πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,549
Total CVEs
66
CISA KEV (Actively Exploited)
Sep 2, 2026
Last Updated

40,549 vulnerabilities found (page 1611 of 1622)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
CVE-2024-0761
< 7.2.2
LOW N/A File Manager < 7.2.2 - Sensitive Information Exposure via Backup Filenames wpscan
CVE-2024-0685
< 3.7.2
LOW N/A Ninja Forms Contact Form < 3.7.2 - Unauthenticated Second Order SQL Injection wpscan
CVE-2024-0586
< 5.9.5
LOW N/A Essential Addons for Elementor < 5.9.5 - Contributor+ Stored Cross-Site Scritping wpscan
CVE-2024-0585
< 5.9.5
LOW N/A Essential Addons for Elementor < 5.9.5 - Contributor+ Stored Cross-Site Scripting via Image URl wpscan
CVE-2024-0509
< 1.0.4
LOW N/A WP 404 Auto Redirect to Similar Post < 1.0.4 - Reflected Cross-Site Scripting via request wpscan
CVE-2024-0506
< 3.19.0
LOW N/A Elementor Website Builder – More than Just a Page Builder < 3.19.0 - Authenticated (Contributor+) Stored Cross-Site Sc… wpscan
CVE-2023-7044
< 5.9.3
LOW N/A Essential Addons for Elementor < 5.9.3 - Contributor+ Stored XSS wpscan
CVE-2023-6954
< 3.2.86
LOW N/A Download Manager < 3.2.86 - Contributor+ Stored XSS wpscan
CVE-2023-6882
< 4.3.9
LOW N/A Simple Membership < 4.3.9 - Reflected Cross-Site Scripting Vulnerability via environment_mode wpscan
CVE-2023-6825
< 7.2.2
LOW N/A File Manager And File Manager Pro (Multiple Versions) - Directory Traversal wpscan
CVE-2023-6785
< 3.2.85
LOW N/A Download Manager < 3.2.85 - Unauthenticated File Download wpscan
CVE-2023-6751
< 1.9.8
LOW N/A Hostinger < 1.9.8 - Unauthenticated Maintenance Mode Toggle wpscan
CVE-2023-6737
< 4.1.5
LOW N/A Enable Media Replace < 4.1.5 - Reflected Cross-Site Scripting wpscan
CVE-2023-6701
< 6.2.5
LOW N/A Advanced Custom Fields < 6.2.5 - Contributor+ Stored Cross-Site Scripting via Custom Field wpscan
CVE-2023-6557
< 6.2.9
LOW N/A The Events Calendar < 6.2.9 - Unauthenticated Sensitive Information Exposure wpscan
CVE-2023-6449
< 5.8.4
LOW N/A Contact Form 7 < 5.8.4 - Authenticated (Editor+) Arbitrary File Upload wpscan
CVE-2023-6421
< 3.2.83
LOW N/A Download Manager < 3.2.83 - Unauthenticated Protected File Download Password Leak wpscan
CVE-2023-6203
< 6.2.8.1
LOW N/A The Events Calendar < 6.2.8.1 - Unauthenticated Arbitrary Password Protected Post Read wpscan
CVE-2023-5982
< 1.23.11
LOW N/A UpdraftPlus: WordPress Backup & Migration < 1.23.11 - Google Drive Storage Update via CSRF wpscan
CVE-2023-5605
< 1.7.9.1
LOW N/A URL Shortify < 1.7.9.1 - Admin+ Stored XSS wpscan
CVE-2023-5530
< 3.6.34
LOW N/A Ninja Forms < 3.6.34 - Admin+ Stored XSS wpscan
CVE-2023-5381
< 1.12.8
LOW N/A Elementor Addon Elements < 1.12.8 - Admin+ Stored XSS wpscan
CVE-2023-52222
< 8.3.0
LOW N/A WooCommerce < 8.3.0 - Cross-Site Request Forgery wpscan
CVE-2023-52147
< 5.2.5
LOW N/A All In One WP Security < 5.2.5 - Protection Bypass of Renamed Login Page via URL Encoding wpscan
CVE-2023-51682
< 4.9.10
LOW N/A MC4WP < 4.9.10 - Unauthenticated Unpublished Form Preview wpscan
← Prev 1608 1609 1610 1611 1612 1613 1614 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top