ðŸ›¡ï¸ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,549
Total CVEs
66
CISA KEV (Actively Exploited)
Sep 2, 2026
Last Updated

40,549 vulnerabilities found (page 1621 of 1622)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
CVE-2017-18596
< 1.8.0
LOW N/A Elementor Page Builder < 1.8.0 - Authenticated Unrestricted Editing wpscan
CVE-2017-18593
< 1.13.5
LOW N/A Updraftplus < 1.13.5 - XSS wpscan
CVE-2017-18577
< 4.1.8
LOW N/A Mailchimp For WP < 4.1.8 - XSS wpscan
CVE-2017-18574
< 3.0.31
LOW N/A Ninja Forms < 3.0.31 - XSS wpscan
CVE-2017-18499
< 3.5.7
LOW N/A Simple Membership < 3.5.7 - XSS wpscan
CVE-2017-18356
< 3.2.4
LOW N/A WooCommerce <= 3.2.3 - Authenticated PHP Object Injection wpscan
CVE-2017-18032
< 2.9.52
LOW N/A Download Manager <= 2.9.51 - Authenticated Reflected Cross-Site Scripting (XSS) wpscan
CVE-2017-16842
< 5.8
LOW N/A Yoast SEO < 5.8 - Authenticated Cross-Site Scripting (XSS) wpscan
CVE-2017-12651
< 1.3.6
LOW N/A Loginizer <= 1.3.5 - Cross-Site Request Forgery (CSRF) wpscan
CVE-2017-12650
< 1.3.6
LOW N/A Loginizer <= 1.3.5 - Blind SQL Injection wpscan
CVE-2016-1209
< 2.9.43
LOW N/A Ninja Forms 2.9.36 to 2.9.42 - Multiple Vulnerabilities wpscan
CVE-2016-10888
< 4.0.7
LOW N/A All In One WP Security And Firewall < 4.0.7 - Multiple SQL Injections wpscan
CVE-2016-10887
< 4.0.9
LOW N/A All In One WP Security And Firewall < 4.0.9 - Multiple SQL Injections wpscan
CVE-2016-10884
< 3.3.3
LOW N/A Simple Membership < 3.3.3 - Multiple CSRF wpscan
CVE-2016-10871
< 4.0.11
LOW N/A MailChimp for WordPress <= 4.0.10 - Authenticated Cross-Site Scripting (XSS) wpscan
CVE-2016-10868
< 4.0.5
LOW N/A All In One WP Security And Firewall < 4.0.5 - XSS wpscan
CVE-2016-10867
< 4.0.6
LOW N/A All In One WP Security And Firewall < 4.0.6 - XSS wpscan
CVE-2016-10866
< 4.2.0
LOW N/A All In One WP Security & Firewall 4.1.4-4.1.9 - Authenticated Cross-Site Scripting (XSS) wpscan
CVE-2016-10706
< 4.0.3
LOW N/A Jetpack 2.0-4.0.2 - Shortcode Stored Cross-Site Scripting (XSS) wpscan
CVE-2016-10705
< 4.0.4
LOW N/A Jetpack <= 4.0.3 - Multiple Vulnerabilities wpscan
CVE-2016-10112
< 2.6.9
LOW N/A WooCommerce <= 2.6.8 - Authenticated Tax-Rate CSV XSS wpscan
CVE-2015-9360
< 1.9.64
LOW N/A Updraftplus < 1.9.64 - XSS wpscan
CVE-2015-9359
< 3.4.3
LOW N/A Jetpack 3.0-3.4.2 - Cross-Site Scripting (XSS) wpscan
CVE-2015-9357
< 3.1.5
LOW N/A Akismet 2.5.0-3.1.4 - Unauthenticated Stored Cross-Site Scripting (XSS) wpscan
CVE-2015-9310
< 3.9.1
LOW N/A All In One WP Security & Firewall <= 3.9.0 - Blind SQL Injection wpscan
← Prev 1618 1619 1620 1621 1622 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top