Unknown
300 CVEsCVE IDSeverityProduct / summaryPublished
CVE-2026-12513
N/A
Shared Files — The Shared Files WordPress plugin before 1.7.67, shared-files-pro WordPress plugin before 1.7.68 do not prope…● PoC
2026-08-28
CVE-2026-12514
N/A
Shared Files — The Shared Files WordPress plugin before 1.7.67, shared-files-pro WordPress plugin before 1.7.70 do not perfo…● PoC
2026-08-28
CVE-2026-14558
N/A
User Frontend — The User Frontend WordPress plugin before 4.3.10 does not properly validate field type definitions and deseri…● PoC
2026-08-28
CVE-2026-14567
N/A
User Frontend — The User Frontend WordPress plugin before 4.3.10 does not restrict access to its user directory search endpoi…● PoC
2026-08-28
CVE-2026-19084
N/A
Shared Files Pro — The shared-files-pro WordPress plugin before 1.7.70 does not validate the file path supplied when creating a f…● PoC
2026-08-28
CVE-2026-19423
N/A
Ultimate Member — The Ultimate Member WordPress plugin before 2.13.0 does not validate a submitted role selection when it canno…● PoC
2026-08-28
CVE-2026-77701
N/A
Wcfm Marketplace — The WCFM Marketplace WordPress plugin before 3.8.2 does not correctly verify that the person requesting a ref…● PoC
2026-08-28
CVE-2026-79615
N/A
Quiz And Survey Master (Qsm) — The Quiz and Survey Master (QSM) WordPress plugin before 11.2.4 does not check authorisation when returning q…● PoC
2026-08-28
CVE-2026-79706
N/A
Breeze Cache — The Breeze Cache WordPress plugin before 2.5.13 does not sanitise a value taken from the request before using …● PoC
2026-08-28
CVE-2026-79995
N/A
User Registration & Membership — The User Registration & Membership WordPress plugin before 5.2.5 does not verify that the account whose pendi…● PoC
2026-08-28
CVE-2026-79996
N/A
User Registration & Membership — The User Registration & Membership WordPress plugin before 5.2.6 does not perform a capability check when sav…● PoC
2026-08-28
CVE-2026-13414
MEDIUM 4.8
Cmp — The CMP WordPress plugin before 4.1.18 does not perform authorization checks on one of its AJAX actions and r…● PoC
2026-08-27
CVE-2026-13415
HIGH 7.2
Cmp — The CMP WordPress plugin before 4.1.18 does not enforce an option-name allow-list when importing settings via…● PoC
2026-08-27
CVE-2026-13416
LOW 3.5
Cmp — The CMP WordPress plugin before 4.1.18 does not sanitise and escape a settings value before outputting it on …● PoC
2026-08-27
CVE-2026-16567
MEDIUM 5.3
Document Embedder — The Document Embedder WordPress plugin before 2.3.1 does not check a document's status before issuing a downl…● PoC
2026-08-27
CVE-2026-16568
MEDIUM 4.3
Mobile App For Woocommerce: Shopapper Mobile App Builder Service For Woocommerce — The Mobile App for WooCommerce: ShopApper Mobile App Builder Service for WooCommerce WordPress plugin through …● PoC
2026-08-27
CVE-2026-16569
MEDIUM 4.3
Mobile App For Woocommerce: Shopapper Mobile App Builder Service For Woocommerce — The Mobile App for WooCommerce: ShopApper Mobile App Builder Service for WooCommerce WordPress plugin through …● PoC
2026-08-27
CVE-2026-19092
CRITICAL 9.8
Tutor Lms — The Tutor LMS WordPress plugin before 4.0.6 does not prevent request data from overwriting internal variables …● PoC
2026-08-27
CVE-2026-19223
HIGH 7.2
Smush — The Smush WordPress plugin before 4.3.2 does not restrict a network-wide setting to network administrators, a…● PoC
2026-08-27
CVE-2026-19225
MEDIUM 6.6
Defender Security — The Defender Security WordPress plugin before 6.2.0 does not restrict a network-wide setting to network admin…● PoC
2026-08-27
CVE-2026-19454
MEDIUM 4.4
Jetbackup — The JetBackup WordPress plugin before 3.1.23.5 does not perform its multisite authorisation check before serv…● PoC
2026-08-27
CVE-2026-19715
HIGH 7.5
Wp Oauth Server ( Login With Wordpress ) — The WP OAuth Server ( Login with WordPress ) WordPress plugin before 6.3.1 does not restrict access to the deb…● PoC
2026-08-27
CVE-2026-74232
CRITICAL 9.3
L3 V2 8 — Zbtlink L3_V2_8 firmware 3.0.0.4.528, Zbtlink WE826-T2 firmware 19.1101, Zbtlink ZBT-7628 firmware 1.0.0.2.007…● PoC
2026-08-27
CVE-2026-74233
CRITICAL 9.3
We1326 — Zbtlink WE1326, WE357, WE5926, WE5926-WD, WE826-Q, WE826-T2, WE826-WD, WG108, and WG3526 firmware 19.1101, Zbt…● PoC
2026-08-27
CVE-2026-76549
MEDIUM 5.9
Updraftplus: Wp Backup & Migration Plugin — The UpdraftPlus: WP Backup & Migration Plugin WordPress plugin before 1.26.7 does not have CSRF checks in one …● PoC
2026-08-27
CVE-2026-77016
CRITICAL 9.6
Workeera — The Workeera WordPress plugin before 1.0.6 does not restrict which values may be written to a user's own cand…● PoC
2026-08-27
CVE-2026-77017
HIGH 7.7
Workeera — The Workeera WordPress plugin before 1.0.6 does not restrict which profile values a candidate may submit, nor…● PoC
2026-08-27
CVE-2026-77018
HIGH 8.8
Workeera — The Workeera WordPress plugin before 1.0.6 does not restrict which profile values a candidate may submit, nor…● PoC
2026-08-27
CVE-2026-78125
MEDIUM 5.3
Learnpress — The LearnPress WordPress plugin before 4.0.3 does not perform any authorization check on one of its REST endp…● PoC
2026-08-27
CVE-2026-78137
HIGH 7.5
Storegrowth — The StoreGrowth WordPress plugin before 2.1.2 does not validate a browser-supplied product price on two of it…● PoC
2026-08-27
CVE-2026-78138
MEDIUM 4.3
Finale Lite — The Finale Lite WordPress plugin before 2.21.0 does not perform a capability check on an AJAX action that ret…● PoC
2026-08-27
CVE-2026-78139
MEDIUM 4.3
Notifima — The Notifima WordPress plugin before 3.1.4 does not verify that the caller owns the subscription being modifi…● PoC
2026-08-27
CVE-2026-78333
HIGH 8.8
12 Step Meeting List — The 12 Step Meeting List WordPress plugin before 3.19.17 does not sanitise and escape a value submitted by una…● PoC
2026-08-27
CVE-2026-13172
MEDIUM 5.3
Eventin — The Eventin WordPress plugin before 4.1.22 does not restrict access to non-published content by status or own…● PoC
2026-08-26
CVE-2026-13404
MEDIUM 5.3
Royal Addons For Elementor — The Royal Addons for Elementor WordPress plugin before 1.7.1066 does not perform any capability or ownership …● PoC
2026-08-26
CVE-2026-13406
MEDIUM 5.3
Royal Addons For Elementor — The Royal Addons for Elementor WordPress plugin before 1.7.1066 does not perform any capability or nonce chec…● PoC
2026-08-26
CVE-2026-14212
MEDIUM 4.7
Booking For Appointments And Events Calendar — The Booking for Appointments and Events Calendar WordPress plugin before 9.8 does not verify that an authenti…● PoC
2026-08-26
CVE-2026-14216
MEDIUM 5.3
Booking For Appointments And Events Calendar — The Booking for Appointments and Events Calendar WordPress plugin before 2.4.7 does not require authenticatio…● PoC
