WordPress Vulnerability Database

Search All Vulnerabilities

Tip: You can search by CVE ID, software name or slug, or the researcher name. Expand to read about more advanced search options.

If you want to perform more advanced lookups, you can use keywords to further refine your search.

For example, woocommerce researcher:"chloe chamberland" would search for any vulnerabilities discovered by Chloe Chamberland in software that has WooCommerce in the title.

Keywords are added in keyword:value format. If the value contains spaces, you must enclose it in quotation marks.

You can use the following keywords to add criteria to your search:

title
Searches through the title of each vulnerability for matches.
date
Returns vulnerabilities by publication date. Use YYYY-MM-DD, YYYY-MM or YYYY format.
cvss-rating
Use low, medium, high or critical to limit the search to vulnerabilities with the specified rating.
researcher
Returns vulnerabilities credited to researchers containing the given text.
software
Returns vulnerabilities discovered in software containing the given text.
software-slug
Returns vulnerabilities discovered in software exactly matching the given slug.
software-type
Use plugin, theme or core to limit the search to the specified type of software.
By selecting “Search” you acknowledge that you have read and agree to the Wordfence Intelligence Terms and Conditions.

All Vulnerabilities

6.4
CVE ID Unknown
Feb 21, 2020
Researcher: khoabda
6.4
CVE ID Unknown
Jan 15, 2020
Researchers:
6.4
CVE ID Unknown
Jan 14, 2020
Researcher: RE-ALTER
Title CVE ID CVSS Researchers Date
Envira Photo Gallery <= 1.7.6 - Authenticated Stored Cross-Site Scripting CVE-2020-9334 6.4 Vishnupriya Ilango February 25, 2020
Chained Quiz <= 1.1.9 -Stored Cross-Site Scripting 6.4 khoabda February 21, 2020
Real Testimonials <= 2.1.6 - Authenticated Stored Cross-Site Scripting 6.4 Vishnupriya Ilango February 20, 2020
Modula Image Gallery <= 2.2.4 - Authenticated Stored Cross-Site Scripting CVE-2020-9003 6.4 Vishnupriya Ilango February 19, 2020
Contact Form by WPForms <= 1.5.8.2 - Stored Cross-Site Scripting CVE-2020-10385 6.4 Jinson Varghese Behanan February 18, 2020
GDPR Cookie Consent & Compliance Notice <= 1.8.2 - Authenticated Stored Cross-Site Scripting and Authorization Bypass CVE-2020-20633 6.4 Jerome Bruandet February 11, 2020
Ninja Forms Contact Form <= 3.4.22 - Stored Cross-Site Scripting CVE-2020-8594 6.4 Spider Sec Ltd February 3, 2020
GistPress < 3.0.2 - Cross-Site Scripting CVE-2020-8498 6.4 Paul Ritchie January 31, 2020
Elementor Website Builder <= 2.7.5 - Stored Cross-Site Scripting 6.4 Marc-Alexandre Montpas January 29, 2020
CarSpot – Dealership Wordpress Classified Theme <= 2.2.3 - Stored Cross-Site Scripting 6.4 RE-ALTER January 27, 2020
Contextual Adminbar Color <= 0.2 - Stored Cross-Site Scripting 6.4 Julio Potier January 17, 2020
Flamingo <= 2.1 - CSV Injection 6.4 January 15, 2020
Real Estate 7 WordPress < 2.9.5 - Multiple Vulnerabilities 6.4 RE-ALTER January 14, 2020
Contact Form Clean and Simple <= 4.7.0 - Authenticated Stored Cross-Site Scripting 6.4 Jeroen Mulder January 14, 2020
WP Accessibility < 1.7.0 - Authenticated Stored Cross-Site Scripting 6.4 Ananda Krishna December 26, 2019
Donorbox <= 7.1.1 - Authenticated Stored Cross-Site Scripting 6.4 Sybre Waaijer December 19, 2019
WordPress Core < 5.3.1 - Authenticated Stored Cross-Site Scripting CVE-2019-20041 6.4 WordPress.org Security Team December 13, 2019
WordPress Core < 5.3.1 - Authenticated Stored Cross-Site Scripting CVE-2019-20042 6.4 Simon Scannell December 13, 2019
Scoutnet Kalender <= 1.1.0 - Cross-Site Scripting CVE-2019-19198 6.4 Simon Moser December 10, 2019
About Author <= 1.3.9 - Authenticated Stored Cross-Site Scripting 6.4 Lucian Ioan Nitescu October 25, 2019

Researcher Hall of Fame (Past 30 days)

Did you know Wordfence Intelligence provides free personal and commercial API access to our comprehensive WordPress vulnerability database, along with a free webhook integration to stay on top of the latest vulnerabilities added and updated in the database? Get started today!

Learn more

Want to get notified of the latest vulnerabilities that may affect your WordPress site?
Install Wordfence on your site today to get notified immediately if your site is affected by a vulnerability that has been added to our database.

Get Wordfence

The Wordfence Intelligence WordPress vulnerability database is completely free to access and query via API. Please review the documentation on how to access and consume the vulnerability data via API.

Documentation