🛡️ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,590
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 14, 2026
Last Updated

39,590 vulnerabilities found (page 251 of 1584)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
5fbb8506-da9a-4176-824d-9d93135a1d74
< 1.6
HIGH 8.1 The Caliris theme for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.5. This makes … wordfence
5fb90b3b-08bd-4887-a6bf-054b42d3e403
< 1.6.7
HIGH 8.1 The KB Support – WordPress Help Desk and Knowledge Base plugin for WordPress is vulnerable to unauthorized modificatio… wordfence
5f9ae6d4-c0c3-4ef0-948b-4055befbcda2
< 1.2.7
HIGH 8.1 The Connector for Gravity Forms and Google Sheets plugin for WordPress is vulnerable to PHP Object Injection in versions… wordfence
5f994141-f361-4a0e-99dc-1e1951e1e76e
< 1.0.8
HIGH 8.1 The Access Demo Importer plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and includi… wordfence
5f48d58f-8797-46a9-97fa-7db13db31cca
< 1.5
HIGH 8.1 The Roisin - Flower Shop and Florist WordPress Theme theme for WordPress is vulnerable to PHP Object Injection in versio… wordfence
5f3d8928-1257-4e65-9fcf-24d303acdb9e HIGH 8.1 The Remote API plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 0.2 via dese… wordfence
5f29de7a-3f15-4b6d-aad7-6a08151e2113
< 6.5.6
HIGH 8.1 The Bit File Manager plugin for WordPress is vulnerable to Remote Code Execution in versions 6.0 to 6.5.5 via the 'check… wordfence
5edd72d9-3086-4f4f-ae5b-830c8621b83a
< 1.8.2
HIGH 8.1 The Slideshow Gallery LITE plugin for WordPress is vulnerable to time-based SQL Injection via the id parameter in all ve… wordfence
5eccad40-263b-42de-933f-b10f2322668c
< 1.5
HIGH 8.1 The Playroom theme for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 1.4.1 via deser… wordfence
5ea976ab-ecb5-4a7b-a784-afb39b895ab8 HIGH 8.1 The Rhodos theme for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.3.3. This makes… wordfence
5e7ccf1e-2da7-463f-a3a6-0e0f07c8f22b
< 1.1.0
HIGH 8.1 The Elementra - 100% Elementor WordPress Theme theme for WordPress is vulnerable to PHP Object Injection in versions up … wordfence
5e7b5a09-212c-4006-84a7-d87671da6ebc
< 1.1.11
HIGH 8.1 The Premmerce Wholesale Pricing for WooCommerce plugin for WordPress is vulnerable to Local File Inclusion in versions u… wordfence
5e24e99a-2981-4f3e-a672-10f57cf96675
< 250905
HIGH 8.1 The s2Member plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 250701 via des… wordfence
5db3d87c-2b5b-40bf-a0d3-64d66af062c6 HIGH 8.1 The IMDB Profile Widget plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.0… wordfence
5db00b22-d766-4fde-86fe-98d90936028c
< 1.9.3
HIGH 8.1 The Loginizer Security and Loginizer plugins for WordPress are vulnerable to authentication bypass in all versions up to… wordfence
5d7dc644-ab83-4f03-998a-ec8eda695161
< 2.2.44
HIGH 8.1 The BerqWP – Automated All-In-One Page Speed Optimization for Core Web Vitals, Cache, CDN, Images, CSS, and JavaScript… wordfence
5d6ee190-c2ff-46dc-99fa-ba9f0fb6b0a1
< 1.8.8
HIGH 8.1 The BRW plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.8.7. This makes i… wordfence
5d4a08e9-6487-4c4f-93da-d88022bcef2c
< 3.8
HIGH 8.1 The WooCommerce Vehicle Parts Finder plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and i… wordfence
5d48239d-c44b-43fe-b9d9-32221f962d06 HIGH 8.1 The Tripster theme for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.0.10. This ma… wordfence
5cd5d6f9-3011-4da8-a914-1e3e8075fdff
< 7.8
HIGH 8.1 The Super Store Finder plugin for WordPress is vulnerable to Local File Inclusion in versions up to 7.8. This makes it p… wordfence
5c9a5613-770f-4294-997e-17fd5194ab70
< 1.2
HIGH 8.1 The Custom Permalinks plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 1.1 due to i… wordfence
5b951fd9-0fbf-4576-80a9-dbb053c3da92
< 2.6.2
HIGH 8.1 The Sky Addons for Elementor (Free Templates Library, Live Copy, Animations, Post Grid, Post Carousel, Particles, Slider… wordfence
5b9326a5-6373-4fc1-a510-f793c75cf2a2
< 1.3
HIGH 8.1 The Léonie theme for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 1.2.1 via deseri… wordfence
5b815665-8e2c-4cda-8a77-e8a3e4cb7815
< 5.0.1
HIGH 8.1 The Realtyna Organic IDX plugin plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and includ… wordfence
5b42bca7-6556-46d9-807a-dbae82d96636
< 1.0.16
HIGH 8.1 The Widget for Google Reviews plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and includin… wordfence
← Prev 248 249 250 251 252 253 254 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top