πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,590
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 14, 2026
Last Updated

39,590 vulnerabilities found (page 229 of 1584)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
d6f9ed45-f3a0-468a-ad11-d6d8ecaf79fb HIGH 8.1 The White Rabbit theme for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 1.5.2 via d… wordfence
d6ec09e5-4994-4d23-bf8e-26b64d5303fa
< 7.3.1
HIGH 8.1 The Image Optimizer, Resizer and CDN – Sirv plugin for WordPress is vulnerable to unauthorized modification of data th… wordfence
d6e7b44c-fe94-493b-846b-57c40e00d8fe
< 5.16.0
HIGH 8.1 The Customer Reviews for WooCommerce plugin for WordPress is vulnerable to Directory Traversal in versions up to, and in… wordfence
d6da166e-10b4-4a4e-967c-6261d68144dc
< 1.1.5
HIGH 8.1 The WP Insightly for Contact Form 7, WPForms, Elementor, Formidable and Ninja Forms plugin for WordPress is vulnerable t… wordfence
d62b8380-1679-40d8-a77f-17c583e88d39
< 1.5.0
HIGH 8.1 The Search Analytics for WP plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and … wordfence
d5dc39fb-7f68-42f2-8540-b739c5075775 HIGH 8.1 The Edge Decor theme for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 2.2. This mak… wordfence
d5abb538-9e69-485e-9389-90a2422510ca
< 3.1.0
HIGH 8.1 The JupiterX theme for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 3.0.0 via the p… wordfence
d589bada-3568-45ed-9f7c-fb14363a617a
< 4.0.3
HIGH 8.1 Several MainWP extensions for WordPress are vulnerable to authorization bypass due to a missing capability check. This m… wordfence
d50e0b60-31b4-4633-899a-f400442992b5 HIGH 8.1 The Great Lotus | Buddhist Temple WordPress Theme + RTL theme for WordPress is vulnerable to Local File Inclusion in ver… wordfence
d4a5ec27-fe7e-411d-811c-e6b66dd7ba56 HIGH 8.1 The Deston theme for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.0. This makes i… wordfence
d472572a-5696-4020-bc06-88016e4b4afd HIGH 8.1 The FiveStar theme for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.7. This makes… wordfence
d44fe4d7-1af5-4e26-a33c-43a9cce4174c
< 17.1
HIGH 8.1 The Malcure Malware Scanner β€” #1 Toolset for WordPress Malware Removal plugin for WordPress is vulnerable to Arbitrary… wordfence
d4440a99-914d-4cbb-8b9f-9093a1ddd4ad
< 3.2.8.1
HIGH 8.1 The Travel Booking WordPress Theme theme for WordPress is vulnerable to PHP Object Injection in versions up to 3.2.8.1 v… wordfence
d400ee7d-d26e-43fa-988c-0d9448800ec6
< 5.10.5.2
HIGH 8.1 The TheGem Theme Elements (for WPBakery) plugin for WordPress is vulnerable to Local File Inclusion in versions up to, a… wordfence
d3eedeb8-6982-4af8-8377-7a9122f6b232 HIGH 8.1 The Tediss theme for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.2.4. This makes… wordfence
d3a04d92-1ce8-4405-9d26-0635384106b4
< 1.9.1
HIGH 8.1 The Innovio - Multipurpose Landing Page WordPress Theme theme for WordPress is vulnerable to Local File Inclusion in ver… wordfence
d3980ba8-e3f0-45f4-a2c3-c4a810e158ec
< 1.6.1
HIGH 8.1 The Aperitif theme for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 1.6 via deseria… wordfence
d3775d48-5985-475e-8fb9-c4c5fd044772
< 1.5
HIGH 8.1 The Login With OTP plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 1.4.2. … wordfence
d2e342d0-dd34-4ad6-8dd1-c86f677d2acb HIGH 8.1 The Chinchilla theme for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.16. This ma… wordfence
d2c9aff2-56c4-4287-bf49-681ae049e903 HIGH 8.1 The PJ | Life & Business Coaching theme for WordPress is vulnerable to Local File Inclusion in versions up to, and inclu… wordfence
d1e5157d-7e07-4dd7-9c41-9c8a11150745 HIGH 8.1 The Brook theme for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 2.9.0. This makes … wordfence
d19c0112-f205-4848-aa79-07b95c31a14c HIGH 8.1 The Planty theme for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.14.0. This make… wordfence
d174f856-d94a-42ed-b547-67699e175cd8
< 4.15.3
HIGH 8.1 The MStore API – Create Native Android & iOS Apps On The Cloud plugin for WordPress is vulnerable to authentication by… wordfence
d16a7408-9a13-4a8d-80a5-f510ba27e595 HIGH 8.1 The Mamita theme for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.0.9. This makes… wordfence
d1507a4c-8fe6-43f9-b750-2720dc301abd
< 2.3.4
HIGH 8.1 The Solene Core plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 2.3.2. This… wordfence
← Prev 226 227 228 229 230 231 232 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top