漏洞列表 359799
CVE ID 标题 严重程度 CVSS 发布时间 受影响产品 数据源 操作
CVE-2026-27072
WordPress PixelYourSite – Your smart PIXEL (TAG) Manager plugin <= 11.2.0.1 - Cross Site Scripting (XSS) vulnerability
HIGH 7.1 2026-02-20
PixelYourSite PixelYourSite – Your smart PIXEL (TAG) Manager
CVE NVD
CVE-2026-24959
WordPress JS Help Desk plugin <= 3.0.1 - SQL Injection vulnerability
HIGH 8.5 2026-02-20
JoomSky JS Help Desk
CVE NVD
CVE-2026-24956
WordPress Download Manager Addons for Elementor plugin <= 1.3.0 - SQL Injection vulnerability
CRITICAL 9.3 2026-02-20
Shahjada Download Manager Addons for Elementor
CVE NVD
CVE-2026-24955
WordPress Whizz Plugins plugin <= 1.9 - Reflected Cross Site Scripting (XSS) vulnerability
HIGH 7.1 2026-02-20
fox-themes Whizz Plugins
CVE NVD
CVE-2026-24953
WordPress Simple File List plugin <= 6.1.15 - Arbitrary File Download vulnerability
MEDIUM 6.5 2026-02-20
Mitchell Bennis Simple File List
CVE NVD
CVE-2026-24950
WordPress Authorsy plugin <= 1.0.6 - Insecure Direct Object References (IDOR) vulnerability
HIGH 7.5 2026-02-20
themeplugs Authorsy
CVE NVD
CVE-2026-24949
WordPress PhotoMe theme <= 5.7.1 - Cross Site Scripting (XSS) vulnerability
HIGH 7.1 2026-02-20
ThemeGoods PhotoMe
CVE NVD
CVE-2026-24948
WordPress Reflector plugin <= 1.2.2 - Reflected Cross Site Scripting (XSS) vulnerability
HIGH 7.1 2026-02-20
fox-themes Reflector
CVE NVD
CVE-2026-24946
WordPress Print Invoice & Delivery Notes for WooCommerce plugin <= 5.8.0 - Broken Access Control vulnerability
MEDIUM 6.5 2026-02-20
tychesoftwares Print Invoice & Delivery Notes for WooCommerce
CVE NVD
CVE-2026-24944
WordPress Subscribe2 plugin <= 10.44 - Broken Access Control vulnerability
MEDIUM 6.5 2026-02-20
weDevs Subscribe2
CVE NVD
CVE-2026-24943
WordPress Grand Conference theme <= 5.3.4 - Reflected Cross Site Scripting (XSS) vulnerability
HIGH 7.1 2026-02-20
ThemeGoods Grand Conference
CVE NVD
CVE-2026-24941
WordPress WP Job Portal plugin <= 2.4.4 - Broken Access Control vulnerability
HIGH 7.5 2026-02-20
wpjobportal WP Job Portal
CVE NVD
CVE-2026-22384
WordPress Applay - Shortcodes plugin <= 3.7 - PHP Object Injection vulnerability
HIGH 8.8 2026-02-20
leafcolor Applay - Shortcodes
CVE NVD
CVE-2026-22383
WordPress PawFriends - Pet Shop and Veterinary WordPress theme theme <= 1.3 - Insecure Direct Object References (IDOR) vulnerability
HIGH 7.5 2026-02-20
Mikado-Themes PawFriends - Pet Shop and Veterinary WordPress Theme
CVE NVD
CVE-2026-22381
WordPress PawFriends - Pet Shop and Veterinary WordPress Theme theme <= 1.3 - Local File Inclusion vulnerability
HIGH 8.1 2026-02-20
Mikado-Themes PawFriends - Pet Shop and Veterinary WordPress Theme
CVE NVD
CVE-2026-22380
WordPress UnlimHost theme <= 1.2.3 - Local File Inclusion vulnerability
HIGH 8.1 2026-02-20
AncoraThemes UnlimHost
CVE NVD
CVE-2026-22379
WordPress Netmix theme <= 1.0.10 - Local File Inclusion vulnerability
HIGH 8.1 2026-02-20
AncoraThemes Netmix
CVE NVD
CVE-2026-22378
WordPress Blabber theme <= 1.7.0 - Local File Inclusion vulnerability
HIGH 8.1 2026-02-20
AncoraThemes Blabber
CVE NVD
CVE-2026-22377
WordPress Saveo theme <= 1.1.2 - Local File Inclusion vulnerability
HIGH 8.1 2026-02-20
AncoraThemes Saveo
CVE NVD
CVE-2026-22376
WordPress Parkivia theme <= 1.1.9 - Local File Inclusion vulnerability
HIGH 8.1 2026-02-20
AncoraThemes Parkivia
CVE NVD