ðŸ›¡ï¸ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,549
Total CVEs
66
CISA KEV (Actively Exploited)
Sep 2, 2026
Last Updated

40,549 vulnerabilities found (page 1619 of 1622)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
CVE-2020-8594
< 3.4.23
LOW N/A Ninja Forms < 3.4.23 - CSRF to Stored Cross-Site Scripting (XSS) wpscan
CVE-2020-8426
< 2.8.5
LOW N/A Elementor Page Builder < 2.8.5 - Authenticated Reflected XSS wpscan
CVE-2020-7109
< 2.8.4
LOW N/A Elementor Page Builder < 2.8.4 - Cross-Site Scripting (XSS) wpscan
CVE-2020-7055
< 2.7.5
LOW N/A Elementor < 2.7.5 - Authenticated Arbitrary File Upload wpscan
CVE-2020-36703
< 2.9.8
LOW N/A Elementor < 2.9.8 - SVG Sanitizer Bypass leading to Authenticated Stored XSS wpscan
CVE-2020-36175
< 3.4.27.1
LOW N/A Ninja Forms < 3.4.27.1 - Validation Bypass via Email Field wpscan
CVE-2020-36174
< 3.4.27.1
LOW N/A Ninja Forms < 3.4.27.1 - CSRF leading to Arbitrary Plugin Installation wpscan
CVE-2020-36173
< 3.4.28
LOW N/A Ninja Forms < 3.4.28 - Stored Cross-Site Scripting wpscan
CVE-2020-36172
< 5.8.12
LOW N/A Advanced Custom Fields < 5.8.12 - Cross-Site Scripting in Select2 dropdowns wpscan
CVE-2020-36171
< 3.0.14
LOW N/A Elementor < 3.0.14 - SVG Upload Allowed by Default wpscan
CVE-2020-35946
< 3.6.2
LOW N/A All in One SEO Pack < 3.6.2 - Authenticated Stored Cross-Site Scripting wpscan
CVE-2020-35489
< 5.3.2
LOW N/A Contact Form 7 < 5.3.2 - Unrestricted File Upload wpscan
CVE-2020-29172
< 3.6.1
LOW N/A LiteSpeed Cache < 3.6.1 - Authenticated Stored Cross-Site Scripting wpscan
CVE-2020-29171
< 4.4.6
LOW N/A All In One WP Security & Firewall < 4.4.6 - Authenticated Cross-Site Scripting (XSS) wpscan
CVE-2020-29156
< 4.7.0
LOW N/A WooCommerce < 4.7.0 - Arbitrary Order Status Disclosure via IDOR wpscan
CVE-2020-27615
< 1.6.4
LOW N/A Loginizer < 1.6.4 - Unauthenticated SQL Injection wpscan
CVE-2020-25213
< 6.9
LOW N/A File Manager 6.0-6.9 - Unauthenticated Arbitrary File Upload leading to RCE wpscan
CVE-2020-24312
< 6.5
LOW N/A File Manager < 6.5 - Backup File Directory Listing wpscan
CVE-2020-20634
< 2.9.6
LOW N/A Elementor Page Builder < 2.9.6 - Authenticated Safe Mode Privilege Escalation wpscan
CVE-2020-15020
< 2.9.14
LOW N/A Elementor < 2.9.14 - Authenticated Stored Cross-Site Scripting wpscan
CVE-2020-13864
< 2.9.10
LOW N/A Elementor Page Builder < 2.9.10 - Authenticated Stored XSS wpscan
CVE-2020-12462
< 3.4.24.2
LOW N/A Ninja Forms < 3.4.24.2 - CSRF to Stored XSS wpscan
CVE-2020-11515
< 1.0.41
LOW N/A WordPress SEO Plugin - Rank Math < 1.0.41 - Redirect Creation via Unprotected REST API Endpoint wpscan
CVE-2020-11514
< 1.0.41
LOW N/A WordPress SEO Plugin - Rank Math < 1.0.41 - Privilege Escalation via Unprotected REST API Endpoint wpscan
CVE-2020-10385
< 1.5.9
LOW N/A Contact Form by WPForms < 1.5.9 - Authenticated Cross-Site Scripting (XSS) wpscan
← Prev 1616 1617 1618 1619 1620 1621 1622 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top