Vulnerabilities in themefic

39 results
CVE-2025-68055HIGHWordPress Hydra Booking plugin <= 1.1.32 - SQL Injection vulnerabilityEPSS 0.3%CVE-2025-12788MEDIUMHydra Booking – All in One Appointment Booking System | Appointment Scheduling, Booking Calendar & WooCommerce Bookings <= 1.1.27 - Missing Payment Verification to Unauthenticated Payment BypassEPSS 0.3%CVE-2025-68027HIGHWordPress Hydra Booking plugin <= 1.1.32 - Privilege Escalation vulnerabilityEPSS 0.3%CVE-2025-49323HIGHWordPress Hydra Booking plugin <= 1.1.10 - SQL Injection VulnerabilityEPSS 0.3%CVE-2025-6212HIGHUltra Addons for Contact Form 7 3.5.11 - 3.5.19 - Unauthenticated Stored Cross-Site Scripting via Database moduleEPSS 0.3%CVE-2025-12787MEDIUMHydra Booking – All in One Appointment Booking System | Appointment Scheduling, Booking Calendar & WooCommerce Bookings <= 1.1.27 - Unauthenticated Arbitrary Booking Cancellation via Weak Hash GenerationEPSS 0.3%CVE-2025-39585MEDIUMWordPress Travelfic Toolkit plugin <= 1.2.1 - Cross Site Scripting (XSS) VulnerabilityEPSS 0.3%CVE-2026-39571MEDIUMWordPress Instantio plugin <= 3.3.30 - Sensitive Data Exposure vulnerabilityEPSS 0.2%CVE-2024-8860MEDIUMTourfic <= 2.14.5 - Missing Authorization in Multiple FunctionsEPSS 0.2%CVE-2025-49377MEDIUMWordPress Hydra Booking plugin <= 1.1.9 - Broken Access Control vulnerabilityEPSS 0.2%CVE-2026-39543MEDIUMWordPress Tourfic plugin <= 2.21.4 - Broken Access Control vulnerabilityEPSS 0.2%CVE-2024-32433MEDIUMWordPress BEAF plugin <= 4.5.4 - Cross Site Request Forgery (CSRF) vulnerabilityEPSS 0.2%CVE-2026-24945MEDIUMWordPress Ultimate Addons for Contact Form 7 plugin <= 3.5.34 - Broken Access Control vulnerabilityEPSS 0.2%CVE-2025-6756MEDIUMUltra Addons for Contact Form 7 <= 3.5.21 - Authenticated (Contributor+) Stored Cross-Site Scripting via UACF7_CUSTOM_FIELDS ShortcodeEPSS 0.2%CVE-2026-24940MEDIUMWordPress Travelfic Toolkit plugin <= 1.3.3 - Broken Access Control vulnerabilityEPSS 0.2%CVE-2026-42675HIGHWordPress Hydra Booking plugin <= 1.1.41 - Broken Access Control vulnerabilityEPSS 0.2%CVE-2024-8319MEDIUMTourfic <= 2.11.20 - Cross-Site Request Forgery in Multiple FunctionsEPSS 0.2%CVE-2026-39541MEDIUMWordPress Hydra Booking plugin <= 1.1.38 - Cross Site Scripting (XSS) vulnerabilityEPSS 0.2%CVE-2026-32460MEDIUMWordPress Ultimate Addons for Contact Form 7 plugin <= 3.5.36 - Cross Site Scripting (XSS) vulnerabilityEPSS 0.1%