πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,549
Total CVEs
66
CISA KEV (Actively Exploited)
Sep 2, 2026
Last Updated

40,549 vulnerabilities found (page 1607 of 1622)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
CVE-2024-3728
< 5.9.16
LOW N/A Essential Addons for Elementor < 5.9.16 - Contributor+ Stored Cross-Site Scripting wpscan
CVE-2024-37266
< 2.7.2
LOW N/A Tutor LMS < 2.7.2 - Authenticated (Admin+) Path Traversal wpscan
CVE-2024-37254
< 7.2.8
LOW N/A File Manager < 7.2.8 - Missing Authorization wpscan
CVE-2024-3665
< 1.0.217
LOW N/A Rank Math SEO with AI SEO Tools < 1.0.217 - Contributor+ Stored Cross-Site Scripting via 'titleWrapper' wpscan
CVE-2024-3649
< 1.8.8.2
LOW N/A Contact Form by WPForms – Drag & Drop Form Builder for WordPress < 1.8.8.2 - Unauthenticated Price Manipulation wpscan
CVE-2024-3599
< 3.1.0
LOW N/A WP Cookie Consent ( for GDPR, CCPA & ePrivacy ) < 3.1.0 - Missing Authorization to Unauthenticated Arbitrary Post Deleti… wpscan
CVE-2024-35777
< 9.0.0
LOW N/A WooCommerce < 9.0.0 - Shop Manager+ Content Injection wpscan
CVE-2024-35675
< 1.94
LOW N/A Advanced Woo Labels – Product Labels for WooCommerce < 1.94 - Authenticated (Contributor+) Stored Cross-Site Scripting wpscan
CVE-2024-3554
< 4.6.1.1
LOW N/A All in One SEO – Best WordPress SEO Plugin – Easily Improve SEO Rankings & Increase Traffic < 4.6.1.1 - Contributor+… wpscan
CVE-2024-3553
< 2.7.0
LOW N/A Tutor LMS < 2.7.0 - Missing Authorization to Unauthenticated Limited Options Update wpscan
CVE-2024-34764
< 5.9.16
LOW N/A Essential Addons for Elementor < 5.9.16 - Contributor+ Stored XSS wpscan
CVE-2024-3368
< 4.6.1.1
LOW N/A All in One SEO < 4.6.1.1 - Contributor+ Stored XSS wpscan
CVE-2024-3333
< 5.9.15
LOW N/A Essential Addons for Elementor < 5.9.15 - Contributor+ Store XSS via Widget URL wpscan
CVE-2024-32559
< 1.0.5
LOW N/A WP 404 Auto Redirect to Similar Post < 1.0.5 - Reflected Cross-Site Scripting via Debug Mode URI wpscan
CVE-2024-3246
< 6.3
LOW N/A LiteSpeed Cache < 6.3 - Cross-Site Request Forgery to Stored Cross-Site Scripting wpscan
CVE-2024-31248
< 3.6.0
LOW N/A All-in-One Video Gallery < 3.6.0 - Missing Authorization wpscan
CVE-2024-31237
< 240325
LOW N/A s2Member < 240325 - Limited Privilege Escalation wpscan
CVE-2024-31229
< 8.0.0
LOW N/A Really Simple SSL < 8.0.0 - Admin+ Server-Side Request Forgery wpscan
CVE-2024-30468
< 5.2.7
LOW N/A All In One WP Security < 5.2.7 - Cross-Site Request Forgery to IP Blocking wpscan
CVE-2024-30422
< 1.13.2
LOW N/A Elementor Addon Elements < 1.13.2 - Authenticated (Contributor+) Stored Cross-Site Scripting wpscan
CVE-2024-3018
< 5.9.14
LOW N/A Essential Addons for Elementor < 5.9.14 - Author+ PHP Object Injection wpscan
CVE-2024-2974
< 5.9.14
LOW N/A Essential Addons for Elementor < 5.9.14 - Unauthenticated Private/Draft Posts Access wpscan
CVE-2024-29220
< 3.8.1
LOW N/A Ninja Forms – The Contact Form Builder That Grows With You < 3.8.1 - Admin+ Stored Cross-Site Scripting wpscan
CVE-2024-29114
< 3.2.85
LOW N/A Download Manager < 3.2.85 - Contributor+ Stored XSS wpscan
CVE-2024-29107
< 1.12.11
LOW N/A Elementor Addon Elements < 1.12.11 - Contributor+ Stored XSS wpscan
← Prev 1604 1605 1606 1607 1608 1609 1610 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top