πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,652
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 15, 2026
Last Updated

39,652 vulnerabilities found (page 261 of 1587)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
3078861b-3a16-4e93-a4f6-5ae885bc0747 HIGH 8.1 The Ads Pro Plugin - Multi-Purpose WordPress Advertising Manager plugin for WordPress is vulnerable to Local File Inclus… wordfence
306a9960-7139-4142-a249-4de2b3c4b985
< 4.0.3
HIGH 8.1 Several MainWP extensions for WordPress are vulnerable to arbitrary file downloads. This makes it possible for authentic… wordfence
302ce1ff-d3ae-4e64-8019-40923275e46b HIGH 8.1 The Wolmart | Multi-Vendor Marketplace WooCommerce Theme theme for WordPress is vulnerable to Local File Inclusion in ve… wordfence
301a67a5-226c-413a-9198-66747d1b1fd3
< 1.7.35
HIGH 8.1 The Login with phone number plugin for WordPress is vulnerable to unauthorized password resets in versions up to, and in… wordfence
2fd67fe3-199b-418c-925e-e2c9e6abe97a HIGH 8.1 The BeeTeam368 Extensions plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1… wordfence
2f9c190b-a52d-45d1-beed-631bf5704cc9
< 1.0.2
HIGH 8.1 The instantva theme for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in a… wordfence
2f72c94f-b0b6-464b-8bc7-df3d75b22edb
< 4.5
HIGH 8.1 The Simple Share Buttons Adder plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and … wordfence
2f479424-3b7f-4c5c-b27f-5b1805909bc7
< 4.1.4
HIGH 8.1 The Houzez theme for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 4.1.1. This makes… wordfence
2f2fcad0-f948-4da5-9bb1-888fc0ced718
< 1.3.8
HIGH 8.1 The Integration for HubSpot and Contact Form 7, WPForms, Elementor, Ninja Forms plugin for WordPress is vulnerable to PH… wordfence
2f2bdf11-401a-48af-b1dc-aeeb40b9a384
< 3.4.2
HIGH 8.1 The News & Blog Designer Pack – WordPress Blog Plugin β€” (Blog Post Grid, Blog Post Slider, Blog Post Carousel, Blog … wordfence
2ecf86ef-6ace-44a8-bfc3-c6ea9def56f8 HIGH 8.1 The VegaDays - Vegetarian Food Festival & Eco Event WordPress Theme theme for WordPress is vulnerable to Local File Incl… wordfence
2e84a1ca-fc82-46bc-a484-89f1235988e8
< 0.0.17
HIGH 8.1 The Password Reset with Code for WordPress REST API plugin for WordPress is vulnerable to Privilege Escalation in all ve… wordfence
2e24844d-df8b-42a8-b7ef-4f4e3a9f1aca HIGH 8.1 The FitFlex theme for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.6. This makes … wordfence
2e1eb00e-432e-4e40-a758-2451648a8a80
< 4.12
HIGH 8.1 The Newsletters plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 4.11 via de… wordfence
2e001cb1-2c50-40dd-83d8-84ec36631c99 HIGH 8.1 The Splendour theme for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.23. This mak… wordfence
2dbaf8a7-e3cc-42c1-9f8b-7eb14363cf8c
< 5.1.2
HIGH 8.1 The WpEvently plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 5.1.1 via des… wordfence
2dbae27d-a7a9-4c5d-8b38-0d4d52cdb579
< 1.3
HIGH 8.1 The Academist theme for WordPress is vulnerable to Local File Inclusion in versions up to 1.3. This makes it possible fo… wordfence
2d4e4f02-3386-4368-81dd-98a2077184c6
< 6.0.12
HIGH 8.1 The AdForest theme for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 6.0.11. This ma… wordfence
2d3de38b-1b03-4e77-9ea9-f6a54b1ab506 HIGH 8.1 The Estate theme for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 1.3.4 via deseria… wordfence
2d22692f-2bc9-4f20-afc0-82085253ddba
< 1.6
HIGH 8.1 The Laurits theme for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 1.5.1 via deseri… wordfence
2ceff609-fc65-43aa-9b73-747940e1d6c2
< 1.3.5
HIGH 8.1 The Kipso theme for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.3.4. This makes … wordfence
2ce5eefe-af48-45f3-9cc4-4a8961344164 HIGH 8.1 The Don Peppe - Pizza and Fast Food WordPress Theme theme for WordPress is vulnerable to Local File Inclusion in version… wordfence
2cdaf6ae-8406-41ff-a80c-9fc9ff3ab6aa HIGH 8.1 The Etude theme for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.6. This makes it… wordfence
2ca17cb9-97c2-421b-8834-157cb8d0211e HIGH 8.1 The Child Themes Helper plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and includin… wordfence
2c30299e-b77f-426b-90d4-33f2dae72a4c HIGH 8.1 The SNS Vicky theme for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 3.7. This make… wordfence
← Prev 258 259 260 261 262 263 264 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top