🛡️ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,549
Total CVEs
66
CISA KEV (Actively Exploited)
Sep 2, 2026
Last Updated

40,549 vulnerabilities found (page 1594 of 1622)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
CVE-2026-8382
< 6.8.2
LOW N/A Advanced Custom Fields (ACF®) < 6.8.2 - Unauthenticated Arbitrary Post Modification via Front-End Form '_post_title' an… wpscan
CVE-2026-8293
< 9.5.10.1
LOW N/A Really Simple Security < 9.5.10.1 - Two-Factor OTP Bypass wpscan
CVE-2026-82884
< 5.0.0.1
LOW N/A All in One SEO < 5.0.0.1 - Contributor+ Stored XSS via ai-assistant Block wpscan
CVE-2026-7665
< 6.6.5
LOW N/A Essential Addons for Elementor < 6.6.5 - Unauthenticated Sensitive Information Exposure via load_more AJAX Handler wpscan
CVE-2026-7252
< 4.5.3
LOW N/A WP-Optimize < 4.5.3 - Author+ Arbitrary File Deletion via 'original-file' Post Meta wpscan
CVE-2026-6965
< 3.9.10
LOW N/A Tutor LMS < 3.9.10 - Insecure Direct Object Reference to Authenticated (Instructor+) Arbitrary Post Deletion via 'course… wpscan
CVE-2026-66702
< 1.0.275
LOW N/A Rank Math SEO < 1.0.275 - Unauthenticated Stored XSS wpscan
CVE-2026-6459
< 6.6.3
LOW N/A Essential Addons for Elementor < 6.6.3 - Author+ Stored Cross-Site Scripting via Event Calendar Widget wpscan
CVE-2026-6382
< 8.0.4
LOW N/A Multiple elFinder Plugins - Authenticated OS Command Injection wpscan
CVE-2026-6127
< 4.0.5
LOW N/A Elementor Website Builder < 4.0.5 - Contributor+ Stored XSS via REST API wpscan
CVE-2026-6080
< 3.9.9
LOW N/A Tutor LMS < 3.9.9 - Authenticated (Admin+) SQL Injection via 'date' Parameter wpscan
CVE-2026-57722
< 4.2.2
LOW N/A Enable Media Replace < 4.2.2 - Editor+ Stored Cross-Site Scripting wpscan
CVE-2026-57619
< 4.1.4
LOW N/A Elementor < 4.1.4 - Contributor+ Sensitive Data Exposure via elementor-template Shortcode wpscan
CVE-2026-5714
< 4.1.9
LOW N/A Enable Media Replace < 4.1.9 - Author+ Stored XSS via 'location_dir' Parameter wpscan
CVE-2026-5502
< 3.9.9
LOW N/A Tutor LMS < 3.9.9 - Authenticated (Subscriber+) Arbitrary Course Content Manipulation via tutor_update_course_content_or… wpscan
CVE-2026-5357
< 3.3.53
LOW N/A Download Manager < 3.3.53 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode Attributes wpscan
CVE-2026-5193
< 6.6.0
LOW N/A Essential Addons for Elementor < 6.6.0 - Author+ Limited Privilege Escalation via register_user wpscan
CVE-2026-5075
< 4.9.7.1
LOW N/A All in One SEO < 4.9.7.1 - Contributor+ Sensitive Information Exposure via 'internalOptions' Localized Script Data wpscan
CVE-2026-4986
< 1.10.0.5
LOW N/A WPForms Lite < 1.10.0.5 – Unauthenticated PayPal Webhook Forgery wpscan
CVE-2026-49782
< 4.1.1
LOW N/A Elementor Website Builder < 4.1.1 - Missing Authorization wpscan
CVE-2026-49772
< 6.16.3
LOW N/A The Events Calendar 6.15.12-6.16.2 - Unauthenticated SQL Injection wpscan
CVE-2026-48970
< 9.5.10.1
LOW N/A Really Simple Security < 9.5.10.1 - Missing Authorization wpscan
CVE-2026-48969
< 9.5.10
LOW N/A Really Simple Security < 9.5.10 - Missing Authorization wpscan
CVE-2026-48835
< 1.10.0.5
LOW N/A WPForms < 1.10.0.5 - Unauthenticated Missing Authorization wpscan
CVE-2026-4812
< 6.7.1
LOW N/A Advanced Custom Fields (ACF®) < 6.7.1 - Unauthenticated Arbitrary Post/Page Disclosure via AJAX Field Query Parameters wpscan
← Prev 1591 1592 1593 1594 1595 1596 1597 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top