πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,549
Total CVEs
66
CISA KEV (Actively Exploited)
Sep 2, 2026
Last Updated

40,549 vulnerabilities found (page 1600 of 1622)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
CVE-2025-3794
< 1.9.5.1
LOW N/A WPForms Lite < 1.9.5.1 - Contributor+ Stored XSS via 'start_timestamp' Parameter wpscan
CVE-2025-3766
< 2.12
LOW N/A Login Lockdown & Protection < 2.12 - Missing Authorization to Authenticated (Subscriber+) Arbitrary IP Whitelisting wpscan
CVE-2025-3404
< 3.3.13
LOW N/A Download Manager < 3.3.13 - Author+ Arbitrary File Deletion wpscan
CVE-2025-3247
< 6.0.6
LOW N/A Contact Form 7 < 6.0.6 - Order Replay Vulnerability wpscan
CVE-2025-32230
< 3.4.1
LOW N/A Tutor LMS < 3.4.1 - Subscriber+ HTML Injection wpscan
CVE-2025-32223
< 3.9.5
LOW N/A Tutor LMS – eLearning and online course solution < 3.9.5 - Authenticated (Subscriber+) Insecure Direct Object Referenc… wpscan
CVE-2025-32188
< 2.16
LOW N/A Advanced Woo Labels < 2.16 - Contributor+ Stored XSS wpscan
CVE-2025-32137
< 250424
LOW N/A s2Member < 250424 - Administrator+ Local File Inclusion wpscan
CVE-2025-32134
< 1.10.6
LOW N/A URL Shortify < 1.10.6 - Authenticated (Administrator+) Stored Cross-Site Scripting wpscan
CVE-2025-31081
< 4.1.6
LOW N/A Enable Media Replace < 4.1.6 - Reflected XSS wpscan
CVE-2025-3075
< 3.29.1
LOW N/A Elementor < 3.29.1 - Contributor+ Stored XSS wpscan
CVE-2025-3056
< 3.3.13
LOW N/A Download Manager < 3.3.13 - Authenticated (Author+) Stored Cross-Site Scripting via SVG File Upload wpscan
CVE-2025-2892
< 4.8.2
LOW N/A All in One SEO Pack < 4.8.2 - Contributor+ Stored XSS via Post Meta Description and Canonical URL wpscan
CVE-2025-26879
< 250214
LOW N/A s2Member Pro < 250214 - Reflected Cross-Site Scripting wpscan
CVE-2025-26762
< 9.7.1
LOW N/A Woocommerce < 9.7.1 - Shop Manager+ Stored XSS via New Product Form wpscan
CVE-2025-2561
< 3.10.1
LOW N/A Ninja Forms < 3.10.1 - Admin+ Stored XSS wpscan
CVE-2025-2560
< 3.10.1
LOW N/A Ninja Forms < 3.10.1 - Admin+ Stored XSS wpscan
CVE-2025-2524
< 3.10.1
LOW N/A Ninja Forms < 3.10.1 - Admin+ Stored XSS wpscan
CVE-2025-24752
< 6.0.15
LOW N/A Essential Addons for Elementor < 6.0.15 - Reflected Cross-Site Scripting wpscan
CVE-2025-24623
< 9.2.0
LOW N/A Really Simple SSL < 9.2.0 - Cross-Site Request Forgery wpscan
CVE-2025-24537
< 6.7.1
LOW N/A The Events Calendar < 6.7.1 - Trashed Events Restoration via CSRF wpscan
CVE-2025-1785
< 3.3.09
LOW N/A Download Manager < 3.3.09 - Authenticated (Author+) Path Traversal to Limited File Overwrite wpscan
CVE-2025-15516
< 4.7.1
LOW N/A All-in-One Video Gallery 4.1.0 - 4.6.4 - Missing Authorization to Authenticated (Subscriber+) Limited User Meta Update wpscan
CVE-2025-15364
< 3.3.41
LOW N/A Download Manager < 3.3.41 - Unauthenticated Limited Privilege Escalation wpscan
CVE-2025-15043
< 6.15.13.1
LOW N/A The Events Calendar < 6.15.13.1 - Subscriber+ Data Migration Control wpscan
← Prev 1597 1598 1599 1600 1601 1602 1603 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top