πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,549
Total CVEs
66
CISA KEV (Actively Exploited)
Sep 2, 2026
Last Updated

40,549 vulnerabilities found (page 1608 of 1622)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
CVE-2024-28000
< 6.4
LOW N/A LiteSpeed Cache < 6.4 - Unauthenticated Privilege Escalation wpscan
CVE-2024-2792
< 1.13.3
LOW N/A Elementor Addon Elements < 1.13.3 - Contributor+ DOM-Based Stored XSS wpscan
CVE-2024-2654
< 7.2.6
LOW N/A File Manager < 7.2.6 - Authenticated (Administrator+) Directory Traversal wpscan
CVE-2024-2650
< 5.9.12
LOW N/A Essential Addons for Elementor < 5.9.12 - Contributor+ Stored XSS wpscan
CVE-2024-2623
< 5.9.12
LOW N/A Essential Addons for Elementor < 5.9.12 - Contributor+ Stored XSS wpscan
CVE-2024-2536
< 1.0.215
LOW N/A Rank Math SEO with AI SEO Tools < 1.0.215 - Contributor+ Stored XSS wpscan
CVE-2024-24934
< 3.19.1
LOW N/A Elementor < 3.19.1 - Authenticated(Contributor+) Arbitrary File Deletion and PHAR Deserialization wpscan
CVE-2024-2242
< 5.9.2
LOW N/A Contact Form 7 < 5.9.2 - Reflected Cross-Site Scripting wpscan
CVE-2024-22308
< 4.4.2
LOW N/A Simple Membership < 4.4.2 - Open Redirect wpscan
CVE-2024-22155
< 8.6.0
LOW N/A WooCommerce < 8.6.0 - Cross-Site Request Forgery wpscan
CVE-2024-2170
< 9.97.0.0
LOW N/A VK All in One Expansion Unit < 9.97.0.0 - Contributor+ Stored XSS wpscan
CVE-2024-2117
< 3.20.3
LOW N/A Elementor Website Builder < 3.20.3 - Contributor+ DOM Stored XSS wpscan
CVE-2024-2113
< 3.8.1
LOW N/A Ninja Forms Contact Form < 3.8.1 - Publicly Accessible Form Submission Export via CSRF wpscan
CVE-2024-2108
< 3.8.1
LOW N/A Ninja Forms Contact Form < 3.8.1 - Author+ Stored XSS wpscan
CVE-2024-2098
< 3.2.90
LOW N/A Download Manager < 3.2.90 - Improper Authorization via protectMediaLibrary wpscan
CVE-2024-2093
< 9.96.0.0
LOW N/A VK All in One Expansion Unit < 9.96.0.0 - Unauthenticated Password Protected Content Access wpscan
CVE-2024-2092
< 1.13.4
LOW N/A Elementor Addon Elements < 1.13.4 - Authenticated (Contributor+) Stored Cross-Site Scripting via Twitter Widget wpscan
CVE-2024-2091
< 1.13.2
LOW N/A Elementor Addon Elements < 1.13.2 - Contributor+ Stored XSS wpscan
CVE-2024-1985
< 4.4.3
LOW N/A Simple Membership < 4.4.3 - Unauthenticated Stored Self-Based Cross-Site Scripting wpscan
CVE-2024-1766
< 3.2.87
LOW N/A Download Manager < 3.2.87 - Authenticated (Subscriber+) Stored Self-Based Cross-Site Scripting wpscan
CVE-2024-1751
< 2.6.2
LOW N/A Tutor LMS – eLearning and online course solution < 2.6.2 - Authenticated (Subscriber+) SQL Injection wpscan
CVE-2024-1538
< 7.2.5
LOW N/A File Manager < 7.2.5 - Cross-Site Request Forgery to Local JS File Inclusion wpscan
CVE-2024-1537
< 5.9.10
LOW N/A Essential Addons for Elementor < 5.9.10 - Contributor+ Stored Cross-Site Scripting via Data Table wpscan
CVE-2024-1536
< 5.9.10
LOW N/A Essential Addons for Elementor < 5.9.10 - Contributor+ Stored Cross-Site Scripting via Event Calendar wpscan
CVE-2024-1503
< 2.6.2
LOW N/A Tutor LMS – eLearning and online course solution < 2.6.2 - Cross-Site Request Forgery to Plugin Deactivation and Data … wpscan
← Prev 1605 1606 1607 1608 1609 1610 1611 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top