2026-08-26
CVE-2026-14550
MEDIUM 5.3
Wpcafe — The WPCafe WordPress plugin before 3.0.18 does not perform an authorization check when creating a reservation…● PoC
2026-08-26
CVE-2026-16984
MEDIUM 6.5
Privacy Policy Generator, Terms & Conditions, Gdpr, Ccpa, Cookie Policy & Disclaimer Templates — The Privacy Policy Generator, Terms & Conditions, GDPR, CCPA, Cookie Policy & Disclaimer Templates WordPress …● PoC
2026-08-26
CVE-2026-16986
MEDIUM 5.3
Booking Package — The Booking Package WordPress plugin before 1.7.25 does not validate the payment amount server-side against th…● PoC
2026-08-26
CVE-2026-19094
MEDIUM 5.3
Tutor Lms — The Tutor LMS WordPress plugin before 4.0.6 does not validate values used to build a database query, and does…● PoC
2026-08-26
CVE-2026-19220
LOW 3.7
Forminator Forms — The Forminator Forms WordPress plugin before 1.57.1 does not verify that site registration is enabled on the …● PoC
2026-08-26
CVE-2026-19226
MEDIUM 6.8
Royal Addons For Elementor — The Royal Addons for Elementor WordPress plugin before 1.7.1066 does not validate some widget settings before…● PoC
2026-08-26
CVE-2026-19718
HIGH 8.1
Blogvault Backup & Staging — The BlogVault Backup & Staging WordPress plugin before 6.65, MalCare WordPress Security Plugin WordPress plug…● PoC
2026-08-26
CVE-2026-74851
HIGH 7.2
Pods — The Pods WordPress plugin before 3.3.9.1 does not correctly compare a display callback against its list of bl…● PoC
2026-08-26
CVE-2026-74928
HIGH 7.5
Project Manager — The Project Manager WordPress plugin before 4.0.7 does not have any authorisation check on its import routes,…● PoC
2026-08-26
CVE-2026-74929
MEDIUM 5.4
Project Manager — The Project Manager WordPress plugin before 4.0.7 does not restrict several of its REST API routes to the pro…● PoC
2026-08-26
CVE-2026-74930
MEDIUM 4.3
Project Manager — The Project Manager WordPress plugin before 4.0.7 does not check that the user whose activity is being reques…● PoC
2026-08-26
CVE-2026-75797
HIGH 7.7
Ai Engine — The AI Engine WordPress plugin before 3.7.2 does not confine a caller-supplied URL when mapping it to a local…● PoC
2026-08-26
CVE-2026-75798
MEDIUM 5.3
Ai Engine — The AI Engine WordPress plugin before 3.7.2 does not perform an authorisation check on one of its administrat…● PoC
2026-08-26
CVE-2026-77693
HIGH 8.7
Order Tip For Woocommerce — The Order Tip for WooCommerce WordPress plugin before 1.6.0 does not check the capability of the user requesti…● PoC
2026-08-26
CVE-2026-77694
MEDIUM 5.3
Eventin — The Eventin WordPress plugin before 4.1.19 does not properly restrict which changes a guest checkout token is…● PoC
2026-08-26
CVE-2026-77695
MEDIUM 6.5
Return Refund And Exchange For Woocommerce — The Return Refund and Exchange For WooCommerce WordPress plugin before 4.6.4 does not correctly verify the own…● PoC
2026-08-26
CVE-2026-77754
MEDIUM 5.3
Kirki — The Kirki WordPress plugin before 6.0.14 does not perform a capability check on some endpoints of one of its …● PoC
2026-08-26
CVE-2026-77757
MEDIUM 5.4
Directorist: Ai Powered Business Directory, Listings & Classified Ads — The Directorist: AI-Powered Business Directory, Listings & Classified Ads WordPress plugin before 8.9.3 does n…● PoC
2026-08-26
CVE-2026-77758
MEDIUM 5.3
Stripe Payment Forms By Wp Full Pay — The Stripe Payment Forms by WP Full Pay WordPress plugin before 8.5.1 does not properly verify that a custome…● PoC
2026-08-26
CVE-2026-77789
MEDIUM 4.3
Stripe Payment Forms By Wp Full Pay — The Stripe Payment Forms by WP Full Pay WordPress plugin before 8.5.1 does not verify that a subscription bel…● PoC
2026-08-26
CVE-2026-77790
N/A
Registrationmagic — The RegistrationMagic WordPress plugin before 6.0.9.4 does not sanitise and escape a parameter before using i…● PoC
2026-08-26
CVE-2026-78146
MEDIUM 6.5
Simple Newsletter Plugin — The Simple Newsletter Plugin WordPress plugin before 4.3.3 does not verify that the requester is the subscrib…● PoC
2026-08-26
CVE-2026-74932
HIGH 7.5
Wp Fastest Cache — The WP Fastest Cache WordPress plugin before 1.5.1 does not validate the Host header before using it to build …● PoC
2026-08-25
CVE-2026-78572
HIGH 8.1
Kalles Addons — The Kalles Addons plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and includ…
2026-08-25
CVE-2026-13598
N/A
Restrictmate — The RestrictMate WordPress plugin before 1.3.0 does not restrict the user role supplied during account regist…● PoC
2026-08-23
CVE-2026-14853
MEDIUM 4.3
Woocommerce Bookings — The WooCommerce Bookings WordPress plugin before 3.9.0 does not perform a capability check on one of its AJAX …● PoC
2026-08-23
CVE-2026-77003
LOW 2.7
Content Mask — The Content Mask WordPress plugin before 1.8.5.5 does not check the capability required to publish the post ty…● PoC
2026-08-23
CVE-2026-77115
HIGH 7.1
Brave — Brave Popup Builder (brave-popup-builder) up to version 0.8.5 reflects UTM query parameters into popup form HT…● PoC
2026-08-23
CVE-2026-77116
MEDIUM 4.3
Brave — Brave Popup Builder (slug: brave-popup-builder) has a broken access control issue in versions through 0.8.5. A…● PoC
2026-08-23
CVE-2026-14187
LOW 2.7
Tutor Lms — The Tutor LMS WordPress plugin before 4.0.6 does not enforce per-object ownership checks on its course conten…● PoC
2026-08-22
CVE-2026-16260
MEDIUM 6.8
Post Grid, Slider & Carousel Ultimate — The Post Grid, Slider & Carousel Ultimate WordPress plugin before 1.8.1 does not sanitise and escape one of i…● PoC
2026-08-22
CVE-2026-16612
MEDIUM 5.3
Fibosearch — The FiboSearch WordPress plugin before 1.34.1 does not consistently exclude password-protected products from …● PoC
2026-08-22
CVE-2026-16738
MEDIUM 5.3
Conekta Payment Gateway — The Conekta Payment Gateway WordPress plugin before 6.2.2 does not verify the authenticity of incoming payment…● PoC
2026-08-22
CVE-2026-18052
HIGH 8.1
Managewp Worker — The ManageWP Worker WordPress plugin before 4.9.37 does not bind the account being logged in to the signature …● PoC
2026-08-22
CVE-2026-19093
MEDIUM 6.8
Tutor Lms — The Tutor LMS WordPress plugin before 4.0.6 does not validate a stored file path before using it to stream me…● PoC
2026-08-22
CVE-2026-19221
HIGH 7.2
Forminator Forms — The Forminator Forms WordPress plugin before 1.57.0.5 does not restrict a network-wide setting to network adm…● PoC
2026-08-22
CVE-2026-19222
MEDIUM 6.6
Forminator Forms — The Forminator Forms WordPress plugin before 1.57.0.7 does not consistently enforce the role restriction it a…● PoC
2026-08-22
CVE-2026-76789
HIGH 8.8
