πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,590
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 14, 2026
Last Updated

39,590 vulnerabilities found (page 224 of 1584)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
ef3f0b0d-e342-44c9-81bd-a7582802e8c7 HIGH 8.1 The Solaris theme for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 2.5 via deserial… wordfence
ef268946-853f-4bcf-874e-6a5aa344d57e
< 10.1.1.2
HIGH 8.1 The PixelYourSite – Your smart PIXEL (TAG) & API Manager plugin for WordPress is vulnerable to PHP Object Injection in… wordfence
ef267623-ba9a-4eb2-8521-9256350076a2 HIGH 8.1 The M.Williamson theme for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.2.11. Thi… wordfence
eedbb054-5ae0-4e7c-880e-fdc1559032e3
< 1.4
HIGH 8.1 The LuxeDrive theme for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.0. This make… wordfence
eec46e0b-806a-4c34-adb8-a2bdb08a7a93 HIGH 8.1 The Classter theme for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 2.5 via deseria… wordfence
eeb71c31-9e56-4b58-9cfc-a97f6892cc2b
< 4.1.4
HIGH 8.1 The WP User Frontend Pro plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path val… wordfence
eead8dd1-57e5-4a1d-b555-c1efd2087757 HIGH 8.1 The Playful theme for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.19.0. This mak… wordfence
eead3429-f913-4047-bb56-32b2a12f2f12 HIGH 8.1 The Tails theme for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.4.12. This makes… wordfence
ee5df5fe-4213-4d36-aa8f-7eb2710c32b6
< 3.7.0
HIGH 8.1 The Click Mag - Viral WordPress News Magazine/Blog Theme theme for WordPress is vulnerable to unauthorized modification … wordfence
ee41c75d-3a4f-463d-a70e-323c903c6e08 HIGH 8.1 The Gracioza theme for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.0.15. This ma… wordfence
ee2902be-a9a5-4f9b-a112-e786a46331f7 HIGH 8.1 The Humanum theme for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.1.4. This make… wordfence
ed757ddf-cd02-41a0-9d2b-7c03af7a4497 HIGH 8.1 The Plugin Central plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including… wordfence
ed5f2c6d-a548-44c1-a07a-e33999bb164d
< 3.4.4
HIGH 8.1 The Privacy Policy Generator, Terms & Conditions Generator WordPress Plugin : WP Legal Pages plugin for WordPress is vul… wordfence
ed581d7d-ef03-4d15-81ed-8d6215397c22 HIGH 8.1 The Yokoo theme for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.1.11. This makes… wordfence
ed06ab6d-cd88-40ce-a21d-afdb12821c29 HIGH 8.1 The Lingvico theme for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.0.14. This ma… wordfence
ed03bfca-4044-4815-835b-d90bc7b77b89 HIGH 8.1 The Fermentio β€” Brewery and Winemaking Restaurant WordPress Theme theme for WordPress is vulnerable to Local File Incl… wordfence
ece2fb02-0b65-4a03-806e-4ef6abd19bae HIGH 8.1 The FixTeam | Electronics & Mobile Devices Repair WordPress Theme theme for WordPress is vulnerable to Local File Inclus… wordfence
ecc0f60f-d63b-498c-ab00-47551c62c89e HIGH 8.1 The Mixtape theme for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 2.1. This makes … wordfence
ecbbe9f0-bf6c-4153-9843-8ae7713adef9
< 3.1.16
HIGH 8.1 The Nested Pages WordPress plugin <= 3.1.15 was vulnerable to Cross-Site Request Forgery via the `npBulkAction`s and `np… wordfence
ec7fa746-6df0-4bb4-9dff-1aeda2c53196 HIGH 8.1 The Police Department theme for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 2.17. … wordfence
ec29bc37-db27-4bf3-b55f-15c4a7274acd
< 2.7.0
HIGH 8.1 The option-tree plugin before 2.7.0 for WordPress has Object Injection by leveraging a valid nonce. wordfence
ec017311-f150-4a14-a4b4-b5634f574e2b
< 1.0.79
HIGH 8.1 The SureTriggers: All-in-One Automation Platform plugin for WordPress is vulnerable to an authentication bypass leading … wordfence
ebd358b6-ad81-4808-a627-11d519e76510
< 1.6
HIGH 8.1 The EasyMeals theme for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 1.5.1 via dese… wordfence
ebae4b18-5b5f-45c3-86e2-02eefd7abdb7
< 2.7.5
HIGH 8.1 The Customer Email Verification for WooCommerce plugin for WordPress is vulnerable to Email Verification and Authenticat… wordfence
eb8a673e-a192-41d4-b53b-7d786887242d
< 3.6.14
HIGH 8.1 The TinyPNG – JPEG, PNG & WebP image compression plugin for WordPress is vulnerable to arbitrary file deletion due to … wordfence
← Prev 221 222 223 224 225 226 227 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top