πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,590
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 14, 2026
Last Updated

39,590 vulnerabilities found (page 242 of 1584)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
9156e536-a58e-4d78-b136-af8a9613ee23
< 5.3.4
HIGH 8.1 The MainWP Child – Securely Connects to the MainWP Dashboard to Manage Multiple Sites plugin for WordPress is vulnerab… wordfence
91365d3b-8e93-4202-8d44-9d217aaae0a4
< 6.5.2
HIGH 8.1 The LiteSpeed Cache plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 6.5… wordfence
91142cb2-aae4-496a-bfa3-6d5d8516aba1 HIGH 8.1 The Kitring theme for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 2.8. This makes … wordfence
90fe067f-ecd5-4d73-821b-31549dcb0d03 HIGH 8.1 The Panda theme for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.21. This makes i… wordfence
90f63303-32a1-472a-830a-1d165b134360 HIGH 8.1 The CedCommerce Integration for Good Market plugin for WordPress is vulnerable to Local File Inclusion in versions up to… wordfence
90de88d4-5cd0-4dc9-add1-563bb030e4a6
< 4.11
HIGH 8.1 The Newsletters plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 4.10. T… wordfence
90d40b66-e178-4f2b-beb3-9e45269abaea
< 1.4
HIGH 8.1 The ShiftUp theme for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 1.3 via deserial… wordfence
9048eaa1-159f-4464-89da-fcd80b732f18
< 1.8
HIGH 8.1 The Halstein - Business Consulting WordPress Theme theme for WordPress is vulnerable to PHP Object Injection in all vers… wordfence
902312d2-8cd8-4e22-a5b8-d3ec50126cdb HIGH 8.1 The The Aisle Core plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 2.0.5. T… wordfence
901da3fd-930f-4253-978b-93e9b1d5e902
< 1.5.2
HIGH 8.1 The Database for Contact Form 7, WPforms, Elementor forms plugin for WordPress is vulnerable to PHP Object Injection in … wordfence
90162481-c20e-4c35-b6ed-79433529b89d HIGH 8.1 The Anarkali theme for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.0.9. This mak… wordfence
8fe1609d-17d6-4afe-90b2-5473dc9b6c3b
< 13.7.0
HIGH 8.1 The WPBot Pro Wordpress Chatbot plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file p… wordfence
8f95276c-7486-4dbe-a79d-702fd6be9cfa HIGH 8.1 The Invelity Product Feeds plugin for WordPress is vulnerable to arbitrary file deletion via path traversal in all versi… wordfence
8f32791a-4249-4f9b-aa66-cab66f1bf1fc HIGH 8.1 The FindAll - Business Directory WordPress Theme theme for WordPress is vulnerable to Local File Inclusion in versions u… wordfence
8e3a5566-eee5-4f71-9c93-e59abf913d04
< 1.2.6
HIGH 8.1 The SiteGround Security plugin for WordPress is vulnerable to authentication bypass that allows unauthenticated users to… wordfence
8dfd2822-29c8-4929-b153-6530c70431b6
< 3.8.1
HIGH 8.1 The Support Board plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 3.8.0. Th… wordfence
8dee7376-0177-4b9d-88f6-d2df054aca65
< 1.7
HIGH 8.1 The Zermatt theme for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 1.6.1 via deseri… wordfence
8ddbad10-6827-4587-b039-3d22d8383c12 HIGH 8.1 The Beautique theme for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.5. This make… wordfence
8da902c8-7b48-4628-a83f-91bd01451ff0 HIGH 8.1 The AutoParts theme for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.5.8. This ma… wordfence
8d93a157-ca5d-4e30-bb9d-c46311d46453
< 1.3.6
HIGH 8.1 The WP Gravity Forms FreshDesk Plugin plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, … wordfence
8c2747e6-dcaf-4627-801a-1a40ac12b343 HIGH 8.1 The Legacy theme for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.9. This makes i… wordfence
8c10cbe0-4996-4f70-8c00-1ae866a483fc HIGH 8.1 The Fortius theme for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 2.3.0. This make… wordfence
8be18b89-378c-4506-a8e0-b92c2b6f2f11 HIGH 8.1 The Advice - Psychology, Therapy & Counseling Theme theme for WordPress is vulnerable to PHP Object Injection in version… wordfence
8bc861b2-1e8a-42be-b70b-e9f9224bd8bb HIGH 8.1 The eCommerce plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 3.15.1 via de… wordfence
8ba608a6-16f3-4ded-a08e-53bc75f73d2f HIGH 8.1 The DroneX theme for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.1.12. This make… wordfence
← Prev 239 240 241 242 243 244 245 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top