Vulnerability index

Browse CVEs

7 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

MEDIUM 5.4 CVE-2025-6997 The ThemeREX Addons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 2.35… Addons 2.35.2.2+ Fix from $1,6002025-07-19 CRITICAL 9.8 CVE-2024-13770 The Puzzles | WP Magazine / Review with Store WordPress Theme + RTL theme for WordPress is vulnerable to PHP Object Injection in all versions up to, … Puzzles 4.2.5+ Fix from $2,3002025-02-13 MEDIUM 5.4 CVE-2025-0837 The Puzzles theme for WordPress is vulnerable to Stored Cross-Site Scripting via shortcodes in versions up to, and including, 4.2.6 due to insufficie… Puzzles after 4.2.6 Fix from $1,6002025-02-13 MEDIUM 5.4 CVE-2024-13769 The Puzzles | WP Magazine / Review with Store WordPress Theme + RTL theme for WordPress is vulnerable to Stored Cross-Site Scripting due to a missing… Puzzles 4.2.5+ Fix from $1,6002025-02-12 CRITICAL 9.8 CVE-2024-13448 The ThemeREX Addons plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'trx_addons_uploads_save_… Addons 2.34.0+ Fix from $2,3002025-01-28 HIGH 8.8 CVE-2025-0682 The ThemeREX Addons plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 2.33.0 via the 'trx_sc_reviews' … Addons 2.34.0+ Fix from $1,9502025-01-25 CRITICAL 9.8 CVE-2020-10257EPSS 9% The ThemeREX Addons plugin before 2020-03-09 for WordPress lacks access control on the /trx_addons/v2/get/sc_layout REST API endpoint, allowing for P… Addons 1.0.1 / 1.0.1.2001+ Fix from $2,3002020-03-10