Slider Hero With Video Background, Animation — The Slider Hero with Video Background, Animation WordPress plugin before 9.1.3 does not have authorisation and…● PoC
2026-08-22
CVE-2026-76793
HIGH 8.1
Firebase Authentication — The Firebase Authentication WordPress plugin before 1.7.1 does not require the email address in an authenticat…● PoC
2026-08-22
CVE-2026-77000
CRITICAL 9.8
Wp Social Media Login — The WP Social Media Login WordPress plugin through 1.0.6 does not verify that a social login was actually comp…● PoC
2026-08-22
CVE-2026-77001
CRITICAL 9.8
Social Login & Sharing Buttons With Analytics By Soclever — The Social Login & Sharing buttons with Analytics By SoClever WordPress plugin through 1.2.0 does not perform …● PoC
2026-08-22
CVE-2026-77002
CRITICAL 9.8
Smilepass Selfie Login — The SmilePass Selfie Login WordPress plugin through 1.0.2 does not perform any server-side verification of the…● PoC
2026-08-22
CVE-2026-13176
LOW 2.7
Eventin — The Eventin WordPress plugin before 4.1.21 does not validate a user-supplied webhook URL stored on events nor …● PoC
2026-08-21
CVE-2026-13736
MEDIUM 5.3
Newpath Wildapricotpress Add On — The NewPath WildApricotPress Add-on WordPress plugin through 1.0.0 does not enforce its members-only field pr…● PoC
2026-08-21
CVE-2026-14325
LOW 3.5
Drag And Drop Multiple File Upload For Contact Form 7 — The Drag and Drop Multiple File Upload for Contact Form 7 WordPress plugin before 1.3.9.9 does not escape one …● PoC
2026-08-21
CVE-2026-14601
MEDIUM 6.8
Link Whisper Free — The Link Whisper Free WordPress plugin before 0.9.7 does not properly sanitize and escape a parameter before u…● PoC
2026-08-21
CVE-2026-15046
MEDIUM 4.2
Litextension — The LitExtension WordPress plugin through 1.2.5 does not verify a nonce before an administrative action that o…● PoC
2026-08-21
CVE-2026-15150
MEDIUM 5.3
Mycred — The myCred WordPress plugin before 3.2.5 does not verify that the receiver of an incoming payment gateway noti…● PoC
2026-08-21
CVE-2026-16575
MEDIUM 5.3
Dokan: Ai Powered Woocommerce Multivendor Marketplace Solution — The Dokan: AI Powered WooCommerce Multivendor Marketplace Solution WordPress plugin before 5.0.14 does not re…● PoC
2026-08-21
CVE-2026-16576
HIGH 7.2
Dokan: Ai Powered Woocommerce Multivendor Marketplace Solution — The Dokan: AI Powered WooCommerce Multivendor Marketplace Solution WordPress plugin before 5.0.14 does not co…● PoC
2026-08-21
CVE-2026-16577
LOW 2.7
Dokan: Ai Powered Woocommerce Multivendor Marketplace Solution — The Dokan: AI Powered WooCommerce Multivendor Marketplace Solution WordPress plugin before 5.0.14 does not va…● PoC
2026-08-21
CVE-2026-16650
MEDIUM 5.3
Charitable — The Charitable WordPress plugin before 1.8.12 does not verify the authenticity of incoming Square payment webh…● PoC
2026-08-21
CVE-2026-16959
MEDIUM 6.8
Media Library Assistant — The Media Library Assistant WordPress plugin before 3.40 does not validate a search parameter before concatena…● PoC
2026-08-21
CVE-2026-16962
MEDIUM 5.3
Tamara Checkout — The Tamara Checkout WordPress plugin through 1.9.9.20 does not verify the order key, a nonce, or any capabilit…● PoC
2026-08-21
CVE-2026-17559
MEDIUM 5.3
Passster — The Passster WordPress plugin before 4.3.9 does not correctly match its own public endpoint paths when decidin…● PoC
2026-08-21
CVE-2026-18356
LOW 3.7
Limit Login Attempts Security — The Limit Login Attempts Reloaded WordPress plugin before 3.3.5 does not compare logins against its username d…● PoC
2026-08-21
CVE-2026-18781
HIGH 8.1
Drag And Drop Multiple File Upload For Contact Form 7 — The Drag and Drop Multiple File Upload for Contact Form 7 WordPress plugin before 1.3.9.9 does not validate th…● PoC
2026-08-21
CVE-2026-19085
LOW 2.7
Duplicate Post — The Duplicate Post WordPress plugin before 1.5.6 does not check that a user may read the content of a post bef…● PoC
2026-08-21
CVE-2026-19435
LOW 2.7
Duplicate Post — The Duplicate Post WordPress plugin before 1.5.6 does not check the user's capabilities before returning post …● PoC
2026-08-21
CVE-2026-19848
MEDIUM 6.5
Profilepress — The ProfilePress WordPress plugin before 4.17.1 does not strip shortcodes from two of its profile fields befor…● PoC
2026-08-21
CVE-2026-75796
HIGH 7.2
Ai Engine — The AI Engine WordPress plugin before 3.6.1 does not verify that the requesting user is authorized to act on …● PoC
2026-08-21
CVE-2025-15671
MEDIUM 5.4
Welcart E Commerce — The Welcart e-Commerce WordPress plugin before 2.12.1 does not regenerate the session identifier on authentica…● PoC
2026-08-21
CVE-2026-13405
MEDIUM 6.6
Royal Addons For Elementor — The Royal Addons for Elementor WordPress plugin before 1.7.1066 does not correctly sanitise custom widget mar…● PoC
2026-08-20
CVE-2026-15049
HIGH 7.2
Depicter — Popup & Slider Builder — The Depicter — Popup & Slider Builder WordPress plugin before 4.8.0 does not validate the type of a file uploa…● PoC
2026-08-20
CVE-2026-19615
MEDIUM 6.8
Admin And Site Enhancements (Ase) — The Admin and Site Enhancements (ASE) WordPress plugin before 9.0.1 does not sanitise uploaded SVG files on ev…● PoC
2026-08-20
CVE-2026-19697
MEDIUM 6.8
Gutenkit — The GutenKit WordPress plugin before 2.5.0 does not sanitise uploaded SVG files on all of the upload paths it…● PoC
2026-08-20
CVE-2026-19699
LOW 2.7
Gutenkit — The GutenKit WordPress plugin before 2.5.0 does not have a sufficient capability check on some of its REST AP…● PoC
2026-08-20
CVE-2026-74992
MEDIUM 6.8
Kirki — The Kirki WordPress plugin before 6.2.3 does not properly validate the files contained in archives uploaded b…● PoC
2026-08-20
CVE-2026-75860
CRITICAL 9.8
Json Options — The JSON Options WordPress plugin through 0.0.4 does not have any capability check or nonce verification on on…● PoC
2026-08-20
CVE-2026-11565
HIGH 8.5
Advanced File Manager — The Advanced File Manager WordPress plugin before 5.4.13 does not perform capability checks in several of its…● PoC
2026-08-19
CVE-2026-12983
HIGH 8.6
Dinatur — The Dinatur WordPress plugin through 1.18 does not sanitize and escape user input before using it in a SQL que…● PoC
2026-08-19
CVE-2026-13169
HIGH 8.1
Eventin — The Eventin WordPress plugin before 4.1.21 does not properly verify ownership of events before allowing them …● PoC
2026-08-19
CVE-2026-13173
LOW 2.7
Eventin — The Eventin WordPress plugin before 4.1.21 does not verify the current user's permission to edit other users …● PoC
2026-08-19
CVE-2026-13174
HIGH 7.2
Eventin — The Eventin WordPress plugin before 4.1.21 does not verify ownership or capability before deleting user accou…● PoC
2026-08-19
CVE-2026-13175
MEDIUM 6.5
