🛡️ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,590
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 14, 2026
Last Updated

39,590 vulnerabilities found (page 243 of 1584)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
8b5cbabb-e236-4abd-a195-9689cb9aa785 HIGH 8.1 The AC Services | HVAC, Air Conditioning & Heating Company WordPress theme for WordPress is vulnerable to Local File Inc… wordfence
8b5b0d41-165b-4e4b-8bf2-d8c36880a2ea HIGH 8.1 The Metro theme for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 2.13. This makes i… wordfence
8b189452-0d77-4a83-8afc-27bc2e52b060 HIGH 8.1 The Ironfit theme for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.5. This makes … wordfence
8b0ecf40-d68d-4059-a89b-c6532d1292d7 HIGH 8.1 The Honor | Shooting Club & Weapon and Gun Store Theme theme for WordPress is vulnerable to Local File Inclusion in vers… wordfence
8b08f273-2d38-4559-9120-1aef8e8a69e4 HIGH 8.1 The Build App Online plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1.… wordfence
8af105f0-171d-40d3-a62c-062de897592c
< 1.6.7
HIGH 8.1 The Travelicious theme for WordPress is vulnerable to PHP Object Injection in versions up to 1.6.7 via deserialization o… wordfence
8ab3df33-0644-4983-8818-23f63db4c89f HIGH 8.1 The Piqes theme for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.0.11. This makes… wordfence
8a934ccd-9330-4585-9994-838940d24980
< 2.11.11
HIGH 8.1 The WCFM Membership – WooCommerce Memberships for Multivendor Marketplace plugin for WordPress is vulnerable to Insecu… wordfence
8a6784cc-f673-4783-bea5-6a57c4c00ca4
< 2.11.27
HIGH 8.1 The Cena Store theme for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 2.11.26. This… wordfence
8a4978c1-087f-4784-9691-91ca5044f60a HIGH 8.1 The Single-user-chat plugin for WordPress is vulnerable to unauthorized modification of data that can lead to a denial o… wordfence
89dbc40a-d2a2-408f-a337-f9b7c14e0a04 HIGH 8.1 The Tennis SportClub - Tennis Sports Events WordPress Theme theme for WordPress is vulnerable to PHP Object Injection in… wordfence
89916f4e-71a2-4e26-9cfb-40f11a101321
< 1.7
HIGH 8.1 The Stål - Industry WordPress Theme theme for WordPress is vulnerable to PHP Object Injection in all versions up to 1.7… wordfence
897ce9a9-8b3e-40bc-9815-c55cc7a838f9
< 1.3.2
HIGH 8.1 The Exertio Framework plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up… wordfence
894b43ed-143d-4c0b-afd1-05fcd6fa5018
< 3.2.9
HIGH 8.1 The Extensions For CF7 (Contact form 7 Database, Conditional Fields and Redirection) plugin for WordPress is vulnerable … wordfence
8923d9c9-7af6-4109-9c39-b5faee57f8e1
< 8.3.9
HIGH 8.1 The Woodmart theme for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 8.3.8 via deser… wordfence
8915c76f-84ca-4d8d-b5ec-43dc22aeffa2 HIGH 8.1 The Harper theme for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.13. This makes … wordfence
8886e9f8-81d6-458a-b029-f62d4baaf189
< 1.5
HIGH 8.1 The WaveRide theme for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.4. This makes… wordfence
88864e88-30c8-440c-9263-4995f239cdec HIGH 8.1 The Clearblue® Ovulation Calculator plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and i… wordfence
88442edf-bec6-49df-89a9-7d6852dd87db HIGH 8.1 The Chronicle theme for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.0. This make… wordfence
88291698-32e4-4b48-a9d5-9ad337ea6095 HIGH 8.1 The Spare theme for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 1.7 via deserializ… wordfence
87888350-1230-4fec-9de2-c58fa24e6a05
< 5.4.9
HIGH 8.1 The XML Sitemap & Google News plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and incl… wordfence
8730912d-6098-44c9-bff3-87f1c3e0aa3d
< 2.15.5
HIGH 8.1 The Paid Membership Subscriptions – Effortless Memberships, Recurring Payments & Content Restriction plugin for WordPr… wordfence
87154180-620b-47da-9ee5-c5d08ed862f4
< 1.3.66
HIGH 8.1 The Falang multilanguage for WordPress plugin for WordPress is vulnerable to PHP Object Injection in all versions up to,… wordfence
87084994-04ea-47ce-ae3a-5f29c30f61d0 HIGH 8.1 The Work & Travel Company theme for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 1.… wordfence
86d7d9a0-9bb3-4110-99d3-bf044d513ebe HIGH 8.1 The Kings & Queens theme for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.1.16. T… wordfence
← Prev 240 241 242 243 244 245 246 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top