🛡️ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,652
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 15, 2026
Last Updated

39,652 vulnerabilities found (page 259 of 1587)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
3bfafa37-b28f-4951-9741-46046fb11a15
< 3.12.0
HIGH 8.1 The Funnel Builder by FunnelKit plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and includ… wordfence
3bdd726e-d67b-4fed-bfa4-6002521942a5 HIGH 8.1 The My Album Gallery plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validat… wordfence
3bce9b64-29b4-4eb0-a02e-9f751c88f4be
< 2.2.5
HIGH 8.1 The Premmerce Product Search for WooCommerce plugin for WordPress is vulnerable to Local File Inclusion in versions up t… wordfence
3ba8bc04-ac35-4799-ac02-556c1cd07293 HIGH 8.1 The Truemag theme for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 4.3.14.2. This m… wordfence
3a9fd0d5-5681-4c54-8d2e-c76ce80e5e55 HIGH 8.1 The SeaFood Company theme for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 1.4 via … wordfence
3a657b85-b4e2-4f97-90cf-b170f0184304 HIGH 8.1 The Printo theme for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.11. This makes … wordfence
3a0faf14-77bf-4776-8685-12a348a4a6c8
< 4.1.1
HIGH 8.1 The MainWP File Uploader Extension for WordPress is vulnerable to arbitrary file download. This makes it possible for au… wordfence
3a00980c-2d27-4363-acad-ed9d1e7e37b2
< 4.5.4
HIGH 8.1 The OMGF WordPress plugin before 4.5.4 does not enforce path validation, authorisation and CSRF checks in the omgf_ajax_… wordfence
3923c732-80b5-4a04-80dd-b4d5b5e5567d
< 7.19.1
HIGH 8.1 The Import Export Suite for CSV and XML Datafeed plugin for WordPress is vulnerable to arbitrary file deletion due to in… wordfence
38f95d40-a6d4-429c-9872-9d2531e942eb
< 1.3.9.8
HIGH 8.1 The Drag and Drop Multiple File Upload for Contact Form 7 plugin for WordPress is vulnerable to arbitrary file upload in… wordfence
38ea5328-f728-45de-8edd-80fd400f0902
< 1.3
HIGH 8.1 The Valeska theme for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 1.2.2 via deseri… wordfence
38db0ebd-681c-41a7-b3a9-daf7a9c5eb65 HIGH 8.1 The Granola theme for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.13. This makes… wordfence
38c23f59-8332-49ab-a219-1f5fac8a283c HIGH 8.1 The hiWeb Export Posts plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and inclu… wordfence
38b37788-1c41-4410-a830-1f5fdbb34835 HIGH 8.1 The Love Story theme for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 1.3.12 via de… wordfence
3853f4b7-dfac-454c-857d-c5929d4adb36 HIGH 8.1 The Vango theme for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.3.3. This makes … wordfence
37ca7081-df1f-4f2e-bb52-7cb87f74fb5d
< 1.0.5
HIGH 8.1 The Product Stock Manager plugin for WordPress is vulnerable to authorization bypass due to missing capability checks on… wordfence
377b1964-2b7c-42c4-954e-25b1cc61c074
< 1.7.0
HIGH 8.1 The Kapee theme for WordPress is vulnerable to PHP Object Injection in versions up to 1.7.0 via deserialization of untru… wordfence
37698746-f825-4e8c-8a72-f483aae898d4
< 2.3
HIGH 8.1 The Malmö theme for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 2.2. This makes i… wordfence
374e91a3-a02a-40b9-b5f0-4bcbd7faa537 HIGH 8.1 The AnyComment plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 0.3.6. This … wordfence
36c97e15-1935-4390-b742-d21bd7870dee HIGH 8.1 The Consult Aid theme for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 1.4.3 via de… wordfence
36c6a116-37cc-4ade-b601-5f9d6aaf9217
< 1.2.14
HIGH 8.1 The WooCommerce Add to Cart Custom Redirect plugin for WordPress is vulnerable to unauthorized modification of data and … wordfence
35fc9a16-3775-48c0-82af-692974f54c33
< 1.4.1
HIGH 8.1 The Easy!Appointments plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check … wordfence
35822026-8db8-458b-a304-6b5363346861 HIGH 8.1 The FitLine theme for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.6. This makes … wordfence
35724a49-cdd0-445d-8570-ae6a042f2b4b HIGH 8.1 The Spike theme for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.2. This makes it… wordfence
354a5b89-8845-4486-8cc5-7339a6a107c0
< 2.6.2
HIGH 8.1 WordPress before 2.6.2 does not properly handle MySQL warnings about insertion of username strings that exceed the maxim… wordfence
← Prev 256 257 258 259 260 261 262 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top