Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total519
Critical73
High150
Medium296
Reset
Showing 101-120 of 519 records
Threat Entry Updated 2026-06-17

CVE-2026-1097 - ThemeRuby Multi Authors – Assign Multiple Writers to Posts

The ThemeRuby Multi Authors – Assign Multiple Writers to Posts plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'before' and 'after' shortcode attributes in all versions up to, and including, 1.0.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

THEME ThemeRuby Multi Authors – Assign Multiple Writers to Posts

CVE-2026-1097

MEDIUM CVSS 6.4 2026-01-24
Threat Entry Updated 2026-06-17

CVE-2026-1095 - Canto Testimonials Theme

The Canto Testimonials plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'fx' shortcode attribute in all versions up to, and including, 1.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

THEME Canto Testimonials

CVE-2026-1095

MEDIUM CVSS 6.4 2026-01-24
Threat Entry Updated 2026-06-17

CVE-2026-22382 - PawFriends - Pet Shop and Veterinary WordPress Theme

Cross-Site Request Forgery (CSRF) vulnerability in Mikado-Themes PawFriends - Pet Shop and Veterinary WordPress Theme pawfriends allows Cross Site Request Forgery.This issue affects PawFriends - Pet Shop and Veterinary WordPress Theme: from n/a through

THEME PawFriends - Pet Shop and Veterinary WordPress Theme

CVE-2026-22382

MEDIUM CVSS 5.4 2026-01-22
Threat Entry Updated 2026-01-28

CVE-2025-69004 - Bajaar Allows Php Local File Inclusion Theme

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in XpeedStudio Bajaar - Highly Customizable WooCommerce WordPress Theme bajaar allows PHP Local File Inclusion.This issue affects Bajaar - Highly Customizable WooCommerce WordPress Theme: from n/a through

THEME Bajaar Allows Php Local File Inclusion

CVE-2025-69004

HIGH CVSS 8.1 2026-01-22
Threat Entry Updated 2026-06-17

CVE-2026-0726 - Nexter Extension – Security, Performance, Code Snippets & Site Toolkit Theme

The Nexter Extension – Site Enhancements Toolkit plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 4.4.6 via deserialization of untrusted input in the 'nxt_unserialize_replace' function. This makes it possible for unauthenticated attackers to inject a PHP Object. No known POP chain is present in the vulnerable software, which means this vulnerability has no impact unless another plugin or theme containing a POP chain is installed on the site. If a POP chain is present via an additional plugin or theme installed on…

THEME Nexter Extension – Security, Performance, Code Snippets & Site Toolkit

CVE-2026-0726

HIGH CVSS 8.1 2026-01-20
Threat Entry Updated 2026-06-17

CVE-2026-0548 - Tutor LMS – eLearning and online course solution Theme

The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to unauthorized attachment deletion due to a missing capability check on the `delete_existing_user_photo` function in all versions up to, and including, 3.9.4. This makes it possible for authenticated attackers, with subscriber level access and above, to delete arbitrary attachments on the site.

THEME Tutor LMS – eLearning and online course solution

CVE-2026-0548

MEDIUM CVSS 5.4 2026-01-20
Threat Entry Updated 2026-06-17

CVE-2026-0808 - Spin Wheel – Interactive spinning wheel that offers coupons Theme

The Spin Wheel plugin for WordPress is vulnerable to client-side prize manipulation in all versions up to, and including, 2.1.0. This is due to the plugin trusting client-supplied prize selection data without server-side validation or randomization. This makes it possible for unauthenticated attackers to manipulate which prize they win by modifying the 'prize_index' parameter sent to the server, allowing them to always select the most valuable prizes.

THEME Spin Wheel – Interactive spinning wheel that offers coupons

CVE-2026-0808

MEDIUM CVSS 5.3 2026-01-17
Threat Entry Updated 2026-01-16

CVE-2025-12895 - Woocommerce Theme

The Kalium 3 | Creative WordPress & WooCommerce Theme theme for WordPress is vulnerable to unauthorized email sending due to a missing capability check on the kalium_vc_contact_form_request() function in all versions up to, and including, 3.29. This makes it possible for unauthenticated attackers to use the theme an an open mail relay and send email to arbitrary email addresses on the server's behalf.

