漏洞列表 359799
CVE ID 标题 严重程度 CVSS 发布时间 受影响产品 数据源 操作
CVE-2025-69395
WordPress Gable theme <= 1.5 - Local File Inclusion vulnerability
HIGH 8.1 2026-02-20
ThemeREX Gable
CVE NVD
CVE-2025-69394
WordPress Cnvrse plugin <= 026.02.10.20 - Insecure Direct Object References (IDOR) vulnerability
HIGH 7.5 2026-02-20
cnvrse Cnvrse
CVE NVD
CVE-2025-69393
WordPress Exzo theme <= 1.2.4 - Broken Access Control vulnerability
HIGH 7.5 2026-02-20
Jthemes Exzo
CVE NVD
CVE-2025-69392
WordPress iMoney plugin <= 0.36 - Reflected Cross Site Scripting (XSS) vulnerability
HIGH 7.1 2026-02-20
itex iMoney
CVE NVD
CVE-2025-69391
WordPress Diamond theme <= 2.4.8 - Reflected Cross Site Scripting (XSS) vulnerability
HIGH 7.1 2026-02-20
GT3themes Diamond
CVE NVD
CVE-2025-69390
WordPress Business Template Blocks for WPBakery (Visual Composer) Page Builder plugin <= 1.3.2 - Reflected Cross Site Scripting (XSS) vulnerability
HIGH 7.1 2026-02-20
themebon Business Template Blocks for WPBakery (Visual Composer) Page Builder
CVE NVD
CVE-2025-69389
WordPress Visitor Maps Extended Referer Field plugin <= 1.2.6 - Reflected Cross Site Scripting (XSS) vulnerability
HIGH 7.1 2026-02-20
Hugh Mungus Visitor Maps Extended Referer Field
CVE NVD
CVE-2025-69388
WordPress Cliengo – Chatbot plugin <= 3.0.4 - Broken Access Control vulnerability
MEDIUM 6.5 2026-02-20
cliengo Cliengo – Chatbot
CVE NVD
CVE-2025-69387
WordPress Simple Retail Menus plugin <= 4.2.1 - Local File Inclusion vulnerability
HIGH 7.5 2026-02-20
whatwouldjessedo Simple Retail Menus
CVE NVD
CVE-2025-69386
WordPress RVCFDI para Woocommerce plugin <= 8.1.8 - Reflected Cross Site Scripting (XSS) vulnerability
HIGH 7.1 2026-02-20
realvirtualmx RVCFDI para Woocommerce
CVE NVD
CVE-2025-69385
WordPress Cartify - WooCommerce Gutenberg WordPress Theme theme <= 1.3 - Arbitrary Content Deletion vulnerability
MEDIUM 6.5 2026-02-20
AgniHD Cartify - WooCommerce Gutenberg WordPress Theme
CVE NVD
CVE-2025-69384
WordPress Timeline Event History plugin <= 3.2 - Reflected Cross Site Scripting (XSS) vulnerability
HIGH 7.1 2026-02-20
wpdiscover Timeline Event History
CVE NVD
CVE-2025-69383
WordPress WP shop plugin <= 2.6.1 - Local File Inclusion vulnerability
HIGH 7.5 2026-02-20
Agence web Eoxia - Montpellier WP shop
CVE NVD
CVE-2025-69382
WordPress Themesflat Elementor plugin <= 1.0.1 - PHP Object Injection vulnerability
CRITICAL 9.8 2026-02-20
themesflat Themesflat Elementor
CVE NVD
CVE-2025-69381
WordPress WooCommerce Bulk Product Editor plugin <= 3.0 - Broken Access Control vulnerability
HIGH 7.1 2026-02-20
vanquish WooCommerce Bulk Product Editor
CVE NVD
CVE-2025-69380
WordPress Upload Files Anywhere plugin <= 2.8 - Arbitrary File Download vulnerability
HIGH 7.5 2026-02-20
vanquish Upload Files Anywhere
CVE NVD
CVE-2025-69379
WordPress Upload Files Anywhere plugin <= 2.8 - Arbitrary File Deletion vulnerability
HIGH 8.6 2026-02-20
vanquish Upload Files Anywhere
CVE NVD
CVE-2025-69378
WordPress Product Filter for WooCommerce plugin <= 9.1.2 - Privilege Escalation vulnerability
HIGH 7.3 2026-02-20
XforWooCommerce Product Filter for WooCommerce
CVE NVD
CVE-2025-69377
WordPress User Extra Fields plugin <= 17.0 - Arbitrary File Deletion vulnerability
HIGH 7.7 2026-02-20
vanquish User Extra Fields
CVE NVD
CVE-2025-69376
WordPress User Extra Fields plugin <= 17.0 - Arbitrary File Deletion vulnerability
HIGH 8.6 2026-02-20
vanquish User Extra Fields
CVE NVD