Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total519
Critical73
High150
Medium296
Reset
Showing 81-100 of 519 records
Threat Entry Updated 2026-06-17

CVE-2026-2486 - Master Addons For Elementor – Widgets, Extensions, Theme Builder, Popup Builder & Template Kits

The Master Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'ma_el_bh_table_btn_text' parameter in versions up to, and including, 2.1.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

THEME Master Addons For Elementor – Widgets, Extensions, Theme Builder, Popup Builder & Template Kits

CVE-2026-2486

MEDIUM CVSS 6.4 2026-02-20
Threat Entry Updated 2026-06-17

CVE-2026-27052 - Sales Countdown Timer for WooCommerce and WordPress Theme

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in villatheme Sales Countdown Timer for WooCommerce and WordPress sctv-sales-countdown-timer allows PHP Local File Inclusion.This issue affects Sales Countdown Timer for WooCommerce and WordPress: from n/a through < 1.1.9.

THEME Sales Countdown Timer for WooCommerce and WordPress

CVE-2026-27052

HIGH CVSS 7.5 2026-02-19
Threat Entry Updated 2026-06-17

CVE-2026-25416 - News Kit Elementor Addons Theme

Missing Authorization vulnerability in blazethemes News Kit Elementor Addons news-kit-elementor-addons allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects News Kit Elementor Addons: from n/a through

THEME News Kit Elementor Addons

CVE-2026-25416

MEDIUM CVSS 4.3 2026-02-19
Threat Entry Updated 2026-06-17

CVE-2026-22333 - YITH WooCommerce Compare Theme

Deserialization of Untrusted Data vulnerability in YITHEMES YITH WooCommerce Compare yith-woocommerce-compare allows Object Injection.This issue affects YITH WooCommerce Compare: from n/a through

THEME YITH WooCommerce Compare

CVE-2026-22333

HIGH CVSS 7.2 2026-02-19
Threat Entry Updated 2026-02-19

CVE-2025-14357 - Mega Store Woocommerce Theme

The Mega Store Woocommerce theme for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the setup_widgets() function in core/includes/importer/whizzie.php in all versions up to, and including, 5.9. This makes it possible for authenticated attackers, with Subscriber-level access and above, to create arbitrary pages and modify site settings.

THEME Mega Store Woocommerce

CVE-2025-14357

MEDIUM CVSS 5.3 2026-02-19
Threat Entry Updated 2026-02-19

CVE-2025-13091 - Shopire Theme

The Shopire theme for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the shopire_admin_install_plugin() function in all versions up to, and including, 1.0.57. This makes it possible for authenticated attackers, with Subscriber-level access and above, to install the 'fable-extra' plugin.

THEME Shopire

CVE-2025-13091

MEDIUM CVSS 4.3 2026-02-19
Threat Entry Updated 2026-02-19

CVE-2025-12821 - Newsblogger Theme

The NewsBlogger theme for WordPress is vulnerable to Cross-Site Request Forgery in versions 0.2.5.6 to 0.2.6.1. This is due to missing or incorrect nonce validation on the newsblogger_install_and_activate_plugin() function. This makes it possible for unauthenticated attackers to upload arbitrary files and achieve remote code execution via a forged request granted they can trick a site administrator into performing an action such as clicking on a link. This is due to a reverted fix of CVE-2025-1305.

THEME Newsblogger

CVE-2025-12821

HIGH CVSS 8.8 2026-02-19
Threat Entry Updated 2026-02-19

CVE-2025-12117 - Renden Theme

The Renden theme for WordPress is vulnerable to Stored Cross-Site Scripting via the post title in all versions up to, and including, 1.8.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

THEME Renden

CVE-2025-12117

MEDIUM CVSS 6.4 2026-02-19
Threat Entry Updated 2026-02-19

CVE-2025-12116 - Drift Theme

The Drift theme for WordPress is vulnerable to Stored Cross-Site Scripting via the post title in all versions up to, and including, 1.5.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

THEME Drift

CVE-2025-12116

MEDIUM CVSS 6.4 2026-02-19
Threat Entry Updated 2026-06-17

CVE-2026-2386 - The Plus Addons for Elementor – Addons for Elementor, Page Templates, Widgets, Mega Menu, WooCommerce Theme

The The Plus Addons for Elementor – Addons for Elementor, Page Templates, Widgets, Mega Menu, WooCommerce plugin for WordPress is vulnerable to Incorrect Authorization in all versions up to, and including, 6.4.7. This is due to the tpae_create_page() AJAX handler authorizing users only with current_user_can('edit_posts') while accepting a user-controlled 'post_type' value passed directly to wp_insert_post() without post-type-specific capability checks. This makes it possible for authenticated attackers, with Author-level access and above, to create arbitrary draft posts for restricted post types (e.g., 'page' and 'nxt_builder') via the 'post_type' parameter.

