ðŸ›¡ï¸ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,549
Total CVEs
66
CISA KEV (Actively Exploited)
Sep 2, 2026
Last Updated

40,549 vulnerabilities found (page 1622 of 1622)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
CVE-2015-9294
< 3.9.5
LOW N/A All In One WP Security And Firewall < 3.9.5 - XSS wpscan
CVE-2015-9293
< 3.9.8
LOW N/A All In One WP Security & Firewall <= 3.9.7 - Unauthenticated Cross-Site Scripting (XSS) wpscan
CVE-2015-2329
< 2.3.6
LOW N/A WooCommerce 2.3 - 2.3.5 - SQL Injection wpscan
CVE-2015-2292
< 1.7.4
LOW N/A Yoast SEO < 1.7.4 - Blind SQL Injection wpscan
CVE-2015-2220
< 2.8.9
LOW N/A Ninja Forms <= 2.8.8 - Stored & Reflected XSS wpscan
CVE-2015-2069
< 2.2.11
LOW N/A WooCommerce <= 2.2.10 - Cross-Site Scripting (XSS) wpscan
CVE-2015-0902
< 2.2.6
LOW N/A All in One SEO Pack < 2.2.6 - Information Disclosure wpscan
CVE-2015-0895
< 3.9.0
LOW N/A All In One WP Security & Firewall < 3.9.0 - CSRF wpscan
CVE-2015-0894
< 3.8.8
LOW N/A All In One WP Security & Firewall <= 3.8.7 - SQL Injection wpscan
CVE-2014-9688
< 2.8.10
LOW N/A Ninja Forms <= 2.8.9 - Unspecified Issue Affecting Admin Users wpscan
CVE-2014-9260
< 2.7.3
LOW N/A Download Manager <= 2.7.2 - Privilege Escalation wpscan
CVE-2014-8815
< 2.8.7
LOW N/A Ninja Forms 2.8.6 - Reflected Cross-Site Scripting (XSS) wpscan
CVE-2014-6313
< 2.2.3
LOW N/A WooCommerce <= 2.2.2 - Reflected Cross-Site Scripting (XSS) wpscan
CVE-2014-6242
< 3.8.3
LOW N/A All In One WP Security plugin 3.8.2 - 2xSQL Injections wpscan
CVE-2014-4932
< 5.1.5
LOW N/A Wordfence <= 5.1.4 - Cross-Site Scripting (XSS) wpscan
CVE-2014-4664
< 5.2.5
LOW N/A Wordfence <= 5.2.4 - Multiple Vulnerabilities (XSS & Bypasses) wpscan
CVE-2014-2265
< 3.7.2
LOW N/A Contact Form 7 <= 3.7.1 - CAPTCHA Bypass wpscan
CVE-2014-10378
< 2.6
LOW N/A Duplicate Post 2.5 - duplicate-post-admin.php User Login Cookie Value SQL Injection wpscan
CVE-2014-0173
< 2.9.3
LOW N/A Jetpack <= 2.9.2 - class.jetpack.php XML-RPC Access Control Bypass wpscan
CVE-2013-7319
< 2.5.9
LOW N/A Download Manager <= 2.5.8 - Download Package file Parameter Stored XSS wpscan
CVE-2013-5988
< 2.0.3.1
LOW N/A All in One SEO Pack <= 2.0.3 - XSS wpscan
CVE-2013-2011
< 1.3.2
LOW N/A WP-Super-Cache 1.3 - Remote Code Execution wpscan
CVE-2013-2008
< 1.3.1
LOW N/A WP Super Cache 1.3 - trunk/plugins/awaitingmoderation.php URI XSS wpscan
CVE-2012-6692
< 2.2
LOW N/A Yoast SEO < 2.2 - Authenticated Stored DOM XSS wpscan
← Prev 1619 1620 1621 1622

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top