Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total519
Critical73
High150
Medium296
Reset
Showing 61-80 of 519 records
Threat Entry Updated 2026-06-17

CVE-2026-27339 - Buzz Stone | Magazine & Viral Blog WordPress Theme

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in AncoraThemes Buzz Stone | Magazine & Viral Blog WordPress Theme buzzstone allows PHP Local File Inclusion.This issue affects Buzz Stone | Magazine & Viral Blog WordPress Theme: from n/a through

THEME Buzz Stone | Magazine & Viral Blog WordPress Theme

CVE-2026-27339

HIGH CVSS 8.1 2026-03-05
Threat Entry Updated 2026-06-17

CVE-2026-27337 - Chronicle - Lifestyle Magazine & Blog WordPress Theme

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in AncoraThemes Chronicle - Lifestyle Magazine & Blog WordPress Theme chronicle allows PHP Local File Inclusion.This issue affects Chronicle - Lifestyle Magazine & Blog WordPress Theme: from n/a through

THEME Chronicle - Lifestyle Magazine & Blog WordPress Theme

CVE-2026-27337

HIGH CVSS 8.1 2026-03-05
Threat Entry Updated 2026-06-17

CVE-2026-27336 - Consultor | Consulting, Accounting & Legal Counsel WordPress Theme

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in AncoraThemes Consultor | Consulting, Accounting & Legal Counsel WordPress Theme consultor allows PHP Local File Inclusion.This issue affects Consultor | Consulting, Accounting & Legal Counsel WordPress Theme: from n/a through

THEME Consultor | Consulting, Accounting & Legal Counsel WordPress Theme

CVE-2026-27336

HIGH CVSS 8.1 2026-03-05
Threat Entry Updated 2026-06-17

CVE-2026-27326 - AC Services | HVAC, Air Conditioning & Heating Company WordPress Theme

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in axiomthemes AC Services | HVAC, Air Conditioning & Heating Company WordPress Theme window-ac-services allows PHP Local File Inclusion.This issue affects AC Services | HVAC, Air Conditioning & Heating Company WordPress Theme: from n/a through

THEME AC Services | HVAC, Air Conditioning & Heating Company WordPress Theme

CVE-2026-27326

HIGH CVSS 8.1 2026-03-05
Threat Entry Updated 2026-06-17

CVE-2026-27097 - CasaMia | Property Rental Real Estate WordPress Theme

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in AncoraThemes CasaMia | Property Rental Real Estate WordPress Theme casamia allows PHP Local File Inclusion.This issue affects CasaMia | Property Rental Real Estate WordPress Theme: from n/a through

THEME CasaMia | Property Rental Real Estate WordPress Theme

CVE-2026-27097

HIGH CVSS 8.1 2026-03-05
Threat Entry Updated 2026-06-17

CVE-2026-2583 - Blocksy Theme

The Blocksy theme for WordPress is vulnerable to Stored Cross-Site Scripting via the `blocksy_meta` metadata fields in all versions up to, and including, 2.1.30 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

THEME Blocksy

CVE-2026-2583

MEDIUM CVSS 6.4 2026-03-02
Threat Entry Updated 2026-06-17

CVE-2026-3132 - Master Addons for Elementor Premium Theme

The Master Addons for Elementor Premium plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 2.1.3 via the 'JLTMA_Widget_Admin::render_preview'. This is due to missing capability check. This makes it possible for authenticated attackers, with Subscriber-level access and above, to execute code on the server.

THEME Master Addons for Elementor Premium

CVE-2026-3132

HIGH CVSS 8.8 2026-03-02
Threat Entry Updated 2026-02-27

CVE-2025-12981 - Listee Theme

The Listee theme for WordPress is vulnerable to privilege escalation in all versions up to, and including, 1.1.6. This is due to a broken validation check in the bundled listee-core plugin's user registration function that fails to properly sanitize the user_role parameter. This makes it possible for unauthenticated attackers to register as Administrator by manipulating the user_role parameter during registration.

THEME Listee

CVE-2025-12981

CRITICAL CVSS 9.8 2026-02-27
Threat Entry Updated 2026-02-27

CVE-2025-14040 - Automotive Car Dealership Business Wordpress Theme

The Automotive Car Dealership Business WordPress Theme for WordPress is vulnerable to Stored Cross-Site Scripting via the 'Call to Action' custom fields in all versions up to, and including, 13.4. This is due to insufficient input sanitization and output escaping on user-supplied attributes in the 'action_text', 'action_button_text', 'action_link', and 'action_class' custom fields. This makes it possible for authenticated attackers, with contributor-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

THEME Automotive Car Dealership Business Wordpress

CVE-2025-14040

MEDIUM CVSS 6.4 2026-02-27
Threat Entry Updated 2026-06-17

CVE-2026-28132 - WooCommerce Photo Reviews Theme

Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in villatheme WooCommerce Photo Reviews woocommerce-photo-reviews allows Code Injection.This issue affects WooCommerce Photo Reviews: from n/a through

THEME WooCommerce Photo Reviews

CVE-2026-28132

MEDIUM CVSS 5.3 2026-02-26
Threat Entry Updated 2026-06-17

CVE-2026-1311 - Worry Proof Backup Theme

The Worry Proof Backup plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 0.2.4 via the backup upload functionality. This makes it possible for authenticated attackers, with Subscriber-level access and above, to upload a malicious ZIP archive with path traversal sequences to write arbitrary files anywhere on the server, including executable PHP files. This can lead to remote code execution.

