πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,549
Total CVEs
66
CISA KEV (Actively Exploited)
Sep 2, 2026
Last Updated

40,549 vulnerabilities found (page 1596 of 1622)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
CVE-2026-28131
< 1.14.5
LOW N/A Elementor Addon Elements < 1.14.5 - Authenticated (Contributor+) Information Exposure wpscan
CVE-2026-2712
< 4.5.1
LOW N/A WP-Optimize < 4.5.1 - Subscriber+ Settings Update and Image Manipulation wpscan
CVE-2026-2571
< 3.3.50
LOW N/A Download Manager < 3.3.50 - Missing Authorization to Authenticated (Subscriber+) User Email Enumeration via 'user' Param… wpscan
CVE-2026-25440
< 6.6.0
LOW N/A Essential Addons for Elementor < 6.6.0 - Unauthenticated Missing Authorization wpscan
CVE-2026-25385
< 1.12.4
LOW N/A URL Shortify < 1.12.4 - Authenticated (Author+) Server-Side Request Forgery wpscan
CVE-2026-25339
< 1.9.9.2
LOW N/A WPForms < 1.9.9.2 - Unauthenticated Sensitive Information Exposure wpscan
CVE-2026-25308
< 4.7.0
LOW N/A Simple Membership < 4.7.0 - Missing Authorization wpscan
CVE-2026-2515
< 1.3.9
LOW N/A Hostinger Reach < 1.3.9 - Subscriber+ Arbitrary API Key Update wpscan
CVE-2026-23799
< 3.9.6
LOW N/A Tutor LMS – eLearning and online course solution < 3.9.6 - Missing Authorization wpscan
CVE-2026-23545
< 3.0.5
LOW N/A Aruba HiSpeed Cache < 3.0.5 - Missing Authorization wpscan
CVE-2026-23543
< 6.5.6
LOW N/A Essential Addons for Elementor < 6.5.6 - Unauthenticated Missing Authorization wpscan
CVE-2026-2268
< 3.14.1
LOW N/A Ninja Forms < 3.14.1 - Unauthenticated Information Disclosure wpscan
CVE-2026-1924
< 3.0.5
LOW N/A Aruba HiSpeed Cache < 3.0.5 - Cross-Site Request Forgery to Plugin Settings Reset wpscan
CVE-2026-18039
< 6.7.2
LOW N/A Essential Addons for Elementor < 6.7.2 - Unauthenticated Privilege Escalation via Custom Profile Field Mass Assignment wpscan
CVE-2026-1781
< 4.12.0
LOW N/A MC4WP: Mailchimp for WordPress < 4.12.0 - Unauthenticated Arbitrary Subscription Deletion wpscan
CVE-2026-17533
< 7.108
LOW N/A All-in-One WP Migration and Backup < 7.108 - Multisite Subsite Admin+ Network-Wide PHP Code Execution via REST Import wpscan
CVE-2026-15782
< 2.0.0.2
LOW N/A WPForms < 2.0.0.2 - Contributor+ Stored Cross-Site Scripting via OptinMonster Integration wpscan
CVE-2026-15663
< 3.14.10
LOW N/A Ninja Forms < 3.14.10 - Admin+ SQL Injection via Import File settings Key wpscan
CVE-2026-15425
< 28.1
LOW N/A Yoast SEO < 28.1 - Author+ Stored Cross-Site Scripting via Post Slug wpscan
CVE-2026-15256
< 3.14.10
LOW N/A Ninja Forms < 3.14.10 - Unauthenticated Arbitrary Shortcode Execution via Query-String Populated Field Default wpscan
CVE-2026-15156
< 6.7.0
LOW N/A Essential Addons for Elementor < 6.7.0 - Contributor+ Stored Cross-Site Scripting via Reading Progress Global Color Sett… wpscan
CVE-2026-15155
< 6.6.11
LOW N/A Essential Addons for Elementor < 6.6.11 - Contributor+ Account Takeover via Email Header Injection wpscan
CVE-2026-15145
< 6.7.0
LOW N/A Essential Addons for Elementor < 6.7.0 - Contributor+ Stored Cross-Site Scripting via Fancy Text Widget wpscan
CVE-2026-1512
< 6.5.10
LOW N/A Essential Addons for Elementor < 6.5.10 - Contributor+ Stored XSS wpscan
CVE-2026-15022
< 4.0.1
LOW N/A Tutor LMS < 4.0.1 - Authenticated (Subscriber+) SQL Injection via Stored Quiz Answer Array wpscan
← Prev 1593 1594 1595 1596 1597 1598 1599 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top