Eventin — The Eventin WordPress plugin before 4.1.21 does not verify ownership before allowing schedule records to be m…● PoC
2026-08-19
CVE-2026-14196
MEDIUM 4.3
Wcfm Marketplace — The WCFM Marketplace WordPress plugin before 3.8.1 does not verify that a marketplace vendor owns a review be…● PoC
2026-08-19
CVE-2026-14287
MEDIUM 4.7
10web Booster — The 10Web Booster WordPress plugin before 2.33.5 does not correctly validate an access token on an unauthenti…● PoC
2026-08-19
CVE-2026-14334
HIGH 8.8
Booking Calendar, Appointment Booking System — The Booking calendar, Appointment Booking System WordPress plugin through 3.2.36 does not properly sanitize up…● PoC
2026-08-19
CVE-2026-14825
LOW 2.7
Quiz And Survey Master (Qsm) — The Quiz and Survey Master (QSM) WordPress plugin before 11.2.4 does not perform a per-object ownership check…● PoC
2026-08-19
CVE-2026-14826
LOW 2.7
Quiz And Survey Master (Qsm) — The Quiz and Survey Master (QSM) WordPress plugin before 11.2.4 does not perform a per-object ownership check…● PoC
2026-08-19
CVE-2026-14861
HIGH 7.5
User Verification By Pickplugins — The User Verification by PickPlugins WordPress plugin through 2.0.47 does not verify that a request to resend …● PoC
2026-08-19
CVE-2026-15253
MEDIUM 6.8
Easy Media Replace — The Easy Media Replace WordPress plugin through 0.2.0 does not sanitise and escape an attachment title before …● PoC
2026-08-19
CVE-2026-16058
MEDIUM 5.3
Yaycurrency — The YayCurrency WordPress plugin before 3.3.5 does not perform any capability or ownership check on several o…● PoC
2026-08-19
CVE-2026-16570
HIGH 7.1
Nextscripts: Social Networks Auto Poster — The NextScripts: Social Networks Auto-Poster WordPress plugin before 4.4.8 does not escape some of the query-s…● PoC
2026-08-19
CVE-2026-16616
HIGH 8.6
Simple File List — The Simple File List WordPress plugin through 6.3.11 does not validate the source path of a file-move operatio…● PoC
2026-08-19
CVE-2026-16617
HIGH 8.8
Simple File List — The Simple File List WordPress plugin through 6.3.11 does not properly sanitise and escape a file's descriptio…● PoC
2026-08-19
CVE-2026-16950
HIGH 8.6
Product Shortlist — The Product Shortlist WordPress plugin through 1.0.4 does not properly sanitise and escape a parameter before …● PoC
2026-08-19
CVE-2026-16979
MEDIUM 4.3
Smartcrawl Seo Checker, Analyzer & Optimizer — The SmartCrawl SEO checker, analyzer & optimizer WordPress plugin before 3.16.3 does not perform capability ch…● PoC
2026-08-19
CVE-2026-17565
HIGH 7.2
Animation Addons For Elementor — The Animation Addons for Elementor WordPress plugin before 2.7.2 does not validate a user-supplied value befo…● PoC
2026-08-19
CVE-2026-18031
CRITICAL 9.8
Tabapay Gateway — The TabaPay Gateway WordPress plugin through 1.4.0 does not validate the payment callback before establishing …● PoC
2026-08-19
CVE-2026-18051
CRITICAL 10
W3 Total Cache — The W3 Total Cache WordPress plugin before 2.10.5 does not properly validate the request path it uses to build…● PoC
2026-08-19
CVE-2026-18202
MEDIUM 6.8
Jetengine — The JetEngine WordPress plugin before 3.8.14 adds SVG to the site-wide list of allowed upload types without sa…● PoC
2026-08-19
CVE-2026-18231
MEDIUM 5.3
Wp Directory Kit — The WP Directory Kit WordPress plugin before 1.5.7 does not perform any authorization check on one of its publ…● PoC
2026-08-19
CVE-2026-18466
MEDIUM 5.4
Wp Maps — The WP Maps WordPress plugin before 4.9.8 does not perform a capability check, nor validate a nonce, in one o…● PoC
2026-08-19
CVE-2026-18776
CRITICAL 9.8
Truebooker — The TrueBooker WordPress plugin before 1.2.7 does not have proper authorisation checks in some of its AJAX ac…● PoC
2026-08-19
CVE-2026-18777
MEDIUM 5.3
Truebooker — The TrueBooker WordPress plugin before 1.2.7 does not have proper authorisation checks in one of its AJAX act…● PoC
2026-08-19
CVE-2026-18778
MEDIUM 5.3
Truebooker — The TrueBooker WordPress plugin before 1.2.7 does not have proper authorisation checks in some of its AJAX ac…● PoC
2026-08-19
CVE-2026-18779
MEDIUM 5.3
Truebooker — The TrueBooker WordPress plugin before 1.2.7 does not have proper authorisation checks in one of its AJAX act…● PoC
2026-08-19
CVE-2026-18937
CRITICAL 9
Broken Link Checker — The Broken Link Checker WordPress plugin before 2.4.12 does not limit which query variables it accepts from us…● PoC
2026-08-19
CVE-2026-19055
HIGH 7.1
Prosolution Wp Client — The ProSolution WP Client WordPress plugin before 2.0.11 does not sanitise and escape several parameters befor…● PoC
2026-08-19
CVE-2026-19056
HIGH 7.1
Prosolution Wp Client — The ProSolution WP Client WordPress plugin before 2.0.11 does not sanitise and escape a parameter before refle…● PoC
2026-08-19
CVE-2026-19406
LOW 2.7
Easy Appointments — The Easy Appointments WordPress plugin before 4.0.1 does not restrict one of its appointment-listing REST endp…● PoC
2026-08-19
CVE-2026-19416
MEDIUM 4.3
Kivicare — The KiviCare WordPress plugin before 4.5.4 does not verify that the requesting user owns the appointment bein…● PoC
2026-08-19
CVE-2026-19417
MEDIUM 6.5
Kivicare — The KiviCare WordPress plugin before 4.5.4 does not verify that the requesting user is entitled to the media …● PoC
2026-08-19
CVE-2026-19709
MEDIUM 5.3
Membership For Woocommerce — The Membership For WooCommerce WordPress plugin before 3.1.2 does not check that an API consumer secret has ac…● PoC
2026-08-19
CVE-2026-19782
MEDIUM 5.4
Wps Bidouille — The WPS Bidouille WordPress plugin before 1.33.5 does not have proper authorisation checks in an AJAX action, …● PoC
2026-08-19
CVE-2026-19842
HIGH 8.8
Saml Single Sign On — The SAML Single Sign On WordPress plugin before 5.4.7 does not verify the signature of a SAML response before…● PoC
2026-08-19
CVE-2026-13700
MEDIUM 5.9
Wooms — The WooMS WordPress plugin through 9.14 does not validate a user-supplied URL before using it in a server-side…● PoC
2026-08-17
CVE-2026-14832
MEDIUM 5.3
Shopsmart Loyalty For Woocommerce — The ShopSmart Loyalty for WooCommerce WordPress plugin through 1.0.0 does not perform any authorization or own…● PoC
2026-08-17
CVE-2026-13712
MEDIUM 5.4
Divi — The Divi WordPress theme before 5.9.0 does not properly escape some of its Social Media Follow module settings…● PoC
2026-08-16
CVE-2026-15384
MEDIUM 5.7
Manual Image Crop — The Manual Image Crop WordPress plugin before 1.15 does not perform any capability check or nonce verification…● PoC
2026-08-16
CVE-2026-17533
HIGH 7.2
All In One Wp Migration And Backup — The All-in-One WP Migration and Backup WordPress plugin before 7.108 does not restrict its migration import fu…● PoC
