ðŸ›¡ï¸ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,634
Total CVEs
66
CISA KEV (Actively Exploited)
Sep 3, 2026
Last Updated

40,634 vulnerabilities found (page 1616 of 1626)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
CVE-2023-45000
< 5.7.0.1
LOW N/A LiteSpeed Cache < 5.7.0.1 - Unauthenticated CDN Status Update wpscan
CVE-2023-44983
< 2.0.7
LOW N/A Aruba HiSpeed Cache < 2.0.7 - Unauthenticated Log File Access wpscan
CVE-2023-4372
< 5.7
LOW N/A LiteSpeed Cache < 5.7 - Contributor+ Stored XSS wpscan
CVE-2023-4294
< 1.7.6
LOW N/A URL Shortify < 1.7.6 - Unauthenticated Stored XSS via referer header wpscan
CVE-2023-41957
< 4.3.5
LOW N/A Simple Membership < 4.3.5 - Privilege escalation via Registration wpscan
CVE-2023-41956
< 4.3.5
LOW N/A Simple Membership < 4.3.5 - Account Takeover via Password Reset wpscan
CVE-2023-41955
< 5.8.9
LOW N/A Essential Addons for Elementor < 5.8.9 - Authenticated (Contributor+) Privilege Escalation wpscan
CVE-2023-4109
< 3.6.26
LOW N/A Ninja Forms < 3.6.26 - Admin+ Stored HTML Injection wpscan
CVE-2023-40680
< 21.1
LOW N/A Yoast SEO < 21.1 - Authenticated (Seo Manager+) Stored Cross-Site Scripting wpscan
CVE-2023-40206
< 1.0.4
LOW N/A WP 404 Auto Redirect to Similar Post < 1.0.4 - Admin+ Stored XSS wpscan
CVE-2023-40000
< 5.7.0.1
LOW N/A LiteSpeed Cache < 5.7.0.1 - Unauthenticated Stored XSS wpscan
CVE-2023-38393
< 3.6.26
LOW N/A Ninja Forms < 3.6.26 - Subscriber+ Form Entries Export wpscan
CVE-2023-38386
< 3.6.26
LOW N/A Ninja Forms < 3.6.26 - Contributor+ Form Entries Export wpscan
CVE-2023-37979
< 3.6.26
LOW N/A Ninja Forms < 3.6.26 - Reflected Cross-Site Scripting wpscan
CVE-2023-3779
< 5.8.2
LOW N/A Essential Addons For Elementor < 5.8.2 - Unauthenticated MailChimp API Key Disclosure wpscan
CVE-2023-36505
< 3.6.25
LOW N/A Ninja Forms < 3.6.25 - Admin+ Arbitrary File Deletion wpscan
CVE-2023-3524
< 2.0.13.1
LOW N/A WPCode < 2.0.13.1 - Reflected XSS wpscan
CVE-2023-33999
< 6.1.0
LOW N/A Freemius SDK < 2.5.10 - Reflected Cross-Site Scripting wpscan
CVE-2023-32960
< 1.23.4
LOW N/A UpdraftPlus < 1.23.4 - CSRF wpscan
CVE-2023-32600
< 1.0.119.1
LOW N/A Rank Math SEO < 1.0.119.1 - Contributor+ Stored XSS wpscan
CVE-2023-32243
< 5.7.2
LOW N/A Essential Addons for Elementor 5.4.0-5.7.1 - Unauthenticated Privilege Escalation wpscan
CVE-2023-3133
< 2.2.1
LOW N/A Tutor LMS < 2.2.1 - Unauthenticated Access to Tutor LMS Lesson Resources via REST API wpscan
CVE-2023-3129
< 1.7.0
LOW N/A URL Shortify < 1.7.0 - Admin+ Cross Site Scripting wpscan
CVE-2023-30777
< 6.1.6
LOW N/A Advanced Custom Fields < 6.1.6 - Reflected XSS wpscan
CVE-2023-30500
< 1.8.1.3
LOW N/A Contact Form by WPForms < 1.8.1.3 - Reflected XSS wpscan
← Prev 1613 1614 1615 1616 1617 1618 1619 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top