πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,549
Total CVEs
66
CISA KEV (Actively Exploited)
Sep 2, 2026
Last Updated

40,549 vulnerabilities found (page 1603 of 1622)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
CVE-2024-8902
< 1.13.9
LOW N/A Elementor Addon Elements < 1.13.9 - Authenticated (Contributor+) Sensitive Information Exposure via table_saved_sections wpscan
CVE-2024-8852
< 7.87
LOW N/A All-in-One WP Migration and Backup < 7.87 - Unauthenticated Information Disclosure via Error Logs wpscan
CVE-2024-8850
< 4.9.17
LOW N/A MC4WP: Mailchimp for WordPress 4.9.9 - 4.9.16 - Reflected Cross-Site Scripting wpscan
CVE-2024-8742
< 6.0.4
LOW N/A Essential Addons for Elementor < 6.0.4 - Authenticated (Contributor+) Stored Cross-Site Scripting via Filterable Gallery… wpscan
CVE-2024-8680
< 4.9.17
LOW N/A MailChimp for Wordpress < 4.9.17 - Authenticated (Administrator+) Stored Cross-Site Scripting wpscan
CVE-2024-8493
< 6.6.4
LOW N/A The Events Calendar < 6.6.4 - Admin+ Stored XSS wpscan
CVE-2024-8444
< 3.3.00
LOW N/A Download Manager < 3.3.00 - Contributor+ Stored XSS wpscan
CVE-2024-8440
< 6.0.4
LOW N/A Essential Addons for Elementor -- Best Elementor Templates, Widgets, Kits & WooCommerce Builders < 6.0.4 - Authenticated… wpscan
CVE-2024-8326
< 241216
LOW N/A s2Member – Excellent for All Kinds of Memberships, Content Restriction Paywalls & Member Access Subscriptions < 241216… wpscan
CVE-2024-8284
< 3.2.99
LOW N/A Download Manager <= 3.2.98 - Admin+ Stored XSS wpscan
CVE-2024-8275
< 6.6.4.1
LOW N/A The Events Calendar < 6.6.4.1 - Unauthenticated SQL Injection wpscan
CVE-2024-8236
< 3.25.8
LOW N/A Elementor Website Builder < 3.25.8 - Contributor+ Stored XSS wpscan
CVE-2024-7354
< 3.8.11
LOW N/A Ninja Forms 3.8.6-3.8.10 - Reflected XSS wpscan
CVE-2024-7122
< 1.13.7
LOW N/A Elementor Addon Elements < 1.13.7 - Authenticated (Contributor+) Stored Cross-Site Scripting via Multiple Widgets wpscan
CVE-2024-7092
< 6.0.0
LOW N/A Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders < 6.0.0 - Authenticate… wpscan
CVE-2024-7082
< 2.0.68
LOW N/A easy-table-of-contents < 2.0.68 - Editor+ Stored XSS wpscan
CVE-2024-7056
< 1.9.1.6
LOW N/A WPForms < 1.9.1.6 - Admin+ Stored XSS wpscan
CVE-2024-6931
< 6.5.2
LOW N/A The Events Calendar < 6.5.2 - Unauthenticated Stored Cross-Site Scripting wpscan
CVE-2024-6757
< 3.24.6
LOW N/A Elementor < 3.24.6 - Contributor+ Information Exposure via get_image_alt wpscan
CVE-2024-6694
< 4.1.0
LOW N/A WP Mail SMTP < 4.1.0 - Admin+ SMTP Password Exposure wpscan
CVE-2024-6629
< 3.8.3
LOW N/A All-in-One Video Gallery < 3.8.3 - Authenticated (Contributor+) Stored Cross-Site Scripting via Video Shortcode wpscan
CVE-2024-6334
< 2.0.67.1
LOW N/A Easy Table of Contents < 2.0.67 - Editor+ Stored XSS wpscan
CVE-2024-6208
< 3.2.98
LOW N/A Download Manager < 3.2.98 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode wpscan
CVE-2024-5647
< 6.0.5
LOW N/A Magnific Popups JavaScript Library < 1.2.0 - Contributor+ Stored XSS wpscan
CVE-2024-56276
< 1.9.2.3
LOW N/A Contact Form by WPForms < 1.9.2.3 - Contributor+ Custom Form Theme Creation wpscan
← Prev 1600 1601 1602 1603 1604 1605 1606 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top