vciy

CVEs we hold for Theme

Records whose assigning authority named Theme as the affected vendor. Newest identifiers first, capped at 200.

CVE-2026-9832Payment Gateway of Stripe for WooCommerce <= 5.0.8 - Unauthenticated Improper Verification of Cryptographic Signature…themehigh Payment Gateway of Stripe for WooCommerce
CVE-2026-92465WordPress WP Mega Menu plugin <= 1.4.2 - SQL Injection vulnerabilityThemeum WP Mega Menu
CVE-2026-9018Easy Elements for Elementor – Addons & Website Templates <= 1.4.5 - Unauthenticated Privilege Escalation via…themewant Easy Elements for Elementor – Addons & Website…
CVE-2026-8976RSS Aggregator by Feedzy <= 5.1.7 - Missing Authorization to Authenticated (Contributor+) Import Job Creation…themeisle RSS Aggregator by Feedzy – Feed to Post…
CVE-2026-89333Tutor LMS <= 4.0.8 - Insecure Direct Object Reference to Authenticated (Subscriber+) Sensitive Information Exposure via…themeum Tutor LMS – eLearning and online course solution
CVE-2026-89081Tutor LMS <= 4.0.8 - Reflected Cross-Site Scripting via 'back_url' and 'search' Parametersthemeum Tutor LMS – eLearning and online course solution
CVE-2026-89023ThemeAtelier Domain For Sale < 3.5.2 Missing Authorization via REST APIThemeAtelier Domain For Sale
CVE-2026-88944Tutor LMS <= 4.0.8 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Post Deletion via 'lesson_id'…themeum Tutor LMS – eLearning and online course solution
CVE-2026-8713Avada (Fusion) Builder <= 3.15.3 - Unauthenticated Arbitrary File Deletion via Form Entry Valuethemefusion Avada (Fusion) Builder
CVE-2026-8689Visualizer: Tables and Charts Manager for WordPress <= 3.11.14 - Missing Authorization to Authenticated (Subscriber+)…themeisle Visualizer: Tables and Charts Manager for…
CVE-2026-85198MPG <= 4.2.1 - Unauthenticated SQL Injection via URL Paththemeisle MPG – Multiple Page Generator, Bulk Landing Pages…
CVE-2026-8206Kirki 6.0.0 - 6.0.6 - Unauthenticated Privilege Escalation via 'handle_forgot_password'themeum Kirki – Freeform Page Builder, Website Builder &…
CVE-2026-81785WordPress BuddyForms plugin <= 2.9.0 - Broken Access Control vulnerabilityThemekraft BuddyForms
CVE-2026-81583Theme My Login 7.0 - 7.1.15 - Subscriber+ Unauthorised Multisite Site Creation and Privilege EscalationUnknown Theme My Login
CVE-2026-8096Kirki <= 6.0.6 - Missing Authorization to Authenticated (Subscriber+) Sensitive Form Submission Data Exposure via…themeum Kirki – Freeform Page Builder, Website Builder &…
CVE-2026-8073Kirki <= 6.0.6 - Unauthenticated Limited Arbitrary File Read and Deletion via downloadZIPthemeum Kirki – Freeform Page Builder, Website Builder &…
CVE-2026-78290WordPress Magazine Blocks plugin <= 1.8.6 - Cross Site Scripting (XSS) vulnerabilityThemeGrill Magazine Blocks
CVE-2026-78175Tutor LMS <= 4.0.7 - Authenticated (Subscriber+) PHP Object Injection to Remote Code Executionthemeum Tutor LMS – eLearning and online course solution
CVE-2026-73347WordPress TrueBooker plugin <= 1.2.6 - Privilege Escalation vulnerabilityThemetechMount TrueBooker
CVE-2026-73189WordPress WP Crowdfunding plugin < 2.2.1 - Insecure Direct Object References (IDOR) vulnerabilityThemeum WP Crowdfunding
