🛡️ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,590
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 14, 2026
Last Updated

39,590 vulnerabilities found (page 225 of 1584)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
eb794a38-b35b-403a-8a08-37c3ac76a669 HIGH 8.1 The Gioia theme for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.4. This makes it… wordfence
eb3c0108-dfb6-4786-af04-9d54cb22c74c
< 3.3.6
HIGH 8.1 The Support Board WordPress plugin before 3.3.6 does not have any CSRF checks in actions handled by the include/ajax.php… wordfence
eb1a2611-5cab-4940-ae9c-77a172fdbef7 HIGH 8.1 The Militarology theme for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.0.15. Thi… wordfence
eb0d3b72-2ea6-48ce-b474-0253c7bb5413 HIGH 8.1 The Bassein theme for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.0.15. This mak… wordfence
eae61f87-a624-452a-8fb7-5a0ed9e83799
< 5.4.0
HIGH 8.1 The SlimStat Analytics plugin for WordPress is vulnerable to PHP Object Injection in all versions up to 5.4.0 (exclusive… wordfence
eac56190-4f81-464d-9737-ae2e3d4b0d0d HIGH 8.1 The Cool Tag Cloud plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'cool_tag_cloud' s… wordfence
eaa59ec3-1c53-4e9c-acff-7921fca7cf3c HIGH 8.1 The Barberry theme for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 2.9.9.87. This … wordfence
ea5533ab-068a-4a94-bf0a-fc15fcfb383b
< 3.15.5
HIGH 8.1 The Avada (Fusion) Builder plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path v… wordfence
ea4a207e-bbe0-4974-a414-248d29c8fdf3
< 1.5
HIGH 8.1 The Esmée theme for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 1.4 via deseriali… wordfence
ea3ae3b3-216c-47d4-b5f2-07e612443955 HIGH 8.1 The Quanzo - Creative Portfolio Template Kit theme for WordPress is vulnerable to Local File Inclusion in versions up to… wordfence
ea399af7-f542-4209-aacc-3f469c844931 HIGH 8.1 The Sound | Musical Instruments Online Store WordPress Theme theme for WordPress is vulnerable to PHP Object Injection i… wordfence
e9fdc833-8384-42c0-ad9b-72e5b6351964
< 3.25.1
HIGH 8.1 The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to privilege escalation in all versions up to, and i… wordfence
e9f73654-2e5a-4762-8cac-613e24d3216a
< 2.9.42.1
HIGH 8.1 The Ninja Forms plugin before 2.9.42.1 for WordPress allows remote attackers to conduct PHP object injection attacks via… wordfence
e97d1928-3aaf-4dfe-8b17-e85bed5c937f HIGH 8.1 The Snowy theme for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.13. This makes i… wordfence
e970da7d-1bdb-4209-af1e-b72fb2ca8d30 HIGH 8.1 The URL Shortener plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 3.0.7 via… wordfence
e95cedaf-ebdc-450c-9962-28923507d1d5 HIGH 8.1 The Morning Records - Music Sound Studio WordPress Theme theme for WordPress is vulnerable to PHP Object Injection in ve… wordfence
e91f43b9-bbe1-4f32-9e85-84b51bd1a519
< 3.0.8
HIGH 8.1 The JobSearch plugin for WordPress is vulnerable to PHP Object Injection in versions up to 3.0.8 via deserialization of … wordfence
e898b0ec-6180-485f-aa01-29c243681ebf HIGH 8.1 The Chroma theme for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.11. This makes … wordfence
e868661c-987b-434f-a7a6-f37dd9ddccdb HIGH 8.1 The Organic Beauty theme for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 1.4.6 via… wordfence
e7e9cb89-6ed0-4096-82eb-b6f948d3bfd4 HIGH 8.1 The HeartStar theme for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.0.14. This m… wordfence
e7bcc4cc-58e9-41b6-9283-5723e58ab039 HIGH 8.1 The Eros theme for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.3. This makes it … wordfence
e7a2fd76-d760-4324-bbc3-7867bb9770b5 HIGH 8.1 The Printy theme for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.8. This makes i… wordfence
e791a7fc-d5b4-403c-a0e2-2300d9a102b0 HIGH 8.1 The Accalia | Dermatology Clinic & Cosmetology WordPress Theme + Elementor theme for WordPress is vulnerable to PHP Obje… wordfence
e7837208-97e3-45f9-8f9f-b1906a4fcbcc
< 3.5.0
HIGH 8.1 The kama-clic-counter plugin 3.4.9 for WordPress has SQL injection via the admin.php order parameter. wordfence
e6fb9558-06e5-4297-93df-ee9a6971f0ec
< 2.8.5
HIGH 8.1 The Page View Count plugin for WordPress is vulnerable to unauthorized modification of data that can lead to a denial of… wordfence
← Prev 222 223 224 225 226 227 228 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top