πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,549
Total CVEs
66
CISA KEV (Actively Exploited)
Sep 2, 2026
Last Updated

40,549 vulnerabilities found (page 1601 of 1622)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
CVE-2025-15033
< 8.1.3
LOW N/A WooCommerce - Subscriber/Customer+ Order Data Disclosure wpscan
CVE-2025-14947
< 4.7.1
LOW N/A All-in-One Video Gallery < 4.7.1 - Missing Authorization to Unauthenticated Bunny Stream Video Creation/Deletion wpscan
CVE-2025-14732
< 3.35.6
LOW N/A Elementor Website Builder < 3.35.6 - Contributor+ Stored XSS via REST API wpscan
CVE-2025-14481
< 26.6
LOW N/A Yoast SEO < 26.6 - Contributor+ IDOR to Sensitive Information Exposure via post_id Parameter wpscan
CVE-2025-14384
< 4.9.3
LOW N/A All in One SEO < 4.9.3 - Contributor+ AI Access Token and Credit Disclosure wpscan
CVE-2025-14072
< 3.13.3
LOW N/A Ninja Forms < 3.13.3 - Unauthenticated Token Generation and Submission Disclosure wpscan
CVE-2025-14061
< 4.0.8
LOW N/A Cookie Banner, Cookie Consent, Consent Log, Cookie Scanner, Script Blocker (for GDPR, CCPA & ePrivacy) : WP Cookie Conse… wpscan
CVE-2025-13977
< 6.5.4
LOW N/A Essential Addons for Elementor < 6.5.4 - Contributor+ Stored XSS wpscan
CVE-2025-13950
< 3.6.2
LOW N/A OneSignal – Web Push Notifications < 3.6.2 - Missing Authorization to Unauthenticated Plugin Settings Update wpscan
CVE-2025-13935
< 3.9.4
LOW N/A Tutor LMS – eLearning and online course solution < 3.9.4 - Missing Authorization to Authenticated (Subscriber+) Arbitr… wpscan
CVE-2025-13934
< 3.9.4
LOW N/A Tutor LMS – eLearning and online course solution < 3.9.4 - Missing Authorization to Authenticated (Subscriber+) Course… wpscan
CVE-2025-13732
< 260101
LOW N/A s2Member < 260101 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode wpscan
CVE-2025-13679
< 3.9.4
LOW N/A Tutor LMS < 3.9.4 - Missing Authorization to Authenticated (Subscriber+) Sensitive Information Exposure via tutor_order_… wpscan
CVE-2025-13673
< 3.9.7
LOW N/A Tutor LMS < 3.9.7 - Unauthenticated SQL Injection via coupon_code wpscan
CVE-2025-13628
< 3.9.4
LOW N/A Tutor LMS – eLearning and online course solution < 3.9.4 - Missing Authorization to Authenticated (Subscriber+) Arbitr… wpscan
CVE-2025-13498
< 3.3.33
LOW N/A Download Manager < 3.3.33 - Missing Authorization to Authenticated (Subscriber+) Media Attachment Password Disclosure wpscan
CVE-2025-13355
< 1.11.4
LOW N/A URL Shortify < 1.11.4 - Reflected XSS wpscan
CVE-2025-12966
< 4.6.4
LOW N/A All-in-One Video Gallery 4.5.4 - 4.5.7 – Authenticated (Author+) Arbitrary File Upload via Import ZIP wpscan
CVE-2025-12957
< 4.6.4
LOW N/A All-in-One Video Gallery < 4.6.4 - Authenticated (Author+) Arbitrary File Upload via VTT Upload Bypass wpscan
CVE-2025-12847
< 4.9.0
LOW N/A All in One SEO < 4.9.0 - Contributor+ Arbitrary Media Deletion wpscan
CVE-2025-12714
< 1.0.271.1
LOW N/A Rank Math SEO < 1.0.271.1 - Unauthenticated Homepage SEO Settings Modification wpscan
CVE-2025-12684
< 1.11.3
LOW N/A URL Shortify < 1.11.3 - Reflected XSS wpscan
CVE-2025-12537
< 1.14.4
LOW N/A Addon Elements for Elementor < 1.14.4 - Authenticated (Contributor+) Stored Cross-Site Scripting wpscan
CVE-2025-12450
< 7.6
LOW N/A LiteSpeed Cache < 7.6 - Reflected XSS wpscan
CVE-2025-12197
< 6.15.10
LOW N/A The Events Calendar 6.15.1.1 - 6.15.9 - Unauthenticated SQL Injection via s wpscan
← Prev 1598 1599 1600 1601 1602 1603 1604 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top