πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,549
Total CVEs
66
CISA KEV (Actively Exploited)
Sep 2, 2026
Last Updated

40,549 vulnerabilities found (page 1602 of 1622)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
CVE-2025-12192
< 6.15.10
LOW N/A The Events Calendar < 6.15.10 - Unauthenticated Sensitive Information Exposure wpscan
CVE-2025-12177
< 3.3.31
LOW N/A Download Manager < 3.3.31 - Unauthenticated Cron Trigger due to Hardcoded Cron Key wpscan
CVE-2025-12175
< 6.15.10
LOW N/A The Events Calendar < 6.15.10 - Subscriber+ Draft Event Title/QR Code Exposure wpscan
CVE-2025-11748
< 3.8.0
LOW N/A Groups < 3.8.0 - Authenticated (Subscriber+) Insecure Direct Object Reference to Arbitrary Group Join wpscan
CVE-2025-11707
< 2.15
LOW N/A Login Lockdown & Protection < 2.15 - IP Block Bypass wpscan
CVE-2025-11564
< 3.9.0
LOW N/A Tutor LMS – eLearning and online course solution < 3.9.0 - Missing Authorization to Unauthenticated Payment Status Upd… wpscan
CVE-2025-11267
< 9.112.2
LOW N/A VK All in One Expansion Unit < 9.112.2 - Authenticated (Contributor+) Stored Cross-Site Scripting wpscan
CVE-2025-11265
< 9.112.2
LOW N/A VK All in One Expansion Unit < 9.112.2 - Authenticated (Contributor+) Stored Cross-Site Scripting wpscan
CVE-2025-11220
< 3.33.4
LOW N/A Elementor < 3.33.4 - Contributor+ Stored DOM-Based XSS via Text Path wpscan
CVE-2025-10499
< 3.12.1
LOW N/A Ninja Forms < 3.12.1 - Statistics Collection Opt In via CSRF wpscan
CVE-2025-10498
< 3.12.1
LOW N/A Ninja Forms < 3.12.1 - Limited File Deletion via CSRF wpscan
CVE-2025-10146
< 3.3.24
LOW N/A Download Manager < 3.3.24 - Reflected Cross-Site Scripting via `user_ids` Parameter wpscan
CVE-2025-0215
< 1.25.1
LOW N/A UpdraftPlus - Backup/Restore < 1.25.1 - Reflected XSS wpscan
CVE-2024-9994
< 6.1.13
LOW N/A Essential Addons for Elementor < 6.1.13 - Contributor+ Stored XSS via Pricing Table Widget wpscan
CVE-2024-9993
< 6.1.13
LOW N/A Essential Addons for Elementor < 6.1.13 - Contributor+ Stored XSS via Event Calendar Widget wpscan
CVE-2024-9944
< 9.1.0
LOW N/A WooCommerce < 9.1.0 - Unauthenticated HTML Injection wpscan
CVE-2024-9926
< 3.9.10
LOW N/A Jetpack < 13.9.1 - Subscriber+ Arbitrary Feedback Access wpscan
CVE-2024-9529
< 6.3.6.3
LOW N/A Secure Custom Fields < 6.3.6.3 - Admin+ Remote Code Execution wpscan
CVE-2024-9314
< 1.0.229
LOW N/A Rank Math SEO < 1.0.229 - Admin+ PHP Object Injection wpscan
CVE-2024-9169
< 6.5
LOW N/A litespeed cache < 6.5 - Authenticated (Administrator+) Stored Cross-Site Scripting wpscan
CVE-2024-9162
< 7.87
LOW N/A All-in-One WP Migration and Backup < 7.87 - Authenticated (Administrator+) Arbitrary PHP Code Injection wpscan
CVE-2024-9161
< 1.0.229
LOW N/A Rank Math SEO < 1.0.229 - Unauthenticated User and Term Metadata Insert/Update/Deletion wpscan
CVE-2024-8979
< 6.0.10
LOW N/A Essential Addons for Elementor – Best Elementor Addon, Templates, Widgets, Kits & WooCommerce Builders < 6.0.10 - Auth… wpscan
CVE-2024-8978
< 6.0.10
LOW N/A Essential Addons for Elementor – Best Elementor Addon, Templates, Widgets, Kits & WooCommerce Builders < 6.0.10 - Auth… wpscan
CVE-2024-8961
< 6.0.8
LOW N/A Essential Addons for Elementor – Best Elementor Addon, Templates, Widgets, Kits & WooCommerce Builders < 6.0.8 - Authe… wpscan
← Prev 1599 1600 1601 1602 1603 1604 1605 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top