πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,652
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 15, 2026
Last Updated

39,652 vulnerabilities found (page 264 of 1587)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
22d8f1db-1b7e-4b68-a381-01f51dd34b2b
< 1.9.33
HIGH 8.1 The Vikinger theme for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in th… wordfence
2249ef72-9955-4636-b32f-e88720923268
< 8.4.9
HIGH 8.1 The Directorist: AI-Powered Business Directory Plugin with Classified Ads Listings plugin for WordPress is vulnerable to… wordfence
21e397a4-0b32-4b13-a46b-c465acea0796
< 6.7.26
HIGH 8.1 The WCFM – Frontend Manager for WooCommerce along with Bookings Subscription Listings Compatible plugin for WordPress … wordfence
21869bed-4678-4091-a0c5-cafd2306c207 HIGH 8.1 The Holmes - Digital Agency WordPress Theme theme for WordPress is vulnerable to Local File Inclusion in versions up to,… wordfence
217cc880-8400-4a97-a024-7b55e6ab69dd
< 3.26.7
HIGH 8.1 The Wishlist Member plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validati… wordfence
217445a3-5abf-4690-88f1-ba8822392424 HIGH 8.1 The Struktur theme for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 2.5.1. This mak… wordfence
213aa9cf-5d3b-485a-997d-583a46053b4f
< 3.47
HIGH 8.1 The Goldish theme for WordPress is vulnerable to PHP Object Injection in versions up to 3.47 via deserialization of untr… wordfence
213a67d3-3670-490b-bcee-cd29867fa217 HIGH 8.1 The FreightCo theme for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.1.7. This ma… wordfence
21291ed7-cdc0-4698-9ec4-8417160845ed
< 4.2.5.8
HIGH 8.1 The LearnPress plugin for WordPress is vulnerable to Command Injection in all versions up to, and including, 4.2.5.7 via… wordfence
20f461d1-aeb2-4913-804c-6a081e48765a
< 2.1.3
HIGH 8.1 The Inspiro theme for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.1.2.… wordfence
20c50747-6b87-46d4-8232-597509a3b70f HIGH 8.1 The GlamChic theme for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.0.11. This ma… wordfence
203ba9ca-2054-465f-ad93-ff103cade8aa
< 3.4.2
HIGH 8.1 The wpDataTables – Tables & Table Charts premium WordPress plugin before 3.4.2 has Improper Access Control. A low priv… wordfence
202a8493-6df0-4a5e-b6bf-099219830e01
< 3.6.33
HIGH 8.1 The My auctions allegro plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including,… wordfence
200229af-06c5-42a2-a1ed-7763279fc794 HIGH 8.1 The Extensive VC Addons for WPBakery page builder plugin for WordPress is vulnerable to Local File Inclusion in versions… wordfence
1ffd28cb-6e70-447b-958d-f325b6226a22 HIGH 8.1 The A.Williams plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.3.1 vi… wordfence
1fe1582c-d48a-437e-93bd-6ae2e5aec3e3
< 2.1.3
HIGH 8.1 The Alloggio - Hotel Booking WordPress Theme theme for WordPress is vulnerable to PHP Object Injection in versions up to… wordfence
1fd359f8-1622-4883-b161-d50056cf9c03 HIGH 8.1 The Crown Art | Drawing and Music School WordPress Theme theme for WordPress is vulnerable to Local File Inclusion in ve… wordfence
1f862ed1-007b-48ac-bb39-be7648e0b48a HIGH 8.1 The TopFit - Fitness and Gym WordPress theme for WordPress is vulnerable to Local File Inclusion in versions up to, and … wordfence
1f6e9583-ca67-469c-a665-590a2e7e2a6f HIGH 8.1 The MinimogWP theme for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 3.9.6. This ma… wordfence
1f6dd110-b81f-4a99-8108-82911530b801
< 1.55.1
HIGH 8.1 The Famita theme for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.54. This makes … wordfence
1f6b4d46-dd5e-4dbf-b168-9423bef1c1fb HIGH 8.1 The Consultor | A Business Financial Advisor PSD Template theme for WordPress is vulnerable to Local File Inclusion in v… wordfence
1f4b45f6-8b6e-49f5-84e4-511431aef2c2 HIGH 8.1 The Ingenioso theme for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.14.0. This m… wordfence
1f36f0d8-4510-4d94-b8e5-5a3d98b0a8b4
< 1.1.7
HIGH 8.1 The Integration for Constant Contact and Contact Form 7, WPForms, Elementor, Ninja Forms plugin for WordPress is vulnera… wordfence
1f21f3b1-920b-415b-bd93-27eb2be5de19
< 5.25
HIGH 8.1 The KIDZ theme for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 5.24 via deserializ… wordfence
1f21b4d7-3893-4838-8c0e-768c66746700
< 1.5.6
HIGH 8.1 The Tripgo theme for WordPress is vulnerable to Local File Inclusion in versions up to, and excluding, 1.5.6. This makes… wordfence
← Prev 261 262 263 264 265 266 267 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top