Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total519
Critical73
High150
Medium296
Reset
Showing 121-140 of 519 records
Threat Entry Updated 2025-12-01

CVE-2025-9191 - Houzez Theme

The Houzez theme for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 4.1.6 via deserialization of untrusted input in saved-search-item.php. This makes it possible for authenticated attackers, with Subscriber-level access and above, to inject a PHP Object. No known POP chain is present in the vulnerable software, which means this vulnerability has no impact unless another plugin or theme containing a POP chain is installed on the site. If a POP chain is present via an additional plugin or theme installed on the target…

THEME Houzez

CVE-2025-9191

MEDIUM CVSS 6.3 2025-11-26
Threat Entry Updated 2025-12-01

CVE-2025-9163 - Houzez Theme

The Houzez theme for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 4.1.6 due to insufficient input sanitization and output escaping in the houzez_property_img_upload() and houzez_property_attachment_upload() functions. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses the SVG file.

THEME Houzez

CVE-2025-9163

MEDIUM CVSS 6.1 2025-11-26
Threat Entry Updated 2025-11-24

CVE-2025-5092 - Changeset Theme

Multiple plugins and/or themes for WordPress are vulnerable to Stored Cross-Site Scripting via the plugin's bundled lightGallery library (

THEME Changeset

CVE-2025-5092

MEDIUM CVSS 6.4 2025-11-20
Threat Entry Updated 2025-11-14

CVE-2025-10295 - Fashion Model Agency Wordpress Cms Theme

The Angel – Fashion Model Agency WordPress CMS Theme theme for WordPress is vulnerable to Stored Cross-Site Scripting the profile media uploader in all versions up to, and including, 3.2.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with subscriber-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This requires the user has access to the edit profile form with the media upload option.

THEME Fashion Model Agency Wordpress Cms Theme

CVE-2025-10295

MEDIUM CVSS 6.4 2025-11-13
Threat Entry Updated 2026-01-20

CVE-2025-60199 - Inhype Allows Php Local File Inclusion Theme

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in dedalx InHype - Blog & Magazine WordPress Theme inhype allows PHP Local File Inclusion.This issue affects InHype - Blog & Magazine WordPress Theme: from n/a through

THEME Inhype Allows Php Local File Inclusion

CVE-2025-60199

HIGH CVSS 8.2 2025-11-06
Threat Entry Updated 2026-01-20

CVE-2025-60198 - Saxon Allows Php Local File Inclusion Theme

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in dedalx Saxon - Viral Content Blog & Magazine Marketing WordPress Theme saxon allows PHP Local File Inclusion.This issue affects Saxon - Viral Content Blog & Magazine Marketing WordPress Theme: from n/a through

THEME Saxon Allows Php Local File Inclusion

CVE-2025-60198

HIGH CVSS 8.1 2025-11-06
Threat Entry Updated 2025-11-04

CVE-2025-6990 - Kallyas Theme

The kallyas theme for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 4.24.0 via the `TH_PhpCode` pagebuilder widget. This is due to the theme not restricting access to the code editor widget for non-administrators. This makes it possible for authenticated attackers, with Contributor-level access and above, to execute code on the server.

THEME Kallyas

CVE-2025-6990

HIGH CVSS 8.8 2025-11-01
Threat Entry Updated 2025-11-04

CVE-2025-6988 - Kallyas Theme

The kallyas theme for WordPress is vulnerable to Stored Cross-Site Scripting via several of the plugin's shortcodes in all versions up to, and including, 4.23.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

THEME Kallyas

CVE-2025-6988

MEDIUM CVSS 6.4 2025-11-01
Threat Entry Updated 2025-11-04

CVE-2025-10897 - Woocommerce Designer Pro Theme

The WooCommerce Designer Pro theme for WordPress is vulnerable to arbitrary file read in all versions up to, and including, 1.9.28. This makes it possible for unauthenticated attackers to read arbitrary files on the server, which can expose DB credentials when the wp-config.php file is read.

THEME Woocommerce Designer Pro

CVE-2025-10897

HIGH CVSS 8.6 2025-10-31
Threat Entry Updated 2025-11-04

CVE-2025-5397 - Noo Jobmonster Theme

The Noo JobMonster theme for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 4.8.1. This is due to the check_login() function not properly verifying a user's identity prior to successfully authenticating them This makes it possible for unauthenticated attackers to bypass standard authentication and access administrative user accounts. Please note social login needs to be enabled in order for a site to be impacted by this vulnerability.