CVE-2026-73181WordPress Extra Product Options & Add-Ons for WooCommerce plugin < 7.6 - Arbitrary File Download vulnerabilityThemeComplete Extra Product Options & Add-Ons for…
CVE-2026-7284Easy Elements for Elementor <= 1.4.4 - Unauthenticated Privilege Escalation via easyel_handle_registerthemewant Easy Elements for Elementor – Addons & Website…
CVE-2026-6965Tutor LMS <= 3.9.9 - Insecure Direct Object Reference to Authenticated (Instructor+) Arbitrary Post Deletion via…themeum Tutor LMS – eLearning and online course solution
CVE-2026-66652WordPress Grand Tour theme <= 5.5.1 - Cross Site Request Forgery (CSRF) vulnerabilityThemeGoods Grand Tour
CVE-2026-66650WordPress FreightCo theme <= 1.1.15 - PHP Object Injection vulnerabilityTheme-Rex FreightCo
CVE-2026-66629WordPress Kirki plugin <= 6.2.3 - Cross Site Scripting (XSS) vulnerabilityThemeum Kirki
CVE-2026-66607WordPress Advance Product Search plugin <= 1.4.8 - Cross Site Scripting (XSS) vulnerabilityThemeHunk Advance Product Search
CVE-2026-66606WordPress SmartSMTP plugin <= 1.2.0 - Cross Site Scripting (XSS) vulnerabilityThemeGrill SmartSMTP
CVE-2026-66586WordPress WP Cafe Pro plugin < 3.0.15 - Local File Inclusion vulnerabilityThemewinter WP Cafe Pro
CVE-2026-66471WordPress Accordion plugin <= 3.0.6 - Cross Site Scripting (XSS) vulnerabilityThemepoints Accordion
CVE-2026-66437WordPress Feedzy plugin <= 5.2.4 - Server Side Request Forgery (SSRF) vulnerabilityThemeisle Feedzy
CVE-2026-65573WordPress Abelle theme <= 1.22 - PHP Object Injection vulnerabilityThemeREX Abelle
CVE-2026-65563WordPress Orbit Fox by ThemeIsle plugin <= 3.0.7 - Cross Site Scripting (XSS) vulnerabilityThemeIsle
CVE-2026-65537WordPress Cyr to Lat reloaded – transliteration of links and file names plugin <= 1.3.3 - Broken Access Control…Themeisle Cyr to Lat reloaded – transliteration of links…
CVE-2026-65531WordPress Qubely plugin <= 1.8.14 - Broken Access Control vulnerabilityThemeum Qubely
CVE-2026-65526WordPress Visualizer plugin <= 4.0.1 - SQL Injection vulnerabilityThemeisle Visualizer
CVE-2026-65524WordPress Avada Custom Branding plugin <= 1.2 - Broken Access Control vulnerabilityThemeFusion Avada Custom Branding
CVE-2026-65487WordPress Photography theme <= 7.7.6 - Broken Access Control vulnerabilityThemeGoods Photography
CVE-2026-65439WordPress Ultimate Addons for Contact Form 7 plugin <=3.5.45 - Cross Site Scripting (XSS) vulnerabilityThemefic Ultimate Addons for Contact Form 7
CVE-2026-65436WordPress Kirki plugin <= 6.0.13 - Arbitrary File Deletion vulnerabilityThemeum Kirki
CVE-2026-65433WordPress RT Mega Menu – Mega Menu Builder for Elementor & Gutenberg plugin <= 1.5.1 - Broken Access Control…themewant RT Mega Menu – Mega Menu Builder for Elementor…
CVE-2026-6279Avada (Fusion) Builder <= 3.15.2 - Unauthenticated Remote Code Execution via PHP Function Injection via 'render_logics'…themefusion Avada (Fusion) Builder
CVE-2026-62105WordPress ThemeREX Addons plugin < 2.45.0 - PHP Object Injection vulnerabilityThemeREX Addons
CVE-2026-61970WordPress Auto Featured Image (Auto Post Thumbnail) plugin <= 5.0.4 - Server Side Request Forgery (SSRF) vulnerabilityThemeisle Auto Featured Image (Auto Post Thumbnail)
