πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,590
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 14, 2026
Last Updated

39,590 vulnerabilities found (page 228 of 1584)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
dc82bfca-75de-4c77-a0ac-b34525b29a8d HIGH 8.1 Multiple themes for WordPress by axiomthemes, ThemeRex, and AncoraThemes are vulnerable to Local File Inclusion in vario… wordfence
dc684b36-d054-4933-bb0f-f49ae27b000f
< 4.0.8
HIGH 8.1 The Houzez theme for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 4.0.4. This makes… wordfence
dc3e3d47-cae3-46a6-9b60-ad1eb6b7ced7
< 1.1.2
HIGH 8.1 The Employee, Leave and Recruitment Management System – Crew HRM plugin for WordPress is vulnerable to PHP Object Inje… wordfence
db96104a-fc97-4809-a1d5-5edb51a0dcdf HIGH 8.1 The Atlas theme for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 2.1.0. This makes … wordfence
db805bbb-ec5b-47a9-b010-561857141933 HIGH 8.1 The SevenHills theme for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 1.6.2 via des… wordfence
db6da907-4e5e-4b50-80ac-ada77c85e78e HIGH 8.1 The OchaHouse theme for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 2.2.8. This ma… wordfence
db24042e-c2f9-4437-8623-951b814e54b9
< 3.4.1
HIGH 8.1 The Solene theme for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 3.4. This makes i… wordfence
daded527-bf03-42d0-8e7a-f9eed492a609
< 1.4
HIGH 8.1 The Leroux - Business Consulting WordPress Theme theme for WordPress is vulnerable to PHP Object Injection in versions u… wordfence
dac2a6f0-54c1-4999-ba6a-e574ab23609a HIGH 8.1 The Prisma theme for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.10. This makes … wordfence
da575fd4-7e04-415b-a2fb-248b664bd619 HIGH 8.1 The Kayon theme for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.3. This makes it… wordfence
d9c51f6b-e3ce-4408-8fcb-a56c3b1eee04
< 6.0.13
HIGH 8.1 The Kirki – Freeform Page Builder, Website Builder & Customizer plugin for WordPress is vulnerable to PHP Object Injec… wordfence
d99bc021-ba9e-4294-8dd2-c25bc8007d05
< 5.1.3
HIGH 8.1 The User Registration & Membership plugin for WordPress is vulnerable to authentication bypass in versions up to, and in… wordfence
d9305e0d-195d-43ef-ab8a-c6cdf70aafad HIGH 8.1 The Alchemists theme for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 4.6.0. This m… wordfence
d926e4e1-6e48-427d-b814-1027f1b96d45 HIGH 8.1 The Lione theme for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.16. This makes i… wordfence
d8ee82cf-916c-41e9-82d2-f25cc7a632ae
< 2.0.6
HIGH 8.1 The PropertyHive plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 2.0.5 … wordfence
d8895dc9-5854-433d-801b-c8aebd6bc126
< 6.0.3
HIGH 8.1 The WP Ticket Customer Service Software & Support Ticket System plugin for WordPress is vulnerable to PHP Object Injecti… wordfence
d83cd6a0-d69c-4e6c-b76f-00c398b5f7e6
< 1.0.14
HIGH 8.1 The Blaze Demo Importer plugin for WordPress is vulnerable to unauthorized database resets and file deletion due to a mi… wordfence
d826fcda-5076-476c-950f-4d95c93311d4
< 2.5
HIGH 8.1 The Grevo theme for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 2.4. This makes it… wordfence
d8264557-30e2-4f9f-95db-7c135ff437ec HIGH 8.1 The Resurs theme for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.3. This makes i… wordfence
d81dd459-766f-4cb7-a7d2-da82a4ca9412 HIGH 8.1 The Lella theme for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.2. This makes it… wordfence
d7fd5efe-8b21-44e5-a09e-6f8b95b29835 HIGH 8.1 The Monyxi theme for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.1.8. This makes… wordfence
d7c0f21a-b04c-407e-9e8c-f81a146deaa8
< 1.4.4
HIGH 8.1 The Social Login, Passkeys, Magic Link & Email OTP – Passwordless Login by VentraConnect plugin for WordPress is vulne… wordfence
d776874c-d8ca-4d36-9e94-8bb95077d8f3
< 4.4.5
HIGH 8.1 The EduMall theme for WordPress is vulnerable to Local File Inclusion in versions up to 4.4.5. This makes it possible fo… wordfence
d76fa916-8abe-43ef-8104-f1e1ec2c0437
< 7.3.24
HIGH 8.1 The Paid Videochat Turnkey Site – HTML5 PPV Live Webcams plugin for WordPress is vulnerable to PHP Object Injection in… wordfence
d730645c-1bed-4d55-a192-e28e858a73b5
< 1.2.4
HIGH 8.1 The Cook&Meal theme for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.2.3. This ma… wordfence
← Prev 225 226 227 228 229 230 231 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top