ðŸ›¡ï¸ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,652
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 15, 2026
Last Updated

39,652 vulnerabilities found (page 269 of 1587)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
08d4bf7e-fae9-4be6-9e97-e8b6532523ff
< 3.0.23
HIGH 8.1 Path Traversal and Unrestricted File Upload exists in the Ninja Forms plugin before 3.0.23 for WordPress (when the Uploa… wordfence
08d2d4cc-b349-4a91-8a38-b0c305627ac0 HIGH 8.1 The Triompher | Golf Course & Sports Club WordPress Theme theme for WordPress is vulnerable to Local File Inclusion in v… wordfence
08a15d7d-a7e6-4742-b02d-d74aa1d09550 HIGH 8.1 The Snow Mountain theme for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.4.3. Thi… wordfence
089cde8a-2896-4e4c-90c1-30605ccc919d
< 6.10.2
HIGH 8.1 Vulnerable versions of the Jupiter and JupiterX Themes allow logged-in users, including subscriber-level users, to perfo… wordfence
0886a451-319f-4678-b8a1-abb7faf11804 HIGH 8.1 The Buzz Stone | Magazine & Viral Blog WordPress theme for WordPress is vulnerable to Local File Inclusion in versions u… wordfence
07bb17bd-c534-4b11-a1dd-7d2f2786ffec
< 4.1.9
HIGH 8.1 The Meow Gallery WordPress plugin before 4.1.9 does not sanitise, validate or escape the ids attribute of its gallery sh… wordfence
078d66c5-dc99-43d6-bba1-afcbf857b450 HIGH 8.1 The Lymcoin theme for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.3.12. This mak… wordfence
0747bba7-01fa-4d70-a419-2732cd25a9ad HIGH 8.1 The Abogado - Lawyer WordPress Theme theme for WordPress is vulnerable to PHP Object Injection in versions up to, and in… wordfence
073f1c3b-638a-4d83-9dd2-6fc07e164b21 HIGH 8.1 The Hanani theme for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.2.11. This make… wordfence
06de719e-edee-42f2-b715-efcf98fffea6
< 1.2.1
HIGH 8.1 The Amfissa theme for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.1. This makes … wordfence
06862d82-fc24-4433-bd73-3139c5394be9
< 1.3
HIGH 8.1 The Kamperen - Camping and Adventure Tourism WordPress Theme theme for WordPress is vulnerable to PHP Object Injection i… wordfence
06838a3f-5291-4950-be80-4a2391d9276f HIGH 8.1 The Fribbo theme for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.1.0. This makes… wordfence
067c974c-b3bb-4f06-8f7c-3963112c40d2
< 24.5.0
HIGH 8.1 The WooCommerce Recover Abandoned Cart plugin for WordPress is vulnerable to PHP Object Injection in all versions up to,… wordfence
06614b39-392b-46c0-969c-99dde4dbd042
< 1.0.10
HIGH 8.1 The Blogprise theme for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.0.9. This ma… wordfence
060f7e19-072a-486e-9d6c-df73ee63078f HIGH 8.1 The Equadio theme for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.1.3. This make… wordfence
05f87510-28c3-4ad1-b2be-2408a199cf68
< 2.4.4
HIGH 8.1 The Homey theme for WordPress is vulnerable to authentication bypass in versions up to, and including, 2.4.3. This is du… wordfence
05db21e4-9c51-4d66-8f40-c0afacfb9728 HIGH 8.1 The Issabella theme for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.1.2. This ma… wordfence
05c4eece-6f4c-4a19-8eea-f6d82f3bcb14 HIGH 8.1 The Artrium theme for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.0.14. This mak… wordfence
05a27a34-b324-4968-937e-2c0d24175d2a
< 1.0.3
HIGH 8.1 The WooCommerce Purchase Orders plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file p… wordfence
0591afc1-58b2-4afb-bd7d-e0707fd1f62f
< 1.3.0
HIGH 8.1 The Goldenblatt theme for WordPress is vulnerable to PHP Object Injection in versions up to 1.3.0 via deserialization of… wordfence
05873114-ceed-404c-9cc2-d85aa92ef6f3
< 3.7.5
HIGH 8.1 WordPress before 3.7.5, 3.8.x before 3.8.5, 3.9.x before 3.9.3, and 4.x before 4.0.1 might allow remote attackers to obt… wordfence
0563f873-994d-47ab-a7b9-e85d1bc97f9e HIGH 8.1 The Coworking theme for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.6.1. This ma… wordfence
0548608d-17d5-46f4-9d64-6e3b0552bf9d
< 1.1.4
HIGH 8.1 The Drag and Drop File Upload for Contact Form 7 plugin for WordPress is vulnerable to arbitrary file upload in versions… wordfence
052aeacb-6bb4-400f-993f-d1eff8dd1006 HIGH 8.1 The Malta theme for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.3.3. This makes … wordfence
048625e8-10b7-418d-a13b-329f1d7e0171
< 1.2.9
HIGH 8.1 The WPC Shop as a Customer for WooCommerce plugin for WordPress is vulnerable to account takeover and privilege escalati… wordfence
← Prev 266 267 268 269 270 271 272 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top