πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,549
Total CVEs
66
CISA KEV (Actively Exploited)
Sep 2, 2026
Last Updated

40,549 vulnerabilities found (page 1609 of 1622)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
CVE-2024-1502
< 2.6.2
LOW N/A Tutor LMS – eLearning and online course solution < 2.6.2 - Missing Authorization to Authenticated (Subscriber+) Arbitr… wpscan
CVE-2024-1422
< 1.13
LOW N/A Elementor Addon Elements < 1.13 - Authenticated(Contributor+) Stored Cross-Site Scripting via Modal Popup effet wpscan
CVE-2024-1393
< 1.13
LOW N/A Elementor Addon Elements < 1.13 - Authenticated (Contributor+) Stored Cross-Site Scripting via Content Switcher Widget wpscan
CVE-2024-1392
< 1.13
LOW N/A Elementor Addon Elements < 1.13 - Contributor+ Stored XSS wpscan
CVE-2024-1391
< 1.13
LOW N/A Elementor Addon Elements < 1.13 - Contributor+ Stored XSS wpscan
CVE-2024-1358
< 1.13
LOW N/A Elementor Addon Elements < 1.13 - Contributor+ to LFI wpscan
CVE-2024-13470
< 3.8.25
LOW N/A Ninja Forms < 3.8.25 - Contributor+ Stored XSS wpscan
CVE-2024-13445
< 3.27.5
LOW N/A Elementor Website Builder < 3.27.5 - Contributor+ Stored XSS wpscan
CVE-2024-13403
< 1.9.3.2
LOW N/A WPForms Lite < 1.9.3.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via fieldHTML Parameter wpscan
CVE-2024-1340
< 2.09
LOW N/A Login Lockdown – Protect Login Form < 2.09 - Subscriber+ Options Leak wpscan
CVE-2024-13362
< 1.10.5.1
LOW N/A Freemius < 2.11.0 - Reflected DOM-Based XSS via url Parameter wpscan
CVE-2024-13229
< 1.0.236
LOW N/A Rank Math SEO < 1.0.236 - Contributor+ Arbitrary Schema Deletion wpscan
CVE-2024-13227
< 1.0.236
LOW N/A Rank Math SEO < 1.0.236 - Contributor+ Stored XSS via Rank Math API wpscan
CVE-2024-13215
< 1.14
LOW N/A Elementor Addon Elements < 1.14 - Contributor+ Sensitive Information Disclosure wpscan
CVE-2024-13126
< 3.3.07
LOW N/A Download Manager < 3.3.07 - Unauthenticated Data Exposure wpscan
CVE-2024-1310
< 8.6
LOW N/A WooCommerce < 8.6 - Contributor+ Private/Draft Products Access wpscan
CVE-2024-1295
< 6.4.0.1
LOW N/A The Events Calendar Free & Pro <= 6.4.0 - Contributor+ Missing Authorization to Authenticated Arbitrary Events Access wpscan
CVE-2024-1276
< 5.9.9
LOW N/A Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders < 5.9.9 - Contributor+… wpscan
CVE-2024-1236
< 5.9.9
LOW N/A Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders < 5.9.9 - Contributor+… wpscan
CVE-2024-12238
< 3.8.23
LOW N/A Ninja Forms < 3.8.23 - Subscriber+ Arbitrary Shortcode Execution wpscan
CVE-2024-12118
< 6.9.1
LOW N/A The Events Calendar < 6.9.1 - Contributor+ Stored XSS wpscan
CVE-2024-11768
< 3.3.04
LOW N/A Download manager < 3.3.04 - Unauthenticated Download of Password-Protected Files wpscan
CVE-2024-11740
< 3.3.04
LOW N/A Download Manager < 3.3.04 - Unauthenticated Arbitrary Shortcode Execution wpscan
CVE-2024-11724
< 3.6.6
LOW N/A Cookie Consent for WP – Cookie Consent, Consent Log, Cookie Scanner, Script Blocker (for GDPR, CCPA & ePrivacy) < 3.6.… wpscan
CVE-2024-1172
< 5.9.9
LOW N/A Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders < 5.9.9 - Contributor+… wpscan
← Prev 1606 1607 1608 1609 1610 1611 1612 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top