πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,652
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 15, 2026
Last Updated

39,652 vulnerabilities found (page 263 of 1587)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
289b270c-a9d1-4fbb-81d6-edbf662f2661 HIGH 8.1 The Secudeal Payments for Ecommerce plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and in… wordfence
28868ab9-ee2a-4489-ad61-1a18caffead5
< 2.4.4
HIGH 8.1 The WooCommerce Store Toolkit plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and includin… wordfence
28594fe2-e789-4bb3-9085-791a1ebc8d14 HIGH 8.1 The Kelly Young theme for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.1.0. This … wordfence
280cd088-57eb-4c65-9bcd-682987f3cf8e
< 1.0.13
HIGH 8.1 The ChamaWP – Monetize With Donations, Memberships, Crowdfunding, Commissions & Restricted Content plugin for WordPres… wordfence
27e9449a-637f-4ae3-bf48-587dc2f22397
< 2.0.9
HIGH 8.1 The Kiddy theme for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 2.0.8. This makes … wordfence
27c511d7-5b0d-4410-98ab-171232913160 HIGH 8.1 The Amuli theme for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 2.3.0. This makes … wordfence
2794f688-bea1-462d-815c-4d050025e354
< 2.2.5
HIGH 8.1 The Product File Upload for WooCommerce plugin for WordPress is vulnerable to arbitrary file deletion due to insufficien… wordfence
27506ce5-76ef-4c26-a88d-927d9a1a4d7d HIGH 8.1 The N7 | Golf Club Sports & Events theme for WordPress is vulnerable to Local File Inclusion in versions up to, and incl… wordfence
271eb963-96dd-4bbf-81b9-d63c6ba4932e HIGH 8.1 The The Mounty | Hiking Campground & Children Camping WordPress Theme theme for WordPress is vulnerable to Local File In… wordfence
2702c285-b55d-40f0-a0d6-85b2e6f74eb7 HIGH 8.1 The Katelyn theme for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.0.10. This mak… wordfence
26654f89-38ae-480c-9851-08a6bf0f6d84
< 4.1.4
HIGH 8.1 The Houzez Theme - Functionality plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and in… wordfence
262f5d31-1c69-4d0c-a6e6-80acd36de52e
< 1.3.0
HIGH 8.1 The Amwerk theme for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 1.2.0 via deseria… wordfence
261f1522-7857-4414-8c4a-8a89bb433af9
< 1.52.1
HIGH 8.1 The Domnoo theme for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.49. This makes … wordfence
2611fe3a-3991-4dda-80f5-50f00a216c53 HIGH 8.1 The Vocal theme for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.12. This makes i… wordfence
24aadf0c-0266-4c39-ac7b-d6f09053d903
< 3.1.16
HIGH 8.1 An issue was discovered in the CardGate Payments plugin through 3.1.15 for WooCommerce. Lack of origin authentication in… wordfence
249b08c5-7429-4690-9f08-fc3f049aa62c
< 1.9.3
HIGH 8.1 The MaxiBlocks: 2200+ Patterns, 190 Pages, 14.2K Icons & 100 Styles plugin for WordPress is vulnerable to arbitrary file… wordfence
23f53ff1-f0bc-4ad3-9b9e-cf365f064066
< 3.6.0
HIGH 8.1 The Flex Mag - Responsive WordPress News Theme theme for WordPress is vulnerable to unauthorized modification of data th… wordfence
23ece2d6-5eff-4897-ab4b-56443b77fdf0
< 5.1.2
HIGH 8.1 The Employee Spotlight plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 5.1.… wordfence
23c89d9f-8958-4333-8604-54173c31efac
< 1.9.12
HIGH 8.1 The Live2DWebCanvas plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validati… wordfence
23bff566-ec45-4b87-adfd-6e4fade97e9f
< 7.0.11
HIGH 8.1 The Grand Restaurant theme for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 7.0.10 … wordfence
23a95be7-4d23-4595-ae89-48bfcb4c78c5
< 0.9.11
HIGH 8.1 The POEditor plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 0.9.… wordfence
2335533d-c38a-450c-9fa1-0e236b5e92e6
< 1.7
HIGH 8.1 The Reset plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.6. Th… wordfence
22fe2fd1-e0f2-41fb-b96a-99de88416a55 HIGH 8.1 The Anubis theme for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.25. This makes … wordfence
22fb6ed8-18e7-450a-8db0-83c45ac258b6
< 3.2.6
HIGH 8.1 The Traveler theme for WordPress is vulnerable to Local File Inclusion in versions up to 3.2.6. This makes it possible f… wordfence
22e91e0a-052f-4d35-a608-3caf865d2f80
< 1.3
HIGH 8.1 The Valiance theme for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 1.2 via deseria… wordfence
← Prev 260 261 262 263 264 265 266 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top