THEME The Plus Addons for Elementor – Addons for Elementor, Page Templates, Widgets, Mega Menu, WooCommerce

CVE-2026-2386

MEDIUM CVSS 4.3 2026-02-18
Threat Entry Updated 2026-06-17

CVE-2026-2019 - Cart All In One For WooCommerce Theme

The Cart All In One For WooCommerce plugin for WordPress is vulnerable to Code Injection in all versions up to, and including, 1.1.21. This is due to insufficient input validation on the 'Assign page' field which is passed directly to the eval() function. This makes it possible for authenticated attackers, with Administrator-level access and above, to execute arbitrary PHP code on the server.

THEME Cart All In One For WooCommerce

CVE-2026-2019

HIGH CVSS 7.2 2026-02-18
Threat Entry Updated 2026-02-18

CVE-2025-12074 - Context Blog Theme

The Context Blog theme for WordPress is vulnerable to Information Exposure in all versions up to, and including, 1.2.5 via the 'context_blog_modal_popup' due to insufficient restrictions on which posts can be included. This makes it possible for unauthenticated attackers to extract data from password protected, private, or draft posts that they should not have access to.

THEME Context Blog

CVE-2025-12074

MEDIUM CVSS 5.3 2026-02-18
Threat Entry Updated 2026-06-17

CVE-2026-1793 - Element Pack Addons for Elementor Theme

The Element Pack Addons for Elementor plugin for WordPress is vulnerable to arbitrary file reads in all versions up to, and including, 8.3.17 via the SVG widget and a lack of sufficient file validation in the 'render_svg' function. This makes it possible for authenticated attackers, with contributor-level access and above, to read the contents of arbitrary files on the server, which can contain sensitive information.

THEME Element Pack Addons for Elementor

CVE-2026-1793

MEDIUM CVSS 6.5 2026-02-15
Threat Entry Updated 2026-06-17

CVE-2026-1729 - Adforest Theme

The AdForest theme for WordPress is vulnerable to authentication bypass in all versions up to, and including, 6.0.12. This is due to the plugin not properly verifying a user's identity prior to authenticating them through the 'sb_login_user_with_otp_fun' function. This makes it possible for unauthenticated attackers to log in as arbitrary users, including administrators.

THEME Adforest

CVE-2026-1729

CRITICAL CVSS 9.8 2026-02-12
Threat Entry Updated 2026-06-17

CVE-2026-1319 - Robin Image Optimizer – Unlimited Image Optimization & WebP Converter Theme

The Robin Image Optimizer – Unlimited Image Optimization & WebP Converter plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'Alternative Text' field of a Media Library image in all versions up to, and including, 2.0.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Author-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

THEME Robin Image Optimizer – Unlimited Image Optimization & WebP Converter

CVE-2026-1319

MEDIUM CVSS 6.4 2026-02-05
Threat Entry Updated 2026-06-17

CVE-2026-0867 - Essential Widgets Theme

The Essential Widgets plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's ew-author, ew-archive, ew-category, ew-page, and ew-menu shortcodes in all versions up to, and including, 3.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. NOTE: This vulnerability was partially fixed in version 3.0.

THEME Essential Widgets

CVE-2026-0867

MEDIUM CVSS 6.4 2026-02-05
Threat Entry Updated 2026-06-17

CVE-2026-1755 - Menu Icons by ThemeIsle

The Menu Icons by ThemeIsle plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘_wp_attachment_image_alt’ post meta in all versions up to, and including, 0.13.20 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Author-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

THEME Menu Icons by ThemeIsle

CVE-2026-1755

MEDIUM CVSS 6.4 2026-02-03
Threat Entry Updated 2026-06-17

CVE-2026-24945 - Ultimate Addons for Contact Form 7 Theme

Missing Authorization vulnerability in Themefic Ultimate Addons for Contact Form 7 ultimate-addons-for-contact-form-7 allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Ultimate Addons for Contact Form 7: from n/a through

THEME Ultimate Addons for Contact Form 7

CVE-2026-24945

MEDIUM CVSS 5.3 2026-02-03
Threat Entry Updated 2026-06-17

CVE-2026-1375 - Tutor LMS – eLearning and online course solution Theme

The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to Insecure Direct Object References (IDOR) in all versions up to, and including, 3.9.5. This is due to missing object-level authorization checks in the `course_list_bulk_action()`, `bulk_delete_course()`, and `update_course_status()` functions. This makes it possible for authenticated attackers, with Tutor Instructor-level access and above, to modify or delete arbitrary courses they do not own by manipulating course IDs in bulk action requests.

THEME Tutor LMS – eLearning and online course solution

CVE-2026-1375

HIGH CVSS 8.1 2026-02-03
Threat Entry Updated 2026-06-17

CVE-2026-1371 - Tutor LMS – eLearning and online course solution Theme

The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.9.5. This is due to missing authorization checks in the `ajax_coupon_details()` function, which only validates nonces but does not verify user capabilities. This makes it possible for authenticated attackers, with Subscriber-level access and above, to retrieve sensitive coupon information including coupon codes, discount amounts, usage statistics, and course/bundle applications.

THEME Tutor LMS – eLearning and online course solution

CVE-2026-1371

MEDIUM CVSS 5.3 2026-02-03
Scroll to top