THEME Worry Proof Backup

CVE-2026-1311

HIGH CVSS 8.8 2026-02-26
Threat Entry Updated 2026-06-17

CVE-2026-2498 - WP Social Meta Theme

The WP Social Meta plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 1.0.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This only affects multi-site installations and installations where unfiltered_html has been disabled.

THEME WP Social Meta

CVE-2026-2498

MEDIUM CVSS 4.4 2026-02-26
Threat Entry Updated 2026-06-17

CVE-2026-2410 - Disable Admin Notices – Hide Dashboard Notifications Theme

The Disable Admin Notices – Hide Dashboard Notifications plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.4.2. This is due to missing nonce validation in the `showPageContent()` function. This makes it possible for unauthenticated attackers to add arbitrary URLs to the blocked redirects list via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

THEME Disable Admin Notices – Hide Dashboard Notifications

CVE-2026-2410

MEDIUM CVSS 4.3 2026-02-25
Threat Entry Updated 2026-06-17

CVE-2026-1614 - Rise Blocks – A Complete Gutenberg Page Builder Theme

The Rise Blocks – A Complete Gutenberg Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘logoTag’ Site Identity block attribute in all versions up to, and including, 3.7 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

THEME Rise Blocks – A Complete Gutenberg Page Builder

CVE-2026-1614

MEDIUM CVSS 6.4 2026-02-25
Threat Entry Updated 2026-06-17

CVE-2026-2385 - The Plus Addons for Elementor – Addons for Elementor, Page Templates, Widgets, Mega Menu, WooCommerce Theme

The The Plus Addons for Elementor – Addons for Elementor, Page Templates, Widgets, Mega Menu, WooCommerce plugin for WordPress is vulnerable to Insufficient Verification of Data Authenticity in all versions up to, and including, 6.4.7. This is due to the plugin decrypting and trusting attacker-controlled email_data in an unauthenticated AJAX handler without cryptographic authenticity guarantees. This makes it possible for unauthenticated attackers to tamper with form email routing and redirection values to trigger unauthorized email relay and attacker-controlled redirection via the 'email_data' parameter.

THEME The Plus Addons for Elementor – Addons for Elementor, Page Templates, Widgets, Mega Menu, WooCommerce

CVE-2026-2385

MEDIUM CVSS 5.3 2026-02-22
Threat Entry Updated 2026-06-17

CVE-2026-22381 - PawFriends - Pet Shop and Veterinary WordPress Theme

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Mikado-Themes PawFriends - Pet Shop and Veterinary WordPress Theme pawfriends allows PHP Local File Inclusion.This issue affects PawFriends - Pet Shop and Veterinary WordPress Theme: from n/a through

THEME PawFriends - Pet Shop and Veterinary WordPress Theme

CVE-2026-22381

HIGH CVSS 8.1 2026-02-20
Threat Entry Updated 2026-06-17

CVE-2026-22383 - PawFriends - Pet Shop and Veterinary WordPress Theme

Authorization Bypass Through User-Controlled Key vulnerability in Mikado-Themes PawFriends - Pet Shop and Veterinary WordPress Theme pawfriends allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects PawFriends - Pet Shop and Veterinary WordPress Theme: from n/a through

THEME PawFriends - Pet Shop and Veterinary WordPress Theme

CVE-2026-22383

HIGH CVSS 7.5 2026-02-20
Threat Entry Updated 2026-02-23

CVE-2025-69385 - Cartify Allows Exploiting Incorrectly Configured Access Control Security Levels Theme

Missing Authorization vulnerability in AgniHD Cartify - WooCommerce Gutenberg WordPress Theme cartify allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Cartify - WooCommerce Gutenberg WordPress Theme: from n/a through

THEME Cartify Allows Exploiting Incorrectly Configured Access Control Security Levels

CVE-2025-69385

MEDIUM CVSS 6.5 2026-02-20
Threat Entry Updated 2026-02-23

CVE-2025-69368 - Soho Allows Dom Based Xss Theme

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in GT3themes SOHO - Photography WordPress Theme soho allows DOM-Based XSS.This issue affects SOHO - Photography WordPress Theme: from n/a through

THEME Soho Allows Dom Based Xss

CVE-2025-69368

HIGH CVSS 7.1 2026-02-20
Threat Entry Updated 2026-02-23

CVE-2025-69367 - Oyster Allows Dom Based Xss Theme

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in GT3themes Oyster - Photography WordPress Theme oyster allows DOM-Based XSS.This issue affects Oyster - Photography WordPress Theme: from n/a through

THEME Oyster Allows Dom Based Xss

CVE-2025-69367

HIGH CVSS 7.1 2026-02-20
Scroll to top