πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,590
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 14, 2026
Last Updated

39,590 vulnerabilities found (page 256 of 1584)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
48ba51f0-5ae6-4aa0-a7fc-40264ada7998
< 2.5.7
HIGH 8.1 The CMSMasters Content Composer plugin for WordPress is vulnerable to Local File Inclusion in versions up to 2.5.7. This… wordfence
4849dc51-766d-43b8-ae3a-876798969177
< 1.2.2
HIGH 8.1 The Integration for Keap/infusionsoft and Contact Form 7, WPForms, Elementor, Formidable, Ninja Forms plugin for WordPre… wordfence
48285f43-3ee2-4b6b-a12d-ac96618da7b8
< 2.2
HIGH 8.1 The NaturaLife Extensions plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 2… wordfence
47ed52b3-4bfe-46ce-aabc-7a4647ab7db5
< 3.12.28
HIGH 8.1 The Easy Appointments plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capabilit… wordfence
47b0be04-c4ff-4a20-8880-ab40fa7a11c3
< 3.2.1
HIGH 8.1 The Powerlift theme for WordPress is vulnerable to Local File Inclusion in versions up to 3.2.1. This makes it possible … wordfence
471527e8-8a72-49dd-9dff-27fb8300ce6a
< 1.6
HIGH 8.1 The SingleMalt theme for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 1.5 via deser… wordfence
46fdd494-8073-4a68-a4ab-1f5767011f67
< 1.1.0
HIGH 8.1 The package simple-git is vulnerable to Remote Code Execution in versions before 3.16.0 via the clone(), pull(), push() … wordfence
46edd7fd-1a28-4cd3-89df-d5cb0ba16540
< 4.2.0
HIGH 8.1 The Houzez theme for WordPress is vulnerable to Local File Inclusion in versions up to 4.2.0. This makes it possible for… wordfence
46e4b441-651b-4755-a440-1a4496f5c79e HIGH 8.1 The S.King theme for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.5.3. This makes… wordfence
46e49743-7609-46bb-ba5b-d2751dd77021
< 1.4
HIGH 8.1 The Roisin theme for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.2.1. This makes… wordfence
46c5d4ba-8c88-4b63-bafa-9d5afc37a7e0 HIGH 8.1 The Fabric theme for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.5.0. This makes… wordfence
466ff226-a47e-46f1-a46c-6260208ffd42
< 1.8
HIGH 8.1 The Registration Forms – User Registration Forms, Invitation-Based Registrations, Front-end User Profile, Login Form … wordfence
466568c5-33a9-4891-b4ad-9bc6052603cb HIGH 8.1 The Wptobe-memberships plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path valid… wordfence
464e64f8-de64-4a49-afd3-43142793c24d
< 2.0.2
HIGH 8.1 The Top Bar – PopUps – by WPOptin plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, … wordfence
462d6d01-ce4c-4c76-932a-6466f9a8d807
< 4.1.3
HIGH 8.1 The LearnPress Export Import plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including… wordfence
461ae519-413f-4ccd-82bb-5e50e6bfbaf3 HIGH 8.1 The Snow Club theme for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.1. This make… wordfence
45ccf71d-3853-43f3-afe9-61984eed73b0 HIGH 8.1 The Dharma Booking plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 2.28.3. … wordfence
45c8d883-1f97-4c9d-b406-c61e33a0959e HIGH 8.1 The WP Foodbakery plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation… wordfence
458f8d67-3395-4db1-8653-59550131c4bf HIGH 8.1 The CasaMia | Property Rental Real Estate WordPress Theme theme for WordPress is vulnerable to Local File Inclusion in v… wordfence
45647fa6-a98d-4eb4-a287-f523e434688b
< 4.4.5
HIGH 8.1 The AppPresser – Mobile App Framework plugin for WordPress is vulnerable to privilege escalation via account takeover … wordfence
45494716-b9d4-462a-808a-c10f01aa0eb0
< 1.1.11
HIGH 8.1 The Premmerce Wishlist for WooCommerce plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and… wordfence
4508d3a9-cf3e-4fc6-8788-a62942100d1a HIGH 8.1 The Critique theme for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.17. This make… wordfence
44fcc1c1-3a22-4ac8-923e-5c56c14e3dab
< 1.2.1
HIGH 8.1 The Ippsum theme for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 1.2.0 via deseria… wordfence
44ea3322-10f6-4f52-8fa8-8cc2632b67ce
< 2.7.3
HIGH 8.1 The myCred – Loyalty Points and Rewards plugin for WordPress and WooCommerce – Give Points, Ranks, Badges, Cashback,… wordfence
44be9f20-4800-4d3f-bd0b-e8d0b8eaaadf
< 1.9.1
HIGH 8.1 The CozyStay theme for WordPress is vulnerable to Local File Inclusion in versions up to 1.9.1. This makes it possible f… wordfence
← Prev 253 254 255 256 257 258 259 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top