πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,590
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 14, 2026
Last Updated

39,590 vulnerabilities found (page 235 of 1584)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
b53ce9a7-bc88-4940-8397-6eb0012ac276 HIGH 8.1 The ChildHope theme for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.1.8. This ma… wordfence
b50bdf83-d6e1-46bd-be6c-4fcb77ef94db
< 2.7.3
HIGH 8.1 The option-tree plugin before 2.7.3 for WordPress has Object Injection because the + character is mishandled. wordfence
b4658546-bf57-414b-a3c9-bf7a5692c5fe
< 0.0.14
HIGH 8.1 The SureForms – Drag and Drop Form Builder for WordPress plugin for WordPress is vulnerable to arbitrary file deletion… wordfence
b44e6c52-9b17-4d4c-910f-20f49262afde
< 3.1.2
HIGH 8.1 The Graphina – Elementor Charts and Graphs plugin for WordPress is vulnerable to Local File Inclusion in all versions … wordfence
b40177a3-e4d1-4025-9071-856537dc78eb HIGH 8.1 The Premium Addons for KingComposer plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and in… wordfence
b3dbe34e-7961-4a08-b5d9-86b727cbf5f5 HIGH 8.1 The Pearl - Corporate Business theme for WordPress is vulnerable to Local File Inclusion in versions up to, and includin… wordfence
b3a84201-6cd8-4528-ae7a-7fd813c8da18
< 2.1.5
HIGH 8.1 The BWL Advanced FAQ Manager plugin for WordPress is vulnerable to unauthorized modification of data that can lead to a … wordfence
b391f7ca-655b-4028-9711-5bd41f694de3
< 3.2.2
HIGH 8.1 The Captivate Sync plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 3.0.3 vi… wordfence
b380283c-0dbb-4d67-9f66-cb7c400c0427
< 1.4.0
HIGH 8.1 The Backup Migration plugin for WordPress is vulnerable to Remote File Inclusion in versions 1.0.8 to 1.3.9 via the 'con… wordfence
b360f121-449f-43a8-b5e4-1cffddbaac77
< 2.10.0
HIGH 8.1 The W3 Total Cache plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 2.9… wordfence
b2cb4af8-4cb5-4f79-93c1-21dbdc7c406f
< 4.4.1
HIGH 8.1 The Save as PDF Plugin by Pdfcrowd plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and… wordfence
b2ab2178-7438-43ef-961e-b54d0d230f4a
< 1.1.2
HIGH 8.1 The Feather Login Page plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability che… wordfence
b2941cb4-57dc-425e-8ed7-d82096c73b44 HIGH 8.1 The Gat theme for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.16. This makes it … wordfence
b267f163-966a-43f7-8a7c-67d34c2c7e9d
< 2.0.0
HIGH 8.1 The WPForms Pro plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 1.10.1… wordfence
b249ec90-a364-4644-94fb-d42eb6cc4d9a
< 3.2.8
HIGH 8.1 The Redirection for Contact Form 7 plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type… wordfence
b24245ef-4c4a-4dda-9bd0-b03a24980e0d
< 2.3
HIGH 8.1 The Greenify theme for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 2.2. This makes… wordfence
b22179cc-4dae-4f0e-8788-a52bab72471a HIGH 8.1 The Dazzle theme for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.0.0. This makes… wordfence
b20a793a-82ff-41ba-95a2-3c3b4f98617d HIGH 8.1 The Background Control plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including… wordfence
b1b7b653-496f-467a-9513-4be1891f38ae
< 2.3
HIGH 8.1 The OTP Login Woocommerce & Gravity Forms plugin for WordPress is vulnerable to authentication bypass. This is due to th… wordfence
b19c81c9-d4ea-4a62-ba37-7904cc3ca95a HIGH 8.1 The Saveo theme for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.1.2. This makes … wordfence
b1376596-571a-48d2-bbb7-e6bc69de00ac HIGH 8.1 The Biagiotti Core plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 2.1.1. T… wordfence
b1117f36-a8a2-4ed5-89be-ed0215fda0b1 HIGH 8.1 The Sounder | Internet Radio & Streaming Elementor Template Kit theme for WordPress is vulnerable to Local File Inclusio… wordfence
b0e63d48-8749-4c10-a086-425e81df6920 HIGH 8.1 The Helion | Personal Portfolio & Agency WordPress Theme theme for WordPress is vulnerable to Local File Inclusion in ve… wordfence
b086b0cb-bff7-4c04-9cee-15063acf430c HIGH 8.1 The 777 theme for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.3. This makes it p… wordfence
b03b0096-61f5-4886-80ea-108f6a4c4c49
< 1.3.0
HIGH 8.1 The WP Gravity Forms Zoho CRM and Bigin plugin for WordPress is vulnerable to PHP Object Injection in all versions up to… wordfence
← Prev 232 233 234 235 236 237 238 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top