漏洞列表 359799
CVE ID 标题 严重程度 CVSS 发布时间 受影响产品 数据源 操作
CVE-2025-68028
WordPress GA4WP: Google Analytics for WordPress plugin <= 2.10.0 - Broken Access Control vulnerability
MEDIUM 6.5 2026-02-20
Passionate Brains GA4WP: Google Analytics for WordPress
CVE NVD
CVE-2025-68026
WordPress LC Wizard plugin <= 2.1.1 - Settings Change vulnerability
MEDIUM 6.5 2026-02-20
Niaj Morshed LC Wizard
CVE NVD
CVE-2025-68025
WordPress Addonify Floating Cart For WooCommerce plugin <= 1.2.17 - Broken Access Control vulnerability
MEDIUM 6.5 2026-02-20
Addonify Addonify Floating Cart For WooCommerce
CVE NVD
CVE-2025-68024
WordPress Addonify – WooCommerce Wishlist plugin <= 2.0.15 - Settings Change vulnerability
MEDIUM 6.5 2026-02-20
Addonify Addonify – WooCommerce Wishlist
CVE NVD
CVE-2025-68023
WordPress Addonify – Compare Products For WooCommerce plugin <= 1.1.17 - Settings Change vulnerability
MEDIUM 6.5 2026-02-20
Addonify Addonify &#8211; Compare Products For WooCommerce
CVE NVD
CVE-2025-68022
WordPress Plugin BlueX for WooCommerce plugin <= 3.1.6 - Broken Access Control vulnerability
MEDIUM 6.3 2026-02-20
soporteblue Plugin BlueX for WooCommerce
CVE NVD
CVE-2025-68021
WordPress ConveyThis plugin <= 269.5 - Broken Access Control vulnerability
MEDIUM 6.5 2026-02-20
ConveyThis ConveyThis
CVE NVD
CVE-2025-68005
WordPress Easy Hotel Booking plugin <= 1.8.7 - Broken Access Control vulnerability
MEDIUM 6.5 2026-02-20
themewant Easy Hotel Booking
CVE NVD
CVE-2025-68002
WordPress Open User Map plugin <= 1.4.16 - Arbitrary File Download vulnerability
MEDIUM 6.5 2026-02-20
100plugins Open User Map
CVE NVD
CVE-2025-68000
WordPress Testimonial Slider plugin <= 2.0.15 - Broken Access Control vulnerability
MEDIUM 6.5 2026-02-20
PickPlugins Testimonial Slider
CVE NVD
CVE-2025-67998
WordPress Miraculous Elementor plugin <= 2.0.7 - Broken Authentication vulnerability
HIGH 8.8 2026-02-20
kamleshyadav Miraculous Elementor
CVE NVD
CVE-2025-67997
WordPress Travelicious theme < 1.6.7 - PHP Object Injection vulnerability
CRITICAL 9.8 2026-02-20
BoldThemes Travelicious
CVE NVD
CVE-2025-67996
WordPress Nestin theme < 1.2.6 - PHP Object Injection vulnerability
CRITICAL 9.8 2026-02-20
BoldThemes Nestin
CVE NVD
CVE-2025-67995
WordPress PatioTime theme < 2.1 - PHP Object Injection vulnerability
CRITICAL 9.8 2026-02-20
LoftOcean PatioTime
CVE NVD
CVE-2025-67994
WordPress YayCurrency plugin <= 3.3 - Arbitrary Content Deletion vulnerability
HIGH 7.5 2026-02-20
YayCommerce YayCurrency
CVE NVD
CVE-2025-67993
WordPress Atarim plugin <= 4.2.1 - Broken Access Control vulnerability
MEDIUM 6.5 2026-02-20
Vito Peleg Atarim
CVE NVD
CVE-2025-67992
WordPress PatioTime theme < 2.1 - Local File Inclusion vulnerability
HIGH 8.1 2026-02-20
LoftOcean PatioTime
CVE NVD
CVE-2025-67991
WordPress User Extra Fields plugin <= 16.8 - Cross Site Scripting (XSS) vulnerability
HIGH 7.1 2026-02-20
vanquish User Extra Fields
CVE NVD
CVE-2025-67990
WordPress GMap Targeting plugin <= 1.1.7 - Cross Site Scripting (XSS) vulnerability
HIGH 7.1 2026-02-20
RealMag777 GMap Targeting
CVE NVD
CVE-2025-67988
WordPress CozyStay theme < 1.9.1 - Local File Inclusion vulnerability
HIGH 8.1 2026-02-20
LoftOcean CozyStay
CVE NVD