πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,590
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 14, 2026
Last Updated

39,590 vulnerabilities found (page 222 of 1584)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
f76adafd-1218-4e80-af63-8d2bfb0aa5d1 HIGH 8.1 The Samex - Clean, Minimal Shop WooCommerce WordPress Theme theme for WordPress is vulnerable to Local File Inclusion in… wordfence
f757cea8-9133-410a-92d7-960490b018e9 HIGH 8.1 The Aviation Weather from NOAA plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file pa… wordfence
f6b18abe-28dd-420d-b570-fc001e4b5cd3
< 1.4
HIGH 8.1 The Askka - Candle Shop WordPress Theme theme for WordPress is vulnerable to PHP Object Injection in versions up to, and… wordfence
f67d93a7-a76c-476b-abba-e415ab4c6a52
< 1.2.12.1
HIGH 8.1 The Mr. Murphy - Custom Dress Tailoring Clothing WordPress Theme theme for WordPress is vulnerable to PHP Object Injecti… wordfence
f677b257-606a-45f2-ba85-3a56b8df2a3c
< 200.3.10
HIGH 8.1 The miniOrange Social Login and Register (Discord, Google, Twitter, LinkedIn) Pro Addon plugin for WordPress is vulnerab… wordfence
f627e9a4-378f-4c05-bd6e-bc0c4523df89
< 30.1
HIGH 8.1 The Hostiko - Hosting WordPress & WHMCS Theme theme for WordPress is vulnerable to Local File Inclusion in all versions … wordfence
f616be03-229b-4c50-b837-508da4d2b090
< 2.12.1
HIGH 8.1 The ZoxPress - The All-In-One WordPress News Theme theme for WordPress is vulnerable to unauthorized modification of dat… wordfence
f6047ae6-b1b4-4b31-aa12-560927e1040b
< 1.0.23
HIGH 8.1 The Build App Online plugin for WordPress is vulnerable to account takeover due to a weak password reset mechanism in al… wordfence
f5c07162-e970-4fbc-b97f-61c535ea696c
< 1.7.7
HIGH 8.1 The PrintXtore theme for WordPress is vulnerable to Local File Inclusion in versions up to, and excluding, 1.7.7. This m… wordfence
f5b17c94-995a-458a-b712-3388a7144e14 HIGH 8.1 The Redy theme for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.0.2. This makes i… wordfence
f5492bff-cfd9-41ed-a59b-4445d5e83e86 HIGH 8.1 The WP Quick FrontEnd Editor plugin for WordPress is vulnerable to page content injection in versions up to, and includi… wordfence
f53875aa-9347-464c-aaeb-e8248628fca2
< 5.5
HIGH 8.1 The miniOrange's Google Authenticator WordPress plugin before 5.5 does not have proper authorisation and CSRF checks whe… wordfence
f4d347bd-b23e-4445-957a-3b66740bcfc0
< 2.0.6
HIGH 8.1 The WooCommerce Product Filters plugin for WordPress is vulnerable to PHP Object Injection in versions 2.0.0 through 2.0… wordfence
f4c85fa1-ee4f-4f77-86a4-b0859a40162d HIGH 8.1 The Helvig theme for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.0. This makes i… wordfence
f4a46dcb-ee62-4c18-a1d9-d56be7a7ca69 HIGH 8.1 The Spin - Cricket Team Sports WordPress Theme + AI theme for WordPress is vulnerable to Local File Inclusion in version… wordfence
f4723aef-f248-47aa-b53b-ed1ab189bf2c
< 1.6.5
HIGH 8.1 The Cryptocurrency Widgets For Elementor plugin for WordPress is vulnerable to Local File Inclusion in all versions up t… wordfence
f4556e6e-45e7-4d79-8cea-0de1ede7306d HIGH 8.1 Several themes for WordPress by Themeton are vulnerable to PHP Object Injection in versions up to, and including, 1.6.5 … wordfence
f44d7a90-330f-42fb-a4f3-427e60ed7af8
< 3.4.2
HIGH 8.1 The Print My Blog WordPress Plugin before 3.4.2 does not enforce nonce (CSRF) checks, which allows attackers to make log… wordfence
f41d71a5-b603-40d4-b250-56db0f298778 HIGH 8.1 The EcoBlue theme for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.15. This makes… wordfence
f3db30b6-e361-4504-978b-d04e4bf67979 HIGH 8.1 The Isida theme for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.4.2. This makes … wordfence
f3af6f70-aa7e-4f33-88c0-45befaab2b29
< 12.7.0
HIGH 8.1 The WP Review Slider Pro plugin for WordPress is vulnerable to Arbitrary File Deletion in versions up to and including 1… wordfence
f3a20047-a325-4d29-a848-7ffa525d0bad
< 1.9.1
HIGH 8.1 The SureMail – SMTP and Email Logs Plugin for WordPress is vulnerable to Unrestricted Upload of File with Dangerous Ty… wordfence
f37852ae-a190-43f2-8f67-256a3f2dba26
< 1.0.14
HIGH 8.1 The Premmerce User Roles plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.… wordfence
f374db6e-4df6-47c1-9ae2-3ec9c134a1d4 HIGH 8.1 The 777 theme for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 1.13.0 via deseriali… wordfence
f32cd8e4-51bf-4fdf-ae14-155f8661dbdb
< 6.1.5
HIGH 8.1 The Awesome Support – WordPress HelpDesk & Support Plugin plugin for WordPress is vulnerable to arbitrary file deletio… wordfence
← Prev 219 220 221 222 223 224 225 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top