πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,590
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 14, 2026
Last Updated

39,590 vulnerabilities found (page 238 of 1584)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
a53c1462-38da-4444-84ae-610fa6d3ddec HIGH 8.1 The Legal Stone theme for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.2.11. This… wordfence
a4a1be5d-ebd0-4c69-a4d0-303c7b38b6fd HIGH 8.1 The Spock theme for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.17. This makes i… wordfence
a4149783-ffa3-4efd-af55-5aa1c0e44443
< 4.1.3
HIGH 8.1 The User Registration & Membership plugin for WordPress is vulnerable to authentication bypass in versions up to, and in… wordfence
a3c5e30e-a2d4-47cf-b00e-54c007ce5ec3
< 1.3.15
HIGH 8.1 The Zota theme for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.3.14. This makes … wordfence
a3902a32-2bb9-44bb-9dbd-3887f0b5be81
< 3.1.1
HIGH 8.1 The wpForo Forum plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 3.1.0 via … wordfence
a351c250-f9c8-408d-8013-58996d7cbddf HIGH 8.1 The Asia Garden theme for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.3.1. This … wordfence
a34ba31b-3106-4d46-955a-83f005f7226f HIGH 8.1 The Scientia theme for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.2.4. This mak… wordfence
a32842ff-8d5c-4467-acd2-7beeb933fb0d HIGH 8.1 The Employee Directory – Staff Listing & Team Directory Plugin for WordPress plugin for WordPress is vulnerable to… wordfence
a2bd106e-03b2-4b91-8c44-c0f9ff6f1097 HIGH 8.1 The Food Drop theme for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.3. This make… wordfence
a2bb5f83-f331-49d4-b26c-6307d305572e HIGH 8.1 The Netmix theme for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.0.10. This make… wordfence
a2abbc26-d228-45eb-bd2e-727f9ec606d7 HIGH 8.1 The Image Shadow plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation … wordfence
a28f9860-395d-4087-9e0d-cf0332aba39f
< 6.8.0
HIGH 8.1 The WP Travel Engine – Tour Booking Plugin – Tour Operator Software plugin for WordPress is vulnerable to PHP Object… wordfence
a288b1e1-a5b3-4818-bff3-77f54ca02d28 HIGH 8.1 The Portfolio Manager Pro plugin for WordPress is vulnerable to PHP Object Injection in versions up to 3.8 via deseriali… wordfence
a26f4bb7-fe61-4343-82ee-19639c16d978
< 1.9
HIGH 8.1 The Images to WebP WordPress plugin before 1.9 does not have CSRF checks in place when performing some administrative ac… wordfence
a26e35a5-d93a-49fb-8a70-d32a7624ffc1
< 1.2.7
HIGH 8.1 The WP Gravity Forms HubSpot plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and inclu… wordfence
a1c6eed6-7b3f-4b37-85f8-6613527daa54
< 3.5.6
HIGH 8.1 The Advanced Order Export For WooCommerce plugin for WordPress is vulnerable to PHP Object Injection in all versions up … wordfence
a1a00374-e9d6-46f9-a28c-cb7768505787
< 1.7.5
HIGH 8.1 The Image Optimizer plugin for WordPress is vulnerable to arbitrary file deletion in versions up to and including 1.7.4.… wordfence
a18963cb-24c7-45b4-987d-5a8789b1ab0a
< 2.2.2
HIGH 8.1 The Workreap WordPress theme before 2.2.2 had several AJAX actions missing authorization checks to verify that a user wa… wordfence
a161858b-dd88-4643-b735-a7b21577b3ba HIGH 8.1 The Gamic theme for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.15. This makes i… wordfence
a1050801-a2d9-46f1-8b56-bacf24d77722 HIGH 8.1 The Zita theme for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.6.5. This makes i… wordfence
9ff74fee-ba89-46fb-adb0-47fbe07c2a5c
< 3.9.1
HIGH 8.1 The WP Travel Gutenberg Blocks plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and includi… wordfence
9f86ec30-7a9d-4c36-8559-bde331c8b958
< 4.3.2
HIGH 8.1 The Popup Builder – Create highly converting, mobile friendly marketing popups. plugin for WordPress is vulnerable to … wordfence
9f6f0322-98ef-4523-b105-fd89c7efcf67 HIGH 8.1 The Saxon - Viral Content Blog & Magazine Marketing WordPress theme for WordPress is vulnerable to Local File Inclusion … wordfence
9f51f514-7a8b-4f2b-a365-93c932253bdb HIGH 8.1 The Abelle theme for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 1.22 via deserial… wordfence
9f2774e8-8b55-4c25-93c3-e0806208b1f3
< 7.4.0
HIGH 8.1 The Uncanny Automator – Easy Automation, Integration, Webhooks & Workflow Builder Plugin plugin for WordPress is vulne… wordfence
← Prev 235 236 237 238 239 240 241 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top