πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,590
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 14, 2026
Last Updated

39,590 vulnerabilities found (page 234 of 1584)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
bbd7bce1-c447-4c47-a364-f2ffbff8c812 HIGH 8.1 The Leyka plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 3.31.9. This make… wordfence
bb762cd0-1925-4161-bd12-9e781de60c9c HIGH 8.1 The Simple Single Sign On plugin for WordPress is vulnerable to authorization bypass due to insecurely configured OAuth … wordfence
bb5c8cb3-df67-4f2c-869a-48e34f5619ff
< 9.2.4
HIGH 8.1 The Nex Forms – Ultimate Form Builder – Lite plugin for WordPress is vulnerable to arbitrary file deletion via path … wordfence
bb02a55d-8d53-463d-ac29-94a69647b539
< 1.2.2
HIGH 8.1 The Magways theme for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.2.1. This make… wordfence
ba8824a2-624d-47ab-9ffa-e485d0e60dd0 HIGH 8.1 The Handyman theme for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 1.4 via deseria… wordfence
ba708a4f-d987-4d63-a218-2ed1c6daa010
< 2.1.0
HIGH 8.1 The Eco Nature - Environment & Ecology WordPress Theme theme for WordPress is vulnerable to unauthorized modification of… wordfence
b9ef344d-cd56-43f9-b185-de83a92800de
< 3.3.102
HIGH 8.1 The Zephyr Project Manager plugin for WordPress is vulnerable to limited privilege escalation in all versions up to, and… wordfence
b9922431-fc88-4c3d-8193-4313588d0935 HIGH 8.1 The Audrey theme for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.5. This makes i… wordfence
b90dc8f1-3f02-41e0-933c-8d9b8e7dc103
< 1.6.12
HIGH 8.1 The The Issue theme for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.6.11. This m… wordfence
b8b8af19-e6d7-425d-896d-ecae63b549e2 HIGH 8.1 The Kingler theme for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 1.7 via deserial… wordfence
b8807275-bd44-43e0-9016-031e863a83d0 HIGH 8.1 The Save Life theme for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.2.13. This m… wordfence
b844b6a4-77e3-423e-9dcd-9d2227886de0 HIGH 8.1 The Takeout theme for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.3.0. This make… wordfence
b81ec608-e0c8-410a-b7ea-af5bfd9ee601
< 1.5
HIGH 8.1 The Eldon - Artist Portfolio WordPress Theme theme for WordPress is vulnerable to PHP Object Injection in versions up to… wordfence
b7925df5-140a-4fc5-84f4-faafe73423d2 HIGH 8.1 The Nirvana theme for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 2.6. This makes … wordfence
b73320e0-0751-4b0a-bc18-00f70c4ad5aa HIGH 8.1 The Lettuce theme for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.1.7. This make… wordfence
b72fe40f-8dfc-4f1c-ae52-b8fd111685db HIGH 8.1 The RT-Theme 18 Responsive WordPress Theme plugin for WordPress is vulnerable to PHP Object Injection in versions up to,… wordfence
b720704d-41f1-4ea5-8b0c-21d1071f9619 HIGH 8.1 The Indoor Plants theme for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.2.7. Thi… wordfence
b6f51a8e-4a59-4b64-b0c6-2ce3933a1df5
< 8.6.5
HIGH 8.1 The Contact Manager plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in … wordfence
b6aa3b1b-458a-4b7c-8ef8-2d434eaa80c9 HIGH 8.1 The Crafti - Handmade Store WordPress Theme theme for WordPress is vulnerable to Local File Inclusion in versions up to,… wordfence
b6763ece-d914-487c-8ad5-befa2e64e7e8 HIGH 8.1 The Smash theme for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.7. This makes it… wordfence
b6395439-da45-4b64-8e30-b106dffd46c1
< 2.9.22
HIGH 8.1 The Gravity Forms plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in th… wordfence
b61f0137-2ef0-4808-ae9b-d6714c245331 HIGH 8.1 The Plan My Day theme for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.1.13. This… wordfence
b5a6e427-d46c-4ed9-b149-101d9d87a7c5 HIGH 8.1 The RT-Theme 18 Responsive WordPress Theme plugin for WordPress is vulnerable to Local File Inclusion in versions up to,… wordfence
b58f6681-800e-4ae1-8f89-2160c4446064 HIGH 8.1 The Scape theme for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 1.5.13 via deseria… wordfence
b5891b39-5ab6-4002-97c2-ae6a5e4d8d5f HIGH 8.1 The Wanium theme for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.9.8. This makes… wordfence
← Prev 231 232 233 234 235 236 237 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top