8.1

CVSS3.1

CVE-2026-22363 - WordPress Rhodos theme <= 1.3.3 - Local File Inclusion vulnerability

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in axiomthemes Rhodos rhodos allows PHP Local File Inclusion.This issue affects Rhodos: from n/a through <= 1.3.3.

πŸ“… Published: Feb. 20, 2026, 3:47 p.m. πŸ”„ Last Modified: April 16, 2026, 4:45 p.m.

8.1

CVSS3.1

CVE-2026-22362 - WordPress Photolia theme <= 1.0.3 - Local File Inclusion vulnerability

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in axiomthemes Photolia photolia allows PHP Local File Inclusion.This issue affects Photolia: from n/a through <= 1.0.3.

πŸ“… Published: Feb. 20, 2026, 3:47 p.m. πŸ”„ Last Modified: April 17, 2026, 5:30 p.m.

8.1

CVSS3.1

CVE-2026-22361 - WordPress A-Mart theme <= 1.0.2 - Local File Inclusion vulnerability

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in axiomthemes A-Mart a-mart allows PHP Local File Inclusion.This issue affects A-Mart: from n/a through <= 1.0.2.

πŸ“… Published: Feb. 20, 2026, 3:47 p.m. πŸ”„ Last Modified: April 16, 2026, 4:45 p.m.

7.1

CVSS3.1

CVE-2026-22357 - WordPress Link Whisper Free plugin <= 0.9.2 - Cross Site Scripting (XSS) vulnerability

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Spencer Haws Link Whisper Free link-whisper allows Reflected XSS.This issue affects Link Whisper Free: from n/a through <= 0.9.2.

πŸ“… Published: Feb. 20, 2026, 3:47 p.m. πŸ”„ Last Modified: April 16, 2026, 4:45 p.m.

7.5

CVSS3.1

CVE-2026-22356 - WordPress Jetpack CRM plugin <= 6.7.0 - Local File Inclusion vulnerability

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Automattic Jetpack CRM zero-bs-crm allows PHP Local File Inclusion.This issue affects Jetpack CRM: from n/a through <= 6.7.0.

πŸ“… Published: Feb. 20, 2026, 3:47 p.m. πŸ”„ Last Modified: April 16, 2026, 4:45 p.m.

8.8

CVSS3.1

CVE-2026-22354 - WordPress Woocommerce Category Banner Management plugin <= 2.5.1 - PHP Object Injection vulnerabili…

Deserialization of Untrusted Data vulnerability in Dotstore Woocommerce Category Banner Management banner-management-for-woocommerce allows Object Injection.This issue affects Woocommerce Category Banner Management: from n/a through <= 2.5.1.

πŸ“… Published: Feb. 20, 2026, 3:47 p.m. πŸ”„ Last Modified: April 16, 2026, 4:45 p.m.

7.1

CVSS3.1

CVE-2026-22352 - WordPress Persian Woocommerce SMS plugin <= 7.1.1 - Reflected Cross Site Scripting (XSS) vulnerabil…

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in PersianScript Persian Woocommerce SMS persian-woocommerce-sms allows Reflected XSS.This issue affects Persian Woocommerce SMS: from n/a through <= 7.1.1.

πŸ“… Published: Feb. 20, 2026, 3:47 p.m. πŸ”„ Last Modified: April 16, 2026, 6:30 a.m.

7.5

CVSS3.1

CVE-2026-22351 - WordPress WP FullCalendar plugin <= 1.6 - Broken Access Control vulnerability

Missing Authorization vulnerability in Marcus (aka @msykes) WP FullCalendar wp-fullcalendar allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP FullCalendar: from n/a through <= 1.6.

πŸ“… Published: Feb. 20, 2026, 3:47 p.m. πŸ”„ Last Modified: April 24, 2026, 5:46 p.m.

6.5

CVSS3.1

CVE-2026-22350 - WordPress PDF for Elementor Forms + Drag And Drop Template Builder plugin <= 6.3.1 - Broken Access …

Missing Authorization vulnerability in add-ons.org PDF for Elementor Forms + Drag And Drop Template Builder pdf-for-elementor-forms allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects PDF for Elementor Forms + Drag And Drop Template Builder: from n/a through <…

πŸ“… Published: Feb. 20, 2026, 3:47 p.m. πŸ”„ Last Modified: April 24, 2026, 5:46 p.m.

8.8

CVSS3.1

CVE-2026-22346 - WordPress Slider Responsive Slideshow – Image slider, Gallery slideshow plugin <= 1.5.4 - PHP Objec…

Deserialization of Untrusted Data vulnerability in A WP Life Slider Responsive Slideshow – Image slider, Gallery slideshow slider-responsive-slideshow allows Object Injection.This issue affects Slider Responsive Slideshow – Image slider, Gallery slideshow: from n/a through <= 1.5.4.

πŸ“… Published: Feb. 20, 2026, 3:47 p.m. πŸ”„ Last Modified: April 16, 2026, 6:30 a.m.
Total resulsts: 349182
Page 1515 of 34,919
Β« previous page Β» next page
Filters