2026-08-16
CVE-2026-18653
HIGH 7.2
Wp Directory Kit — The WP Directory Kit WordPress plugin before 1.5.7 does not sanitise and escape a parameter before using it in…● PoC
2026-08-16
CVE-2026-19613
MEDIUM 6.5
Ecs — The ECS WordPress plugin before 4.3.10 does not perform ownership or post-status checks when one of its dynam…● PoC
2026-08-16
CVE-2026-19711
MEDIUM 6.5
Premium Packages — The Premium Packages WordPress plugin before 7.0.7 does not validate a withdrawal request against the request…● PoC
2026-08-16
CVE-2026-19712
MEDIUM 6.1
Masteriyo Lms — The Masteriyo LMS WordPress plugin before 2.3.3 does not sanitise and escape a quiz field before outputting i…● PoC
2026-08-16
CVE-2026-19714
CRITICAL 9.1
Simple Jwt Login — The Simple JWT Login WordPress plugin before 3.6.8 does not validate the audience of the Google identity toke…● PoC
2026-08-16
CVE-2026-19717
HIGH 7.5
Catfolders Document Gallery & Pdf Library — The CatFolders Document Gallery & PDF Library WordPress plugin before 2.0.7 does not have authorisation checks…● PoC
2026-08-16
CVE-2026-19725
CRITICAL 9.1
Wpvivid — Backup, Migration & Staging — The WPvivid — Backup, Migration & Staging WordPress plugin before 0.9.131 does not sanitise a value taken from…● PoC
2026-08-16
CVE-2026-19726
MEDIUM 6.5
Visualizer — The Visualizer WordPress plugin before 4.0.7 does not properly authorise access to the configuration of its c…● PoC
2026-08-16
CVE-2026-19728
HIGH 7.5
Extra Product Options Builder For Woocommerce — The Extra Product Options Builder for WooCommerce WordPress plugin before 1.2.176 does not verify that the req…● PoC
2026-08-16
CVE-2026-14229
MEDIUM 5.3
Ecs — The ECS WordPress plugin before 4.3.8 does not check the post status or any capability when rendering an Elem…● PoC
2026-08-15
CVE-2026-14230
MEDIUM 5.4
Ecs — The ECS WordPress plugin before 4.3.8 does not perform capability or object-ownership checks on its Dynamic R…● PoC
2026-08-15
CVE-2026-16541
MEDIUM 6.5
Simply Schedule Appointments — The Simply Schedule Appointments WordPress plugin before 1.6.12.17 does not restrict the user records returned…● PoC
2026-08-15
CVE-2026-16611
HIGH 7.5
Product Feed Pro For Woocommerce By Adtribes — The Product Feed PRO for WooCommerce by AdTribes WordPress plugin before 13.5.7 does not perform an authoriza…● PoC
2026-08-15
CVE-2026-18216
MEDIUM 6.5
Backup Migration — The Backup Migration WordPress plugin before 2.1.7 does not properly restrict a post-restore automatic login m…● PoC
2026-08-15
CVE-2026-18807
MEDIUM 4.3
Ecs — The ECS WordPress plugin before 4.3.8 does not have capability or ownership checks on its dynamic repeater ac…● PoC
2026-08-15
CVE-2026-14290
MEDIUM 6.8
Embed Google Photos Album — The Embed Google Photos album WordPress plugin through 2.2.1 does not escape a shortcode attribute value befor…● PoC
2026-08-14
CVE-2026-15205
HIGH 8.6
Paymob For Woocommerce — The Paymob for WooCommerce WordPress plugin before 4.1.9 does not properly sanitise a client-supplied identifi…● PoC
2026-08-14
CVE-2026-16739
MEDIUM 5.9
Epeken All Kurir For Woocommerce — The Epeken All Kurir for Woocommerce WordPress plugin through 2.1.2 does not verify that a payment-confirmatio…● PoC
2026-08-14
CVE-2026-18039
HIGH 8.1
Essential Addons For Elementor — The Essential Addons for Elementor WordPress plugin before 6.7.2 does not prevent user-supplied registration …● PoC
2026-08-14
CVE-2026-13328
MEDIUM 5.3
Food Menu — The Food Menu WordPress plugin before 6.0.2 does not perform any capability or ownership check on its reserva…● PoC
2026-08-13
CVE-2026-13610
HIGH 7.5
Kivicare — The KiviCare WordPress plugin before 4.5.2 does not restrict the roles assignable through its unauthenticated…● PoC
2026-08-13
CVE-2026-14182
CRITICAL 9.8
Customer Email Verification For Woocommerce — The Customer Email Verification for WooCommerce WordPress plugin before 3.2.6 does not correctly validate the …● PoC
2026-08-13
CVE-2026-14213
LOW 3.7
Booking For Appointments And Events Calendar — The Booking for Appointments and Events Calendar WordPress plugin before 2.4.6 does not verify that an authen…● PoC
2026-08-13
CVE-2026-14332
MEDIUM 5.4
Ecwid By Lightspeed Ecommerce Shopping Cart — The Ecwid by Lightspeed Ecommerce Shopping Cart WordPress plugin before 7.0.9 does not perform a capability ch…● PoC
2026-08-13
CVE-2026-15413
CRITICAL 10
Link Factory — The Link Factory WordPress plugin is a backdoor. Distributed as a "homepage sentence publisher", it exposes an…● PoC
2026-08-13
CVE-2026-18945
HIGH 8.2
Wp Helper Premium — The WP Helper Premium WordPress plugin before 4.7.6 does not verify the order key when rendering its custom or…● PoC
2026-08-13
CVE-2026-19088
MEDIUM 5.4
Shopengine Elementor Woocommerce Builder Addon — The ShopEngine Elementor WooCommerce Builder Addon WordPress plugin before 4.9.3 does not protect one of its …● PoC
2026-08-13
CVE-2026-12976
MEDIUM 6.5
Learnpress — The LearnPress WordPress plugin before 4.4.4 does not verify that a user is enrolled in a course before proce…● PoC
2026-08-12
CVE-2026-13168
MEDIUM 6.5
Eventin — The Eventin WordPress plugin before 4.1.20 does not properly restrict access to stored customer records, allo…● PoC
2026-08-12
CVE-2026-13171
HIGH 8.2
Eventin — The Eventin WordPress plugin before 4.1.20 does not perform an authorization check on its waiting-list regist…● PoC
2026-08-12
CVE-2026-13177
MEDIUM 4.3
Eventin — The Eventin WordPress plugin before 4.1.20 does not properly restrict access to individual order records, all…● PoC
2026-08-12
CVE-2026-13612
MEDIUM 4.3
Kivicare — The KiviCare WordPress plugin before 4.5.2 does not verify that the requesting user owns the records being ac…● PoC
2026-08-12
CVE-2026-13613
HIGH 8.8
Kivicare — The KiviCare WordPress plugin before 4.5.2 does not properly sanitise and escape user-supplied parameters bef…● PoC
2026-08-12
CVE-2026-14857
MEDIUM 4.3
Wp Crowdfunding — The WP Crowdfunding WordPress plugin before 2.2.1 does not verify ownership of a campaign before allowing its …● PoC
2026-08-12
CVE-2026-14858
MEDIUM 4.3
Wp Crowdfunding — The WP Crowdfunding WordPress plugin before 2.2.1 does not verify order ownership before returning order detai…● PoC
2026-08-12
CVE-2026-14859
MEDIUM 4.3
Wp Crowdfunding — The WP Crowdfunding WordPress plugin before 2.2.1 does not check the campaign-submission capability in one of …● PoC
2026-08-12
CVE-2026-14925
HIGH 7.5
Import Wp — The Import WP WordPress plugin before 2.14.23 does not perform any authorization check on one of its export-f…● PoC
2026-08-12
CVE-2026-15039
CRITICAL 9.8
