πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,549
Total CVEs
66
CISA KEV (Actively Exploited)
Sep 2, 2026
Last Updated

40,549 vulnerabilities found (page 1604 of 1622)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
CVE-2024-56217
< 3.3.04
LOW N/A Download Manager < 3.3.04 - Missing Authorization wpscan
CVE-2024-56063
< 6.0.8
LOW N/A Essential Addons for Elementor < 6.0.8 - Contributor+ Stored XSS wpscan
CVE-2024-5573
< 2.0.66
LOW N/A Easy Table of Contents < 2.0.66 - Admin+ Stored XSS wpscan
CVE-2024-54444
< 3.25.11
LOW N/A Elementor Website Builder < 3.25.11 - Contributor+ Stored XSS wpscan
CVE-2024-5438
< 2.7.2
LOW N/A Tutor LMS – eLearning and online course solution < 2.7.2 - Authenticated (Instructor+) Insecure Direct Object Referenc… wpscan
CVE-2024-5416
< 3.24.0
LOW N/A Elementor Website Builder – More than Just a Page Builder < 3.24.0 - Authenticated (Contributor+) Stored Cross-Site Sc… wpscan
CVE-2024-5333
< 6.8.2.1
LOW N/A The Events Calendar < 6.8.2.1 - Unauthenticated Password Protected Event Disclosure wpscan
CVE-2024-5266
< 3.2.94
LOW N/A Download Manager < 3.2.94 - Authenticated (Author+) Stored Cross-Site Scripting via Multiple Shortcodes wpscan
CVE-2024-51915
< 6.5.3
LOW N/A LiteSpeed Cache < 6.5.3 - Contributor+ Stored XSS wpscan
CVE-2024-5189
< 5.9.24
LOW N/A Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders < 5.9.24 - Authenticat… wpscan
CVE-2024-5188
< 5.9.23
LOW N/A Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders < 5.9.23 - Authenticat… wpscan
CVE-2024-51815
< 241216
LOW N/A s2Member (Pro) < 241216 - Unauthenticated Remote Code Execution wpscan
CVE-2024-5073
< 5.9.22
LOW N/A Essential Addons for Elementor < 5.9.22 - Contributor+ Stored Cross-Site Scripting via Twitter Feed wpscan
CVE-2024-50555
< 3.29.1
LOW N/A Elementor Website Builder < 3.29.1 - Contributor+ Stored XSS wpscan
CVE-2024-50550
< 6.5.2
LOW N/A LiteSpeed Cache < 6.5.2 - Unauthenticated Privilege Escalation wpscan
CVE-2024-50515
< 3.8.18
LOW N/A Ninja Forms < 3.8.18 - Admin+ Stored XSS wpscan
CVE-2024-50514
< 3.8.18
LOW N/A Ninja Forms < 3.8.18 - Admin+ Stored XSS wpscan
CVE-2024-4984
< 22.7
LOW N/A Yoast SEO < 22.7 - Authenticated (Contributor+) Stored Cross-Site Scripting wpscan
CVE-2024-49682
< 4.5.4
LOW N/A Simple Membership < 4.5.4 - Unauthenticated Open Redirect wpscan
CVE-2024-49593
< 6.3.6.3
LOW N/A Secure Custom Fields < 6.3.6.3 - Admin+ Stored XSS wpscan
CVE-2024-4902
< 2.7.2
LOW N/A Tutor LMS – eLearning and online course solution < 2.7.2 -Authenticated (Administrator+) SQL Injection wpscan
CVE-2024-4869
< 3.3.0
LOW N/A WP Cookie Consent ( for GDPR, CCPA & ePrivacy ) < 3.3.0 - Unauthenticated Stored Cross-Site Scripting via Client-IP head… wpscan
CVE-2024-47637
< 6.5.1
LOW N/A LiteSpeed Cache < 6.5.1 - Author+ Path Traversal wpscan
CVE-2024-47622
< 2.02
LOW N/A Advanced Woo Labels < 2.02 - Authenticated (Contributor+) Stored Cross-Site Scripting wpscan
CVE-2024-47374
< 6.5.1
LOW N/A LiteSpeed Cache < 6.5.1 - Unauthenticated Stored Cross-Site Scripting wpscan
← Prev 1601 1602 1603 1604 1605 1606 1607 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top