πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,549
Total CVEs
66
CISA KEV (Actively Exploited)
Sep 2, 2026
Last Updated

40,549 vulnerabilities found (page 1599 of 1622)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
CVE-2025-64295
< 4.8.7
LOW N/A All In One SEO Pack < 4.8.7 - Subscriber+ Information Exposure wpscan
CVE-2025-63070
< 3.3.33
LOW N/A Download Manager < 3.3.33 - Authenticated (Subscriber+) Information Exposure wpscan
CVE-2025-6244
< 6.1.20
LOW N/A Essential Addons for Elementor – Popular Elementor Templates and Widgets < 6.1.20 - Authenticated (Contributor+) Store… wpscan
CVE-2025-62023
< 251005
LOW N/A s2Member < 251005 - Unauthenticated Remote Code Execution wpscan
CVE-2025-60093
< 3.3.25
LOW N/A Download Manager < 3.3.25 - Cross-Site Request Forgery wpscan
CVE-2025-60092
< 3.3.26
LOW N/A Download Manager < 3.3.26 - Unauthenticated Sensitive Information Exposure wpscan
CVE-2025-58998
< 250905
LOW N/A s2Member < 250905 - Unauthenticated PHP Object Injection wpscan
CVE-2025-58993
< 3.8.0
LOW N/A Tutor LMS < 3.8.0 - Authenticated (Administrator+) SQL Injection wpscan
CVE-2025-58650
< 4.8.7.2
LOW N/A All In One SEO Pack < 4.8.7.2 - Missing Authorization wpscan
CVE-2025-58649
< 4.8.7.2
LOW N/A All In One SEO Pack < 4.8.7.2 - Contributor+ Sensitive Information Exposure wpscan
CVE-2025-54940
< 6.4.3
LOW N/A Advanced Custom Fields < 6.4.3 - HTML Injection wpscan
CVE-2025-5398
< 3.10.2.2
LOW N/A Ninja Forms < 3.10.2.2 - Contributor+ Stored XSS via CSTI wpscan
CVE-2025-5144
< 6.13.2.1
LOW N/A The Events Calendar < 6.13.2.1 - Contributor+ DOM-Based Stored XSS wpscan
CVE-2025-5062
< 9.4.3
LOW N/A WooCommerce < 9.4.3 - Reflected XSS wpscan
CVE-2025-49333
< 4.6.4
LOW N/A Simple Membership < 4.6.4 - Authenticated (Administrator+) Stored Cross-Site Scripting wpscan
CVE-2025-49285
< 3.8.1
LOW N/A WP Cookie Notice for GDPR, CCPA & ePrivacy Consent < 3.8.1 - Cross-Site Request Forgery wpscan
CVE-2025-49042
< 10.0.3
LOW N/A WooCommerce < 10.0.3 - Shop manager+ Stored XSS wpscan
CVE-2025-48246
< 6.12.0
LOW N/A The Events Calendar < 6.12.0 - Subscriber+ Import Creation wpscan
CVE-2025-47555
< 3.9.5
LOW N/A Tutor LMS < 3.9.5 - Authenticated (Instructor+) Insecure Direct Object Reference wpscan
CVE-2025-47437
< 7.1
LOW N/A LiteSpeed Cache < 7.1 - Editor+ Server-Side Request Forgery wpscan
CVE-2025-4566
< 3.30.3
LOW N/A Elementor < 3.30.3 - Contributor+ Stored XSS via Text Path Widget wpscan
CVE-2025-4367
< 3.3.19
LOW N/A Download Manager < 3.3.19 - Authenticated (Author+) Stored Cross-site Scripting via wpdm_user_dashboard Shortcode wpscan
CVE-2025-39590
< 6.1.10
LOW N/A Essential Addons for Elementor < 6.1.10 - Contributor+ Stored XSS wpscan
CVE-2025-39589
< 6.1.10
LOW N/A Essential Addons for Elementor < 6.1.10 - Contributor+ Information Disclosure wpscan
CVE-2025-3951
< 4.2.0
LOW N/A WP-Optimize < 4.2.0 - Admin+ SQLi wpscan
← Prev 1596 1597 1598 1599 1600 1601 1602 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top