πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,590
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 14, 2026
Last Updated

39,590 vulnerabilities found (page 246 of 1584)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
7b3b2b53-4984-4841-8a25-621e16eb5802
< 3.3.6
HIGH 8.1 The Workreap plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in a… wordfence
7aff5aa6-59b1-4d5e-b3a9-5101a489fb37 HIGH 8.1 The Hygia theme for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.16. This makes i… wordfence
7acf0035-12c1-4b94-8c46-dfe92cf984d9
< 1.6
HIGH 8.1 The Borgholm theme for WordPress is vulnerable to PHP Object Injection in versions up to 1.6 via deserialization of untr… wordfence
7a9c1a7a-c09b-4c2d-b294-7cd42883c853 HIGH 8.1 The Verse theme for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.7.0. This makes … wordfence
7a893319-a83d-4475-991a-2bb7fc90836c
< 1.1
HIGH 8.1 The Amoli theme for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.0. This makes it… wordfence
7a6a39d6-570a-4ffe-b9a4-abdfbebd7a61
< 2.4.19
HIGH 8.1 The Kali Forms β€” Contact Form & Drag-and-Drop Builder plugin for WordPress is vulnerable to arbitrary file deletion du… wordfence
7a59ccdc-d265-4e8c-96b2-4eba3bb33591
< 5.0.2
HIGH 8.1 The Divi Booster plugin for WordPress is vulnerable to PHP Object Injection in versions up to 5.0.2 via deserialization … wordfence
7a573ee8-2d11-4653-8454-7f1cbed0c80e HIGH 8.1 The Good Mood theme for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.16. This mak… wordfence
7a4ea418-2ae0-4a3a-8dad-123f144b1f7d
< 1.0.8
HIGH 8.1 The Blogvy theme for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.0.7. This makes… wordfence
7a4a0c26-6b7b-4dcf-a266-a6548431e6a8
< 4.3.0
HIGH 8.1 The Edumall theme for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 4.2.4 via th… wordfence
7a42716b-76b7-4f24-be54-4175d06215f6 HIGH 8.1 The CTUsers plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.0.0. This mak… wordfence
7a38b41c-0371-4488-a941-0ae70368ce9b HIGH 8.1 The Heart theme for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.8. This makes it… wordfence
79cc102a-6777-41be-a395-8c2eeb6deb73
< 3.0.6
HIGH 8.1 The wpForo Forum plugin for WordPress is vulnerable to Arbitrary File Deletion in versions up to and including 3.0.5. Th… wordfence
79ae062c-b084-4045-9407-2d94919993af
< 6.45
HIGH 8.1 The Spam protection, Anti-Spam, FireWall by CleanTalk plugin for WordPress is vulnerable to unauthorized Arbitrary Plugi… wordfence
7934c73c-17cf-4cec-a8da-654cee453b8f
< 2.3.12
HIGH 8.1 The Backup by Supsystic plugin for WordPress is vulnerable to Arbitrary File Download and Deletion in versions up to, an… wordfence
78fd6eba-4458-4737-89fc-f846049af905
< 2.0
HIGH 8.1 The Konsept theme for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 1.9 via deserial… wordfence
7875e975-0559-4c18-819b-1171d2c8b87e
< 1.4
HIGH 8.1 The Micdrop theme for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 1.3.1 via deseri… wordfence
786af6d8-64ca-4dd8-9539-f521b30796b9 HIGH 8.1 The Marcell theme for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.2.14. This mak… wordfence
77c4078a-0549-4b9e-ade6-f6133be73b1c HIGH 8.1 The Zio Alberto theme for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.2.2. This … wordfence
773c20a3-d1db-4e1c-a3d9-c3a544e81f56
< 1.27
HIGH 8.1 The Tasty Daily theme for WordPress is vulnerable to PHP Object Injection in versions up to 1.27 via deserialization of … wordfence
77104b2f-2348-45df-90b1-41a3a3983101 HIGH 8.1 The Jardi | Winery, Vineyard & Wine Shop WordPress Theme theme for WordPress is vulnerable to PHP Object Injection in ve… wordfence
76c9384d-880b-4dc5-9961-cb727f2d7cdf HIGH 8.1 The Berger theme for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.1.1. This makes… wordfence
7699f6bd-b965-412d-80f5-a999f2299e12 HIGH 8.1 The Playa | Beach & Pool Club WordPress Theme theme for WordPress is vulnerable to Local File Inclusion in versions up t… wordfence
7662e554-b62f-49a8-8aab-74c967cd9db5
< 1.7
HIGH 8.1 The Hendon theme for WordPress is vulnerable to Local File Inclusion in versions up to 1.7. This makes it possible for u… wordfence
75c2b82e-cf1c-4db2-811c-82d05c6a1212
< 5.0.1
HIGH 8.1 The WPMU DEV Dashboard plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including,… wordfence
← Prev 243 244 245 246 247 248 249 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top