THEME Woocommerce Theme

CVE-2025-12895

MEDIUM CVSS 5.3 2026-01-15
Threat Entry Updated 2026-06-17

CVE-2026-22521 - Handmade Framework Theme

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in G5Theme Handmade Framework handmade-framework allows PHP Local File Inclusion.This issue affects Handmade Framework: from n/a through

THEME Handmade Framework

CVE-2026-22521

HIGH CVSS 7.5 2026-01-08
Threat Entry Updated 2026-06-17

CVE-2026-0676 - Zorka Theme

Missing Authorization vulnerability in G5Theme Zorka zorka allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Zorka: from n/a through

THEME Zorka

CVE-2026-0676

MEDIUM CVSS 5.3 2026-01-08
Threat Entry Updated 2026-01-08

CVE-2025-31051 - Allows Retrieve Embedded Sensitive Data Theme

Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in EngoTheme Plant - Gardening & Houseplants WordPress Theme allows Retrieve Embedded Sensitive Data.This issue affects Plant - Gardening & Houseplants WordPress Theme: from n/a through 1.0.0.

THEME Allows Retrieve Embedded Sensitive Data

CVE-2025-31051

MEDIUM CVSS 5.3 2026-01-07
Threat Entry Updated 2026-01-08

CVE-2025-30996 - Cted Upload Of File With Dangerous Type Vulnerability In Themify Themify Sidepane Theme

Unrestricted Upload of File with Dangerous Type vulnerability in Themify Themify Sidepane WordPress Theme, Themify Themify Newsy, Themify Themify Folo, Themify Themify Edmin, Themify Bloggie, Themify Photobox, Themify Wigi, Themify Rezo, Themify Slide allows Upload a Web Shell to a Web Server.This issue affects Themify Sidepane WordPress Theme: from n/a through 1.9.8; Themify Newsy: from n/a through 1.9.9; Themify Folo: from n/a through 1.9.6; Themify Edmin: from n/a through 2.0.0; Bloggie: from n/a through 2.0.8; Photobox: from n/a through 2.0.1; Wigi: from n/a through 2.0.1; Rezo: from n/a through 1.9.7;…

THEME Cted Upload Of File With Dangerous Type Vulnerability In Themify Themify Sidepane

CVE-2025-30996

CRITICAL CVSS 9.9 2026-01-06
Threat Entry Updated 2026-01-08

CVE-2025-4776 - Phlox Theme

The Phlox theme for WordPress is vulnerable to Stored Cross-Site Scripting via the `data-caption` HTML attribute in all versions up to, and including, 2.17.7 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

THEME Phlox

CVE-2025-4776

MEDIUM CVSS 6.4 2026-01-06
Threat Entry Updated 2026-01-20

CVE-2025-68987 - For Movie Studios And Filmmakers Cinerama Allows Php Local File Inclusion Theme

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Edge-Themes Cinerama - A WordPress Theme for Movie Studios and Filmmakers cinerama allows PHP Local File Inclusion.This issue affects Cinerama - A WordPress Theme for Movie Studios and Filmmakers: from n/a through

THEME For Movie Studios And Filmmakers Cinerama Allows Php Local File Inclusion

CVE-2025-68987

CRITICAL CVSS 9.8 2025-12-30
Threat Entry Updated 2025-12-15

CVE-2025-7058 - Kingcabs Theme

The Kingcabs theme for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘progressbarLayout’ parameter in all versions up to, and including, 1.1.9 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

THEME Kingcabs

CVE-2025-7058

MEDIUM CVSS 6.4 2025-12-13
Threat Entry Updated 2025-12-15

CVE-2025-11164 - Mavix Education Theme

The Mavix Education theme for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'mavix_education_activate_plugin' AJAX action in all versions up to, and including, 1.0. This makes it possible for authenticated attackers, with Subscriber-level access and above, to activate the Creativ Demo Importer plugin.

THEME Mavix Education

CVE-2025-11164

MEDIUM CVSS 4.3 2025-12-13
Threat Entry Updated 2026-01-09

CVE-2025-10684 - Construction Light Theme

The Construction Light WordPress theme before 1.6.8 does not have authorisation and CSRF when activating via an AJAX action, allowing any authenticated users, such as subscriber to activate arbitrary .

THEME Construction Light

CVE-2025-10684

MEDIUM CVSS 4.3 2025-12-12
Threat Entry Updated 2025-12-01

CVE-2025-13675 - Tiger Theme

The Tiger theme for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 101.2.1. This is due to the 'paypal-submit.php' file not restricting what user roles a user can register with. This makes it possible for unauthenticated attackers to supply the 'administrator' role during registration and gain administrator access to the site.

THEME Tiger

CVE-2025-13675

CRITICAL CVSS 9.8 2025-11-27
Threat Entry Updated 2025-12-01

CVE-2025-13680 - Tiger Theme

The Tiger theme for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 101.2.1. This is due to the plugin allowing a user to update the user role through the $user->set_role() function. This makes it possible for authenticated attackers, with Subscriber-level access and above, to elevate their privileges to that of an administrator.

THEME Tiger

CVE-2025-13680

HIGH CVSS 8.8 2025-11-27
Scroll to top