πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,590
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 14, 2026
Last Updated

39,590 vulnerabilities found (page 252 of 1584)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
5b2bcb7e-7248-4b65-9149-b9877de133ce HIGH 8.1 The Exit Game theme for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.4.3. This ma… wordfence
5ac98bf7-0773-4a91-9022-105968481a47 HIGH 8.1 The GoTravel theme for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 2.1. This makes… wordfence
5ac8a125-121c-4392-846e-625726043972
< 7.2.5
HIGH 8.1 The Booster for WooCommerce plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type valida… wordfence
5a98fb59-6bb2-46a4-b56c-6033640af9fa
< 1.1.43.1
HIGH 8.1 The ITok theme for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.1.42. This makes … wordfence
5a806bc8-cff4-47ff-a295-82520c9079e9
< 1.3.0
HIGH 8.1 The Posts in Page plugin for WordPress is vulnerable to Directory Traversal in versions up to, and including, 1.2.4 via … wordfence
5a7609bf-5b20-440c-9984-eeb26962ada8
< 21.8
HIGH 8.1 The Bookly plugin for WordPress is vulnerable to arbitrary file deletion in versions up to, and including, 21.7.1. This … wordfence
5a6bcfa6-7a40-4566-b4d2-62b696ded2d6
< 7.28
HIGH 8.1 The WP Import – Ultimate CSV XML Importer for WordPress plugin for WordPress is vulnerable to arbitrary file deletion … wordfence
5a6980de-29b1-42cd-8b86-2ebe392afb72
< 1.5
HIGH 8.1 The Blanka - One Page WordPress theme for WordPress is vulnerable to Local File Inclusion in versions up to 1.5. This ma… wordfence
5a67e002-f5ef-4edf-9b21-5ea4e0f0d9d7 HIGH 8.1 The Hoverex | Cryptocurrency & ICO Elementor Template Kit theme for WordPress is vulnerable to Local File Inclusion in v… wordfence
5a34fc7b-66e7-4a6b-b351-09deb36bc876 HIGH 8.1 The smart SEO theme for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 2.9. This make… wordfence
5a34d459-7a20-4546-bcef-e320acabee84 HIGH 8.1 The Emberlyn theme for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.3.1. This mak… wordfence
59f68dee-586c-4729-833e-0665954081ff
< 1.3.5
HIGH 8.1 The Remons theme for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.3.4. This makes… wordfence
59f30135-6dd9-4367-90a9-a10ad491357d
< 3.1
HIGH 8.1 The coreActivity: Activity Logging for WordPress plugin for WordPress is vulnerable to PHP Object Injection in all versi… wordfence
59c1b745-7559-4b80-9118-152ee2340c47
< 1.13.5
HIGH 8.1 The 10Web Form Maker plugin before 1.13.5 for WordPress allows CSRF via the wp-admin/admin-ajax.php action parameter, wi… wordfence
5949980f-2506-49be-9105-40ec2d2a4f77
< 6.2.4
HIGH 8.1 The LoginPress Pro plugin for WordPress is vulnerable to Authentication Bypass via Unverified OAuth Email in all version… wordfence
58f52ad6-02d0-4f34-af04-11c00fdcdae7
< 7.8.9
HIGH 8.1 The Link Library plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation … wordfence
58df5dc1-c56a-43ba-ad5a-b700351b42dc HIGH 8.1 The Nuss - Hotel Booking WordPress theme for WordPress is vulnerable to Local File Inclusion in all versions up to, and … wordfence
58b9dab8-8539-4b53-b08d-f6ee3e1e744c
< 2.6.0
HIGH 8.1 The Perfmatters plugin for WordPress is vulnerable to arbitrary file deletion via path traversal in all versions up to, … wordfence
58b54c95-7c5a-4efd-bca4-cbb6341aa5c9
< 1.5.2
HIGH 8.1 The Gravity Forms Salesforce plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including… wordfence
584c65d0-b9c0-4ebc-b68d-36c348bdbd0a HIGH 8.1 The Jack Well theme for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.0.14. This m… wordfence
580ae2da-76f2-42b3-a26c-62ad8d6d1686
< 3.5.31
HIGH 8.1 The ConvertPlus plugin for WordPress is vulnerable to unauthorized modification of data that can lead to a denial of ser… wordfence
57c0f95c-6d5c-4c78-8eff-cbfd9857b62a HIGH 8.1 The Tuning theme for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.3. This makes i… wordfence
57837060-433f-471c-9413-6d9b95b69f2a
< 1.1.90
HIGH 8.1 The Image Slider plugin for WordPress is vulnerable to Arbitrary File Deletion in versions up to, and including, 1.1.89.… wordfence
578001b0-2253-4265-b808-de92dfddc6af HIGH 8.1 The Bonbon theme for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.6. This makes i… wordfence
57599ae1-2a6a-4011-9e6f-824b23891a91 HIGH 8.1 The Winger theme for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.0.16. This make… wordfence
← Prev 249 250 251 252 253 254 255 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top