Giftware — The giftware WordPress plugin before 4.2.10 does not validate the type of uploaded files in one of its upload …● PoC
2026-08-12
CVE-2026-15045
MEDIUM 6.5
Wallet System For Woocommerce — The Wallet System for WooCommerce WordPress plugin before 2.7.10 does not validate a user-supplied wallet amou…● PoC
2026-08-12
CVE-2026-15213
MEDIUM 5.3
Welcart E Commerce — The Welcart e-Commerce WordPress plugin before 2.11.33 does not verify the authenticity of its convenience-sto…● PoC
2026-08-12
CVE-2026-15249
MEDIUM 5.4
Patterns Kit — The Patterns Kit WordPress plugin through 1.0.3 does not escape a link attribute before its client-side script…● PoC
2026-08-12
CVE-2026-15388
MEDIUM 4.3
Cookie Consent — The Cookie Consent WordPress plugin before 0.0.10 does not correctly enforce its intended administrator-only …● PoC
2026-08-12
CVE-2026-16051
CRITICAL 9.8
Wpmudev Updates — The wpmudev-updates WordPress plugin before 5.0.1 does not verify the integrity of the packages installed thro…● PoC
2026-08-12
CVE-2026-16066
MEDIUM 5.4
Welcart E Commerce — The Welcart e-Commerce WordPress plugin before 2.11.34 does not sanitise or escape a product field before outp…● PoC
2026-08-12
CVE-2026-16253
HIGH 7.5
Total Upkeep — The Total Upkeep WordPress plugin before 1.17.3 does not adequately protect the secret that authorizes its ba…● PoC
2026-08-12
CVE-2026-16294
HIGH 7.1
Powerpress Podcasting Plugin By Blubrry — The PowerPress Podcasting plugin by Blubrry WordPress plugin before 11.17.1 does not validate one of its Podca…● PoC
2026-08-12
CVE-2026-16538
CRITICAL 9.1
Wallet For Woocommerce — The Wallet for WooCommerce WordPress plugin before 1.6.10 does not verify the amount actually collected for a …● PoC
2026-08-12
CVE-2026-16621
MEDIUM 5.3
Payment Gateway For Paypal On Woocommerce — The Payment Gateway for PayPal on WooCommerce WordPress plugin before 9.2.1 does not verify that payment actua…● PoC
2026-08-12
CVE-2026-16737
MEDIUM 5.3
Wp Travel Engine — The WP Travel Engine WordPress plugin before 6.8.5 does not perform authorization or ownership checks when lo…● PoC
2026-08-12
CVE-2026-16747
MEDIUM 6.5
Kirki — The Kirki WordPress plugin before 6.2.1 does not properly authorise its front-end form submission REST routes …● PoC
2026-08-12
CVE-2026-16977
HIGH 8.1
Form Maker By 10web — The Form Maker by 10Web WordPress plugin before 1.15.45 does not properly parameterize a user-controlled valu…● PoC
2026-08-12
CVE-2026-16990
MEDIUM 5.3
Payment Button For Paypal — The Payment Button for PayPal WordPress plugin through 1.2.3.44 does not enforce the merchant-configured price…● PoC
2026-08-12
CVE-2026-17008
MEDIUM 5.3
Quick Paypal Payments — The Quick Paypal Payments WordPress plugin through 5.7.50 does not verify the paid amount, receiver, or paymen…● PoC
2026-08-12
CVE-2026-17013
MEDIUM 6.1
Wp Photo Album Plus — The WP Photo Album Plus WordPress plugin before 9.2.07.002 does not sanitise and escape a parameter before ref…● PoC
2026-08-12
CVE-2026-18035
MEDIUM 5.3
User Access Manager — The User Access Manager WordPress plugin before 2.3.15 does not apply its access restrictions to REST API requ…● PoC
2026-08-12
CVE-2026-18044
LOW 3.7
Estatik Real Estate Plugin — The Estatik Real Estate Plugin WordPress plugin before 4.3.4 does not validate the same recipient list that it…● PoC
2026-08-12
CVE-2026-18046
MEDIUM 4.3
Cookie Consent — The Cookie Consent WordPress plugin before 0.0.10 does not correctly enforce its intended administrator-only …● PoC
2026-08-12
CVE-2026-18048
HIGH 7.5
Wp Photo Album Plus — The WP Photo Album Plus WordPress plugin before 9.2.07.002 does not validate a client-controlled value used to…● PoC
2026-08-12
CVE-2026-18049
HIGH 7.5
Wp Photo Album Plus — The WP Photo Album Plus WordPress plugin before 9.2.07.002 does not perform any capability or nonce check on o…● PoC
2026-08-12
CVE-2026-18057
HIGH 8.1
Events Manager — The Events Manager WordPress plugin before 7.4.1 does not sanitise and escape a user-controlled value before …● PoC
2026-08-12
CVE-2026-18230
HIGH 8.1
Wp Directory Kit — The WP Directory Kit WordPress plugin before 1.5.6 does not sanitise and escape a parameter before using it in…● PoC
2026-08-12
CVE-2026-18366
CRITICAL 9.8
Events Manager — The Events Manager WordPress plugin before 7.4.1 does not properly scope its capability mapping, discarding t…● PoC
2026-08-12
CVE-2026-18391
CRITICAL 9.8
Woocommerce Subscriptions — The WooCommerce Subscriptions WordPress plugin before 9.1.0 does not validate user input before unserializing …● PoC
2026-08-12
CVE-2026-18474
HIGH 8.6
Wp Directory Kit — The WP Directory Kit WordPress plugin before 1.5.6 does not sanitise and escape a parameter before using it in…● PoC
2026-08-12
CVE-2026-18789
HIGH 7.5
Ezoic — The Ezoic WordPress plugin before 2.23.1 does not properly restrict access to some of its content export funct…● PoC
2026-08-12
CVE-2026-18943
MEDIUM 6.5
Wpc Admin Columns — The WPC Admin Columns WordPress plugin before 2.3.4 does not have authorisation checks in one of its AJAX acti…● PoC
2026-08-12
CVE-2026-18962
MEDIUM 4.3
Wp Photo Album Plus — The WP Photo Album Plus WordPress plugin before 9.2.09.002 does not check that the current user is allowed to …● PoC
2026-08-12
CVE-2026-19050
MEDIUM 6.4
Prosolution Wp Client — The ProSolution WP Client WordPress plugin before 2.0.9 does not validate a user-supplied URL, and does not ch…● PoC
2026-08-12
CVE-2026-19052
MEDIUM 4.3
Prosolution Wp Client — The ProSolution WP Client WordPress plugin before 2.0.9 does not perform capability checks on two administrati…● PoC
2026-08-12
CVE-2026-19073
MEDIUM 5.3
Order Sync With Zendesk For Woocommerce — The Order Sync with Zendesk for WooCommerce WordPress plugin before 2.2.3 does not perform any capability chec…● PoC
2026-08-12
CVE-2026-19217
MEDIUM 5.4
Royal Addons For Elementor — The Royal Addons for Elementor WordPress plugin before 1.7.1065 does not validate a widget setting used to bu…● PoC
2026-08-12
CVE-2026-14548
MEDIUM 6.5
Ray Enterprise Translation — The Ray Enterprise Translation WordPress plugin through 1.7.3 does not perform any capability or nonce checks …● PoC
2026-08-11
CVE-2026-14549
MEDIUM 4.3
Ray Enterprise Translation — The Ray Enterprise Translation WordPress plugin through 1.7.3 does not perform any capability or nonce checks …● PoC
2026-08-11
CVE-2026-12971
LOW 2.2
Learnpress — The LearnPress WordPress plugin before 4.4.4 does not validate a user-supplied URL before the server fetches …● PoC
2026-08-10
CVE-2026-13170
HIGH 7.2
Eventin — The Eventin WordPress plugin before 4.1.20 does not properly validate a template path setting before using it…● PoC
2026-08-10
