πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,590
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 14, 2026
Last Updated

39,590 vulnerabilities found (page 255 of 1584)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
4cb1c945-230c-4d53-b69d-c0cb5c2816c0 HIGH 8.1 The Sofass theme for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.3.4. This makes… wordfence
4c8f2c6f-c231-477c-895b-df892569ef95
< 0.1.0.86
HIGH 8.1 The InstaWP Connect – 1-click WP Staging & Migration plugin for WordPress is vulnerable to Local File Inclusion in all… wordfence
4c5b3685-881f-49e8-b551-c29cbd73c4c8 HIGH 8.1 The Celeste theme for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 1.3.6 via deseri… wordfence
4c44c36a-c4c7-49c2-b750-1589e7840dde
< 4.3.0
HIGH 8.1 The AppPresser plugin for WordPress is vulnerable to unauthorized password resets in versions up to, and including 4.2.5… wordfence
4c20791e-924f-48d9-befc-98c995168bbf HIGH 8.1 The Translogic theme for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.2.11. This … wordfence
4be6b66b-1868-467b-a48e-1721b753e9fe HIGH 8.1 The Plumbing theme for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 1.6 via deseria… wordfence
4bcf82bb-3606-4fdc-9dc0-cdba93d650b1 HIGH 8.1 The Hope theme for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 3.0.0. This makes i… wordfence
4bc15539-d816-4873-9684-862c7c9fcda7
< 1.6.27
HIGH 8.1 The weForms – Easy Drag & Drop Contact Form Builder For WordPress plugin for WordPress is vulnerable to PHP Object Inj… wordfence
4b71b187-2e05-4bea-9177-cbf66fe08a44
< 4.6.0.3
HIGH 8.1 An issue was discovered in the RegistrationMagic plugin 4.6.0.2 for WordPress. There is SQL injection via the rm_analyti… wordfence
4b4d3454-c83f-4a13-9764-163c53ede744 HIGH 8.1 The RexCoin theme for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.2.6. This make… wordfence
4ab9d7e9-9a81-48f8-bc37-ad6de43a566f
< 4.2.5
HIGH 8.1 The Dokan: AI Powered WooCommerce Multivendor Marketplace Solution – Build Your Own Amazon, eBay, Etsy plugin for Word… wordfence
4a689b45-b29e-4807-9146-c900332f5946
< 2.1.5
HIGH 8.1 The Feedy theme for WordPress is vulnerable to Local File Inclusion in versions up to 2.1.5. This makes it possible for … wordfence
4a6492c8-19f0-4a97-bc17-f8ece14b7cba
< 7.7.5
HIGH 8.1 The Photography theme for WordPress is vulnerable to Local File Inclusion in versions up to 7.7.5. This makes it possibl… wordfence
4a0f77ca-2fb5-4e73-a0fa-dfbeb39fbd84
< 3.5.29
HIGH 8.1 The WP User Frontend plugin for WordPress is vulnerable to privilege escalation due to the default user role checking on… wordfence
49e7b85d-3bd4-4cbf-92b9-cd338a470c89 HIGH 8.1 The EasyEat theme for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.9.0. This make… wordfence
49b464ae-538e-4d12-a125-23e75e075b32 HIGH 8.1 The Frame theme for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 2.4.0. This makes … wordfence
49a935cc-7b95-4abd-9a4d-c7e14c765863 HIGH 8.1 The WordPress Helpdesk Integration plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and… wordfence
4990bb50-f9b4-46a4-adb5-a60502cece29
< 3.2.6
HIGH 8.1 The MaxCoach theme for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 3.2.5. This… wordfence
49711408-5d04-4fdd-a6c4-b224959ba1bc HIGH 8.1 The Extensive VC Addons for WPBakery page builder plugin for WordPress is vulnerable to Local File Inclusion in all vers… wordfence
4963053a-e63a-4e7b-bb72-f3defd0f16a6 HIGH 8.1 The Myour theme for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.5.1. This makes … wordfence
4941a0ce-67f1-430d-bbad-3c97a4ed449e HIGH 8.1 The Pie Forms for WP plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 1… wordfence
4921f41a-a9b1-4ae2-a903-c14ed22dcc15
< 2.3.7.2
HIGH 8.1 The Swift Performance Lite plugin for WordPress is vulnerable to Local PHP File Inclusion in all versions up to, and inc… wordfence
4902d71e-77b2-460e-b994-4d07dabf9fff HIGH 8.1 The Plank theme for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.7. This makes it… wordfence
48dd9098-38e6-49da-8d22-27e12fddef51
< 2.0
HIGH 8.1 The Import and export users and customers plugin for WordPress is vulnerable to privilege escalation in all versions up … wordfence
48d9f8a1-fa25-4026-97bc-43ccb9413bd0 HIGH 8.1 The Eject theme for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 2.17. This makes i… wordfence
← Prev 252 253 254 255 256 257 258 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top