Recent Advisories

Severity ID Title Vendor Product Date Type
HIGH 8.1 CVE-2026-40753

WordPress EasyMeals theme <= 1.5.1 - PHP Object Injection vulnerability_CVE-2026-40753

Unauthenticated PHP Object Injection in EasyMeals

Mikado-Themes EasyMeals n/a CVE
HIGH 8.1 CVE-2026-40735

WordPress Reina theme <= 2.1 - PHP Object Injection vulnerability_CVE-2026-40735

Unauthenticated PHP Object Injection in Reina

Edge-Themes Reina n/a CVE
HIGH 8.1 CVE-2026-40731

WordPress ChapterOne theme <= 1.7 - Local File Inclusion vulnerability_CVE-2026-40731

Unauthenticated Local File Inclusion in ChapterOne

Mikado-Themes ChapterOne n/a CVE
HIGH 8.2 CVE-2026-40726

WordPress User Registration Stripe plugin <= 1.3.14 - Broken Access Control vulnerability_CVE-2026-40726

Unauthenticated Broken Access Control in User Registration Stripe

ThemeGrill User Registration Stripe n/a CVE
HIGH 7.5 CVE-2026-40721

WordPress Element Pack Pro plugin <= 9.0.6 - Local File Inclusion vulnerability_CVE-2026-40721

Contributor Local File Inclusion in Element Pack Pro

BdThemes Element Pack Pro n/a CVE
HIGH 7.1 CVE-2026-39597

WordPress WPZOOM Addons for Elementor plugin <= 1.3.4 - Reflected Cross Site Scripting (XSS) vulnerability_CVE-2026-39597

Unauthenticated Cross Site Scripting (XSS) in WPZOOM Addons for Elementor

WPZOOM WPZOOM Addons for Elementor n/a CVE
HIGH 8.1 CVE-2026-39582

WordPress Hitek theme < 1.8.3 - Local File Inclusion vulnerability_CVE-2026-39582

Unauthenticated Local File Inclusion in Hitek < 1.8.3 versions.

xtemos Hitek n/a CVE
HIGH 8.1 CVE-2026-39573

WordPress Mildhill theme <= 1.5 - PHP Object Injection vulnerability_CVE-2026-39573

Unauthenticated PHP Object Injection in Mildhill

Select-Themes Mildhill n/a CVE
HIGH 8.1 CVE-2026-39558

WordPress Malmö theme <= 2.2 - Local File Inclusion vulnerability_CVE-2026-39558

Unauthenticated Local File Inclusion in Malmö

Elated-Themes Malmö n/a CVE
HIGH 7.6 CVE-2026-39546

WordPress MultiLoca plugin <= 4.2.15 - Privilege Escalation vulnerability_CVE-2026-39546

Subscriber Privilege Escalation in MultiLoca

Techspawn MultiLoca n/a CVE