漏洞列表 359799
CVE ID 标题 严重程度 CVSS 发布时间 受影响产品 数据源 操作
CVE-2025-67987
WordPress Quiz And Survey Master plugin <= 10.3.1 - SQL Injection vulnerability
HIGH 8.5 2026-02-20
ExpressTech Systems Quiz And Survey Master
CVE NVD
CVE-2025-67984
WordPress NPS computy plugin <= 2.8.2 - Cross Site Scripting (XSS) vulnerability
HIGH 7.1 2026-02-20
calliko NPS computy
CVE NVD
CVE-2025-67982
WordPress Urna theme <= 2.5.12 - Local File Inclusion vulnerability
HIGH 8.1 2026-02-20
thembay Urna
CVE NVD
CVE-2025-67981
WordPress Besa theme <= 2.3.15 - Local File Inclusion vulnerability
HIGH 8.1 2026-02-20
thembay Besa
CVE NVD
CVE-2025-67980
WordPress Hara theme <= 1.2.17 - Local File Inclusion vulnerability
HIGH 8.1 2026-02-20
thembay Hara
CVE NVD
CVE-2025-67979
WordPress WPForms Google Sheet Connector plugin <= 4.0.1 - Remote Code Execution (RCE) vulnerability
CRITICAL 9.9 2026-02-20
WesternDeal WPForms Google Sheet Connector
CVE NVD
CVE-2025-67978
WordPress Educare plugin <= 1.6.1 - Cross Site Scripting (XSS) vulnerability
HIGH 7.1 2026-02-20
FixBD Educare
CVE NVD
CVE-2025-67977
WordPress HAPPY plugin <= 1.0.8 - Broken Access Control vulnerability
HIGH 8.2 2026-02-20
VillaTheme HAPPY
CVE NVD
CVE-2025-67975
WordPress aDirectory plugin <= 3.0.3 - Broken Access Control vulnerability
MEDIUM 6.5 2026-02-20
aDirectory aDirectory
CVE NVD
CVE-2025-67974
WordPress WPLegalPages plugin <= 3.5.4 - Broken Access Control vulnerability
HIGH 7.5 2026-02-20
WP Legal Pages WPLegalPages
CVE NVD
CVE-2025-67973
WordPress Sunshine Photo Cart plugin <= 3.5.6.2 - Broken Access Control vulnerability
MEDIUM 6.5 2026-02-20
sunshinephotocart Sunshine Photo Cart
CVE NVD
CVE-2025-67972
WordPress Prague plugin <= 2.2.8 - Cross Site Scripting (XSS) vulnerability
HIGH 7.1 2026-02-20
fox-themes Prague
CVE NVD
CVE-2025-67971
WordPress FluentCart plugin < 1.3.0 - Cross Site Scripting (XSS) vulnerability
HIGH 7.1 2026-02-20
WPManageNinja FluentCart
CVE NVD
CVE-2025-67970
WordPress Schedula plugin <= 1.0 - Broken Access Control vulnerability
MEDIUM 5.3 2026-02-20
vertim Schedula
CVE NVD
CVE-2025-67969
WordPress UPI QR Code Payment Gateway for WooCommerce plugin <= 1.5.1 - Broken Access Control vulnerability
MEDIUM 6.5 2026-02-20
knitpay UPI QR Code Payment Gateway for WooCommerce
CVE NVD
CVE-2025-67624
WordPress Optimize More! – Images plugin <= 1.1.3 - Broken Access Control vulnerability
MEDIUM 6.5 2026-02-20
Arya Dhiratara Optimize More! &#8211; Images
CVE NVD
CVE-2025-67547
WordPress Konte theme <= 2.4.6 - Broken Access Control vulnerability
MEDIUM 6.5 2026-02-20
uixthemes Konte
CVE NVD
CVE-2025-60183
WordPress Silencesoft RSS Reader Plugin <= 0.6 - Cross Site Scripting (XSS) Vulnerability
MEDIUM 5.9 2026-02-20
silence Silencesoft RSS Reader
CVE NVD
CVE-2025-60087
WordPress Extensive VC Addons for WPBakery page builder plugin <= 1.9.1 - Local File Inclusion vulnerability
HIGH 8.1 2026-02-20
Nenad Obradovic Extensive VC Addons for WPBakery page builder
CVE NVD
CVE-2025-53237
WordPress WP Wizard Cloak Plugin <= 1.0.1 - Cross Site Scripting (XSS) Vulnerability
HIGH 7.1 2026-02-20
Soflyy WP Wizard Cloak
CVE NVD