🛡️ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,590
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 14, 2026
Last Updated

39,590 vulnerabilities found (page 244 of 1584)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
86af62b9-8a32-4521-85ad-b58c1cb3de35 HIGH 8.1 The CookieHint WP plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.0.0. Th… wordfence
86520275-85f8-4010-bd28-21bf2e5768fb HIGH 8.1 The Cobble theme for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.7. This makes i… wordfence
8641eb53-6a9a-4549-b8ef-e37acbcc7f03
< 3.4.5
HIGH 8.1 The Everest Forms plugin for WordPress is vulnerable to Arbitrary File Read and Deletion in all versions up to, and incl… wordfence
86015938-0b07-4116-9752-b45db148fd44 HIGH 8.1 The Apollo | Night Club, DJ Event WordPress theme for WordPress is vulnerable to Local File Inclusion in versions up to,… wordfence
8575de20-a108-40df-a304-44e5fc8049f4
< 6.5
HIGH 8.1 The Taskbot plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in al… wordfence
856a7d47-4c76-4163-a3e2-7e62024dd98a HIGH 8.1 The Malgré theme for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.0.3. This make… wordfence
855f3030-3d0b-4886-8d40-a2245a787ab4
< 7.3.7
HIGH 8.1 The Events Manager – Calendar, Bookings, Tickets, and more! plugin for WordPress is vulnerable to PHP Object Injection… wordfence
853562ed-7f2e-453c-b3d0-67c90bd0231f
< 8.2
HIGH 8.1 The Directorist: AI-Powered Business Directory Plugin with Classified Ads Listings plugin for WordPress is vulnerable to… wordfence
84e25621-6535-43d7-a762-1dd4ffe87ee0
< 7.5.1
HIGH 8.1 The Jannah theme for WordPress is vulnerable to Local File Inclusion in versions up to, and excluding, 7.5.1. This makes… wordfence
8483196e-f476-41e5-a988-bcd8a9952a64
< 1.6.3
HIGH 8.1 The User Activity Log plugin for WordPress is vulnerable to generic SQL Injection via the username value when logging in… wordfence
83d50e66-85d9-4514-9020-96cfcab50d96 HIGH 8.1 The FlashMart theme for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 2.0.15. This m… wordfence
83d4e8d6-079e-4615-bdc8-b3e20060727f HIGH 8.1 The Lagom theme for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 2.0 via deserializ… wordfence
839c3b99-189d-4a74-b295-d44eb39d86c8 HIGH 8.1 The Bei Fen – WordPress Backup Plugin plugin for WordPress is vulnerable to Local File Inclusion in all versions up to… wordfence
837eea49-0b2c-46b4-a325-526d7c143fdc
< 1.4.3
HIGH 8.1 The easy-wp-smtp plugin before 1.4.4 for WordPress allows Administrator account takeover, as exploited in the wild in De… wordfence
8341c7fb-6f3f-45ee-86c3-9c9d2617594a
< 4.16.3
HIGH 8.1 The Meta Box plugin before 4.16.3 for WordPress allows file deletion via ajax, with the wp-admin/admin-ajax.php?action=r… wordfence
8323dbff-3d35-4b31-8ec6-645de676adab HIGH 8.1 The Paragon theme for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.1. This makes … wordfence
82f1a77d-1068-48e5-8c3b-1fa4b43221f8
< 1.6
HIGH 8.1 The Mildhill theme for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 1.5 via deseria… wordfence
82540d34-c42b-451c-a837-54e26e09c596 HIGH 8.1 The LuxMed | Medicine & Healthcare Doctor WordPress theme for WordPress is vulnerable to Local File Inclusion in version… wordfence
8206ed66-8a90-4104-af49-d18c9a751deb HIGH 8.1 The Mandala theme for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 2.8. This makes … wordfence
81eb489c-ee56-4587-90b8-0a1a1c66ae66 HIGH 8.1 The Pantry theme for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.4. This makes i… wordfence
8167b8c1-d365-4b52-9be0-28cbd0f4c36a HIGH 8.1 The WooCommerce Amazon Affiliates - Wordpress Plugin plugin for WordPress is vulnerable to arbitrary file deletion due t… wordfence
815055b7-9bb0-4af3-93fa-b7565bfbccd0
< 6.7.3
HIGH 8.1 The PenNews theme for WordPress is vulnerable to Local File Inclusion in versions up to 6.7.3. This makes it possible fo… wordfence
811bd2b0-1e66-4351-8b69-70f5d93ac144
< 1.2.15
HIGH 8.1 The Nika theme for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.2.14. This makes … wordfence
80dfbcf3-61e9-4187-a2bf-38234348e535
< 2.0.6
HIGH 8.1 The Monki theme for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 2.0.5. This makes … wordfence
80beb6d5-a032-4e35-a4f2-18b6127f031c HIGH 8.1 The Choreo theme for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.6. This makes i… wordfence
← Prev 241 242 243 244 245 246 247 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top