漏洞列表 359799
CVE ID 标题 严重程度 CVSS 发布时间 受影响产品 数据源 操作
CVE-2025-68543
WordPress Diza theme <= 1.3.15 - Local File Inclusion vulnerability
HIGH 8.1 2026-02-20
thembay Diza
CVE NVD
CVE-2025-68542
WordPress Checkout Gateway for IRIS plugin <= 1.3 - Broken Access Control vulnerability
MEDIUM 6.5 2026-02-20
vgdevsolutions Checkout Gateway for IRIS
CVE NVD
CVE-2025-68541
WordPress Ippsum theme <= 1.2.0 - PHP Object Injection vulnerability
CRITICAL 9.8 2026-02-20
BoldThemes Ippsum
CVE NVD
CVE-2025-68539
WordPress Fana theme <= 1.1.35 - Local File Inclusion vulnerability
HIGH 8.1 2026-02-20
thembay Fana
CVE NVD
CVE-2025-68536
WordPress Zota theme <= 1.3.14 - Local File Inclusion vulnerability
HIGH 8.1 2026-02-20
thembay Zota
CVE NVD
CVE-2025-68534
WordPress PDF for WPForms plugin <= 6.3.0 - Broken Access Control vulnerability
MEDIUM 6.5 2026-02-20
add-ons.org PDF for WPForms
CVE NVD
CVE-2025-68531
WordPress ModelTheme Addons for WPBakery and Elementor plugin < 1.5.6 - PHP Object Injection vulnerability
HIGH 8.8 2026-02-20
modeltheme ModelTheme Addons for WPBakery and Elementor
CVE NVD
CVE-2025-68526
WordPress Modal Popup Box plugin <= 1.6.1 - PHP Object Injection vulnerability
HIGH 8.8 2026-02-20
A WP Life Modal Popup Box
CVE NVD
CVE-2025-68514
WordPress Paid Member Subscriptions plugin <= 2.16.8 - Insecure Direct Object References (IDOR) vulnerability
MEDIUM 6.5 2026-02-20
Cozmoslabs Paid Member Subscriptions
CVE NVD
CVE-2025-68501
WordPress Mollie Payments for WooCommerce plugin <= 8.1.1 - Reflected Cross Site Scripting (XSS) vulnerability
HIGH 7.1 2026-02-20
Mollie Mollie Payments for WooCommerce
CVE NVD
CVE-2025-68495
WordPress JetEngine plugin <= 3.8.0 - Reflected Cross Site Scripting (XSS) vulnerability
HIGH 7.1 2026-02-20
Crocoblock JetEngine
CVE NVD
CVE-2025-68069
WordPress Directorist plugin <= 8.5.10 - Broken Access Control vulnerability
HIGH 7.1 2026-02-20
wpWax Directorist
CVE NVD
CVE-2025-68051
WordPress Shiprocket plugin <= 2.0.8 - Insecure Direct Object References (IDOR) vulnerability
HIGH 7.4 2026-02-20
Shiprocket Shiprocket
CVE NVD
CVE-2025-68050
WordPress Leadpages plugin <= 1.1.3 - Broken Access Control vulnerability
MEDIUM 6.5 2026-02-20
Leadpages Leadpages
CVE NVD
CVE-2025-68048
WordPress NextMove Lite plugin <= 2.23.0 - Broken Access Control vulnerability
HIGH 7.5 2026-02-20
XLPlugins NextMove Lite
CVE NVD
CVE-2025-68043
WordPress LottieFiles plugin <= 3.0.0 - Broken Access Control vulnerability
HIGH 7.3 2026-02-20
LottieFiles LottieFiles
CVE NVD
CVE-2025-68042
WordPress Travelpayouts plugin <= 1.2.1 - Broken Access Control vulnerability
MEDIUM 6.5 2026-02-20
Travelpayouts Travelpayouts
CVE NVD
CVE-2025-68037
WordPress Export Media URLs plugin <= 2.2 - Reflected Cross Site Scripting (XSS) vulnerability
HIGH 7.1 2026-02-20
Atlas Gondal Export Media URLs
CVE NVD
CVE-2025-68032
WordPress Advanced WC Analytics plugin <= 3.19.0 - Settings Change vulnerability
MEDIUM 6.5 2026-02-20
Passionate Brains Advanced WC Analytics
CVE NVD
CVE-2025-68031
WordPress افزونه پیامک حرفه ای فراز اس ام اس plugin <= 2.7.3 - Reflected Cross Site Scripting (XSS) vulnerability
HIGH 7.1 2026-02-20
faraz sms افزونه پیامک حرفه ای فراز اس ام اس
CVE NVD