Designthemes
26 CVEs tracked since 2025. Since Jul 2025, none of them reached CISA KEV.
Designthemes CVEs per month
| Month | CVEs | In CISA KEV |
|---|---|---|
| 2025-07 | 5 | 0 |
| 2025-08 | null or fewer | |
| 2025-09 | null or fewer | |
| 2025-10 | 7 | 0 |
| 2025-11 | null or fewer | |
| 2025-12 | 7 | 0 |
| 2026-01 | null or fewer | |
| 2026-02 | null or fewer | |
| 2026-03 | 7 | 0 |
Products
The products that kept showing up in Designthemes's monthly top three, with their CVEs summed over those months.
Latest CVEs
The 15 most recently published vulnerabilities affecting Designthemes.
- CVE-2026-11355DT LMS <= 1.1 - Missing Authorization to Unauthenticated Arbitrary Plugin Settings Modification via Multiple AJAX Actions5.3
- CVE-2026-27404WordPress LMS theme <= 9.7 - Reflected Cross Site Scripting (XSS) vulnerability7.1
- CVE-2026-27402WordPress Kids Life | Children School WordPress theme <= 5.2 - Cross Site Scripting (XSS) vulnerability7.1
- CVE-2025-69155WordPress Fitness Zone WordPress Theme theme <= 5.7 - Cross Site Scripting (XSS) vulnerability7.1
- CVE-2025-69154WordPress SpaLab | Beauty Salon WordPress Theme theme <= 6.7 - Cross Site Scripting (XSS) vulnerability7.1
- CVE-2025-69153WordPress Trendy Travel theme <= 6.7 - Reflected Cross Site Scripting (XSS) vulnerability7.1
- CVE-2026-27983WordPress LMS Elementor Pro plugin <= 1.0.4 - Privilege Escalation vulnerability9.8
- CVE-2026-27389WordPress WeDesignTech Ultimate Booking Addon plugin <= 1.0.1 - Account Takeover vulnerability9.8
- CVE-2026-27390WordPress WeDesignTech Ultimate Booking Addon plugin <= 1.0.1 - Account Takeover vulnerability8.8
- CVE-2026-27388WordPress DesignThemes Booking Manager plugin <= 2.0 - Broken Access Control vulnerability7.5
- CVE-2026-27386WordPress DesignThemes Directory Addon plugin <= 1.8 - Broken Access Control vulnerability7.5
- CVE-2026-27385WordPress DesignThemes Portfolio plugin <= 1.3 - Reflected Cross Site Scripting (XSS) vulnerability7.1
- CVE-2026-22473WordPress Dental Clinic theme <= 3.7 - PHP Object Injection vulnerability8.8
- CVE-2025-69302WordPress DesignThemes Core Features plugin <= 2.3 - Reflected Cross Site Scripting (XSS) vulnerability7.1
- CVE-2025-69095WordPress Reservation Plugin plugin <= 1.7 - Settings Change vulnerability6.5
The record
- Peak rank
- #128 in Dec 2025
- Busiest month shown
- Oct 2025, 7 CVEs
- Months with a KEV entry
- 0 since Jul 2025
- Monthly snapshots
- 4 since 2025