πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,590
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 14, 2026
Last Updated

39,590 vulnerabilities found (page 254 of 1584)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
50970977-79c7-4014-8f90-a1e6ff47b6f3 HIGH 8.1 The Skyward theme for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.10. This makes… wordfence
5090f734-71f4-44e3-8733-430ab61aca08 HIGH 8.1 The Nuts theme for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.10. This makes it… wordfence
506006ce-7b1c-4f9d-93f3-abc87abea2bb HIGH 8.1 The Frontend File Manager Plugin plugin for WordPress is vulnerable to Authenticated Arbitrary File Deletion in versions… wordfence
502e71ab-9974-45dc-b777-b43bf1c56297 HIGH 8.1 The Pubzinne theme for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.0.12. This ma… wordfence
4ff2088e-c7f8-47e8-8858-f6bf6a801812 HIGH 8.1 The Tourimo theme for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.2.3. This make… wordfence
4feccf0a-983d-4435-9cd6-5f7cb23f41a9 HIGH 8.1 The Rashy theme for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.1.3. This makes … wordfence
4fe1aa29-9f50-4503-9539-c9859e50e753
< 1.13.19
HIGH 8.1 The Geo Mashup plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.13.18. Thi… wordfence
4fd88ad7-e983-4419-8951-30c50969946a HIGH 8.1 The Weedles theme for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.1.12. This mak… wordfence
4fd78299-f71f-473d-9c62-77be9495393f HIGH 8.1 The The Qlean theme for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 2.12. This mak… wordfence
4fb5b208-0443-4d75-902b-8687217e26fd HIGH 8.1 The WP Pipes plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.4.3. This ma… wordfence
4f74991b-8b24-40c0-a550-0f7971e148fb
< 1.2.18
HIGH 8.1 The Hara theme for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.2.17. This makes … wordfence
4f3ee9f6-6465-4caf-9aef-72dd37c61a2c
< 6.2.4
HIGH 8.1 The LoginPress Pro plugin for WordPress is vulnerable to Authentication Bypass via the GitHub OAuth callback in versions… wordfence
4f02ee56-40bd-4132-92e1-e2897ff2a4c4
< 1.7.17
HIGH 8.1 The WPCOM Member plugin for WordPress is vulnerable to authentication bypass via brute force in all versions up to, and … wordfence
4eedc291-7fa3-4c47-8edb-3a3edade96d6
< 1.4.4
HIGH 8.1 The Integration for Salesforce and Contact Form 7, WPForms, Elementor, Formidable, Ninja Forms plugin for WordPress is v… wordfence
4ea2ed8b-b24a-4da2-9ee7-5a3a4a7a4280
< 1.1.2
HIGH 8.1 The Hashthemes Demo Importer Plugin for WordPress contained several AJAX functions which relied on a nonce which was vis… wordfence
4e95b32b-c050-41eb-8fce-461257420eb6
< 3.9.6
HIGH 8.1 The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to Insecure Direct Object Refe… wordfence
4e8e52a7-1f5a-4cc0-81db-9b97b5ea7491 HIGH 8.1 The Victo theme for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.4.16. This makes… wordfence
4e725c3c-3c12-4aa8-a0f8-80b4fbbf0b24
< 1.8.3
HIGH 8.1 The Hitek theme for WordPress is vulnerable to Local File Inclusion in versions up to 1.8.3. This makes it possible for … wordfence
4e4ee98d-695a-4c47-864b-0d60e1691b8a HIGH 8.1 The Agricola theme for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.1.0. This mak… wordfence
4e0f666b-0549-4728-b056-4d59cf262c4b HIGH 8.1 The Seil - A Responsive WordPress Blog Theme theme for WordPress is vulnerable to PHP Object Injection in all versions u… wordfence
4dd62de7-76c6-40aa-ba0b-e227109a9fcb
< 1.10
HIGH 8.1 The Pelicula theme for WordPress is vulnerable to PHP Object Injection in versions up to 1.10 via deserialization of unt… wordfence
4d218a19-6f8c-468d-aad2-90b0f73687b4 HIGH 8.1 The Abelle theme for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.22. This makes … wordfence
4d2034a0-f0d8-418f-8fd9-04e50e5e804e
< 2.1.0
HIGH 8.1 The Subscribe to Download plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 2… wordfence
4cd2a38a-3cd6-40e6-9134-8b9f02d761be
< 1.5.9
HIGH 8.1 The PeakShops theme for WordPress is vulnerable to Local File Inclusion in versions up to 1.5.9. This makes it possible … wordfence
4cc62b7b-9603-4f12-9cb0-9183365822a7 HIGH 8.1 The Store Locator for WordPress with Google Maps – LotsOfLocales plugin for WordPress is vulnerable to Local File Incl… wordfence
← Prev 251 252 253 254 255 256 257 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top