ðŸ›¡ï¸ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,549
Total CVEs
66
CISA KEV (Actively Exploited)
Sep 2, 2026
Last Updated

40,549 vulnerabilities found (page 1618 of 1622)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
CVE-2021-24255
< 4.5.4
LOW N/A Essential Addons for Elementor < 4.5.4 - Contributor+ Stored Cross-Site Scripting (XSS) wpscan
CVE-2021-24242
< 1.8.8
LOW N/A Tutor LMS < 1.8.8 - Authenticated Local File Inclusion wpscan
CVE-2021-24216
< 7.41
LOW N/A All-in-One WP Migration < 7.41 - Admin+ Arbitrary File Upload to RCE wpscan
CVE-2021-24209
< 1.7.2
LOW N/A WP Super Cache < 1.7.2 - Authenticated Remote Code Execution (RCE) wpscan
CVE-2021-24206
< 3.1.4
LOW N/A Elementor < 3.1.4 - Authenticated Stored Cross-Site Scripting (XSS) in Image Box Widget wpscan
CVE-2021-24205
< 3.1.4
LOW N/A Elementor < 3.1.4 - Authenticated Stored Cross-Site Scripting (XSS) in Icon Box Widget wpscan
CVE-2021-24204
< 3.1.4
LOW N/A Elementor < 3.1.4 - Authenticated Stored Cross-Site Scripting (XSS) in Accordion Widget wpscan
CVE-2021-24203
< 3.1.4
LOW N/A Elementor < 3.1.4 - Authenticated Stored Cross-Site Scripting (XSS) in Divider Widget wpscan
CVE-2021-24202
< 3.1.4
LOW N/A Elementor < 3.1.4 - Authenticated Stored Cross-Site Scripting (XSS) in Heading Widget wpscan
CVE-2021-24201
< 3.1.4
LOW N/A Elementor < 3.1.4 - Authenticated Stored Cross-Site Scripting (XSS) in Column Element wpscan
CVE-2021-24186
< 1.8.3
LOW N/A Tutor LMS < 1.8.3 - SQL Injection via tutor_answering_quiz_question/get_answer_by_id wpscan
CVE-2021-24185
< 1.7.7
LOW N/A Tutor LMS < 1.7.7 - SQL Injection via tutor_place_rating wpscan
CVE-2021-24184
< 1.7.7
LOW N/A Tutor LMS < 1.7.7 - Unprotected AJAX including Privilege Escalation wpscan
CVE-2021-24183
< 1.8.3
LOW N/A Tutor LMS < 1.8.3 - SQL Injection via tutor_quiz_builder_get_question_form wpscan
CVE-2021-24182
< 1.8.3
LOW N/A Tutor LMS < 1.8.3 - SQL Injection via tutor_quiz_builder_get_answers_by_question wpscan
CVE-2021-24181
< 1.7.7
LOW N/A Tutor LMS < 1.7.7 - SQL Injection via tutor_mark_answer_as_correct wpscan
CVE-2021-24177
< 7.1
LOW N/A WP File Manager < 7.1 - Reflected Cross-Site Scripting (XSS) wpscan
CVE-2021-24166
< 3.4.34
LOW N/A Ninja Forms < 3.4.34 - CSRF to OAuth Service Disconnection wpscan
CVE-2021-24165
< 3.4.34
LOW N/A Ninja Forms < 3.4.34 - Administrator Open Redirect wpscan
CVE-2021-24164
< 3.4.34.1
LOW N/A Ninja Forms < 3.4.34.1 - Authenticated OAuth Connection Key Disclosure wpscan
CVE-2021-24163
< 3.4.34
LOW N/A Ninja Forms < 3.4.34 - Authenticated SendWP Plugin Installation and Client Secret Key Disclosure wpscan
CVE-2021-24153
< 3.4.1
LOW N/A Yoast SEO < 3.4.1 - Authenticated Stored Cross-Site Scripting (XSS) wpscan
CVE-2021-20865
< 5.11
LOW N/A Advanced Custom Fields < 5.11 - Subscriber+ Arbitrary ACF Data/Field Groups View and Fields Move wpscan
CVE-2020-8934
< 1.8.0
LOW N/A Site Kit by Google < 1.8.0 - Privilege Escalation to gain Search Console Access wpscan
CVE-2020-8615
< 1.5.3
LOW N/A Tutor LMS < 1.5.3 - Cross-Site Request Forgery (CSRF) wpscan
← Prev 1615 1616 1617 1618 1619 1620 1621 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top