Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total470
Critical68
High135
Medium267
Reset
Showing 101-120 of 470 records
Threat Entry Updated 2025-09-09

CVE-2025-9113 - Doccure Theme

The Doccure theme for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'doccure_temp_upload_to_media' function in all versions up to, and including, 1.4.8. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's server which may make remote code execution possible.

THEME Doccure

CVE-2025-9113

CRITICAL CVSS 9.8 2025-09-08
Threat Entry Updated 2025-09-09

CVE-2025-9112 - Doccure Theme

The Doccure theme for WordPress is vulnerable to arbitrary file uploads due to incorrect file type validation in the 'doccure_temp_file_uploader' function in all versions up to, and including, 1.4.8. This makes it possible for authenticated attackers, with subscriber-level and above permissions, to upload arbitrary files on the affected site's server which may make remote code execution possible.

THEME Doccure

CVE-2025-9112

HIGH CVSS 8.8 2025-09-08
Threat Entry Updated 2025-09-08

CVE-2025-8359 - Adforest Theme

The AdForest theme for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 6.0.9. This is due to the plugin not properly verifying a user's identity prior to authenticating them. This makes it possible for unauthenticated attackers to log in as other users, including administrators, without access to a password.

THEME Adforest

CVE-2025-8359

CRITICAL CVSS 9.8 2025-09-06
Threat Entry Updated 2025-09-08

CVE-2025-7366 - Multi Vendor Marketplace Wordpress Theme

The The REHub - Price Comparison, Multi Vendor Marketplace Wordpress Theme theme for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 19.9.7. This is due to the software allowing users to execute an action that does not properly validate a value before running do_shortcode. This makes it possible for unauthenticated attackers to execute arbitrary shortcodes.

THEME Multi Vendor Marketplace Wordpress Theme

CVE-2025-7366

HIGH CVSS 7.3 2025-09-06
Threat Entry Updated 2025-09-08

CVE-2025-7368 - Multi Vendor Marketplace Wordpress Theme

The REHub - Price Comparison, Multi Vendor Marketplace Wordpress Theme theme for WordPress is vulnerable to Information Exposure in all versions up to, and including, 19.9.7 via the 'ajax_action_re_getfullcontent' function due to insufficient restrictions on which posts can be included. This makes it possible for unauthenticated attackers to extract data from password protected posts that they should not have access to.

THEME Multi Vendor Marketplace Wordpress Theme

CVE-2025-7368

MEDIUM CVSS 5.3 2025-09-06
Threat Entry Updated 2026-01-20

CVE-2025-8944 - Before 4 Theme

The OceanWP WordPress theme before 4.1.2 is vulnerable to an option update due to a missing capability check on one of its AJAX request handler, allowing any authenticated users, such as subscriber to update the darkMod` setting.

THEME Before 4

CVE-2025-8944

MEDIUM CVSS 4.3 2025-09-05
Threat Entry Updated 2025-09-05

CVE-2025-8684 - Flatsome Theme

The Flatsome Theme for WordPress is vulnerable to Stored Cross-Site Scripting via the theme's shortcodes in all versions up to, and including, 3.20.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

THEME Flatsome

CVE-2025-8684

MEDIUM CVSS 6.4 2025-09-05
Threat Entry Updated 2025-08-22

CVE-2025-9331 - Spacious Theme

The Spacious theme for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'welcome_notice_import_handler' function in all versions up to, and including, 1.9.11. This makes it possible for authenticated attackers, with Subscriber-level access and above, to import demo data into the site.

THEME Spacious

CVE-2025-9331

MEDIUM CVSS 4.3 2025-08-22
Threat Entry Updated 2025-08-22

CVE-2025-8592 - Inspiro Theme

The Inspiro theme for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.1.2. This is due to missing or incorrect nonce validation on the inspiro_install_plugin() function. This makes it possible for unauthenticated attackers to install plugins from the repository via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

THEME Inspiro

CVE-2025-8592

HIGH CVSS 8.1 2025-08-21
Threat Entry Updated 2025-08-20

CVE-2025-49382 - Allows Privilege Escalation Theme

Cross-Site Request Forgery (CSRF) vulnerability in DexignZone JobZilla - Job Board WordPress Theme allows Privilege Escalation. This issue affects JobZilla - Job Board WordPress Theme: from n/a through 2.0.

THEME Allows Privilege Escalation

CVE-2025-49382

HIGH CVSS 8.8 2025-08-20
Threat Entry Updated 2025-08-20

CVE-2025-9202 - Colormag Theme

The ColorMag theme for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the welcome_notice_import_handler() function in all versions up to, and including, 4.0.19. This makes it possible for authenticated attackers, with Subscriber-level access and above, to install the ThemeGrill Demo Importer plugin.

