πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,590
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 14, 2026
Last Updated

39,590 vulnerabilities found (page 223 of 1584)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
f321b8f6-0712-4932-b861-b208debb368f
< 1.8.7
HIGH 8.1 The VaultPress plugin for WordPress is vulnerable to Remote Code Execution in versions up to, and including, 1.8.6 via t… wordfence
f2a98c03-6660-4997-b60f-6b95e6ffe57b
< 1.1.5
HIGH 8.1 The WP Zendesk for Contact Form 7, WPForms, Elementor, Formidable and Ninja Forms plugin for WordPress is vulnerable to … wordfence
f27d2dc9-c26e-4cb9-999f-da6359881867
< 2025.1.1
HIGH 8.1 The WP REST Cache plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 2025.1.0.… wordfence
f23d0089-b216-4d02-af23-e06262b44004 HIGH 8.1 The Barista theme for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 2.5.1. This make… wordfence
f1eacb72-df11-4a3b-9064-f8f776f3522b HIGH 8.1 The Login with NEAR plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 0.… wordfence
f1e31357-7fbc-414b-a4f4-53fa5f2fc715 HIGH 8.1 The User Email Verification for WooCommerce plugin for WordPress is vulnerable to authentication bypass via authenticate… wordfence
f1b9725b-dee5-44ca-bb33-c6812fb76adc
< 28.1.6
HIGH 8.1 The Contest Gallery plugin for WordPress is vulnerable to an authentication bypass leading to admin account takeover in … wordfence
f1b7768a-9204-429d-a4d2-db9f240e92a4
< 2.9.17
HIGH 8.1 The WP User Manager – User Profile Builder & Membership plugin for WordPress is vulnerable to arbitrary file deletion … wordfence
f16eea85-fa55-46b4-85a8-e441a119a569 HIGH 8.1 The Gunslinger theme for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.7. This mak… wordfence
f15f29e6-ecb7-403c-881f-f4dfdd7b8a84
< 2.4.22
HIGH 8.1 The EmallShop theme for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 2.4.21 via des… wordfence
f12936a0-26c3-459b-8c81-fba40186cbd7 HIGH 8.1 The Progress theme for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.2. This makes… wordfence
f0c69764-d64b-4231-8251-2f289dce69e1
< 1.1.9
HIGH 8.1 The VintWood theme for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.1.8. This mak… wordfence
f0a0ed90-a20e-40c6-b128-d46e6e9a0131
< 1.8.6
HIGH 8.1 The Ireca theme for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.8.5. This makes … wordfence
f0638310-7ea0-4f3a-8fda-c83360747926
< 2.1
HIGH 8.1 The PatioTime theme for WordPress is vulnerable to PHP Object Injection in versions up to 2.1 via deserialization of unt… wordfence
f048b2ca-bd20-4af7-8f44-a5c9cbca95ed HIGH 8.1 The VideoPro theme for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 2.3.8.1. This m… wordfence
f03732fa-ce5d-4e5f-b39a-c556ed1f16a8 HIGH 8.1 The Hyori theme for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.3.6. This makes … wordfence
f035edda-69ca-46ae-98f8-2a84ce682d1f HIGH 8.1 The Photocart Link plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.6. Thi… wordfence
f026d837-7c1c-4468-be3f-7728a644af59 HIGH 8.1 The Dentario theme for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 1.5 via deseria… wordfence
efd279c2-9e95-45bd-9494-fb53a6333c65
< 4.7.8
HIGH 8.1 The Jupiter X Core plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 4.7… wordfence
efd27466-f68e-4d8a-a1ec-90dbb6ff126b
< 2.7.4
HIGH 8.1 The WP Abstracts plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, … wordfence
efa65940-1a46-4a91-be8f-689d2addeabd HIGH 8.1 The Dixon theme for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.4.2.1. This make… wordfence
efa4c442-0281-4f7e-a43e-0191cb31c3a4 HIGH 8.1 The Simple Retail Menus plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 4.2… wordfence
ef9ad6b4-40f0-40ce-9f17-37077cb1a5ca HIGH 8.1 The CoSchool LMS – A complete Learning Management System to Create and Sell Your Courses Online plugin for WordPress i… wordfence
ef9a6ef5-368e-40df-9a17-2779e453dfcc
< 2.7.8
HIGH 8.1 The Autoptimize WordPress plugin before 2.7.8 attempts to remove potential malicious files from the extracted archive up… wordfence
ef5a0b2d-8ee7-4d4e-b126-00ea11e81ddb
< 2.4.6
HIGH 8.1 The Atomlab theme for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 2.4.5. This make… wordfence
← Prev 220 221 222 223 224 225 226 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top