designthemes
Web & CMS Pluginscommercial
Latest CVEs
The 15 most recently published vulnerabilities affecting designthemes.
- CVE-2026-27983WordPress LMS Elementor Pro plugin <= 1.0.4 - Privilege Escalation vulnerability9.8
- CVE-2026-27390WordPress WeDesignTech Ultimate Booking Addon plugin <= 1.0.1 - Account Takeover vulnerability8.8
- CVE-2026-27389WordPress WeDesignTech Ultimate Booking Addon plugin <= 1.0.1 - Account Takeover vulnerability9.8
- CVE-2026-27388WordPress DesignThemes Booking Manager plugin <= 2.0 - Broken Access Control vulnerability7.5
- CVE-2026-27386WordPress DesignThemes Directory Addon plugin <= 1.8 - Broken Access Control vulnerability7.5
- CVE-2026-27385WordPress DesignThemes Portfolio plugin <= 1.3 - Reflected Cross Site Scripting (XSS) vulnerability7.1
- CVE-2026-22473WordPress Dental Clinic theme <= 3.7 - PHP Object Injection vulnerability8.8
- CVE-2025-69302WordPress DesignThemes Core Features plugin <= 2.3 - Reflected Cross Site Scripting (XSS) vulnerability7.1
- CVE-2025-69095WordPress Reservation Plugin plugin <= 1.7 - Settings Change vulnerability6.5
- CVE-2025-69002WordPress OneLife theme <= 3.9 - PHP Object Injection vulnerability8.8
- CVE-2025-68899WordPress Vivagh theme <= 2.4 - PHP Object Injection vulnerability8.8
- CVE-2025-67619WordPress Kids Heaven theme <= 3.2 - PHP Object Injection vulnerability8.8
- CVE-2025-68982WordPress DesignThemes LMS Addon plugin <= 2.6 - Broken Access Control vulnerability5.3
- CVE-2025-68981WordPress HomeFix Elementor Portfolio plugin <= 1.0.1 - Broken Access Control vulnerability5.3
- CVE-2025-68980WordPress WeDesignTech Portfolio plugin <= 1.0.2 - Broken Access Control vulnerability5.3