THEME Noo Jobmonster

CVE-2025-5397

CRITICAL CVSS 9.8 2025-10-31
Threat Entry Updated 2025-10-27

CVE-2025-11897 - Website And Ecommerce Builder For Wordpress Theme

The The7 — Website and eCommerce Builder for WordPress theme for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘ the7_fancy_title_css’ parameter in all versions up to, and including, 12.9.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

THEME Website And Ecommerce Builder For Wordpress

CVE-2025-11897

MEDIUM CVSS 6.4 2025-10-25
Threat Entry Updated 2025-10-27

CVE-2025-8413 - Listeo Theme

The Listeo theme for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's `soundcloud` shortcode in version less than, or equal to, 2.0.8 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

THEME Listeo

CVE-2025-8413

MEDIUM CVSS 6.4 2025-10-25
Threat Entry Updated 2025-10-27

CVE-2025-10737 - Open Source Genesis Framework Theme

The Open Source Genesis Framework theme for WordPress is vulnerable to Stored Cross-Site Scripting via the theme's shortcodes in all versions up to, and including, 3.6.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

THEME Open Source Genesis Framework

CVE-2025-10737

MEDIUM CVSS 6.4 2025-10-25
Threat Entry Updated 2025-10-27

CVE-2025-6440 - Design Services Theme

The WooCommerce Designer Pro plugin for WordPress, used by the Pricom - Printing Company & Design Services WordPress theme, is vulnerable to arbitrary file uploads due to missing file type validation in the 'wcdp_save_canvas_design_ajax' function in all versions up to, and including, 1.9.26. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's server which may make remote code execution possible.

THEME Design Services

CVE-2025-6440

CRITICAL CVSS 9.8 2025-10-24
Threat Entry Updated 2025-10-16

CVE-2025-10706 - Classified Pro Theme

The Classified Pro theme for WordPress is vulnerable to unauthorized plugin installation due to a missing capability check in the 'cwp_addons_update_plugin_cb' function in all versions up to, and including, 1.0.14. This makes it possible for authenticated attackers, with subscriber-level access and above, to install arbitrary plugins on the affected site's server which may make remote code execution possible. Note: The required nonce for the vulnerability is in the CubeWP Framework plugin.

THEME Classified Pro

CVE-2025-10706

HIGH CVSS 8.8 2025-10-16
Threat Entry Updated 2025-10-16

CVE-2025-6042 - Plugin For Wordpress Is Vulnerable To Privilege Escalation In All Versions Up To Theme

The Lisfinity Core - Lisfinity Core plugin used for pebas® Lisfinity WordPress theme plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 1.4.0. This is due to the plugin assigning the editor role by default. While limitations with respect to capabilities are put in place, use of the API is not restricted. This vulnerability can be leveraged together with CVE-2025-6038 to obtain admin privileges.

THEME Plugin For Wordpress Is Vulnerable To Privilege Escalation In All Versions Up To

CVE-2025-6042

HIGH CVSS 7.3 2025-10-15
Threat Entry Updated 2025-10-16

CVE-2025-11746 - Xstore Theme

The XStore theme for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 9.5.4 via theet_ajax_required_plugins_popup() function. This makes it possible for authenticated attackers, with Subscriber-level access and above, to include and execute arbitrary .php files on the server, allowing the execution of any PHP code in those files. This can be used to bypass access controls, obtain sensitive data, or achieve code execution in cases where .php file types can be uploaded and included.

THEME Xstore

CVE-2025-11746

HIGH CVSS 8.8 2025-10-15
Threat Entry Updated 2025-10-14

CVE-2025-8682 - Newsup Theme

The Newsup theme for WordPress is vulnerable to unauthorized plugin installation due to a missing capability check on the newsup_admin_info_install_plugin() function in all versions up to, and including, 5.0.10. This makes it possible for unauthenticated attackers to install the ansar-import plugin.

THEME Newsup

CVE-2025-8682

MEDIUM CVSS 4.3 2025-10-11
Threat Entry Updated 2025-10-14

CVE-2025-6439 - Design Services Theme

The WooCommerce Designer Pro plugin for WordPress, used by the Pricom - Printing Company & Design Services WordPress theme, is vulnerable to arbitrary file deletion due to insufficient file path validation in the 'wcdp_save_canvas_design_ajax' function in all versions up to, and including, 1.9.26. This makes it possible for unauthenticated attackers to delete all files in an arbitrary directory on the server, which can lead to remote code execution, data loss, or site unavailability.

THEME Design Services

CVE-2025-6439

CRITICAL CVSS 9.8 2025-10-11
Scroll to top