漏洞列表 359408
CVE ID 标题 严重程度 CVSS 发布时间 受影响产品 数据源 操作
CVE-2025-68843
WordPress FeedWordPress Advanced Filters plugin <= 0.6.2 - Reflected Cross Site Scripting (XSS) vulnerability
HIGH 7.1 2026-02-20
Bas Schuiling FeedWordPress Advanced Filters
CVE NVD
CVE-2025-68842
WordPress Widget Logic Visual plugin <= 1.52 - Reflected Cross Site Scripting (XSS) vulnerability
HIGH 7.1 2026-02-20
totalbounty Widget Logic Visual
CVE NVD
CVE-2025-68841
WordPress TopperPack – Complete Elementor Addons, theme & CPT Builder plugin <= 1.2.1 - Local File Inclusion vulnerability
HIGH 7.5 2026-02-20
Themepul TopperPack – Complete Elementor Addons, Theme &amp; CPT Builder
CVE NVD
CVE-2025-68837
WordPress ELEX WordPress HelpDesk & Customer Ticketing System plugin <= 3.3.5 - Broken Access Control vulnerability
MEDIUM 6.5 2026-02-20
ELEXtensions ELEX WordPress HelpDesk & Customer Ticketing System
CVE NVD
CVE-2025-68834
WordPress Sync Master Sheet – Product Sync with Google Sheet for WooCommerce plugin <= 1.1.3 - Broken Access Control vulnerability
MEDIUM -1.0 2026-02-20
Saiful Islam Sync Master Sheet &#8211; Product Sync with Google Sheet for WooCommerce
CVE NVD
CVE-2025-68564
WordPress Sendy plugin <= 3.4.2 - Broken Access Control vulnerability
MEDIUM 6.5 2026-02-20
sendy Sendy
CVE NVD
CVE-2025-68552
WordPress WooCommerce Coming Soon Product with Countdown plugin <= 5.0 - Local File Inclusion vulnerability
MEDIUM 6.3 2026-02-20
WebCodingPlace WooCommerce Coming Soon Product with Countdown
CVE NVD
CVE-2025-68549
WordPress Wiguard theme < 2.0.1 - Arbitrary File Upload vulnerability
CRITICAL 9.9 2026-02-20
zozothemes Wiguard
CVE NVD
CVE-2025-68545
WordPress Nika theme <= 1.2.14 - Local File Inclusion vulnerability
CRITICAL 9.1 2026-02-20
thembay Nika
CVE NVD
CVE-2025-68543
WordPress Diza theme <= 1.3.15 - Local File Inclusion vulnerability
HIGH 8.1 2026-02-20
thembay Diza
CVE NVD
CVE-2025-68542
WordPress Checkout Gateway for IRIS plugin <= 1.3 - Broken Access Control vulnerability
MEDIUM 6.5 2026-02-20
vgdevsolutions Checkout Gateway for IRIS
CVE NVD
CVE-2025-68541
WordPress Ippsum theme <= 1.2.0 - PHP Object Injection vulnerability
CRITICAL 9.8 2026-02-20
BoldThemes Ippsum
CVE NVD
CVE-2025-68539
WordPress Fana theme <= 1.1.35 - Local File Inclusion vulnerability
HIGH 8.1 2026-02-20
thembay Fana
CVE NVD
CVE-2025-68536
WordPress Zota theme <= 1.3.14 - Local File Inclusion vulnerability
HIGH 8.1 2026-02-20
thembay Zota
CVE NVD
CVE-2025-68534
WordPress PDF for WPForms plugin <= 6.3.0 - Broken Access Control vulnerability
MEDIUM 6.5 2026-02-20
add-ons.org PDF for WPForms
CVE NVD
CVE-2025-68531
WordPress ModelTheme Addons for WPBakery and Elementor plugin < 1.5.6 - PHP Object Injection vulnerability
HIGH 8.8 2026-02-20
modeltheme ModelTheme Addons for WPBakery and Elementor
CVE NVD
CVE-2025-68526
WordPress Modal Popup Box plugin <= 1.6.1 - PHP Object Injection vulnerability
HIGH 8.8 2026-02-20
A WP Life Modal Popup Box
CVE NVD
CVE-2025-68514
WordPress Paid Member Subscriptions plugin <= 2.16.8 - Insecure Direct Object References (IDOR) vulnerability
MEDIUM 6.5 2026-02-20
Cozmoslabs Paid Member Subscriptions
CVE NVD
CVE-2025-68501
WordPress Mollie Payments for WooCommerce plugin <= 8.1.1 - Reflected Cross Site Scripting (XSS) vulnerability
HIGH 7.1 2026-02-20
Mollie Mollie Payments for WooCommerce
CVE NVD
CVE-2025-68495
WordPress JetEngine plugin <= 3.8.0 - Reflected Cross Site Scripting (XSS) vulnerability
HIGH 7.1 2026-02-20
Crocoblock JetEngine
CVE NVD