CVE-2026-61960WordPress WP Full Stripe Free plugin <= 8.5.0 - Cross Site Scripting (XSS) vulnerabilityThemeisle WP Full Stripe Free
CVE-2026-61951WordPress TrueBooker plugin <= 1.2.3 - Privilege Escalation vulnerabilitythemetechmount TrueBooker
CVE-2026-61950WordPress TrueBooker plugin <= 1.2.3 - SQL Injection vulnerabilitythemetechmount TrueBooker
CVE-2026-6080Tutor LMS <= 3.9.8 - Authenticated (Admin+) SQL Injection via 'date' Parameterthemeum Tutor LMS – eLearning and online course solution
CVE-2026-60034Joomla Extension - themexpert.com - Authenticated stored XSS in JMedia Extension < 1.6.0themexpert.com JMedia extension for Joomla
CVE-2026-60033Joomla Extension - themexpert.com - SSRF via remote download in JMedia Extension < 1.6.0themexpert.com JMedia extension for Joomla
CVE-2026-60032Joomla Extension - themexpert.com - Authenticated arbitrary file upload in JMedia < 1.6.0themexpert.com JMedia extension for Joomla
CVE-2026-60031Joomla Extension - themexpert.com - Information disclosure in Quix Page Builder < 6.2.1themexpert.com Quix Page Builder Pro extension for Joomla
CVE-2026-60030Joomla Extension - themexpert.com - Broken Access Control for media management in Quix Page Builder < 6.2.1themexpert.com Quix Page Builder Pro extension for Joomla
CVE-2026-60029Joomla Extension - themexpert.com - Authenticated stored XSS in Quix Page Builder < 6.2.1themexpert.com Quix Page Builder Pro extension for Joomla
CVE-2026-60028Joomla Extension - themexpert.com - Authenticated stored XSS in Quix Page Builder < 6.2.1themexpert.com Quix Page Builder Pro extension for Joomla
CVE-2026-60027Joomla Extension - themexpert.com - Unauthenticated path traversal / file read in Quix Page Builder < 6.2.1themexpert.com Quix Page Builder Pro extension for Joomla
CVE-2026-60026Joomla Extension - themexpert.com - Authenticated PHP code execution in Quix Page Builder < 6.2.1themexpert.com Quix Page Builder Pro extension for Joomla
CVE-2026-59559WordPress RT Mega Menu – Mega Menu Builder for Elementor & Gutenberg plugin <= 1.5.1 - Cross Site Scripting (XSS)…themewant RT Mega Menu – Mega Menu Builder for Elementor…
CVE-2026-58078Joomla Extension - themexpert.com - Unauthenticated SQL injection in Quix Page Builder Pro < 6.2.1themexpert.com Quix Page Builder Pro extension for Joomla
CVE-2026-57797WordPress EduMall theme <= 4.5.1 - Broken Access Control vulnerabilityThemeMove EduMall
CVE-2026-57795WordPress Kitchor theme <= 1.4.3 - Local File Inclusion vulnerabilitythemelexus Kitchor
CVE-2026-57791WordPress Brook theme <= 2.9.0 - Local File Inclusion vulnerabilityThemeMove Brook
CVE-2026-57790WordPress Billey theme <= 2.1.8 - Local File Inclusion vulnerabilityThemeMove Billey
CVE-2026-57779WordPress Fascinate theme <= 1.1.5 - Broken Access Control vulnerabilitythemebeez Fascinate
CVE-2026-57770WordPress Grand Photography theme <= 5.7.8 - PHP Object Injection vulnerabilityThemeGoods Grand Photography
CVE-2026-57769WordPress Grand Photography theme <= 5.7.8 - Reflected Cross Site Scripting (XSS) vulnerabilityThemeGoods Grand Photography
CVE-2026-57749WordPress SportsPress Pro plugin <= 2.7.29 - Local File Inclusion vulnerabilityThemeBoy SportsPress Pro
