πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,652
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 15, 2026
Last Updated

39,652 vulnerabilities found (page 267 of 1587)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
165d7b45-6f62-4db6-8890-c785d575727c HIGH 8.1 The Pets Club theme for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 2.3 via deseri… wordfence
16505049-4908-4405-aba4-0e2a03fad575 HIGH 8.1 The Green Planet | Environmental Non-Profit WordPress Theme theme for WordPress is vulnerable to Local File Inclusion in… wordfence
15ba1c72-708c-4f8a-9ad8-9741abac63a2 HIGH 8.1 The Unica - Event Planning & Wedding WordPress Theme theme for WordPress is vulnerable to Local File Inclusion in versio… wordfence
154fe2be-5393-4e6b-b113-04f43bd501d9 HIGH 8.1 The Run Gran theme for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 2.0. This makes… wordfence
151753f3-d6b4-443f-bc09-f859dcb56294 HIGH 8.1 The Backup by Supsystic plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 2.3… wordfence
14bc8256-227e-409a-b853-9157416b46ea
< 4.17.1
HIGH 8.1 The Rezgo Online Booking plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including… wordfence
14351561-bd31-4aaa-931a-e72917458013
< 10.0.1
HIGH 8.1 The The Moneytizer plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including… wordfence
135e6916-5350-4495-a4b7-84631c6c5e65 HIGH 8.1 The The Gig theme for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.18.0. This mak… wordfence
1346a475-7057-467a-a88f-9ba6ec690dde HIGH 8.1 The HealthHub theme for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.3.0. This ma… wordfence
12f314c5-ba73-4204-b276-904d9de7c099
< 12.8
HIGH 8.1 The Indeed Membership Pro plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and includin… wordfence
12da096e-35f1-4e44-9425-15a393831139 HIGH 8.1 The Kicker theme for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 2.2.0. This makes… wordfence
12d2f4fd-fa4d-4583-91fb-7a1f2708ad8a HIGH 8.1 The Wabi-Sabi theme for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.2. This make… wordfence
124f4cd0-68a8-4d6c-8112-a3b03e5a49b1 HIGH 8.1 The AeroLand theme for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.6.6. This mak… wordfence
120d6040-1af1-46fd-9a9c-9c0d4c2e3b64
< 4.1.1
HIGH 8.1 The MyHome Core plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 4.1.0. This… wordfence
119f33f6-cc07-48bc-b691-c01242fa01b7 HIGH 8.1 The Basil theme for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.3.12. This makes… wordfence
1199f213-4e1f-47ec-b202-e711f040f64f HIGH 8.1 The Cerebrum theme for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.12. This make… wordfence
1194c11d-948c-4d6c-9cc7-7b0d05d7ce4c
< 2.15.5
HIGH 8.1 The Paid Membership Subscriptions – Effortless Memberships, Recurring Payments & Content Restriction plugin for WordPr… wordfence
10e05707-02cb-42de-8399-4556d76b01b3
< 19.1.5
HIGH 8.1 The Contest Gallery plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 19.1.4.1 due t… wordfence
105783a4-d572-4378-8fdb-e9bbfeb17592
< 1.43
HIGH 8.1 The Moderno theme for WordPress is vulnerable to PHP Object Injection in versions up to 1.43 via deserialization of untr… wordfence
10552714-c8fb-455c-ad61-c0ef2db4b69f HIGH 8.1 The Recover Exit For WooCommerce plugin for WordPress is vulnerable to Local File Inclusion in all versions up to and in… wordfence
103b7db9-1571-4fce-852f-68d5df7ee4ba
< 3.4.2
HIGH 8.1 The wpDataTables – Tables & Table Charts premium WordPress plugin before 3.4.2 has Improper Access Control. A low priv… wordfence
101675ae-88cf-42fc-b9ea-5dd37cdf7464 HIGH 8.1 The WP AUDIO GALLERY plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validat… wordfence
0fc16431-62b3-4d8e-924d-93d06b0fb89a HIGH 8.1 The Tint theme for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.7. This makes it … wordfence
0fb1e5f5-dc27-4d8a-9561-388ef12e4d39 HIGH 8.1 The Gecko theme for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.9.8. This makes … wordfence
0f831d48-733a-4e79-8559-92b03b8d0356 HIGH 8.1 The KD Coming Soon plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.7 … wordfence
← Prev 264 265 266 267 268 269 270 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top