THEME Colormag

CVE-2025-9202

MEDIUM CVSS 4.3 2025-08-20
Threat Entry Updated 2025-08-19

CVE-2025-6758 - Real Spaces Wordpress Properties Directory Theme

The Real Spaces - WordPress Properties Directory Theme theme for WordPress is vulnerable to privilege escalation via the 'imic_agent_register' function in all versions up to, and including, 3.6. This is due to a lack of restriction in the registration role. This makes it possible for unauthenticated attackers to arbitrarily choose their role, including the Administrator role, during user registration.

THEME Real Spaces Wordpress Properties Directory Theme

CVE-2025-6758

CRITICAL CVSS 9.8 2025-08-19
Threat Entry Updated 2025-08-19

CVE-2025-8218 - Real Spaces Wordpress Properties Directory Theme

The Real Spaces - WordPress Properties Directory Theme theme for WordPress is vulnerable to privilege escalation via the 'change_role_member' parameter in all versions up to, and including, 3.5. This is due to a lack of restriction in the profile update role. This makes it possible for unauthenticated attackers to arbitrarily choose their role, including the Administrator role, during a profile update.

THEME Real Spaces Wordpress Properties Directory Theme

CVE-2025-8218

HIGH CVSS 8.8 2025-08-19
Threat Entry Updated 2025-08-18

CVE-2025-8142 - Soledad Theme

The Soledad theme for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 8.6.7 via the 'header_layout' parameter. This makes it possible for authenticated attackers, with Contributor-level access and above, to include and execute arbitrary .php files on the server, allowing the execution of any PHP code in those files. This can be used to bypass access controls, obtain sensitive data, or achieve code execution in cases where .php file types can be uploaded and included.

THEME Soledad

CVE-2025-8142

HIGH CVSS 8.8 2025-08-16
Threat Entry Updated 2025-08-18

CVE-2025-8105 - The Soledad Theme

The The Soledad theme for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 8.6.7. This is due to the software allowing users to execute an action that does not properly validate a value before running do_shortcode. This makes it possible for unauthenticated attackers to execute arbitrary shortcodes.

THEME The Soledad

CVE-2025-8105

HIGH CVSS 7.3 2025-08-16
Threat Entry Updated 2025-08-18

CVE-2025-8143 - Soledad Theme

The Soledad theme for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘pcsml_smartlists_h’ parameter in all versions up to, and including, 8.6.7 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

THEME Soledad

CVE-2025-8143

MEDIUM CVSS 6.4 2025-08-16
Threat Entry Updated 2025-12-18

CVE-2025-8891 - Oceanwp Theme

The OceanWP theme for WordPress is vulnerable to Cross-Site Request Forgery in versions 4.0.9 to 4.1.1. This is due to missing or incorrect nonce validation on the oceanwp_notice_button_click() function. This makes it possible for unauthenticated attackers to install the Ocean Extra plugin via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

THEME Oceanwp

CVE-2025-8891

MEDIUM CVSS 4.3 2025-08-13
Threat Entry Updated 2025-08-11

CVE-2025-7726 - The7 Theme

The The7 theme for WordPress is vulnerable to Stored Cross-Site Scripting via its lightbox rendering code in all versions up to, and including, 12.6.0 due to insufficient input sanitization and output escaping. The theme’s JavaScript reads user-supplied 'title' and 'data-dt-img-description' attributes directly via jQuery.attr(), concatenates them into an HTML string, and inserts that string into the DOM using methods such as jQuery.html() without escaping or filtering. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a…

THEME The7

CVE-2025-7726

MEDIUM CVSS 6.4 2025-08-09
Threat Entry Updated 2025-08-06

CVE-2025-7399 - Betheme

The Betheme theme for WordPress is vulnerable to Stored Cross-Site Scripting via an Elementor display setting in all versions up to, and including, 28.1.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

THEME Betheme

CVE-2025-7399

MEDIUM CVSS 6.4 2025-08-06
Threat Entry Updated 2025-08-06

CVE-2025-8595 - Zakra Theme

The Zakra theme for WordPress is vulnerable to unauthorized data modification due to a missing capability check on the welcome_notice_import_handler() function in all versions up to, and including, 4.1.5. This makes it possible for authenticated attackers, with Subscriber-level access and above, to import demo settings.

THEME Zakra

CVE-2025-8595

MEDIUM CVSS 4.3 2025-08-06
Scroll to top