ðŸ›¡ï¸ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,549
Total CVEs
66
CISA KEV (Actively Exploited)
Sep 2, 2026
Last Updated

40,549 vulnerabilities found (page 1597 of 1622)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
CVE-2026-14936
< 4.7.7
LOW N/A Simple Membership < 4.7.7 - Unauthenticated Payment Bypass via Missing PayPal IPN Receiver Verification wpscan
CVE-2026-14343
< 3.3.62
LOW N/A Download Manager < 3.3.62 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'note_before' and 'note_after' … wpscan
CVE-2026-14310
< 4.0.0
LOW N/A Tutor LMS < 4.0.0 - Subscriber+ Cross-Course Q&A Content Disclosure and Reply Injection wpscan
CVE-2026-14306
< 3.9.14
LOW N/A Tutor LMS < 3.9.14 - Subscriber+ Paid Course Content Disclosure via Enrollment Check Bypass wpscan
CVE-2026-14235
< 3.3.62
LOW N/A WordPress Download Manager < 3.3.62 - Unauthorized Protected File Download via Reusable Download Key wpscan
CVE-2026-1375
< 3.9.6
LOW N/A Tutor LMS < 3.9.6 - Instructor+ Arbitrary Course Modification and Deletion via IDOR wpscan
CVE-2026-13733
< 3.3.61
LOW N/A Download Manager < 3.3.61 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'no_data_msg' Shortcode Attribu… wpscan
CVE-2026-1371
< 3.9.6
LOW N/A Tutor LMS < 3.9.6 - Authenticated (Subscriber+) Information Disclosure in Coupon Details via 'tutor_coupon_details' AJAX… wpscan
CVE-2026-13443
< 3.9.14
LOW N/A Tutor LMS < 3.9.14 - Authenticated (Author+) Stored Cross-Site Scripting via Lesson Attachment Title wpscan
CVE-2026-13390
< 6.16.5.1
LOW N/A The Events Calendar < 6.16.5.1 - Unauthenticated Event Aggregator Import Status Manipulation wpscan
CVE-2026-13345
< 6.6.10
LOW N/A Essential Addons for Elementor - Lite < 6.6.10 - Unauthenticated Draft/Private WooCommerce Product Disclosure via Compar… wpscan
CVE-2026-13344
< 6.6.10
LOW N/A Essential Addons for Elementor - Lite < 6.6.10 - Contributor+ Stored XSS via Pricing Table Title Tag wpscan
CVE-2026-1307
< 3.14.2
LOW N/A Ninja Forms < 3.14.2 - Contributor+ Sensitive Information Disclosure via Block Editor Token wpscan
CVE-2026-1293
< 26.9
LOW N/A Yoast SEO < 26.9 - Contributor+ Stored XSS wpscan
CVE-2026-12898
< 7.106
LOW N/A All-in-One WP Migration and Backup < 7.106 - Unauthenticated Arbitrary-Location Log File Write via Path Traversal wpscan
CVE-2026-1239
< 3.14.2
LOW N/A Ninja Forms < 3.14.2 - Unauthenticated Sensitive Information Disclosure via token/refresh REST Endpoint wpscan
CVE-2026-12275
< 3.9.13
LOW N/A Tutor LMS < 3.9.13 - Subscriber+ Unauthorized Course Enrollment and Private Course Content Disclosure via Droip/Kirki In… wpscan
CVE-2026-12274
< 3.9.13
LOW N/A Tutor LMS < 3.9.13 - Instructor+ Arbitrary Post Overwrite via IDOR wpscan
CVE-2026-12273
< 3.9.13
LOW N/A Tutor LMS < 3.9.13 - Subscriber+ Arbitrary Auto-Approved Comment Creation wpscan
CVE-2026-12271
< 3.9.13
LOW N/A Tutor LMS < 3.9.13 - Subscriber+ Arbitrary Quiz Attempt Modification via IDOR wpscan
CVE-2026-1217
< 4.6
LOW N/A Yoast Duplicate Post < 4.6 - Contributor+ Arbitrary Post Duplication and Overwrite wpscan
CVE-2026-12127
< 1.10.2.1
LOW N/A WPForms < 1.10.2.1 - Unauthenticated CRLF Email Header Injection via Reply-To Display Name wpscan
CVE-2026-12093
< 4.7.6
LOW N/A Simple Membership < 4.7.6 - Missing Authorization to Unauthenticated Arbitrary Member Account Deactivation via Forged St… wpscan
CVE-2026-1206
< 3.35.8
LOW N/A Elementor Website Builder < 3.35.8 - Contributor+ Sensitive Information Exposure via Elementor Template wpscan
CVE-2026-11855
< 4.7.5
LOW N/A Simple Membership < 4.7.5 - Unauthenticated Stored XSS via Stripe Webhook API Version wpscan
← Prev 1594 1595 1596 1597 1598 1599 1600 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top