πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,652
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 15, 2026
Last Updated

39,652 vulnerabilities found (page 270 of 1587)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
0458282f-199f-4b1f-80e0-a17ac8811915 HIGH 8.1 The Faith & Hope theme for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 2.13.0. Thi… wordfence
0453355e-471f-42c9-8d62-15541f0542d8 HIGH 8.1 The Greeny theme for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 2.6. This makes i… wordfence
043a5f20-c7e8-4e93-ad05-82616a559800
< 2.5.6
HIGH 8.1 The Capella theme for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 2.5.5 via deseri… wordfence
04045ec3-dd8e-4ac5-bd73-eef6205ecc62
< 3.6.1
HIGH 8.1 The Miniorange OTP Verification with Firebase plugin for WordPress is vulnerable to authentication bypass in versions up… wordfence
03c2d0d4-e33e-4b12-9e84-ae6b7b6c3fe2 HIGH 8.1 The Neptunus theme for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.0.11. This ma… wordfence
03c00601-5272-4c94-b248-62958c013d36
< 1.7
HIGH 8.1 The NeoBeat theme for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.2. This makes … wordfence
039641fe-820b-464f-a859-ba2b0ebd5844
< 1.8.1
HIGH 8.1 The SureDash – Community, Courses & Member Dashboard plugin for WordPress is vulnerable to arbitrary file deletion due… wordfence
03926855-d2cc-4105-9927-5871002cb7a0
< 3.7.1.6
HIGH 8.1 The Registration Forms User profile, Content Restriction, Spam Protection, Payment Gateways, Invitation Codes WordPress… wordfence
033333b2-58b1-4810-ac25-65f7c8f13a5b HIGH 8.1 The Eleblog – Elementor Blog And Magazine Addons plugin for WordPress is vulnerable to Local File Inclusion in version… wordfence
02faea1f-ef4b-4b29-8c0d-e1ca6f7c1192
< 2.4
HIGH 8.1 The Optimize theme for WordPress is vulnerable to Local File Inclusion in versions up to 2.4. This makes it possible for… wordfence
02ef976d-2240-4f1c-a313-9fe3130333f2
< 1.3.11
HIGH 8.1 The Diza theme for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.3.9. This makes i… wordfence
02de9287-68e4-46ce-a491-3f6cbb7fc0ed
< 4.4.7
HIGH 8.1 The Nexter Extension – Site Enhancements Toolkit plugin for WordPress is vulnerable to PHP Object Injection in all ver… wordfence
02bfe680-d20d-4246-8fdb-11815114975a
< 1.6.6
HIGH 8.1 The Picture Gallery – Frontend Image Uploads, AJAX Photo List plugin for WordPress is vulnerable to arbitrary file del… wordfence
02b75b0a-9409-4593-bf25-65ff49576dee HIGH 8.1 The VidMov theme for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.9.4. This makes… wordfence
021ff4e6-2e68-49d0-96ad-1cfb604b59cc HIGH 8.1 The Pathfinder theme for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.16. This ma… wordfence
01e041ad-a340-40a1-bd6c-bf11faed4805 HIGH 8.1 The Mr. Cobbler | Custom Shoemaking & Footwear Repairs WordPress Theme theme for WordPress is vulnerable to Local File I… wordfence
01d3c9b4-fce5-41d4-8cd8-2b26f1fe171a HIGH 8.1 The CityGov theme for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.9. This makes … wordfence
01924511-f567-4162-b7cd-e9a51df9953e HIGH 8.1 The Stallion theme for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.17. This make… wordfence
0177ceb7-d507-468a-9b64-629237bc7306
< 2.0.7
HIGH 8.1 The FundPress plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 2.0.6 via des… wordfence
01769760-5bfe-4352-bc5b-141f078c0b6d HIGH 8.1 The Avatar plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in a f… wordfence
0166a2b2-24e2-4dd6-8842-d3e8dd7bb0dc
< 1.1.1
HIGH 8.1 The Hash Form – Drag & Drop Form Builder plugin for WordPress is vulnerable to PHP Object Injection in all versions up… wordfence
012b3e9f-a926-42b3-b825-2314d9f72474 HIGH 8.1 The Reprizo theme for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.0.8. This make… wordfence
011be772-a3e6-418f-ba83-e075af4b7e08 HIGH 8.1 The IDonatePro plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 2.1.8. This … wordfence
01094597-4bdd-4928-959a-13306315389e
< 3.1.11
HIGH 8.1 The Grand Wedding theme for WordPress is vulnerable to PHP Object Injection in versions up to, and excluding, 3.1.11 via… wordfence
008f3754-363d-4f72-86cc-1bcea3b5cdcc
< 3.16.3.3
HIGH 8.1 The BM Content Builder plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path valid… wordfence
← Prev 267 268 269 270 271 272 273 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top