πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,590
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 14, 2026
Last Updated

39,590 vulnerabilities found (page 239 of 1584)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
9f09788d-7f1a-4c3c-9d25-17e7456cee20 HIGH 8.1 The DJ Rainflow theme for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.3.13. This… wordfence
9eaa2a20-c436-44a2-9b17-75a3c96025bb HIGH 8.1 The Daiquiri theme for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.2.4. This mak… wordfence
9e465c41-97fa-4a7f-ac84-d270d1721940 HIGH 8.1 The Midi - Sound & Music WordPress Theme theme for WordPress is vulnerable to Local File Inclusion in versions up to, an… wordfence
9e43cf06-8356-40cd-a0d8-b9f7ab95d793
< 3.0.6.2
HIGH 8.1 The Post Indexer plugin before 3.0.6.2 for WordPress has incorrect handling of data passed to the unserialize function. wordfence
9df43aa5-e355-4936-a366-baa77654166b
< 11.4.0
HIGH 8.1 The SUMO Affiliates Pro plugin for WordPress is vulnerable to PHP Object Injection in versions up to 11.4.0 via deserial… wordfence
9dd7babf-6a0d-443d-b034-7d206e1ee98f HIGH 8.1 The VidoRev theme for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 2.9.9.9.9.9.7. T… wordfence
9dc6b822-356f-4af3-898f-7ebe97a35a68
< 1.23.0
HIGH 8.1 The Joly theme for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.22.0. This makes … wordfence
9dc5861b-9181-45f9-abf5-6eea36edbda7
< 1.2.9
HIGH 8.1 The Ovatheme Events plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.2.8. … wordfence
9d8b985c-c25b-4fad-ad58-2c4ef57712d0 HIGH 8.1 The Iona theme for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.0.8. This makes i… wordfence
9d692aff-8bb2-45bb-9caf-bc33d3ed5b10
< 2.4.21
HIGH 8.1 The Kali Forms β€” Contact Form & Drag-and-Drop Builder plugin for WordPress is vulnerable to Remote Code Execution in a… wordfence
9d40e58d-98a7-4ae3-8497-9b8dd5399b60
< 1.8
HIGH 8.1 The ChapterOne theme for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.7. This mak… wordfence
9cfa753b-dbf5-4fe7-be69-fd8972a45e44
< 2.2.2
HIGH 8.1 Several AJAX actions available in the Workreap WordPress theme before 2.2.2 lacked CSRF protections, as well as allowing… wordfence
9cad3174-b1af-4e23-be72-6afb2d6cea84
< 6.5.0.2
HIGH 8.1 The wpDataTables (Premium) plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, … wordfence
9cacf087-c501-47b2-ab9b-a395e95ae245
< 4.4.1
HIGH 8.1 The Groundhogg β€” CRM, Newsletters, and Marketing Automation plugin for WordPress is vulnerable to arbitrary file delet… wordfence
9c5067e5-90e0-44a1-a263-99f93db004c9 HIGH 8.1 The ProLingua theme for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.1.12. This m… wordfence
9c4cb6fa-986d-4765-a9e5-6e7c0a66f9a9 HIGH 8.1 The RealtyElite theme for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.0.0. This … wordfence
9c32d183-c397-4e9e-9b91-6eda99c44d0b HIGH 8.1 The Muji theme for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.2.0. This makes i… wordfence
9c237580-360b-4c0a-b107-344484c06b7a
< 1.3
HIGH 8.1 The Energox | EV Charging Station WordPress Theme theme for WordPress is vulnerable to arbitrary file deletion due to in… wordfence
9bbd8616-e160-4e1c-8c2c-be38f7768194 HIGH 8.1 The Task Manager plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 3.0.2. Thi… wordfence
9b8cc6bf-4b30-459f-824b-9b5ccec41804 HIGH 8.1 The Creatify theme for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 1.5 via deseria… wordfence
9b2fecbc-9afa-445b-a702-546cf343a67e
< 4.0.2
HIGH 8.1 The WP Easy Contact plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 4.0.1 v… wordfence
9b1cdce5-e88c-40b5-b7c9-308b7303422b HIGH 8.1 The Rosebud - Flower Shop and Florist WordPress Theme theme for WordPress is vulnerable to Local File Inclusion in versi… wordfence
9ae9307c-680c-43c7-8246-a3e6149c1fb6
< 1.0.10
HIGH 8.1 The Check & Log Email plugin for WordPress is vulnerable to Unauthenticated Hook Injection in all versions up to, and in… wordfence
9ae4bf8c-c9be-4737-81b8-62ebb9717796 HIGH 8.1 The FW Gallery plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 8.0.0. This … wordfence
9ae490b5-7181-45d1-8e3b-8ff244de2bec HIGH 8.1 The Sweet Jane - Delightful Cake Shop Theme theme for WordPress is vulnerable to Local File Inclusion in versions up to,… wordfence
← Prev 236 237 238 239 240 241 242 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top