CVE-2026-57747WordPress Booked plugin <= 3.0.0 - Cross Site Request Forgery (CSRF) vulnerabilityThemeREX Booked
CVE-2026-57746WordPress Booked plugin <= 3.0.0 - Broken Access Control vulnerabilityThemeREX Booked
CVE-2026-57727WordPress Kirki plugin <= 6.0.13 - Broken Access Control vulnerabilityThemeum Kirki
CVE-2026-57726WordPress Kirki plugin <= 6.0.12 - SQL Injection vulnerabilityThemeum Kirki
CVE-2026-57725WordPress Kirki plugin <= 6.0.11 - Cross Site Scripting (XSS) vulnerabilityThemeum Kirki
CVE-2026-57724WordPress Kirki plugin <= 6.0.12 - PHP Object Injection vulnerabilityThemeum Kirki
CVE-2026-57694WordPress Tutor LMS plugin <= 3.9.13 - Insecure Direct Object References (IDOR) vulnerabilityThemeum Tutor LMS
CVE-2026-57680WordPress Kirki plugin <= 6.0.11 - Insecure Direct Object References (IDOR) vulnerabilityThemeum Kirki
CVE-2026-57678WordPress Slider Revolution plugin 7.0.0-7.0.16 - Cross Site Scripting (XSS) vulnerabilityThemePunch Slider Revolution
CVE-2026-57627WordPress Kirki plugin <= 6.0.11 - Server Side Request Forgery (SSRF) vulnerabilityThemeum Kirki
CVE-2026-57618WordPress Neve PRO theme <= 3.1.2 - Cross Site Scripting (XSS) vulnerabilityThemeisle Neve PRO
CVE-2026-57405WordPress Open Shop theme <= 1.7.1 - Broken Access Control vulnerabilitythemehunk Open Shop
CVE-2026-57395WordPress Tourfic plugin <= 2.22.5 - Broken Access Control vulnerabilityThemefic Tourfic
CVE-2026-57392WordPress Tourfic plugin <= 2.22.5 - Broken Access Control vulnerabilityThemefic Tourfic
CVE-2026-57388WordPress Hydra Booking plugin <= 1.1.44 - Cross Site Scripting (XSS) vulnerabilityThemefic Hydra Booking
CVE-2026-56070WordPress Advance Product Search plugin <= 1.4.4 - SQL Injection vulnerabilityThemeHunk Advance Product Search
CVE-2026-56064WordPress Tourfic plugin <= 2.22.5 - SQL Injection vulnerabilityThemefic Tourfic
CVE-2026-56058WordPress Quform plugin <= 2.23.0 - Arbitrary File Upload vulnerabilityThemeCatcher Quform
CVE-2026-56050WordPress PPOM for WooCommerce plugin <= 33.0.18 - Broken Access Control vulnerabilityThemeisle PPOM for WooCommerce
CVE-2026-56028WordPress Easy Elements for Elementor – Addons & Website Templates plugin <= 1.4.9 - Privilege Escalation vulnerabilitythemewant Easy Elements for Elementor &#8211; Addons &amp…
CVE-2026-56008WordPress Fusion Builder plugin <= 3.15.4 - Privilege Escalation vulnerabilityThemeFusion Fusion Builder
CVE-2026-5502Tutor LMS <= 3.9.8 - Authenticated (Subscriber+) Arbitrary Course Content Manipulation via…themeum Tutor LMS – eLearning and online course solution
CVE-2026-54807WordPress Registration Form for WooCommerce plugin <= 1.0.9 - Privilege Escalation vulnerabilityThemeGrill Registration Form for WooCommerce
CVE-2026-54194WordPress Fusion Builder plugin <= 3.15.4 - PHP Object Injection vulnerabilityThemeFusion Fusion Builder
CVE-2026-54193WordPress Fusion Builder plugin <= 3.15.4 - Arbitrary File Deletion vulnerabilityThemeFusion Fusion Builder
CVE-2026-54185WordPress Cornerstone plugin < 7.8.8 - SQL Injection vulnerabilityTHEMECO Cornerstone
CVE-2026-5324Brizy – Page Builder <= 2.8.11 - Unauthenticated Stored Cross-Site Scripting via FileUpload Field Valuethemefusecom Brizy – Page Builder