CVE-2026-13600
HIGH 8.1
Autonettv Relay — The AutoNetTV Relay WordPress plugin before 3.0.14 does not perform any capability or authentication check bef…● PoC
2026-08-10
CVE-2026-13701
MEDIUM 4.8
Advanced Excerpt — The Advanced Excerpt WordPress plugin before 4.5 does not sanitise and escape one of its settings before outpu…● PoC
2026-08-10
CVE-2026-14206
HIGH 7.5
Ht Contact Form — The HT Contact Form WordPress plugin before 2.9.3 does not perform any authorization check on the endpoint th…● PoC
2026-08-10
CVE-2026-14211
LOW 3.8
Booking For Appointments And Events Calendar — The Booking for Appointments and Events Calendar WordPress plugin before 9.7 does not verify that an authenti…● PoC
2026-08-10
CVE-2026-14237
HIGH 7.2
Vitepos — The vitepos WordPress plugin before 3.6.0, Vitepos WordPress plugin before 3.5.0 do not perform a per-target …● PoC
2026-08-10
CVE-2026-14238
MEDIUM 4.1
Vitepos — The vitepos WordPress plugin before 3.6.0 does not sanitize or parameterize an identifier taken from a REST re…● PoC
2026-08-10
CVE-2026-14293
HIGH 8.8
Autopay — The Autopay WordPress plugin before 5.0.1 does not perform any capability or nonce check before saving a styli…● PoC
2026-08-10
CVE-2026-14860
MEDIUM 5.3
Podcast Player — The Podcast Player WordPress plugin before 8.3.1 does not validate the destination of a server-side request b…● PoC
2026-08-10
CVE-2026-14941
MEDIUM 5.4
Customer Reviews For Woocommerce — The Customer Reviews for WooCommerce WordPress plugin before 5.116.0 does not perform nonce or capability chec…● PoC
2026-08-10
CVE-2026-15047
MEDIUM 6.8
S2member — The s2Member WordPress plugin before 260805 does not escape several shortcode attributes before outputting th…● PoC
2026-08-10
CVE-2026-15229
MEDIUM 5.3
Pinpoint Booking System — The Pinpoint Booking System WordPress plugin through 2.9.9.7.1 does not validate the booking price on the ser…● PoC
2026-08-10
CVE-2026-15237
MEDIUM 5.3
Motopress Hotel Booking — The MotoPress Hotel Booking WordPress plugin before 6.2.3 does not perform any authorization or ownership chec…● PoC
2026-08-10
CVE-2026-15238
MEDIUM 5.4
Motopress Hotel Booking — The MotoPress Hotel Booking WordPress plugin before 6.2.3 does not verify record ownership before updating cus…● PoC
2026-08-10
CVE-2026-16257
HIGH 8.2
Arvow Ai Seo Writer — The Arvow AI SEO Writer WordPress plugin before 1.5.4 does not properly restrict access to one of its REST end…● PoC
2026-08-10
CVE-2026-16298
CRITICAL 9.8
Foodboxbooker — The FoodBoxBooker WordPress plugin before 1.0.7 does not properly validate the password reset request, allowin…● PoC
2026-08-10
CVE-2026-16299
CRITICAL 9.8
Single Sign On For Tng — The Single Sign On For TNG WordPress plugin before 2.2.0 does not properly validate a password reset request, …● PoC
2026-08-10
CVE-2026-16949
MEDIUM 5.8
Term Pages — The Term Pages WordPress plugin before 2.0.0 does not properly sanitise and escape a parameter before using it…● PoC
2026-08-10
CVE-2026-16985
HIGH 8.8
Squeeze — The Squeeze WordPress plugin before 1.7.12 does not validate the file type or extension of the per-size image…● PoC
2026-08-10
CVE-2026-17010
MEDIUM 5.4
Saitama Addon Pack — The Saitama Addon Pack WordPress plugin through 1.0.8 does not sanitise and escape certain post metadata value…● PoC
2026-08-10
CVE-2026-17012
MEDIUM 5.3
Accept Paypal & Stripe With Subscriptions For Woocommerce — The Accept PayPal & Stripe with Subscriptions for WooCommerce WordPress plugin through 3.1.0 does not verify t…● PoC
2026-08-10
CVE-2026-17016
LOW 3.7
Accept Paypal & Stripe With Subscriptions For Woocommerce — The Accept PayPal & Stripe with Subscriptions for WooCommerce WordPress plugin through 3.1.0 does not validate…● PoC
2026-08-10
CVE-2026-17018
MEDIUM 4.9
Cubewp Framework — The CubeWP Framework WordPress plugin through 1.1.30 does not perform a per-object read authorization check, n…● PoC
2026-08-10
CVE-2026-17019
MEDIUM 6.1
Jetengine — The JetEngine WordPress plugin before 3.8.13.1 does not sanitise uploaded SVG files before storing and serving…● PoC
2026-08-10
CVE-2026-17020
MEDIUM 4.3
Salon Booking System — The Salon Booking System WordPress plugin through 10.31.0 does not verify that a requested booking belongs to…● PoC
2026-08-10
CVE-2026-17021
MEDIUM 5.3
Salon Booking System — The Salon Booking System WordPress plugin before 10.30.34 does not properly restrict access to some of its boo…● PoC
2026-08-10
CVE-2026-17022
HIGH 7.5
Salon Booking System — The Salon Booking System WordPress plugin before 10.30.34 does not properly validate a booking's ownership to…● PoC
2026-08-10
CVE-2026-17023
MEDIUM 4.8
Salon Booking System — The Salon Booking System WordPress plugin through 10.30.33 does not perform any capability check or validate …● PoC
2026-08-10
CVE-2026-17540
HIGH 8.8
File Manager — The File Manager WordPress plugin before 6.9.1 does not properly authorise its file management commands, allow…● PoC
2026-08-10
CVE-2026-17541
HIGH 7.5
File Manager — The File Manager WordPress plugin before 6.9.1 does not have authorisation checks on one of its REST API route…● PoC
2026-08-10
CVE-2026-17542
HIGH 7.5
File Manager — The File Manager WordPress plugin before 6.9.1 does not perform any capability check on one of its file manage…● PoC
2026-08-10
CVE-2026-18030
HIGH 8.1
Bricksforge — The BricksForge WordPress plugin before 3.1.8.8 does not verify the identity of the requester when processing …● PoC
2026-08-10
CVE-2026-18200
MEDIUM 4.3
Foodboxbooker — The FoodBoxBooker WordPress plugin before 1.0.8 does not verify that the user account being updated belongs to…● PoC
2026-08-10
CVE-2026-18468
HIGH 8.1
Login & Register Forms — The Login & Register Forms WordPress plugin before 4.0.2 does not bind the password reset verification state …● PoC
2026-08-10
CVE-2026-18469
HIGH 8.1
Login & Register Forms — The Login & Register Forms WordPress plugin before 4.0.2 does not enforce its password reset attempt limit ag…● PoC
2026-08-10
CVE-2026-18470
HIGH 7.5
Login & Register Forms — The Login & Register Forms WordPress plugin before 4.0.2 does not verify that a password reset request comes …● PoC
2026-08-10
CVE-2026-18666
MEDIUM 4.3
Library Management System — The Library Management System WordPress plugin before 3.6.7 does not sanitize and escape a user-supplied param…● PoC
2026-08-10
CVE-2026-18786
HIGH 8.8
Checkview — The CheckView WordPress plugin before 2.3.2 does not restrict its REST API authentication filter to its own r…● PoC
2026-08-10
CVE-2026-18934
MEDIUM 5.5
Rss Aggregator By Feedzy — The RSS Aggregator by Feedzy WordPress plugin before 5.2.6 does not verify that the requesting user owns or i…● PoC
