🛡️ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,590
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 14, 2026
Last Updated

39,590 vulnerabilities found (page 249 of 1584)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
6849ae28-4918-4726-a139-7c3f8395e59d
< 6.8.6
HIGH 8.1 The StreamVid theme for WordPress is vulnerable to Local File Inclusion in versions up to 6.8.6. This makes it possible … wordfence
67d3c280-507d-4e53-81c4-621fce05b386
< 4.7
HIGH 8.1 The SERPed.net plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 4.6. This ma… wordfence
67cb10e4-5d42-464b-a24f-66811a5d0991
< 6.4.1
HIGH 8.1 The ARforms plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on… wordfence
67ac5336-7504-4a54-aeb3-1b4c96a1d456 HIGH 8.1 The Deliciosa theme for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.10.0. This m… wordfence
670fc073-bdb4-45b1-9257-73ed0c595766
< 1.5.17
HIGH 8.1 The Molla - eCommerce HTML5 Template theme for WordPress is vulnerable to Local File Inclusion in versions up to, and in… wordfence
66ee8428-363e-412e-82b1-0d93bfe8f89c HIGH 8.1 The Top Dog theme for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.0.5. This make… wordfence
66d642e0-c78f-4e50-89d9-03940fa0e34f
< 6.7.1
HIGH 8.1 The Jetpack CRM plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 6.7.0. This… wordfence
66cda4f0-baf1-45e6-89b6-17946118d345
< 2.3.16
HIGH 8.1 The Besa theme for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 2.3.15. This makes … wordfence
66b43042-0332-4bbb-b85b-669c7e716855 HIGH 8.1 The Impacto Patronus theme for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.2.3. … wordfence
66ae4ef6-ae4c-4ecc-84ec-f2974a317250 HIGH 8.1 The Racquet theme for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.12.0. This mak… wordfence
66697f3e-c023-496d-b553-7d20352e33b5
< 8.8.15
HIGH 8.1 The HubSpot WordPress plugin before 8.8.15 does not validate the proxy URL given to the proxy REST endpoint, which could… wordfence
6659646b-80dd-4f37-a275-4def52b9200e HIGH 8.1 The Melania theme for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 2.5.0. This make… wordfence
65d88c4e-5551-4d15-9653-d64352517ec8 HIGH 8.1 The Integro theme for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.8.0. This make… wordfence
65b8e9b3-6078-4a78-86f9-7251c1978199
< 1.7.g
HIGH 8.1 The Eventify - Simple Events plugin for WordPress is vulnerable to SQL Injection via the ‘eventid’ parameter in vers… wordfence
6567afc2-dc96-449e-b64c-af129c4bf245 HIGH 8.1 The Farm Agrico theme for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.3.11. This… wordfence
654bcf34-33a6-425c-8830-1418444acf10
< 3.0.0
HIGH 8.1 The Alukas theme for WordPress is vulnerable to PHP Object Injection in versions up to 3.0.0 via deserialization of untr… wordfence
653fe650-d2b8-4bb3-828b-2606ced2d6a1
< 1.2.8
HIGH 8.1 The Codiqa theme for WordPress is vulnerable to PHP Object Injection in versions up to 1.2.8 via deserialization of untr… wordfence
652f57b8-9472-469a-8edd-32825373fb67 HIGH 8.1 The Putter theme for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.17. This makes … wordfence
652d63ab-8c25-4b49-b6e3-69ffd363151a HIGH 8.1 The MCKinney's Politics theme for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.2.… wordfence
65066a17-653b-4444-9bd0-894ea8c1acb1
< 2.06
HIGH 8.1 The Magic Login Mail or QR Code plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and in… wordfence
64a9d0b3-f33c-4393-8c7c-7b2aeb89ea52 HIGH 8.1 The Ozisti theme for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.1.10. This make… wordfence
645c02b8-595c-42ab-ba83-b0eb40431aee HIGH 8.1 The Le Truffe theme for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.1.7. This ma… wordfence
6391e61d-2e15-4fc5-a7a5-b8f5c45dfe73
< 1.4
HIGH 8.1 The TechLink theme for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 1.3 via deseria… wordfence
638e8e67-38b3-4fc4-bd77-8f268030a93a
< 3.2.2
HIGH 8.1 The Compare Products for WooCommerce plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, a… wordfence
637aaab1-b536-4484-a8ce-646d5f9533b9 HIGH 8.1 The Towny theme for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.16. This makes i… wordfence
← Prev 246 247 248 249 250 251 252 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top