πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,549
Total CVEs
66
CISA KEV (Actively Exploited)
Sep 2, 2026
Last Updated

40,549 vulnerabilities found (page 1610 of 1622)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
CVE-2024-1171
< 5.9.9
LOW N/A Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders < 5.9.9 - Contributor+… wpscan
CVE-2024-11620
< 1.0.232
LOW N/A Rank Math SEO < 1.0.232 - Admin+ Remote Code Execution wpscan
CVE-2024-11376
< 250214
LOW N/A s2Member – Excellent for All Kinds of Memberships, Content Restriction Paywalls & Member Access Subscriptions < 250214… wpscan
CVE-2024-1133
< 2.6.1
LOW N/A Tutor LMS < 2.6.1 - Missing Authorization wpscan
CVE-2024-1128
< 2.6.1
LOW N/A Tutor LMS < 2.6.1 - Student+ HTML Injection via Q&A wpscan
CVE-2024-11223
< 1.9.2.3
LOW N/A WPForms < 1.9.2.3 - Admin+ Stored XSS wpscan
CVE-2024-11205
< 1.9.2.2
LOW N/A WPForms 1.8.4 - 1.9.2.1 - Missing Authorization to Authenticated (Subscriber+) Payment Refund and Subscription Cancellat… wpscan
CVE-2024-11088
< 4.5.6
LOW N/A Simple Membership < 4.5.6 - Exposure of Private Personal Information to an Unauthorized Actor wpscan
CVE-2024-11052
< 3.8.20
LOW N/A Ninja Forms < 3.8.20 - Unauthenticated Stored XSS via Form Calculations wpscan
CVE-2024-10957
< 1.24.12
LOW N/A UpdraftPlus < 1.24.12 - Unauthenticated PHP Object Injection wpscan
CVE-2024-10942
< 7.90
LOW N/A All in One WP Migration < 7.90 - Unauthenticated PHP Object Injection wpscan
CVE-2024-10924
< 9.1.2
LOW N/A Really Simple Security (Free, Pro, and Pro Multisite) 9.0.0 - 9.1.1.1 - Authentication Bypass wpscan
CVE-2024-10858
< 14.1-a.1
LOW N/A Jetpack 13.0-14.0 - Unauthenticated DOM-XSS wpscan
CVE-2024-10706
< 3.3.03
LOW N/A Download Manager < 3.3.03 - Admin+ Stored XSS wpscan
CVE-2024-10593
< 1.9.2.1
LOW N/A WPForms – Easy Form Builder for WordPress < 1.9.2.1 - Cross-Site Request Forgery (CSRF) to Plugin's Log Deletion wpscan
CVE-2024-10453
< 3.25.10
LOW N/A Elementor Website Builder < 3.25.10 - Contributor+ Stored XSS via Typography Settings wpscan
CVE-2024-10400
< 2.7.7
LOW N/A Tutor LMS < 2.7.7 - Unauthenticated SQL Injection via rating_filter wpscan
CVE-2024-10393
< 2.7.7
LOW N/A Tutor LMS < 2.7.7 - User Registration Setting Bypass to Unauthorized User Registration wpscan
CVE-2024-1037
< 5.2.6
LOW N/A All-In-One Security (AIOS) – Security and Firewall < 5.2.6 - Reflected Cross-Site Scripting wpscan
CVE-2024-10097
< 1.9.3
LOW N/A Loginizer Security and Loginizer < 1.9.3 - Authentication Bypass wpscan
CVE-2024-10076
< 13.8
LOW N/A Jetpack < 13.8, Boost < 3.4.8 - Contributor+ Stored XSS wpscan
CVE-2024-10075
< 13.8
LOW N/A Jetpack < 13.8 - Unauthenticated Arbitrary Block & Shortcode Execution wpscan
CVE-2024-0954
< 5.9.8
LOW N/A Essential Addons for Elementor < 5.9.8 - Contributor+ Stored XSS wpscan
CVE-2024-0899
< 240315
LOW N/A s2Member – Best Membership Plugin for All Kinds of Memberships, Content Restriction Paywalls & Member Access Subscript… wpscan
CVE-2024-0834
< 1.12.12
LOW N/A Elementor Addon Elements < 1.12.12 - Authenticated (Contributor+) Stored Cross-Site Scripting wpscan
← Prev 1607 1608 1609 1610 1611 1612 1613 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top