CVE-2026-52701WordPress User Registration plugin <= 5.2.2 - Broken Access Control vulnerabilityThemegrill User Registration
CVE-2026-4945Otter Blocks <= 3.1.7 - Missing Authorization to Unauthenticated Purchase Verification Bypassthemeisle Otter Blocks – Gutenberg Blocks, Page Builder for…
CVE-2026-49113WordPress Cornerstone plugin < 7.8.8 - Arbitrary Code Execution vulnerabilityTHEMECO Cornerstone
CVE-2026-49111WordPress Masteriyo - LMS plugin <= 2.2.0 - Privilege Escalation vulnerabilityThemeGrill Masteriyo - LMS
CVE-2026-49081WordPress User Registration Stripe plugin <= 1.3.12 - Broken Access Control vulnerabilityThemeGrill User Registration Stripe
CVE-2026-48881WordPress TrueBooker plugin <= 1.1.9 - Broken Access Control vulnerabilitythemetechmount TrueBooker
CVE-2026-4804Zakra <= 4.2.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via Post Meta REST APIthemegrill Zakra
CVE-2026-4798Avada Builder <= 3.15.1 - Unauthenticated SQL Injection via 'product_order' Parameterthemefusion Avada (Fusion) Builder
CVE-2026-4782Avada Builder <= 3.15.2 - Authenticated (Subscriber+) Arbitrary File Read via 'custom_svg' Shortcode Parameterthemefusion Avada (Fusion) Builder
CVE-2026-45217WordPress Stripe Payment Gateway for WooCommerce plugin <= 5.0.7 - Broken Authentication vulnerabilityThemeHigh Stripe Payment Gateway for WooCommerce
CVE-2026-4431Easy Post Submission <= 2.3.0 - Missing Authorizationthemeruby Easy Post Submission – Frontend Posting, Guest…
CVE-2026-42749WordPress Disable Comments for Any Post Types (Remove comments) plugin <= 1.3.0 - Broken Authentication vulnerabilityThemeisle Disable Comments for Any Post Types (Remove…
CVE-2026-42743WordPress Masteriyo - LMS plugin <= 2.1.8 - Broken Authentication vulnerabilityThemeGrill Masteriyo - LMS
CVE-2026-42675WordPress Hydra Booking plugin <= 1.1.41 - Broken Access Control vulnerabilityThemefic Hydra Booking
CVE-2026-42378WordPress WP Full Stripe Free plugin <= 8.4.1 - Broken Authentication vulnerabilityThemeisle WP Full Stripe Free
CVE-2026-40743WordPress Tutor LMS plugin <= 3.9.7 - Broken Access Control vulnerabilityThemeum Tutor LMS
CVE-2026-40740WordPress Tutor LMS plugin <= 3.9.7 - Broken Access Control vulnerabilityThemeum Tutor LMS
CVE-2026-40730WordPress ThemeGrill Demo Importer plugin <= 2.0.0.6 - Broken Access Control vulnerabilityThemeGrill Demo Importer
CVE-2026-40726WordPress User Registration Stripe plugin <= 1.3.14 - Broken Access Control vulnerabilityThemeGrill User Registration Stripe
CVE-2026-39663WordPress TrueBooker plugin <= 1.1.5 - Broken Access Control vulnerabilitythemetechmount TrueBooker
CVE-2026-39649WordPress Royale News theme <= 2.2.4 - Broken Access Control vulnerabilitythemebeez Royale News
CVE-2026-39648WordPress Cream Blog theme <= 2.1.7 - Broken Access Control vulnerabilitythemebeez Cream Blog
CVE-2026-39638WordPress Qubely plugin <= 1.8.14 - Cross Site Scripting (XSS) vulnerabilityThemeum Qubely
CVE-2026-39635WordPress Grand Magazine theme <= 3.5.5 - Cross Site Request Forgery (CSRF) vulnerabilityThemeGoods Grand Magazine
CVE-2026-39634WordPress Grand Portfolio theme <= 3.3 - Cross Site Request Forgery (CSRF) vulnerabilityThemeGoods Grand Portfolio
