Recent Advisories

Severity ID Title Vendor Product Date Type
HIGH 7.6 CVE-2026-39546

WordPress MultiLoca plugin <= 4.2.15 - Privilege Escalation vulnerability_CVE-2026-39546

Subscriber Privilege Escalation in MultiLoca

Techspawn MultiLoca n/a CVE
HIGH 8.1 CVE-2026-39545

WordPress Zermatt theme <= 1.6.1 - PHP Object Injection vulnerability_CVE-2026-39545

Unauthenticated PHP Object Injection in Zermatt

Select-Themes Zermatt n/a CVE
HIGH 8.1 CVE-2026-39537

WordPress Mikado Core plugin <= 1.6 - Local File Inclusion vulnerability_CVE-2026-39537

Unauthenticated Local File Inclusion in Mikado Core

Mikado-Themes Mikado Core n/a CVE
HIGH 7.5 CVE-2026-34888

WordPress Bricksforge plugin <= 3.1.8.4 - Sensitive Data Exposure vulnerability_CVE-2026-34888

Unauthenticated Sensitive Data Exposure in Bricksforge

Bricksforge Bricksforge n/a CVE
HIGH 8.6 CVE-2026-27400

WordPress BookPro plugin <= 1.1.0 - Arbitrary File Deletion vulnerability_CVE-2026-27400

Unauthenticated Arbitrary File Deletion in BookPro

Ovatheme BookPro n/a CVE
HIGH 8.1 CVE-2026-25439

WordPress Booknetic plugin <= 4.8.5 - Account Takeover vulnerability_CVE-2026-25439

Unauthenticated Broken Authentication in Booknetic

fs-code Booknetic n/a CVE
HIGH 8.6 CVE-2026-22343

WordPress WordPress Dating Theme theme <= 11.2.0 - Broken Access Control vulnerability_CVE-2026-22343

Unauthenticated Broken Access Control in WordPress Dating Theme

PremiumPress Limited. WordPress Dating Theme n/a CVE
HIGH 8.8 CVE-2026-22342

WordPress WordPress Dating Theme theme <= 11.2.0 - Cross Site Request Forgery (CSRF) to Account Takeover vulnerability_CVE-2026-22342

Unauthenticated Cross Site Request Forgery (CSRF) in WordPress Dating Theme

PremiumPress Limited. WordPress Dating Theme n/a CVE
HIGH 7.1 CVE-2026-22339

WordPress WPJobster theme <= 6.3.5 - Reflected Cross Site Scripting (XSS) vulnerability_CVE-2026-22339

Unauthenticated Cross Site Scripting (XSS) in WPJobster

Jobster Marketplace WPJobster n/a CVE
HIGH 8.1 CVE-2026-22338

WordPress EcoBlue theme <= 1.15 - Local File Inclusion vulnerability_CVE-2026-22338

Unauthenticated Local File Inclusion in EcoBlue

ThemeREX EcoBlue n/a CVE