πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,549
Total CVEs
66
CISA KEV (Actively Exploited)
Sep 2, 2026
Last Updated

40,549 vulnerabilities found (page 1606 of 1622)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
CVE-2024-4279
< 2.7.1
LOW N/A Tutor LMS – eLearning and online course solution < 2.7.1 - Authenticated (Instructor+) Insecure Direct Object Referenc… wpscan
CVE-2024-4275
< 5.9.20
LOW N/A Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders < 5.9.20 - Contributor… wpscan
CVE-2024-4223
< 2.7.1
LOW N/A Tutor LMS < 2.7.1 - Missing Authorization wpscan
CVE-2024-4180
< 6.4.0.1
LOW N/A The Events Calendar < 6.4.0.1 - Reflected XSS wpscan
CVE-2024-4160
< 3.2.91
LOW N/A Download Manager < 3.2.91 - Authenticated (Contributor+) Stored Cross-Site Scripting via wpdm-all-packages Shortcode wpscan
CVE-2024-4156
< 5.9.18
LOW N/A Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders < 5.9.18 - Contributor… wpscan
CVE-2024-4041
< 22.6
LOW N/A Yoast SEO < 22.6 - Reflected Cross-Site Scripting wpscan
CVE-2024-4033
< 3.6.5
LOW N/A All-in-One Video Gallery < 3.6.5 - Contributor+ Arbitrary File Upload via featured image wpscan
CVE-2024-4003
< 5.9.16
LOW N/A Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders < 5.9.16 - Contributor… wpscan
CVE-2024-4001
< 3.2.94
LOW N/A Download Manager < 3.2.94 - Authenticated (Contributor+) Stored Cross-Site Scripting via wpdm_modal_login_form Shortcode wpscan
CVE-2024-3994
< 2.7.0
LOW N/A Tutor LMS – eLearning and online course solution < 2.7.0 - Authenticated (Contributor+) Stored Cross-Site Scripting vi… wpscan
CVE-2024-39666
< 9.1.4
LOW N/A WooCommerce < 9.1.4 - Stored XSS wpscan
CVE-2024-39649
< 5.9.27
LOW N/A Essential Addons for Elementor < 5.9.27 - Contributor+ Stored Cross-Site Scripting wpscan
CVE-2024-39645
< 2.7.3
LOW N/A Tutor LMS < 2.7.3 - Cross-Site Request Forgery wpscan
CVE-2024-39628
< 3.8.7
LOW N/A Ninja Forms < 3.8.7 - Cross-Site Request Forgery wpscan
CVE-2024-3866
< 3.8.16
LOW N/A Ninja Forms Contact Form < 3.8.16 - Reflected Self-Based Cross-Site Scripting via Referer wpscan
CVE-2024-37956
< 9.99.2.0
LOW N/A VK All in One Expansion Unit < 9.99.2.0 - Contributor+ Stored XSS wpscan
CVE-2024-37947
< 2.7.3
LOW N/A Tutor LMS < 2.7.3 - Authenticated (Tutor Instructor+) Stored Cross-Site Scripting wpscan
CVE-2024-37934
< 3.8.5
LOW N/A Ninja Forms < 3.8.5 - Authenticated (Subscriber+) Arbitrary Shortcode Execution wpscan
CVE-2024-37518
< 6.5.1.5
LOW N/A The Events Calendar < 6.5.1.5 - Cross-Site Request Forgery via action_restore_events wpscan
CVE-2024-37437
< 3.22.2
LOW N/A Elementor Website Builder < 3.22.2 - Contributor+ Arbitrary SVG Download wpscan
CVE-2024-3743
< 1.13.4
LOW N/A Elementor Addon Elements < 1.13.4 - Contributor+ Stored XSS wpscan
CVE-2024-3733
< 5.9.16
LOW N/A Essential Addons for Elementor < 5.9.16 - Information Exposure wpscan
CVE-2024-3730
< 4.4.4
LOW N/A Simple Membership < 4.4.4 - Authenticated(Contributor+) Stored Cross-Site Scripting via Shortcode wpscan
CVE-2024-37297
< 8.9.3
LOW N/A WooCommerce 8.8.0 - 8.9.2 - Reflected XSS wpscan
← Prev 1603 1604 1605 1606 1607 1608 1609 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top