Vulnerabilities in ThemeGoods

46 results
CVE-2025-39353MEDIUMWordPress Grand Restaurant WordPress theme <= 7.0 - Broken Access Control vulnerabilityEPSS 0.2%CVE-2025-69321HIGHWordPress Grand Spa theme <= 3.5.5 - Reflected Cross Site Scripting (XSS) vulnerabilityEPSS 0.2%CVE-2025-68518HIGHWordPress Hoteller theme < 6.8.9 - Reflected Cross Site Scripting (XSS) vulnerabilityEPSS 0.2%CVE-2025-68538HIGHWordPress Craft | Coffee Shop Cafe Restaurant WordPress theme <= 2.3.6 - Reflected Cross Site Scripting (XSS) vulnerabilityEPSS 0.2%CVE-2025-68520HIGHWordPress DotLife theme < 4.9.5 - Reflected Cross Site Scripting (XSS) vulnerabilityEPSS 0.2%CVE-2026-27348HIGHWordPress Photography theme < 7.7.6 - Cross Site Scripting (XSS) vulnerabilityEPSS 0.2%CVE-2026-27352HIGHWordPress Starto theme < 2.2.5 - Cross Site Scripting (XSS) vulnerabilityEPSS 0.2%CVE-2025-69151HIGHWordPress Grand Car Rental theme <= 3.7 - Cross Site Scripting (XSS) vulnerabilityEPSS 0.2%CVE-2026-27358HIGHWordPress Architecturer theme < 3.9.5 - Cross Site Scripting (XSS) vulnerabilityEPSS 0.2%CVE-2025-67922HIGHWordPress Grand Restaurant theme < 7.0.9 - Cross Site Scripting (XSS) vulnerabilityEPSS 0.2%CVE-2026-27367HIGHWordPress Musico theme < 3.4.5 - Cross Site Scripting (XSS) vulnerabilityEPSS 0.2%CVE-2026-27353HIGHWordPress Grand News | Magazine Newspaper WordPress theme <= 3.4.3 - Reflected Cross Site Scripting (XSS) vulnerabilityEPSS 0.2%CVE-2025-30964MEDIUMWordPress Photography theme < 7.7.6 - Server Side Request Forgery (SSRF) vulnerabilityEPSS 0.2%CVE-2025-69320HIGHWordPress Grand Magazine theme <= 3.5.7 - Reflected Cross Site Scripting (XSS) vulnerabilityEPSS 0.2%CVE-2025-64217HIGHWordPress Photography theme <= 7.7.2 - Cross Site Scripting (XSS) vulnerabilityEPSS 0.2%CVE-2026-24961MEDIUMWordPress Grand Blog theme < 3.1.5 - Server Side Request Forgery (SSRF) vulnerabilityEPSS 0.2%CVE-2025-64224HIGHWordPress Grand Conference Theme Custom Post Type plugin < 2.6.4 - Cross Site Scripting (XSS) vulnerabilityEPSS 0.2%CVE-2026-24943HIGHWordPress Grand Conference theme <= 5.3.4 - Reflected Cross Site Scripting (XSS) vulnerabilityEPSS 0.2%CVE-2026-24949HIGHWordPress PhotoMe theme <= 5.7.1 - Cross Site Scripting (XSS) vulnerabilityEPSS 0.2%CVE-2026-24381MEDIUMWordPress PhotoMe theme < 5.7.2 - Server Side Request Forgery (SSRF) vulnerabilityEPSS 0.1%