CVE-2026-39633WordPress Grand Car Rental theme <= 3.6.9 - Cross Site Request Forgery (CSRF) vulnerabilityThemeGoods Grand Car Rental
CVE-2026-39632WordPress Grand Blog theme <= 3.1 - Cross Site Request Forgery (CSRF) vulnerabilityThemeGoods Grand Blog
CVE-2026-39618WordPress NewsExo theme <= 7.1 - Cross Site Request Forgery (CSRF) vulnerabilitythemearile NewsExo
CVE-2026-39603WordPress Grand Photography theme <= 5.7.8 - Cross Site Request Forgery (CSRF) vulnerabilityThemeGoods Grand Photography
CVE-2026-39594WordPress Ultra Addons for WPForms plugin <= 1.0.11 - Broken Access Control vulnerabilityThemefic Ultra Addons for WPForms
CVE-2026-39590WordPress Atomlab theme <= 2.4.5 - Local File Inclusion vulnerabilityThemeMove Atomlab
CVE-2026-39571WordPress Instantio plugin <= 3.3.30 - Sensitive Data Exposure vulnerabilityThemefic Instantio
CVE-2026-39544WordPress LabtechCO theme <= 8.3 - Local File Inclusion vulnerabilitythemeStek LabtechCO
CVE-2026-39543WordPress Tourfic plugin <= 2.21.4 - Broken Access Control vulnerabilityThemefic Tourfic
CVE-2026-39541WordPress Hydra Booking plugin <= 1.1.38 - Cross Site Scripting (XSS) vulnerabilityThemefic Hydra Booking
CVE-2026-39529WordPress Elementra theme <= 1.0.9 - PHP Object Injection vulnerabilityThemeREX Group Elementra
CVE-2026-39524WordPress Masteriyo - LMS plugin <= 2.1.5 - Payment Bypass vulnerabilityThemeGrill Masteriyo - LMS
CVE-2026-39507WordPress Social Slider Feed plugin <= 2.3.2 - Cross Site Scripting (XSS) vulnerabilityThemeisle Social Slider Feed
CVE-2026-39500WordPress themesflat-addons-for-elementor plugin <= 2.3.2 - Cross Site Scripting (XSS) vulnerabilitythemesflat-addons-for-elementor
CVE-2026-3371Tutor LMS <= 3.9.7 - Authenticated (Subscriber+) Insecure Direct Object Reference to Arbitrary Course Content…themeum Tutor LMS – eLearning and online course solution
CVE-2026-3360Tutor LMS <= 3.9.7 - Missing Authorization to Unauthenticated Arbitrary Billing Profile Overwrite via 'order_id'…themeum Tutor LMS – eLearning and online course solution
CVE-2026-3358Tutor LMS <= 3.9.7 - Missing Authorization to Authenticated (Subscriber+) Unauthorized Private Course Enrollmentthemeum Tutor LMS – eLearning and online course solution
CVE-2026-32542WordPress Fusion Builder plugin < 3.15.0 - Reflected Cross Site Scripting (XSS) vulnerabilityThemeFusion Fusion Builder
CVE-2026-32532WordPress Contact Form & Lead Form Elementor Builder plugin <= 2.0.1 - Cross Site Scripting (XSS) vulnerabilityThemeHunk Contact Form & Lead Form Elementor Builder
CVE-2026-32471WordPress ProLancer Element plugin <= 1.4.8 - SQL Injection vulnerabilityThemeBing ProLancer Element
CVE-2026-32460WordPress Ultimate Addons for Contact Form 7 plugin <= 3.5.36 - Cross Site Scripting (XSS) vulnerabilityThemefic Ultimate Addons for Contact Form 7
CVE-2026-32454WordPress Avada Core plugin < 5.15.0 - Cross Site Scripting (XSS) vulnerabilityThemeFusion Avada Core
CVE-2026-32453WordPress Avada Core plugin < 5.15.0 - Broken Access Control vulnerabilityThemeFusion Avada Core
CVE-2026-32452WordPress Fusion Builder plugin < 3.15.0 - Broken Access Control vulnerabilityThemeFusion Fusion Builder
CVE-2026-32451WordPress Fusion Builder plugin < 3.15.0 - Broken Access Control vulnerabilityThemeFusion Fusion Builder
