πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,549
Total CVEs
66
CISA KEV (Actively Exploited)
Sep 2, 2026
Last Updated

40,549 vulnerabilities found (page 1595 of 1622)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
CVE-2026-4561
< 4.12.1
LOW N/A MC4WP: Mailchimp for WordPress < 4.12.1 - Author+ Stored XSS via Form Response Messages wpscan
CVE-2026-42663
< 4.7.3
LOW N/A Simple Membership < 4.7.3 - Unauthenticated Stored Cross-Site Scripting wpscan
CVE-2026-40764
< 1.10.0.3
LOW N/A Contact Form by WPForms < 1.10.0.3 - Cross-Site Request Forgery wpscan
CVE-2026-40743
< 3.9.8
LOW N/A Tutor LMS – eLearning and online course solution < 3.9.8 - Missing Authorization wpscan
CVE-2026-40740
< 3.9.8
LOW N/A Tutor LMS < 3.9.8 - Missing Authorization wpscan
CVE-2026-4057
< 3.3.52
LOW N/A Download Manager < 3.3.52 - Missing Authorization to Authenticated (Contributor+) Media File Protection Removal wpscan
CVE-2026-39676
< 3.3.53
LOW N/A Download Manager < 3.3.53 - Missing Authorization wpscan
CVE-2026-39615
< 3.3.54
LOW N/A Download Manager < 3.3.54 - Authenticated (Author+) Stored Cross-Site Scripting wpscan
CVE-2026-39483
< 9.113.4
LOW N/A VK All in One Expansion Unit < 9.113.4 - Authenticated (Contributor+) Stored Cross-Site Scripting wpscan
CVE-2026-3589
< 5.4.4
LOW N/A WooCommerce < 10.5.3 - Arbitrary Admin User Creation via CSRF wpscan
CVE-2026-3585
< 6.15.17.1
LOW N/A The Events Calendar < 6.15.17.1 - Author+ Arbitrary File Read wpscan
CVE-2026-34892
< 1.0.271.1
LOW N/A Rank Math SEO < 1.0.271.1 - Missing Authorization wpscan
CVE-2026-34886
< 4.7.2
LOW N/A Simple Membership < 4.7.2 - Missing Authorization wpscan
CVE-2026-3427
< 27.2
LOW N/A Yoast SEO < 27.2 - Contributor+ Stored XSS via 'jsonText' Block Attribute wpscan
CVE-2026-3375
< 7.8
LOW N/A LiteSpeed Cache < 7.8 - Unauthenticated Stored Cross-Site Scripting via QUIC.cloud CCSS/UCSS REST API Endpoints wpscan
CVE-2026-3371
< 3.9.8
LOW N/A Tutor LMS < 3.9.8 - Authenticated (Subscriber+) Insecure Direct Object Reference to Arbitrary Course Content Modificatio… wpscan
CVE-2026-3360
< 3.9.8
LOW N/A Tutor LMS < 3.9.8 - Unauthenticated Arbitrary Billing Profile Overwrite via 'order_id' wpscan
CVE-2026-3358
< 3.9.8
LOW N/A Tutor LMS < 3.9.8 - Missing Authorization to Authenticated (Subscriber+) Unauthorized Private Course Enrollment wpscan
CVE-2026-32461
< 9.5.8
LOW N/A Really Simple Security < 9.5.8 - Missing Authorization wpscan
CVE-2026-32446
< 1.9.9.4
LOW N/A Contact Form by WPForms < 1.9.9.4 - Missing Authorization wpscan
CVE-2026-32445
< 3.35.6
LOW N/A Elementor Website Builder < 3.35.6 - Missing Authorization wpscan
CVE-2026-32414
< 2.37
LOW N/A Advanced Woo Labels < 2.37 - Authenticated (Admin+) Remote Code Execution wpscan
CVE-2026-32352
< 3.35.6
LOW N/A Elementor Website Builder < 3.35.6 - Contributor+ Stored XSS wpscan
CVE-2026-32343
< 2.0.81
LOW N/A Easy Table of Contents < 2.0.81 - Cross-Site Request Forgery wpscan
CVE-2026-3155
< 3.8.1
LOW N/A OneSignal – Web Push Notifications < 3.8.1 - Missing Authorization to Authenticated (Subscriber+) Post Meta Deletion v… wpscan
← Prev 1592 1593 1594 1595 1596 1597 1598 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top