πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,590
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 14, 2026
Last Updated

39,590 vulnerabilities found (page 248 of 1584)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
6fad3590-86ab-4737-840e-bdf72612c779 HIGH 8.1 The Eldon theme for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.0. This makes it… wordfence
6f8fa20c-ed7f-40bd-b4b9-555acc889a58 HIGH 8.1 The Portfolio Builder plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.2.5… wordfence
6f4b15f4-9002-4cae-9d69-f327b8e67914 HIGH 8.1 The Word Count and Social Shares plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file … wordfence
6eb9d68c-c081-484e-ad5d-5eabcfa6d6f0
< 1.4.6
HIGH 8.1 The FOX – Currency Switcher Professional for WooCommerce plugin for WordPress is vulnerable to unauthorized data loss … wordfence
6e74582f-8e94-4cba-a3eb-0a823a5235ad
< 1.8.48
HIGH 8.1 The WooCommerce OTP Login With Phone Number, OTP Verification plugin for WordPress is vulnerable to authentication bypas… wordfence
6e4bc689-8265-4f7a-bda2-d9ca8420179f HIGH 8.1 The KBx Pro Ultimate plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 8.0.5 … wordfence
6e0bc78e-ff6b-4662-8327-314945cb0211 HIGH 8.1 The Tacticool theme for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.0.13. This m… wordfence
6de8a608-8715-4f9c-9f2f-df60dd1cc579 HIGH 8.1 The JobSearch WP Job Board plugin for WordPress is vulnerable to authentication bypass in all versions up to, and includ… wordfence
6d903981-bc2f-4bf3-8e8c-1c407936c8e3
< 1.2.38
HIGH 8.1 The News Magazine X theme for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.2.37. … wordfence
6d7a4f08-1a6a-4bc3-b09c-ad5fc7c5d1a7
< 1.32.43
HIGH 8.1 The E2Pdf – Export Pdf Tool for WordPress plugin for WordPress is vulnerable to Local File Inclusion in versions up to… wordfence
6d3fef85-70cc-49f1-b0e4-60579a3e9b07 HIGH 8.1 The Especio - Food Blog Elementor Pro Template Kit theme for WordPress is vulnerable to Local File Inclusion in versions… wordfence
6bec79ed-57a9-46b5-a804-3bc41ecd218c
< 1.14.0
HIGH 8.1 The Neuronet theme for WordPress is vulnerable to Local File Inclusion in versions up to 1.14.0. This makes it possible … wordfence
6b908de9-bc83-444e-82d3-a54804785c1d
< 1.4.2
HIGH 8.1 The Nifty theme for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 1.4.1 via deserial… wordfence
6b5af3f3-d2ef-4458-aac1-cd2d6902c145 HIGH 8.1 The Shaha | Islamic Centre & Mosque Theme + RTL theme for WordPress is vulnerable to Local File Inclusion in versions up… wordfence
6b1d212b-75fe-4285-9c22-62b040e5a36c
< 1.1.36
HIGH 8.1 The Heateor Social Login WordPress plugin for WordPress is vulnerable to authentication bypass in all versions up to, an… wordfence
6ae2f78b-5042-4216-903c-d5919f137a94 HIGH 8.1 The Oshine theme for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 7.2.7. This makes… wordfence
6ad7ec7b-c59c-41e7-92ac-134b5ad92673 HIGH 8.1 The ElectroServ | Electrical Repair Service WordPress Theme theme for WordPress is vulnerable to Local File Inclusion in… wordfence
6aa3d312-485a-4a93-a075-fa7152395f11
< 1.3.56
HIGH 8.1 The Royal Elementor Addons plugin for WordPress is vulnerable to authorization bypass due to a missing capability check … wordfence
6a5edba7-2977-4f17-a0cd-857802585401 HIGH 8.1 The Justitia theme for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.1.0. This mak… wordfence
69df711e-45b7-446f-8944-247ca180e0d9
< 7.6.40
HIGH 8.1 The Comments – wpDiscuz plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and includi… wordfence
697ce433-f321-4977-a2ad-68369d9ce9c3
< 3.3.0
HIGH 8.1 The Metform Elementor Contact Form Builder for WordPress is vulnerable to Arbitrary File Upload due to insufficient file… wordfence
697a3235-cf3a-4ec8-b8d2-60ed110d0d24 HIGH 8.1 The Yacht Rental theme for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 2.6. This m… wordfence
6976c62b-9457-481a-b71f-ccd13d74e222 HIGH 8.1 The Super Stage WP plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 1.0.1 vi… wordfence
69455500-e6fb-4f01-8855-de595025fabe
< 2.2.2
HIGH 8.1 The Curly Core plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 2.1.6. This … wordfence
68c5d9ad-f6ca-4a3a-b3fc-6b8997a86981
< 1.1.9
HIGH 8.1 The Integration for Mailchimp and Contact Form 7, WPForms, Elementor, Ninja Forms plugin for WordPress is vulnerable to … wordfence
← Prev 245 246 247 248 249 250 251 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top