ðŸ›¡ï¸ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,590
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 14, 2026
Last Updated

39,590 vulnerabilities found (page 250 of 1584)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
6379ff71-20ba-473d-a2c4-3711c139ba17 HIGH 8.1 The Kossy - Minimalist eCommerce WordPress Theme theme for WordPress is vulnerable to Local File Inclusion in versions u… wordfence
634ccd08-4f2e-4a06-8c64-dfe38fa3a481
< 1.4.5
HIGH 8.1 The WP Super Cache plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 1.4.4 vi… wordfence
633bb792-69c1-4c10-b64a-123ec149fd14
< 5.4.2
HIGH 8.1 The AI Lab theme for WordPress is vulnerable to PHP Object Injection in versions up to 5.4.2 via deserialization of untr… wordfence
631ce289-0f47-4a20-a597-fa33bda793e4 HIGH 8.1 The Soleng theme for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.0.5. This makes… wordfence
62e1aa14-b762-40ea-9a64-b1ecb6ed7153
< 1.4.38
HIGH 8.1 The GPT AI Power plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on an unkn… wordfence
62c8b894-b810-4011-ae0a-db401327142c
< 1.7.2
HIGH 8.1 The Mikado Core plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.6. This m… wordfence
62b7bb00-8bd3-4d2b-b126-6b49b18fd920 HIGH 8.1 The Alloggio - Hotel Booking theme for WordPress is vulnerable to Local File Inclusion in versions up to, and including,… wordfence
62aff7c5-78d8-4ec3-8081-b1ab9985d881 HIGH 8.1 The Corbesier theme for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.15.0. This m… wordfence
62a9b569-bef8-4454-9779-39aec6e715fc HIGH 8.1 The Horizon theme for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.1. This makes … wordfence
6260ecfd-6109-4061-af70-9f170e030c76 HIGH 8.1 The Wanderic theme for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.0.10. This ma… wordfence
61df94e9-0fda-4c0f-941b-090a6f4562e8 HIGH 8.1 The Glamer theme for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.0.2. This makes… wordfence
61b4d6a9-ae6f-4ace-a423-d63489b7e698 HIGH 8.1 The iRecco Core plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.3.6. This… wordfence
61b477c3-88b7-45a4-9fc4-6bca6f7c3604
< 4.11.2
HIGH 8.1 The ProfilePress Pro plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 4… wordfence
61a196b5-bad9-481b-8bec-9e902dc52bae HIGH 8.1 The Gardis theme for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.2.13. This make… wordfence
6164bb46-2fb9-49ae-aa5c-9a8b75efc0a6 HIGH 8.1 The smart SEO theme for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 2.12. This mak… wordfence
613ef6e4-242a-4dae-aad5-123e750a3bc1 HIGH 8.1 The Reisen theme for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 1.4.1 via deseria… wordfence
61365b95-da97-425d-a314-648b3d00236f
< 1.6
HIGH 8.1 The Ultimate Classified Listings plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to,… wordfence
60fe13d1-704a-4935-af38-03f2c69a9cbe HIGH 8.1 The ConFix theme for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.013. This makes… wordfence
60fb6928-96fb-4c1f-989c-cc07965b5266 HIGH 8.1 The Visitor Logic Lite plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, … wordfence
60fb1081-6f1f-40ac-a320-67f53fa7ffe5
< 3.3
HIGH 8.1 The Curly theme for WordPress is vulnerable to Local File Inclusion in versions up to 3.3. This makes it possible for un… wordfence
60d98a7c-b95b-4c56-8356-306e53de4d5a HIGH 8.1 The Rhythmo theme for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.3.4. This make… wordfence
601aa2b5-aeac-49bc-960d-4b4ff83e9229
< 5.0.1
HIGH 8.1 Multiple plugins for WordPress by emarket-design with the 'emd-form-builder-lite' package are vulnerable to Remote Code … wordfence
600f4293-444c-43b6-88b0-dacf3843cd08 HIGH 8.1 The Line Agency theme for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.3.1. This … wordfence
600aef49-b918-4d58-a460-f9cdbeaa17dd HIGH 8.1 The DS.DownloadList plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.3… wordfence
5fe56ffe-14f8-42c7-852e-41351aae9a4a HIGH 8.1 The Fiorello - Florist and Flower Shop WordPress Theme theme for WordPress is vulnerable to Local File Inclusion in vers… wordfence
← Prev 247 248 249 250 251 252 253 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top