
| 2da965b1-1f8d-4905-9711-bb9ad30f444a | < 1.6.65 |
MEDIUM | 6.1 | The SpiderCalendar WordPress plugin through 1.5.65 does not sanitise and escape the callback parameter before outputting… | — | wordfence |
| 2d9bf916-cdbf-410b-95bb-ca7ce6658e1b | MEDIUM | 6.1 | The StudioZen Theme for WordPress is vulnerable to full path disclosure, content spoofing, and cross-site scripting in v… | — | wordfence |
EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.
Scan My Website →