πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,590
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 14, 2026
Last Updated

39,590 vulnerabilities found (page 221 of 1584)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
fe1c1834-eea2-4e02-8727-8db1fb3e96a2 HIGH 8.1 The Peter Mason theme for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.4.5. This … wordfence
fdfdaef2-c02a-4dc6-9ebd-2f35a11b9f97
< 1.7.3
HIGH 8.1 The CF7 WOW Styler plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.7.2. T… wordfence
fd74bcec-df6f-4f82-8f88-6cb1adde35ed
< 1.1.2
HIGH 8.1 The Automatic User Roles Switcher plugin for WordPress is vulnerable to authorization bypass due to missing authorizatio… wordfence
fd15268f-7e06-4e0d-baaf-f27348af61ce
< 2.4.9
HIGH 8.1 The Email Log plugin for WordPress is vulnerable to Unauthenticated Hook Injection in all versions up to, and including,… wordfence
fcc665d3-6d1c-466f-a8ee-df5c1e65590a HIGH 8.1 The Beacon theme for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 2.24. This makes … wordfence
fca24e26-149f-4805-9097-f7d11485a690
< 1.7.19
HIGH 8.1 The Contact Form by WD – responsive drag & drop contact form builder tool plugin for WordPress is vulnerable to author… wordfence
fc77c21e-2322-4f45-87b2-797b54b68489 HIGH 8.1 The Catamaran theme for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.15. This mak… wordfence
fc72f7ea-b7da-4433-a7f5-c2927a2733e0 HIGH 8.1 The Search & Go theme for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 2.8. This ma… wordfence
fc689622-50d6-47c4-a5f6-0314b1a207c9
< 1.7.3
HIGH 8.1 The Login Me Now plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 1.7.2. Th… wordfence
fc5670eb-4bc0-4cfa-826b-53eb9e207c9d HIGH 8.1 The Manoir theme for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.11. This makes … wordfence
fbe1a5b3-a8fc-490a-b402-3fc9a87e5823
< 2.3.78
HIGH 8.1 The Listivo Core plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 2.3.77. Th… wordfence
fbcd569d-f524-4012-add0-ba0afc19e47e
< 1.7.0
HIGH 8.1 The Patreon WordPress plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including,… wordfence
fbbc5c96-7b11-450f-b300-29a6bab9ad6e HIGH 8.1 The Moody theme for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 2.7.3. This makes … wordfence
fb167b30-bdb8-4a9b-90e4-5fb030be0cf1
< 1.4.5
HIGH 8.1 The Kunco theme for WordPress is vulnerable to Local File Inclusion in versions up to 1.4.5. This makes it possible for … wordfence
fae6e691-0d2a-4784-8ab1-4923d650a703
< 6.22.6
HIGH 8.1 The OAuth Single Sign On WordPress plugin before 6.22.6 doesn't validate that OAuth access token requests are legitimate… wordfence
fac1669b-4a86-4542-b34d-fea44127e41c HIGH 8.1 The Lorem Ipsum | Books & Media Store theme for WordPress is vulnerable to PHP Object Injection in versions up to, and i… wordfence
faa4fba5-cd19-4b96-aa09-07ed6d52a107
< 2.1.0
HIGH 8.1 The Quick Restaurant Menu plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions up to, and … wordfence
f9ba7e7e-f906-400c-8133-ccafd3987ca7 HIGH 8.1 The Hot Coffee theme for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 1.7 via deser… wordfence
f99a6b5c-e95d-49d0-a4b2-1d7188447da1 HIGH 8.1 The Astra Security Suite – Firewall & Malware Scan plugin for WordPress is vulnerable to arbitrary file uploads due to… wordfence
f8e1aca8-3d82-4b1a-98c8-29501a377846
< 7.2.5
HIGH 8.1 The Booster for WooCommerce plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type valida… wordfence
f8aa6410-afb7-44fe-9e4d-b357a15612f3 HIGH 8.1 The OnLeash theme for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.5.2. This make… wordfence
f8381b6c-46f4-4b9d-9975-c90310d066d7
< 2.7.3
HIGH 8.1 The option-tree plugin before 2.7.3 for WordPress has Object Injection because serialized classes are mishandled. wordfence
f8248098-dff2-4bac-a138-aa40c7ab7a1c
< 6.7.26
HIGH 8.1 The WCFM – Frontend Manager for WooCommerce along with Bookings Subscription Listings Compatible plugin for WordPress … wordfence
f7895360-67ed-47ee-8519-79dd92dc6cef HIGH 8.1 The MoveMe theme for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.2.15. This make… wordfence
f7751059-b709-4499-acd1-09c0956fd309 HIGH 8.1 The Wizor's theme for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 2.12. This makes… wordfence
← Prev 218 219 220 221 222 223 224 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top