πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,652
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 15, 2026
Last Updated

39,652 vulnerabilities found (page 266 of 1587)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
1a3056b4-06ab-430b-9c67-b915d6cbaf06
< 2.0
HIGH 8.1 The Cortex theme for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.9. This makes i… wordfence
1a1c4f7a-bd24-4ccc-9f4c-98341e7edfed HIGH 8.1 The Manufactory theme for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.4. This ma… wordfence
1a0fa7f6-cc1a-45fe-881d-694c81b841c7
< 19.1.5.1
HIGH 8.1 The Contest Gallery plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 19.1.5 due to … wordfence
1a0b2d5f-688e-44d7-8fa1-2fb4e49e048c HIGH 8.1 The WordPress User Extra Fields plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file p… wordfence
19e9d1bb-bbdf-473d-8479-0656834c278a HIGH 8.1 The Maxify theme for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.0.16. This make… wordfence
19617191-be47-4067-b53d-cd3f2ba51698 HIGH 8.1 The Ludos Paradise theme for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 2.1.3. Th… wordfence
194ee4a0-87c3-42e5-9676-8dd355838b78
< 5.1.1
HIGH 8.1 The MW WP Form plugin for WordPress is vulnerable to arbitrary file moving due to insufficient file path validation via … wordfence
19336fd5-a974-442b-baac-3101b38d6a20 HIGH 8.1 The Eona theme for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.3. This makes it … wordfence
1928f8e4-8bbe-4a3f-8284-aa12ca2f5176
< 7.2.2
HIGH 8.1 The File Manager plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and includi… wordfence
1921371f-5d07-4288-8e8e-d5f43c619357
< 1.5
HIGH 8.1 The Emaurri theme for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.0.1. This make… wordfence
191a98c7-ea37-48a7-b04b-c0941fa0b22a HIGH 8.1 The Rosaleen theme for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 2.8. This makes… wordfence
18c80a60-55d5-4a71-932d-a10b2fb328ce
< 1.5.5
HIGH 8.1 The Gutenify plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.5.4. This ma… wordfence
18c0673c-5e49-4324-a4fc-ae74f64cba94 HIGH 8.1 The Optimize Your Campaigns – Google Shopping – Google Ads – Google Adwords plugin for WordPress is vulnerable to … wordfence
18a7c676-0d88-4492-abc9-150592c80ecf HIGH 8.1 The shop plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 2.6.1. This makes … wordfence
18779761-66fd-437f-a8e3-7ee1b6e36dc7 HIGH 8.1 The Palladio theme for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.1.10. This ma… wordfence
1867be0d-c91a-47a4-a5f2-4948749cfeaf
< 2.5.9.3
HIGH 8.1 The Participants Database plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and includin… wordfence
18112fac-8674-408a-bc65-1513abed1747
< 24.07.04
HIGH 8.1 The Docket Cache plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 24.07.03. … wordfence
17dd0477-daa8-4c51-a40e-44fba62b2d7c
< 8.0.5
HIGH 8.1 The KBx Pro Ultimate plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validat… wordfence
17d4002d-3e87-46a7-9be6-c36e40c31c4a
< 3.0.0
HIGH 8.1 The run_action function of the Facebook for WordPress plugin before 3.0.0 deserializes user supplied data making it poss… wordfence
178b2493-dee3-47ef-9e61-c1d832c33518 HIGH 8.1 The Festy theme for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.13.0. This makes… wordfence
17735732-a6c4-4d84-8b8c-c1730b887e8f
< 7.7.0
HIGH 8.1 The WordPress Social Login and Register plugin for WordPress is vulnerable to Local File Inclusion in versions up to, an… wordfence
17150f49-8a03-4834-b8e0-275599a0e406
< 1.0.10
HIGH 8.1 The Magze theme for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.0.9. This makes … wordfence
170c9eba-9593-4e35-b663-b2d4fad85060 HIGH 8.1 The Moments theme for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 2.2. This makes … wordfence
169d8cd5-0dee-45d1-b5e2-6fd2bc0973c4 HIGH 8.1 The Etchy theme for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.0. This makes it… wordfence
16763837-2bcb-4b7a-9f2d-4855ea277b64 HIGH 8.1 The Everest Forms - Frontend Listing plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and i… wordfence
← Prev 263 264 265 266 267 268 269 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top