CVE-2026-32426WordPress Medilazar Core plugin < 1.4.7 - Local File Inclusion vulnerabilitythemelexus Medilazar Core
CVE-2026-32408WordPress Brizy plugin <= 2.7.23 - Broken Access Control vulnerabilitythemefusecom Brizy
CVE-2026-32400WordPress Boldman theme <= 7.7 - Local File Inclusion vulnerabilityThemetechMount Boldman
CVE-2026-3231Checkout Field Editor (Checkout Manager) for WooCommerce <= 2.1.7 - Unauthenticated Stored Cross-Site Scripting via…themehigh Checkout Field Editor (Checkout Manager) for…
CVE-2026-2892Otter Blocks <= 3.1.4 - Improper Authorization to Unauthenticated Purchase Verification Bypass via Forged Cookiethemeisle Otter Blocks – Gutenberg Blocks, Page Builder for…
CVE-2026-28191WordPress The Grid plugin <= 2.8.0 - Privilege Escalation vulnerabilityThemeOne The Grid
CVE-2026-28190WordPress ProLancer Element plugin <= 1.4.8 - Broken Access Control vulnerabilityThemeBing ProLancer Element
CVE-2026-28188WordPress Hydra Booking plugin <= 1.2.2 - Broken Access Control vulnerabilitythemefic Hydra Booking
CVE-2026-28186WordPress Travelfic Toolkit plugin <= 1.5.1 - Broken Access Control vulnerabilitythemefic Travelfic Toolkit
CVE-2026-28128WordPress Verse theme <= 1.7.0 - Local File Inclusion vulnerabilityThemeREX Verse
CVE-2026-28120WordPress Dr.Patterson theme <= 1.3.2 - Local File Inclusion vulnerabilityThemeREX Dr.Patterson
CVE-2026-28107WordPress Muzicon theme <= 1.9.0 - Local File Inclusion vulnerabilityThemeREX Muzicon
CVE-2026-28105WordPress Good Energy theme <= 1.7.7 - PHP Object Injection vulnerabilityThemeREX Good Energy
CVE-2026-28098WordPress Save Life theme <= 1.2.13 - Local File Inclusion vulnerabilityThemeREX Save Life
CVE-2026-28097WordPress Artrium theme <= 1.0.14 - Local File Inclusion vulnerabilityThemeREX Artrium
CVE-2026-28096WordPress WealthCo theme <= 2.18 - Local File Inclusion vulnerabilityThemeREX WealthCo
CVE-2026-28095WordPress Marcell theme <= 1.2.14 - Local File Inclusion vulnerabilityThemeREX Marcell
CVE-2026-28094WordPress RexCoin theme <= 1.2.6 - Local File Inclusion vulnerabilityThemeREX RexCoin
CVE-2026-28093WordPress Ozisti theme <= 1.1.10 - Local File Inclusion vulnerabilityThemeREX Ozisti
CVE-2026-28092WordPress Sounder theme <= 1.3.11 - Local File Inclusion vulnerabilityThemeREX Sounder
CVE-2026-28091WordPress Coleo theme <= 1.1.7 - Local File Inclusion vulnerabilityThemeREX Coleo
CVE-2026-28090WordPress Gamezone theme <= 1.1.11 - Local File Inclusion vulnerabilityThemeREX Gamezone
CVE-2026-28089WordPress Daiquiri theme <= 1.2.4 - Local File Inclusion vulnerabilityThemeREX Daiquiri
CVE-2026-28088WordPress Aqualots theme <= 1.1.6 - Local File Inclusion vulnerabilityThemeREX Aqualots
CVE-2026-28087WordPress Filmax theme <= 1.1.11 - Local File Inclusion vulnerabilityThemeREX Filmax
CVE-2026-28086WordPress Run Gran theme <= 2.0 - Local File Inclusion vulnerabilityThemeREX Run Gran
CVE-2026-28085WordPress Mahogany theme <= 2.9 - Local File Inclusion vulnerabilityThemeREX Mahogany
CVE-2026-28084WordPress Bazinga theme <= 1.1.9 - Local File Inclusion vulnerabilityThemeREX Bazinga
CVE-2026-28081WordPress Windsor theme <= 2.5.0 - Local File Inclusion vulnerabilityThemeREX Windsor
