🛡️ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,590
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 14, 2026
Last Updated

39,590 vulnerabilities found (page 253 of 1584)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
571937a3-46f8-4cbf-a750-4c2fbb1f944b HIGH 8.1 The Legrand theme for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 2.17. This makes… wordfence
57065e04-d61b-49aa-9c2e-4dd911f893a7 HIGH 8.1 The WealthCo theme for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 2.18. This make… wordfence
56cbe0b8-4bf9-40b2-a839-730c1997f6e7
< 1.13.17
HIGH 8.1 The Geo Mashup plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1.13.16.… wordfence
56a93247-f0b5-4801-a759-ef9af11273d7
< 1.1.28
HIGH 8.1 The OttoKit: All-in-One Automation Platform plugin for WordPress is vulnerable to PHP Object Injection in versions up to… wordfence
567ae087-ee60-4530-92f2-4b90340717f9
< 1.3.3
HIGH 8.1 The Exertio theme for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 1.3.2 via deseri… wordfence
567782f9-a050-4e68-9491-e038d7e383f5
< 2.7.3
HIGH 8.1 The basic_settings function in the download manager plugin for WordPress before 2.7.3 allows remote authenticated users … wordfence
56551a19-b89b-402d-bb77-994198b6f03e
< 1.0.22
HIGH 8.1 The Booktics plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 1.0.21 via des… wordfence
561f9561-0aa2-490c-b0fa-8731dfb6a145 HIGH 8.1 The uReach theme for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.3.3. This makes… wordfence
55666498-be5c-45e8-9230-b5d79d720a1e HIGH 8.1 The SevenTrees theme for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.0.2. This m… wordfence
5542fd84-bb92-4aa9-b161-fa86b45e0a1e
< 1.9
HIGH 8.1 The Töbel - Modern Furniture Store WordPress Theme theme for WordPress is vulnerable to PHP Object Injection in version… wordfence
553224f0-0c09-42bb-bfec-e257ef26c914
< 1.1.8
HIGH 8.1 The Blogmine theme for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.1.7. This mak… wordfence
54ee0f45-6b92-4fa7-80dd-faab4e555e54 HIGH 8.1 The Katerio - Magazine theme for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.5.1… wordfence
548b2c50-251a-431c-a23f-95bbd50dbad5
< 7.1.3
HIGH 8.1 The Broadcast Live Video – Live Streaming : WebRTC, HLS, RTSP, RTMP plugin for WordPress is vulnerable to PHP Object I… wordfence
5341f18f-9d28-4e7d-8348-c9452ea1b5a6 HIGH 8.1 The Quirky theme for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.23. This makes … wordfence
53279e06-8561-47cf-8786-fed21f090530 HIGH 8.1 The Töbel theme for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.6. This makes i… wordfence
5323dbb7-3893-4b43-838b-6326505b2fb7
< 1.3.0
HIGH 8.1 The eMagicOne Store Manager for WooCommerce plugin for WordPress is vulnerable to arbitrary file uploads due to missing … wordfence
531662ac-26bd-41a5-8eeb-03bfafad2b7c HIGH 8.1 The Assembly theme for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.1. This makes… wordfence
52cbc6a4-9825-4b26-8653-0c75cf5247c5
< 1.4.108
HIGH 8.1 The Motors – Car Dealership & Classified Listings Plugin plugin for WordPress is vulnerable to arbitrary file deletion… wordfence
52aade31-7f27-49e3-9d29-5650a1c87bba HIGH 8.1 The Luxury Wine theme for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.1.14. This… wordfence
5215d2aa-60e8-4872-b518-039e6e0d9eed HIGH 8.1 The Equestrian Centre theme for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 1.5 vi… wordfence
51b0c452-481e-409d-81cd-f1498ed6a331 HIGH 8.1 The Anchor smooth scroll plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.… wordfence
518abad2-d3cc-4d15-83d2-8fd99d30500c
< 2.3.12
HIGH 8.1 The Premium Portfolio Features for Phlox theme plugin for WordPress is vulnerable to Local File Inclusion in all version… wordfence
512f68c0-3041-44b0-86de-b3e640cf5055
< 3.8.10.1
HIGH 8.1 The JetEngine plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 3.8.10 via de… wordfence
50e6cfc9-840d-4447-a505-49a1a3bb42d2
< 1.1.5
HIGH 8.1 The Trendustry theme for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.1.4. This m… wordfence
50ce2a61-9a56-4994-b270-3c79be832411
< 1.2.6
HIGH 8.1 The Nestin theme for WordPress is vulnerable to PHP Object Injection in versions up to 1.2.6 via deserialization of untr… wordfence
← Prev 250 251 252 253 254 255 256 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top