Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
7.1 HIGH
CVE-2026-22524 — WordPress Legacy Admin plugin <= 9.5 - Reflected Cross Site Scripting (XSS) vulnerability

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in themepassion Legacy Admin legacy-admin allows Reflected XSS.This issue affects Legacy Admin: from…

Remote | Cross-Site Scripting
Mar 25, 2026 Mar 25, 2026
Mar 25, 2026
Mar 25, 2026
7.1 HIGH
CVE-2026-22523 — WordPress Ultra WordPress Admin plugin <= 11.7 - Reflected Cross Site Scripting (XSS) vul…

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in themepassion Ultra WordPress Admin ultra-admin allows Reflected XSS.This issue affects Ultra Word…

Remote | Cross-Site Scripting
Mar 25, 2026 Mar 25, 2026
Mar 25, 2026
Mar 25, 2026
7.1 HIGH
CVE-2026-22520 — WordPress Handmade Framework plugin <= 3.9 - Reflected Cross Site Scripting (XSS) vulnera…

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in G5Theme Handmade Framework handmade-framework allows Reflected XSS.This issue affects Handmade Fr…

Remote | Cross-Site Scripting
Mar 25, 2026 Mar 25, 2026
Mar 25, 2026
Mar 25, 2026
8.1 HIGH
CVE-2026-22516 — WordPress Wizor's theme <= 2.12 - Local File Inclusion vulnerability

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in AncoraThemes Wizor's wizors-investments allows PHP Local File Inclusion.This i…

Remote | Path Traversal
Mar 25, 2026 Mar 26, 2026
Mar 25, 2026
Mar 26, 2026
8.1 HIGH
CVE-2026-22515 — WordPress VegaDays theme <= 1.2.0 - Local File Inclusion vulnerability

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in AncoraThemes VegaDays vegadays allows PHP Local File Inclusion.This issue affe…

Remote | Path Traversal
Mar 25, 2026 Mar 26, 2026
Mar 25, 2026
Mar 26, 2026
8.1 HIGH
CVE-2026-22514 — WordPress Unica theme <= 1.4.1 - Local File Inclusion vulnerability

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in AncoraThemes Unica unica allows PHP Local File Inclusion.This issue affects Un…

Remote | Injection
Mar 25, 2026 Mar 26, 2026
Mar 25, 2026
Mar 26, 2026
8.1 HIGH
CVE-2026-22513 — WordPress Triompher theme <= 1.1.0 - Local File Inclusion vulnerability

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in AncoraThemes Triompher triompher allows PHP Local File Inclusion.This issue af…

Remote | Path Traversal
Mar 25, 2026 Mar 26, 2026
Mar 25, 2026
Mar 26, 2026
8.1 HIGH
CVE-2026-22512 — WordPress Roisin theme <= 1.2.1 - Local File Inclusion vulnerability

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Elated-Themes Roisin roisin allows PHP Local File Inclusion.This issue affects…

Remote | Path Traversal
Mar 25, 2026 Mar 26, 2026
Mar 25, 2026
Mar 26, 2026
8.1 HIGH
CVE-2026-22511 — WordPress NeoBeat theme <= 1.2 - Local File Inclusion vulnerability

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Elated-Themes NeoBeat neobeat allows PHP Local File Inclusion.This issue affec…

Remote | Path Traversal
Mar 25, 2026 Mar 26, 2026
Mar 25, 2026
Mar 26, 2026
8.1 HIGH
CVE-2026-22510 — WordPress Melody theme <= 1.6.3 - PHP Object Injection vulnerability

Deserialization of Untrusted Data vulnerability in AncoraThemes Melody melodyschool allows Object Injection.This issue affects Melody: from n/a through <= 1.6.3.

Remote | Injection
Mar 25, 2026 Mar 26, 2026
Mar 25, 2026
Mar 26, 2026
8.1 HIGH
CVE-2026-22509 — WordPress Gioia theme <= 1.4 - Local File Inclusion vulnerability

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Elated-Themes Gioia gioia allows PHP Local File Inclusion.This issue affects G…

Remote | Path Traversal
Mar 25, 2026 Mar 26, 2026
Mar 25, 2026
Mar 26, 2026
8.1 HIGH
CVE-2026-22508 — WordPress Dentalux theme <= 3.3 - Local File Inclusion vulnerability

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in AncoraThemes Dentalux dentalux allows PHP Local File Inclusion.This issue affe…

Remote | Path Traversal
Mar 25, 2026 Mar 26, 2026
Mar 25, 2026
Mar 26, 2026
9.8 CRITICAL
CVE-2026-22507 — WordPress Beelove theme <= 1.2.6 - PHP Object Injection vulnerability

Deserialization of Untrusted Data vulnerability in AncoraThemes Beelove beelove allows Object Injection.This issue affects Beelove: from n/a through <= 1.2.6.

Remote | Injection
Mar 25, 2026 Mar 26, 2026
Mar 25, 2026
Mar 26, 2026
8.1 HIGH
CVE-2026-22506 — WordPress Amoli theme <= 1.0 - Local File Inclusion vulnerability

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Elated-Themes Amoli amoli allows PHP Local File Inclusion.This issue affects A…

Remote | Path Traversal
Mar 25, 2026 Mar 26, 2026
Mar 25, 2026
Mar 26, 2026
8.1 HIGH
CVE-2026-22505 — WordPress Morning Records theme <= 1.2 - PHP Object Injection vulnerability

Deserialization of Untrusted Data vulnerability in AncoraThemes Morning Records morning-records allows Object Injection.This issue affects Morning Records: from n/a through <= 1.2.

Remote | Injection
Mar 25, 2026 Mar 26, 2026
Mar 25, 2026
Mar 26, 2026
8.1 HIGH
CVE-2026-22504 — WordPress ProLingua theme <= 1.1.12 - Local File Inclusion vulnerability

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ThemeREX ProLingua prolingua allows PHP Local File Inclusion.This issue affect…

Remote | Path Traversal
Mar 25, 2026 Mar 26, 2026
Mar 25, 2026
Mar 26, 2026
8.1 HIGH
CVE-2026-22503 — WordPress Nelson theme <= 1.2.0 - Local File Inclusion vulnerability

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ThemeREX Nelson nelson allows PHP Local File Inclusion.This issue affects Nels…

Remote | Path Traversal
Mar 25, 2026 Mar 26, 2026
Mar 25, 2026
Mar 26, 2026
8.1 HIGH
CVE-2026-22502 — WordPress Mr. Cobbler theme <= 1.1.9 - Local File Inclusion vulnerability

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in AncoraThemes Mr. Cobbler mr-cobbler allows PHP Local File Inclusion.This issue…

Remote | Path Traversal
Mar 25, 2026 Mar 26, 2026
Mar 25, 2026
Mar 26, 2026
9.8 CRITICAL
CVE-2026-22500 — WordPress m2 | Construction and Tools Store theme <= 1.1.2 - PHP Object Injection vulnera…

Deserialization of Untrusted Data vulnerability in axiomthemes m2 | Construction and Tools Store m2-ce allows Object Injection.This issue affects m2 | Construction and Tools Store: from n/a through <…

Remote | Injection
Mar 25, 2026 Mar 26, 2026
Mar 25, 2026
Mar 26, 2026
8.1 HIGH
CVE-2026-22499 — WordPress Lella theme <= 1.2 - Local File Inclusion vulnerability

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Elated-Themes Lella lella allows PHP Local File Inclusion.This issue affects L…

Remote | Path Traversal
Mar 25, 2026 Mar 26, 2026
Mar 25, 2026
Mar 26, 2026
Showing 20 of 6086 Results