ðŸ›¡ï¸ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,549
Total CVEs
66
CISA KEV (Actively Exploited)
Sep 2, 2026
Last Updated

40,549 vulnerabilities found (page 1615 of 1622)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
CVE-2022-4346
< 5.1.3
LOW N/A All In One WP Security & Firewall < 5.1.3 - Configuration Leak wpscan
CVE-2022-4097
< 5.0.8
LOW N/A All In One WP Security & Firewall < 5.0.8 - IP Spoofing wpscan
CVE-2022-38093
< 4.2.4
LOW N/A All in One SEO < 4.2.4 - Multiple CSRF wpscan
CVE-2022-36376
< 1.0.95.1
LOW N/A Rank Math SEO < 1.0.95.1 - Unauthenticated SSRF wpscan
CVE-2022-36288
< 3.2.49
LOW N/A Download Manager < 3.2.49 - Multiple CSRF wpscan
CVE-2022-34658
< 3.2.49
LOW N/A Download Manager < 3.2.49 - Contributor+ Stored Cross-Site Scripting wpscan
CVE-2022-34347
< 3.2.49
LOW N/A Download Manager < 3.2.49 - Clear Stats & Cache via CSRF wpscan
CVE-2022-3144
< 7.6.1
LOW N/A Wordfence < 7.6.1 - Admin+ Stored Cross-Site Scripting wpscan
CVE-2022-29455
< 3.5.6
LOW N/A Elementor < 3.5.6 - DOM Reflected Cross-Site Scripting wpscan
CVE-2022-2926
< 3.2.55
LOW N/A Download Manager < 3.2.55 - Admin+ Arbitrary File/Folder Access via Path Traversal wpscan
CVE-2022-2903
< 3.6.13
LOW N/A NinjaForms < 3.6.13 - Admin+ PHP Objection Injection wpscan
CVE-2022-2633
< 2.6.1
LOW N/A All-in-One Video Gallery 2.5.8 - 2.6.0 - Unauthenticated Arbitrary File Download & SSRF wpscan
CVE-2022-2594
< 5.12.3
LOW N/A Advanced Custom Fields 5.0-5.12.2 - Unauthenticated File Upload wpscan
CVE-2022-2563
< 2.0.10
LOW N/A Tutor LMS < 2.0.10 - Admin+ Stored Cross-Site Scripting wpscan
CVE-2022-2554
< 4.0.0
LOW N/A Enable Media Replace < 4.0.0 - Admin+ Path Traversal wpscan
CVE-2022-2546
< 7.63
LOW N/A All-in-One WP Migration < 7.63 - Unauthenticated Reflected XSS wpscan
CVE-2022-2436
< 3.2.50
LOW N/A Download Manager < 3.2.50 - Contributor+ PHAR Deserialization wpscan
CVE-2022-2431
< 3.2.51
LOW N/A Download Manager < 3.2.51 - Contributor+ Arbitrary File Deletion wpscan
CVE-2022-2362
< 3.2.50
LOW N/A Download Manager < 3.2.50 - Bypass IP Address Blocking Restriction wpscan
CVE-2022-23183
< 5.12.1
LOW N/A Advanced Custom Fields < 5.12.1 - Contributor+ Database Information Access wpscan
CVE-2022-2317
< 4.1.3
LOW N/A Simple Membership < 4.1.3 - Unauthenticated Membership Privilege Escalation wpscan
CVE-2022-2273
< 4.1.3
LOW N/A Simple Membership < 4.1.3 - Membership Privilege Escalation wpscan
CVE-2022-2168
< 3.2.44
LOW N/A Download Manager < 3.2.44 - Reflected Cross-Site Scripting wpscan
CVE-2022-2101
< 3.2.48
LOW N/A Download Manager < 3.2.48 - Contributor+ Stored Cross-Site Scripting wpscan
CVE-2022-2099
< 6.6.0
LOW N/A WooCommerce < 6.6.0 - Admin+ Stored HTML Injection wpscan
← Prev 1612 1613 1614 1615 1616 1617 1618 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top