CVE-2026-28077WordPress Vapester theme <= 1.1.10 - Local File Inclusion vulnerabilityThemeREX Vapester
CVE-2026-28074WordPress Pizza House theme <= 1.4.0 - PHP Object Injection vulnerabilityThemeREX Pizza House
CVE-2026-28069WordPress Le Truffe theme <= 1.1.7 - Local File Inclusion vulnerabilityThemeREX Le Truffe
CVE-2026-28068WordPress Rhythmo theme <= 1.3.4 - Local File Inclusion vulnerabilityThemeREX Rhythmo
CVE-2026-28067WordPress Bassein theme <= 1.0.15 - Local File Inclusion vulnerabilityThemeREX Bassein
CVE-2026-28066WordPress Legrand theme <= 2.17 - Local File Inclusion vulnerabilityThemeREX Legrand
CVE-2026-28065WordPress Eject theme <= 2.17 - Local File Inclusion vulnerabilityThemeREX Eject
CVE-2026-28064WordPress Edge Decor theme <= 2.2 - Local File Inclusion vulnerabilityThemeREX Edge Decor
CVE-2026-28063WordPress Asia Garden theme <= 1.3.1 - Local File Inclusion vulnerabilityThemeREX Asia Garden
CVE-2026-28062WordPress Happy Baby theme <= 1.2.12 - Local File Inclusion vulnerabilityThemeREX Happy Baby
CVE-2026-28061WordPress Tiger Claw theme <= 1.1.14 - Local File Inclusion vulnerabilityThemeREX Tiger Claw
CVE-2026-28060WordPress S.King theme <= 1.5.3 - Local File Inclusion vulnerabilityThemeREX S.King
CVE-2026-28059WordPress Dermatology Clinic theme <= 1.4.3 - Local File Inclusion vulnerabilityThemeREX Dermatology Clinic
CVE-2026-28058WordPress Dixon theme <= 1.4.2.1 - Local File Inclusion vulnerabilityThemeREX Dixon
CVE-2026-28057WordPress Mandala theme <= 2.8 - Local File Inclusion vulnerabilityThemeREX Mandala
CVE-2026-28056WordPress MCKinney's Politics theme <= 1.2.8 - Local File Inclusion vulnerabilityThemeREX MCKinney's Politics
CVE-2026-28055WordPress M.Williamson theme <= 1.2.11 - Local File Inclusion vulnerabilityThemeREX M.Williamson
CVE-2026-28054WordPress Legal Stone theme <= 1.2.11 - Local File Inclusion vulnerabilityThemeREX Legal Stone
CVE-2026-28053WordPress Miller theme <= 1.3.3 - Local File Inclusion vulnerabilityThemeREX Miller
CVE-2026-28052WordPress Peter Mason theme <= 1.4.5 - Local File Inclusion vulnerabilityThemeREX Peter Mason
CVE-2026-28051WordPress Yacht Rental theme <= 2.6 - Local File Inclusion vulnerabilityThemeREX Yacht Rental
CVE-2026-28050WordPress Beacon theme <= 2.24 - Local File Inclusion vulnerabilityThemeREX Beacon
CVE-2026-28049WordPress Police Department theme <= 2.17 - Local File Inclusion vulnerabilityThemeREX Police Department
CVE-2026-28046WordPress Law Office theme <= 3.3.0 - Local File Inclusion vulnerabilityThemeREX Law Office
CVE-2026-28045WordPress N7 | Golf Club Sports & Events theme <= 2.16.0 - Local File Inclusion vulnerabilityThemeREX N7 | Golf Club Sports & Events
CVE-2026-28043WordPress Healer - Doctor, Clinic & Medical WordPress Theme theme <= 1.0.0 - Local File Inclusion vulnerabilityThemeREX Healer - Doctor, Clinic & Medical WordPress Theme
CVE-2026-28035WordPress Printy theme <= 1.8 - Local File Inclusion vulnerabilityThemeREX Printy

200 records, read from the index as it stood on 20 Sep 2026. Every row opens the record it names, and every value on that record opens its own receipt.

Everything on this page is free. Public data. Withholding it protects nothing.