Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.
40,549 vulnerabilities found (page 1596 of 1622)
| CVE ID | Plugin / Theme | Severity | CVSS | Description | Fixed In | Source |
|---|---|---|---|---|---|---|
| CVE-2026-28131 | < 1.14.5 |
LOW | N/A | Elementor Addon Elements < 1.14.5 - Authenticated (Contributor+) Information Exposure | — | wpscan |
| CVE-2026-2712 | < 4.5.1 |
LOW | N/A | WP-Optimize < 4.5.1 - Subscriber+ Settings Update and Image Manipulation | — | wpscan |
| CVE-2026-2571 | < 3.3.50 |
LOW | N/A | Download Manager < 3.3.50 - Missing Authorization to Authenticated (Subscriber+) User Email Enumeration via 'user' Param… | — | wpscan |
| CVE-2026-25440 | < 6.6.0 |
LOW | N/A | Essential Addons for Elementor < 6.6.0 - Unauthenticated Missing Authorization | — | wpscan |
| CVE-2026-25385 | < 1.12.4 |
LOW | N/A | URL Shortify < 1.12.4 - Authenticated (Author+) Server-Side Request Forgery | — | wpscan |
| CVE-2026-25339 | < 1.9.9.2 |
LOW | N/A | WPForms < 1.9.9.2 - Unauthenticated Sensitive Information Exposure | — | wpscan |
| CVE-2026-25308 | < 4.7.0 |
LOW | N/A | Simple Membership < 4.7.0 - Missing Authorization | — | wpscan |
| CVE-2026-2515 | < 1.3.9 |
LOW | N/A | Hostinger Reach < 1.3.9 - Subscriber+ Arbitrary API Key Update | — | wpscan |
| CVE-2026-23799 | < 3.9.6 |
LOW | N/A | Tutor LMS β eLearning and online course solution < 3.9.6 - Missing Authorization | — | wpscan |
| CVE-2026-23545 | < 3.0.5 |
LOW | N/A | Aruba HiSpeed Cache < 3.0.5 - Missing Authorization | — | wpscan |
| CVE-2026-23543 | < 6.5.6 |
LOW | N/A | Essential Addons for Elementor < 6.5.6 - Unauthenticated Missing Authorization | — | wpscan |
| CVE-2026-2268 | < 3.14.1 |
LOW | N/A | Ninja Forms < 3.14.1 - Unauthenticated Information Disclosure | — | wpscan |
| CVE-2026-1924 | < 3.0.5 |
LOW | N/A | Aruba HiSpeed Cache < 3.0.5 - Cross-Site Request Forgery to Plugin Settings Reset | — | wpscan |
| CVE-2026-18039 | < 6.7.2 |
LOW | N/A | Essential Addons for Elementor < 6.7.2 - Unauthenticated Privilege Escalation via Custom Profile Field Mass Assignment | — | wpscan |
| CVE-2026-1781 | < 4.12.0 |
LOW | N/A | MC4WP: Mailchimp for WordPress < 4.12.0 - Unauthenticated Arbitrary Subscription Deletion | — | wpscan |
| CVE-2026-17533 | < 7.108 |
LOW | N/A | All-in-One WP Migration and Backup < 7.108 - Multisite Subsite Admin+ Network-Wide PHP Code Execution via REST Import | — | wpscan |
| CVE-2026-15782 | < 2.0.0.2 |
LOW | N/A | WPForms < 2.0.0.2 - Contributor+ Stored Cross-Site Scripting via OptinMonster Integration | — | wpscan |
| CVE-2026-15663 | < 3.14.10 |
LOW | N/A | Ninja Forms < 3.14.10 - Admin+ SQL Injection via Import File settings Key | — | wpscan |
| CVE-2026-15425 | < 28.1 |
LOW | N/A | Yoast SEO < 28.1 - Author+ Stored Cross-Site Scripting via Post Slug | — | wpscan |
| CVE-2026-15256 | < 3.14.10 |
LOW | N/A | Ninja Forms < 3.14.10 - Unauthenticated Arbitrary Shortcode Execution via Query-String Populated Field Default | — | wpscan |
| CVE-2026-15156 | < 6.7.0 |
LOW | N/A | Essential Addons for Elementor < 6.7.0 - Contributor+ Stored Cross-Site Scripting via Reading Progress Global Color Sett… | — | wpscan |
| CVE-2026-15155 | < 6.6.11 |
LOW | N/A | Essential Addons for Elementor < 6.6.11 - Contributor+ Account Takeover via Email Header Injection | — | wpscan |
| CVE-2026-15145 | < 6.7.0 |
LOW | N/A | Essential Addons for Elementor < 6.7.0 - Contributor+ Stored Cross-Site Scripting via Fancy Text Widget | — | wpscan |
| CVE-2026-1512 | < 6.5.10 |
LOW | N/A | Essential Addons for Elementor < 6.5.10 - Contributor+ Stored XSS | — | wpscan |
| CVE-2026-15022 | < 4.0.1 |
LOW | N/A | Tutor LMS < 4.0.1 - Authenticated (Subscriber+) SQL Injection via Stored Quiz Answer Array | — | wpscan |
EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.
Scan My Website →