πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,590
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 14, 2026
Last Updated

39,590 vulnerabilities found (page 233 of 1584)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
c172ab2b-ce1f-4a0d-b31f-b75ff2f03506
< 2.6.0
HIGH 8.1 The Perfmatters plugin for WordPress is vulnerable to arbitrary file overwrite via path traversal in all versions up to,… wordfence
c1204614-395a-4226-9d45-c334eaba090d
< 10.8.10.2
HIGH 8.1 The Thrive Apprentice plugin for WordPress is vulnerable to PHP Object Injection in versions up to 10.8.10.2 via deseria… wordfence
c1010470-63d4-49c5-9811-0e86fbeb57d5 HIGH 8.1 The Tiny Bootstrap Elements Light plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and … wordfence
c0c3d504-8e45-42e8-a6e1-27848c347dae HIGH 8.1 The Bazinga theme for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.1.9. This make… wordfence
c0680c2e-5983-4866-ad53-b35bed384d00 HIGH 8.1 The UNIVERSAM plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 8.72.34 via d… wordfence
bfc7c214-8d76-453c-a05d-682aa425b06e
< 2.1.0
HIGH 8.1 The Quick Restaurant Menu plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and includ… wordfence
bfc01e65-fbfa-4639-93e6-7b045b0e2ec4
< 2.0.3
HIGH 8.1 The UPC/EAN/GTIN Code Generator plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file p… wordfence
bf37762d-d7b0-4241-9ed1-f969042d7452
< 3.10.0
HIGH 8.1 The TinySalt theme for WordPress is vulnerable to Local File Inclusion in versions up to 3.10.0. This makes it possible … wordfence
bef61f05-a2dc-4f61-a5da-7161a9912196
< 6.2.4
HIGH 8.1 The LoginPress Pro plugin for WordPress is vulnerable to authentication bypass in versions up to and including 6.2.3 via… wordfence
bed8347e-9d89-4484-ae2a-a949feee552e HIGH 8.1 The Conquerors | American Football & NFL PSD Template theme for WordPress is vulnerable to Local File Inclusion in versi… wordfence
be976b54-2418-440c-9f27-667a4156ef08
< 1.6
HIGH 8.1 The Hiroshi theme for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 1.5.1 via deseri… wordfence
be6592b8-d60f-48c3-bda3-8fd69dcf1d0b HIGH 8.1 The Gable theme for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.5. This makes it… wordfence
be41bf79-8cc3-41fa-856a-1b6c06e647c7 HIGH 8.1 The Pizza House theme for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 1.4.0 via de… wordfence
be224599-ab12-4fb3-9ab4-eecbbc33445b HIGH 8.1 The Strux theme for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.9. This makes it… wordfence
be0a5922-e7ca-448e-aceb-d27002484bea
< 2.7.5
HIGH 8.1 The Abstracts plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 2.7.4. This m… wordfence
bde00f73-853a-420e-9c6c-0205bf371ff3 HIGH 8.1 The Grecko theme for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 5.17. This makes … wordfence
bd8a9b92-8ef5-44bc-a977-58875fc4079b HIGH 8.1 The tf-woo-product-grid plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including,… wordfence
bd331eb2-9ec2-4105-ae79-01c9c772de35 HIGH 8.1 The Cars4Rent | Auto Rental & Taxi WordPress Theme + RTL theme for WordPress is vulnerable to PHP Object Injection in al… wordfence
bd073b97-b9b3-417c-ad82-e07a75cee3c4
< 1.12.4
HIGH 8.1 The Embed Privacy plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation… wordfence
bc308993-7fc5-41db-a396-f05e95fe47b8
< 5.1.2
HIGH 8.1 The MW WP Form plugin for WordPress is vulnerable to Arbitrary File Move/Read in all versions up to and including 5.1.1.… wordfence
bc2db74d-61b9-498a-a0d8-e43466b06f37
< 2.9.4.2
HIGH 8.1 The Beaver Builder – WordPress Page Builder plugin for WordPress is vulnerable to unauthorized access and modification… wordfence
bc1ab4f8-dccf-4d1b-90b8-828a7c6100c7 HIGH 8.1 The PhotoMe theme for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 5.6.11 via deser… wordfence
bc1600b9-b590-47ca-b2d9-d521381da541
< 11.4.0
HIGH 8.1 The Content Egg – Affiliate Product Importer & Price Comparison plugin for WordPress is vulnerable to Arbitrary File D… wordfence
bc11d6bc-d0e6-4ec8-9e7f-ca8a88b2a726 HIGH 8.1 The Agricola - Agriculture & Organic Farm Theme theme for WordPress is vulnerable to PHP Object Injection in versions up… wordfence
bbe5d631-8f2a-49a9-aeb8-b9965a5875ca
< 5.9.0
HIGH 8.1 The Bus Ticket Booking with Seat Reservation plugin for WordPress is vulnerable to PHP Object Injection in versions up t… wordfence
← Prev 230 231 232 233 234 235 236 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top