Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.
40,117 vulnerabilities found (page 970 of 1605)
| CVE ID | Plugin / Theme | Severity | CVSS | Description | Fixed In | Source |
|---|---|---|---|---|---|---|
| 2b818d20-8137-4e12-bc5a-325b6d213ebd | MEDIUM | 6.1 | The Google Docs RSVP plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, … | — | wordfence | |
| 2b72bf37-05c8-424e-98d1-39fe032368ad | < 1.9.1 |
MEDIUM | 6.1 | The wassup plugin before 1.9.1 for WordPress has XSS via the Top stats widget or the wassupURI::add_siteurl method, a di… | — | wordfence |
| 2b6ffd9b-9a3a-4730-ab56-66686b24f214 | < 1.2.0 |
MEDIUM | 6.1 | The Music Store – WordPress eCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all vers… | — | wordfence |
| 2b5ad113-f739-455a-9db6-b4f300b92837 | < 5.16.5 |
MEDIUM | 6.1 | The Phlox PRO theme for WordPress is vulnerable to Reflected Cross-Site Scripting via search parameters in all versions … | — | wordfence |
| 2b58fb0f-c7ac-4ee6-84f1-ac14617a7c2b | MEDIUM | 6.1 | The Zoorum Comments plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and includin… | — | wordfence | |
| 2b4e7c02-48d3-4271-a3bc-e7d3256b7217 | < 1.4.5 |
MEDIUM | 6.1 | The LINE Notify plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'uid' parameter in versions… | — | wordfence |
| 2b3b9576-7c7d-4665-92d5-03aa292cdbbe | < 1.7.0.11 |
MEDIUM | 6.1 | The Charitable plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 1.… | — | wordfence |
| 2b2fa832-ed1b-47e9-b9eb-049541530ab6 | < 0.8.5 |
MEDIUM | 6.1 | The Blogroll Fun – Show Last Post and Last Update Time plugin for WordPress is vulnerable to Reflected Cross-Site Scri… | — | wordfence |
| 2b2302d9-426c-415b-a7d3-3a9de95d87d1 | < 4.6.1 |
MEDIUM | 6.1 | The WPML plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the wp_lang parameter in versions up t… | — | wordfence |
| 2b1261d9-ab21-4ec2-84d7-f12a2013607a | < 1.0.4 |
MEDIUM | 6.1 | The My WP Translate plugin for WordPress is vulnerable to Cross-Site Scripting in versions up to, and including, 1.0.3 d… | — | wordfence |
| 2b107861-753e-4e47-98de-22a3e193e0c2 | MEDIUM | 6.1 | The Famous - Responsive Image And Video Grid Gallery WordPress plugin for WordPress is vulnerable to Reflected Cross-Sit… | — | wordfence | |
| 2b045cef-c17c-4e6e-ab84-c0466a5a90ff | < 2.6.16 |
MEDIUM | 6.1 | The Foliopress WYSIWYG plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the swfupload.swf file i… | — | wordfence |
| 2afa0d46-eead-4eb3-9bf1-81fafd3f0f88 | MEDIUM | 6.1 | Cross-site scripting (XSS) vulnerability in js/test.php in the Appointments Scheduler plugin 1.5 and earlier for WordPre… | — | wordfence | |
| 2ac0694e-6ec7-4e0a-bc7e-573df6a11ea3 | MEDIUM | 6.1 | The Ultimate Subscribe plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and i… | — | wordfence | |
| 2ab6f54d-0358-4f0c-aba5-b4053e1a345d | MEDIUM | 6.1 | The BA Plus plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via an unknown parameter in versions up… | — | wordfence | |
| 2aaa8c34-cf7b-4630-adc8-cbb534deff89 | < 5.4 |
MEDIUM | 6.1 | The tagDiv Composer plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and includin… | — | wordfence |
| 2aa84ea5-5e4e-4f1c-8238-c8ea0c70e248 | MEDIUM | 6.1 | The WPHelpful plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 1.2… | — | wordfence | |
| 2a9a642f-1ca5-4f08-b404-c11deba100e9 | < 2.4.2 |
MEDIUM | 6.1 | The gravity-forms-sms-notifications plugin before 2.4.2 for WordPress has XSS. | — | wordfence |
| 2a95122f-fe5a-43e4-a68c-8a6b96f0df2b | MEDIUM | 6.1 | The Competition Form plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and inc… | — | wordfence | |
| 2a896f57-e742-4eb6-85dc-c45d3f0747d8 | < 11.12.08 |
MEDIUM | 6.1 | Cross-site scripting (XSS) vulnerability in uploadify/get_profile_avatar.php in the WP Symposium plugin before 11.12.08 … | — | wordfence |
| 2a8430ed-6aeb-46a3-8c42-59646845706e | < 0.9.33 |
MEDIUM | 6.1 | The WPvivid Backup for MainWP plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'id' paramete… | — | wordfence |
| 2a82666d-4c35-4aba-9163-834eef6c50ad | < 1.3 |
MEDIUM | 6.1 | The WP Crontrol for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘id’ parameter in versions up … | — | wordfence |
| 2a70ae7b-4b10-454b-8b28-b3d23d939cab | < 3.8 |
MEDIUM | 6.1 | The Gaea theme for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to 3.8 due to insufficient i… | — | wordfence |
| 2a6d72d0-f262-46a1-91c7-1c34ab995614 | < 4.5.0 |
MEDIUM | 6.1 | The Gallery by BestWebSoft plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘category’ p… | — | wordfence |
| 2a695233-01e3-4700-85a2-c4a9680e33db | < 1.4.8 |
MEDIUM | 6.1 | The WP Gravity Forms Salesforce plugin for WordPress is vulnerable to Open Redirect in all versions up to, and including… | — | wordfence |
EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.
Scan My Website →