Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.
40,549 vulnerabilities found (page 1595 of 1622)
| CVE ID | Plugin / Theme | Severity | CVSS | Description | Fixed In | Source |
|---|---|---|---|---|---|---|
| CVE-2026-4561 | < 4.12.1 |
LOW | N/A | MC4WP: Mailchimp for WordPress < 4.12.1 - Author+ Stored XSS via Form Response Messages | — | wpscan |
| CVE-2026-42663 | < 4.7.3 |
LOW | N/A | Simple Membership < 4.7.3 - Unauthenticated Stored Cross-Site Scripting | — | wpscan |
| CVE-2026-40764 | < 1.10.0.3 |
LOW | N/A | Contact Form by WPForms < 1.10.0.3 - Cross-Site Request Forgery | — | wpscan |
| CVE-2026-40743 | < 3.9.8 |
LOW | N/A | Tutor LMS β eLearning and online course solution < 3.9.8 - Missing Authorization | — | wpscan |
| CVE-2026-40740 | < 3.9.8 |
LOW | N/A | Tutor LMS < 3.9.8 - Missing Authorization | — | wpscan |
| CVE-2026-4057 | < 3.3.52 |
LOW | N/A | Download Manager < 3.3.52 - Missing Authorization to Authenticated (Contributor+) Media File Protection Removal | — | wpscan |
| CVE-2026-39676 | < 3.3.53 |
LOW | N/A | Download Manager < 3.3.53 - Missing Authorization | — | wpscan |
| CVE-2026-39615 | < 3.3.54 |
LOW | N/A | Download Manager < 3.3.54 - Authenticated (Author+) Stored Cross-Site Scripting | — | wpscan |
| CVE-2026-39483 | < 9.113.4 |
LOW | N/A | VK All in One Expansion Unit < 9.113.4 - Authenticated (Contributor+) Stored Cross-Site Scripting | — | wpscan |
| CVE-2026-3589 | < 5.4.4 |
LOW | N/A | WooCommerce < 10.5.3 - Arbitrary Admin User Creation via CSRF | — | wpscan |
| CVE-2026-3585 | < 6.15.17.1 |
LOW | N/A | The Events Calendar < 6.15.17.1 - Author+ Arbitrary File Read | — | wpscan |
| CVE-2026-34892 | < 1.0.271.1 |
LOW | N/A | Rank Math SEO < 1.0.271.1 - Missing Authorization | — | wpscan |
| CVE-2026-34886 | < 4.7.2 |
LOW | N/A | Simple Membership < 4.7.2 - Missing Authorization | — | wpscan |
| CVE-2026-3427 | < 27.2 |
LOW | N/A | Yoast SEO < 27.2 - Contributor+ Stored XSS via 'jsonText' Block Attribute | — | wpscan |
| CVE-2026-3375 | < 7.8 |
LOW | N/A | LiteSpeed Cache < 7.8 - Unauthenticated Stored Cross-Site Scripting via QUIC.cloud CCSS/UCSS REST API Endpoints | — | wpscan |
| CVE-2026-3371 | < 3.9.8 |
LOW | N/A | Tutor LMS < 3.9.8 - Authenticated (Subscriber+) Insecure Direct Object Reference to Arbitrary Course Content Modificatio… | — | wpscan |
| CVE-2026-3360 | < 3.9.8 |
LOW | N/A | Tutor LMS < 3.9.8 - Unauthenticated Arbitrary Billing Profile Overwrite via 'order_id' | — | wpscan |
| CVE-2026-3358 | < 3.9.8 |
LOW | N/A | Tutor LMS < 3.9.8 - Missing Authorization to Authenticated (Subscriber+) Unauthorized Private Course Enrollment | — | wpscan |
| CVE-2026-32461 | < 9.5.8 |
LOW | N/A | Really Simple Security < 9.5.8 - Missing Authorization | — | wpscan |
| CVE-2026-32446 | < 1.9.9.4 |
LOW | N/A | Contact Form by WPForms < 1.9.9.4 - Missing Authorization | — | wpscan |
| CVE-2026-32445 | < 3.35.6 |
LOW | N/A | Elementor Website Builder < 3.35.6 - Missing Authorization | — | wpscan |
| CVE-2026-32414 | < 2.37 |
LOW | N/A | Advanced Woo Labels < 2.37 - Authenticated (Admin+) Remote Code Execution | — | wpscan |
| CVE-2026-32352 | < 3.35.6 |
LOW | N/A | Elementor Website Builder < 3.35.6 - Contributor+ Stored XSS | — | wpscan |
| CVE-2026-32343 | < 2.0.81 |
LOW | N/A | Easy Table of Contents < 2.0.81 - Cross-Site Request Forgery | — | wpscan |
| CVE-2026-3155 | < 3.8.1 |
LOW | N/A | OneSignal β Web Push Notifications < 3.8.1 - Missing Authorization to Authenticated (Subscriber+) Post Meta Deletion v… | — | wpscan |
EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.
Scan My Website →