πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,590
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 14, 2026
Last Updated

39,590 vulnerabilities found (page 257 of 1584)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
43ec70b1-dfb7-4218-93cc-7d491e407e39 HIGH 8.1 The Good Energy theme for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 1.7.7 via de… wordfence
43bcf3ab-4201-4a61-82c5-2dc60b684989
< 6.8.1
HIGH 8.1 The Simple:Press plugin for WordPress is vulnerable to Path Traversal in versions up to, and including, 6.8 via the 'fil… wordfence
43adc9dd-1780-440f-90c2-ff05a22eb084
< 5.7.1
HIGH 8.1 The MP3 Audio Player – Music Player, Podcast Player & Radio by Sonaar plugin for WordPress is vulnerable to unauthoriz… wordfence
439032cc-41aa-4a4b-bdd6-7febb8696b80 HIGH 8.1 The North theme for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 5.7.5. This makes … wordfence
437275af-42c9-4064-a744-e2108c017d02 HIGH 8.1 The Adrena | Airsoft Club & Paintball WordPress Theme theme for WordPress is vulnerable to PHP Object Injection in versi… wordfence
4327f414-64f4-4193-a5c0-2a5ecdd75e11
< 14.2.1
HIGH 8.1 The BuddyPress plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 14.1.0 vi… wordfence
42dcc302-b543-42c7-99fa-605f017beb1a
< 1.4.0
HIGH 8.1 The LC Wizard plugin for WordPress is vulnerable to Privilege Escalation due to a missing capability check in the ghl-wi… wordfence
426ea88f-bdd4-4da6-88c2-db82df9e01e5
< 2.6.2
HIGH 8.1 An issue was discovered in the IMPress for IDX Broker plugin before 2.6.2 for WordPress. wrappers.php allows a logged-in… wordfence
418747c5-1c18-46e4-b15c-4815e7397cf2
< 20.8.8
HIGH 8.1 The Client Invoicing by Sprout Invoices plugin for WordPress is vulnerable to PHP Object Injection in versions up to, an… wordfence
4169b390-0972-4aa9-ae04-f5f67afe15ef
< 1.5.2
HIGH 8.1 The Database for Contact Form 7, WPforms, Elementor forms plugin for WordPress is vulnerable to arbitrary file deletion … wordfence
4111e878-d68e-461f-94b8-fb85ddf33914 HIGH 8.1 The Femme theme for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.3.11. This makes… wordfence
40ec1ec5-9a8a-431b-bf6b-d7f23157403a HIGH 8.1 The Craftis - Handcraft & Artisan Elementor Template Kit theme for WordPress is vulnerable to Local File Inclusion in ve… wordfence
40c1ff8f-5498-4542-ad3d-e0d44ebc62ce
< 1.4
HIGH 8.1 The Gracey theme for WordPress is vulnerable to PHP Object Injection in versions up to 1.4 via deserialization of untrus… wordfence
3ff73a18-cb00-4e35-afcf-d1a0ae586a4c HIGH 8.1 The Dermatology Clinic theme for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.4.3… wordfence
3fc4793e-cda0-475e-8cab-411f19c46594 HIGH 8.1 The A-Mart theme for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.0.2. This makes… wordfence
3f1770dc-e473-438c-9732-b51cff57c796 HIGH 8.1 The Renewal theme for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.2.2. This make… wordfence
3eb67a46-49de-40c2-bbac-87f662f98d16 HIGH 8.1 The Verdure - Organic Tea Shop WordPress Theme theme for WordPress is vulnerable to Local File Inclusion in versions up … wordfence
3eb3533c-e33c-41db-b9cf-e9d71a0a5588 HIGH 8.1 The Catalog Importer, Scraper & Crawler plugin for WordPress is vulnerable to PHP code injection in all versions up to, … wordfence
3eb1f22d-e729-41c6-9235-47aa19da2fff HIGH 8.1 The Good Homes theme for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.3.13. This … wordfence
3e5a7741-d8be-400e-ac00-138034580d6e HIGH 8.1 The Right Way theme for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 4.0. This make… wordfence
3e21b550-e1c5-4e23-9999-16c837353da9
< 2.5.3
HIGH 8.1 The Database Backup for WordPress plugin for WordPress is vulnerable to unauthorized arbitrary file read and deletion in… wordfence
3de5c591-89ea-4289-a874-239864bcc886 HIGH 8.1 The Pinevale theme for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.0.14. This ma… wordfence
3dc3b715-23eb-4cb9-8f44-1d3134c560ec
< 1.3.56
HIGH 8.1 The Royal Elementor Addons plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and inclu… wordfence
3d94ffdb-d5e1-4125-b499-5e47f9f67069 HIGH 8.1 The Zuut theme for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 1.4.2 via deseriali… wordfence
3d7b5b50-ea6e-4f9e-bd7b-7682469c63b9
< 7.1.6
HIGH 8.1 The Total processing card payments for WooCommerce plugin for WordPress is vulnerable to Path Traversal in all versions … wordfence
← Prev 254 255 256 257 258 259 260 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top