ðŸ›¡ï¸ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,549
Total CVEs
66
CISA KEV (Actively Exploited)
Sep 2, 2026
Last Updated

40,549 vulnerabilities found (page 1614 of 1622)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
CVE-2023-1809
< 6.3.0
LOW N/A Download Manager Pro < 6.3.0 - Unauthenticated Sensitive Information Disclosure wpscan
CVE-2023-1624
< 2.0.9
LOW N/A WPCode Lite < 2.0.9 - Arbitrary Log File Deletion via CSRF wpscan
CVE-2023-1524
< 3.2.71
LOW N/A Download Manager < 3.2.71 - Broken Access Controls wpscan
CVE-2023-1196
< 6.1.0
LOW N/A Advanced Custom Fields < 6.1.0 - Contributor+ PHP Object Injection wpscan
CVE-2023-1169
< 2.1.5
LOW N/A OoohBoi Steroids for Elementor < 2.1.5 - Arbitrary File Upload wpscan
CVE-2023-1119
< 3.2.13
LOW N/A Multiple Plugins - Cross-Site Scripting From Third-party Library wpscan
CVE-2023-0937
< 9.87.1.0
LOW N/A VK All in One Expansion Unit < 9.87.1.0 - Reflected XSS wpscan
CVE-2023-0586
< 4.3.0
LOW N/A All in One SEO Pack < 4.3.0 - Contributor+ Stored XSS wpscan
CVE-2023-0585
< 4.3.0
LOW N/A All in One SEO Pack < 4.3.0 - Admin+ Stored XSS wpscan
CVE-2023-0336
< 2.1.5
LOW N/A OoohBoi Steroids for Elementor < 2.1.5 - Subscriber+ Attachment Deletion wpscan
CVE-2023-0329
< 3.12.2
LOW N/A Elementor Website Builder < 3.12.2 - Admin+ SQLi wpscan
CVE-2023-0328
< 2.0.7
LOW N/A WPCode < 2.0.7 - Contributor+ WPCode Library Auth Key Update/Deletion wpscan
CVE-2023-0255
< 4.0.2
LOW N/A Enable Media Replace < 4.0.2 - Author+ Arbitrary File Upload wpscan
CVE-2023-0236
< 2.0.10
LOW N/A Tutor LMS < 2.0.10 - Reflected Cross-Site Scripting wpscan
CVE-2023-0230
< 9.86.0.0
LOW N/A VK All in One Expansion Unit < 9.86.0.0 - Contributor+ Stored XSS wpscan
CVE-2023-0157
< 5.1.5
LOW N/A All-In-One Security (AIOS) < 5.1.5 - Admin+ Stored XSS wpscan
CVE-2023-0156
< 5.1.5
LOW N/A All-In-One Security (AIOS) < 5.1.5 - Admin+ Arbitrary File/Folder Access via Traversal wpscan
CVE-2022-4953
< 3.5.5
LOW N/A Elementor < 3.5.5 - Iframe Injection wpscan
CVE-2022-46800
< 5.3.1
LOW N/A LiteSpeed Cache <= 5.3 - CSRF wpscan
CVE-2022-45836
< 3.2.60
LOW N/A Download Manager < 3.2.60 - Reflected XSS wpscan
CVE-2022-45084
< 1.7.6
LOW N/A Loginizer < 1.7.6 - Reflected XSS wpscan
CVE-2022-45079
< 1.7.6
LOW N/A Loginizer <= 1.7.5 - Cross-Site Request Forgery wpscan
CVE-2022-4476
< 3.2.62
LOW N/A Download Manager < 3.2.62 - Contributor+ Stored XSS wpscan
CVE-2022-44737
< 5.1.1
LOW N/A All-In-One Security < 5.1.1 - Bulk Actions via CSRF wpscan
CVE-2022-4469
< 4.2.2
LOW N/A Simple Membership < 4.2.2 - Contributor+ Stored XSS wpscan
← Prev 1611 1612 1613 1614 1615 1616 1617 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top