2026-08-10
CVE-2026-18946
HIGH 7.5
Contact Form To Any Api — The Contact Form to Any API WordPress plugin before 3.0.7 does not use a random filename when copying files up…● PoC
2026-08-10
CVE-2026-18960
MEDIUM 5.4
Block User Account — The Block User Account WordPress plugin before 2.0.1 does not enforce its account block on every authenticatio…● PoC
2026-08-10
CVE-2026-19049
HIGH 8.6
Prosolution Wp Client — The ProSolution WP Client WordPress plugin before 2.0.9 does not sanitise a cookie value before using it in SQ…● PoC
2026-08-10
CVE-2026-19053
CRITICAL 9.1
Prosolution Wp Client — The ProSolution WP Client WordPress plugin before 2.0.6 does not sanitise and escape a parameter before using …● PoC
2026-08-10
CVE-2026-19074
MEDIUM 5.3
Advanced Classifieds & Directory Pro — The Advanced Classifieds & Directory Pro Advanced Classifieds & Directory Pro WordPress plugin before 3.4.3 (<…● PoC
2026-08-10
CVE-2026-19075
MEDIUM 5
All In One Video Gallery — All-in-One Video Gallery registers a public, unauthenticated file-download handler triggered by `?vdl=<post_id…● PoC
2026-08-10
CVE-2026-19077
MEDIUM 6.5
Duplicate Post — The Duplicate Post WordPress plugin before 1.5.5 does not perform per-object authorisation checks in its bulk …● PoC
2026-08-10
CVE-2026-19089
CRITICAL 9.8
Product Input Fields For Woocommerce — The Product Input Fields for WooCommerce WordPress plugin before 2.0.2 does not validate uploaded file types w…● PoC
2026-08-10
CVE-2026-15038
CRITICAL 9.8
Infinitewp Client — The InfiniteWP Client WordPress plugin before 1.13.6 does not properly verify the site-connection state and th…● PoC
2026-08-09
CVE-2026-16032
MEDIUM 6.1
Lws Optimize — The LWS Optimize WordPress plugin before 4.1.2 does not properly escape a value submitted through an unauthen…● PoC
2026-08-09
CVE-2026-16957
LOW 2.7
Slim Seo — The Slim SEO WordPress plugin before 4.9.11 does not restrict a post-meta preview feature to posts the user i…● PoC
2026-08-09
CVE-2026-16965
MEDIUM 4.3
Solace Extra — The Solace Extra WordPress plugin before 1.6.1 does not perform capability or nonce checks in one of its AJAX …● PoC
2026-08-09
CVE-2026-16988
HIGH 7.5
Geodirectory — The GeoDirectory WordPress plugin before 2.8.169 does not perform any authorization check when returning map …● PoC
2026-08-09
CVE-2026-16992
MEDIUM 6.5
Create — The Create WordPress plugin before 2.5.4 does not perform an authorization check before returning content over…● PoC
2026-08-09
CVE-2026-17011
LOW 3.8
Nexter Blocks — The Nexter Blocks WordPress plugin before 5.0.2 does not restrict who can save global CSS through one of its …● PoC
2026-08-09
CVE-2026-17014
MEDIUM 5.3
Wp Photo Album Plus — The WP Photo Album Plus WordPress plugin before 9.2.07.002 does not perform any capability or nonce check on o…● PoC
2026-08-09
CVE-2026-17017
HIGH 8.1
Cubewp Framework — The CubeWP Framework WordPress plugin before 1.1.31 does not properly sanitize and escape a parameter before u…● PoC
2026-08-09
CVE-2026-17044
HIGH 8.6
Iptanus File Upload — The Iptanus File Upload WordPress plugin before 5.1.8 does not properly sanitise and escape a parameter before…● PoC
2026-08-09
CVE-2026-18032
HIGH 7.5
Wp Data Access — The WP Data Access WordPress plugin before 5.5.79 does not validate the column names it accepts on one of its…● PoC
2026-08-09
CVE-2026-18037
MEDIUM 6.5
Create — The Create WordPress plugin before 2.5.4 does not perform an authorization check before rendering content over…● PoC
2026-08-09
CVE-2026-18357
HIGH 7.5
Wpc Order Tip For Woocommerce — The WPC Order Tip for WooCommerce WordPress plugin before 3.3.1 does not perform authorisation or nonce checks…● PoC
2026-08-09
CVE-2026-18464
HIGH 7.5
Wp Maps Pro — The WP MAPS PRO WordPress plugin before 6.1.3 does not perform a capability check in one of its AJAX actions, …● PoC
2026-08-09
CVE-2026-18465
MEDIUM 6.5
Wp Maps Pro — The WP MAPS PRO WordPress plugin before 6.1.3 does not perform a capability check in one of its AJAX actions, …● PoC
2026-08-09
CVE-2026-18473
CRITICAL 9.1
Wp Directory Kit — The WP Directory Kit WordPress plugin before 1.5.5 does not properly sanitise and escape a parameter before us…● PoC
2026-08-09
CVE-2026-18603
MEDIUM 6.5
Piweb Cancel Order / Refund Request For Woocommerce — The PiWeb Cancel order / Refund request for WooCommerce WordPress plugin before 1.3.4.34 does not have authori…● PoC
2026-08-09
CVE-2026-16267
HIGH 8.1
Newsletters — The Newsletters WordPress plugin before 4.16 does not restrict the classes allowed when unserialising a value …● PoC
2026-08-08
CVE-2026-16269
MEDIUM 4.8
Newsletters — The Newsletters WordPress plugin before 4.16 does not strictly compare its API authentication key, allowing un…● PoC
2026-08-08
CVE-2026-16282
MEDIUM 5.3
Appointment Hour Booking — The Appointment Hour Booking WordPress plugin before 1.5.88 does not validate a client-supplied booking price…● PoC
2026-08-08
CVE-2026-16535
MEDIUM 6.1
Link Library — The Link Library WordPress plugin before 7.9.4 does not sanitise and escape a parameter before reflecting it b…● PoC
2026-08-08
CVE-2026-16558
MEDIUM 5.4
Ymc Filter — The YMC Filter WordPress plugin before 3.12.8 does not sanitize and escape a layout builder setting before out…● PoC
2026-08-08
CVE-2026-16559
MEDIUM 6.8
Ymc Filter — The YMC Filter WordPress plugin before 3.12.9 does not sanitize SVG files uploaded through one of its icon upl…● PoC
2026-08-08
CVE-2026-16562
MEDIUM 6.5
Wp Statistics — The WP Statistics WordPress plugin before 14.16.10 does not perform a capability check on a set of dashboard …● PoC
2026-08-08
CVE-2026-16574
MEDIUM 5.4
Dokan: Ai Powered Woocommerce Multivendor Marketplace Solution — The Dokan: AI Powered WooCommerce Multivendor Marketplace Solution WordPress plugin before 5.0.11 does not ve…● PoC
2026-08-08
CVE-2026-16578
HIGH 7.5
Admin Safety Guard — Login Security, Limit Logins, 2fa & Brute Force Protection — The Admin Safety Guard — Login Security, Limit Logins, 2FA & Brute Force Protection WordPress plugin before 1.…● PoC
2026-08-08
CVE-2026-16589
HIGH 7.7
Wp Directory Kit — The WP Directory Kit WordPress plugin before 1.5.5 does not sanitize and escape a parameter before using it in…● PoC
2026-08-08
CVE-2026-16590
MEDIUM 6.5
Wp Directory Kit — The WP Directory Kit WordPress plugin before 1.5.5 does not perform authorization or nonce checks on one of it…● PoC
2026-08-08
CVE-2026-16594
HIGH 7.5
Wp Directory Kit — The WP Directory Kit WordPress plugin before 1.5.5 does not perform authorization or nonce checks on one of it…● PoC
2026-08-08