← Browse

Unknown

153 CVEs
CVE IDSeverityProduct / summaryPublished
CVE-2026-12968 N/A Product Addons And Product Options With Custom Fields — The Product Addons and Product Options With Custom Fields WordPress plugin before 1.6.15 does not restrict an…● PoC 2026-07-22 CVE-2026-12987 N/A Events Manager — The Events Manager WordPress plugin before 7.3.7 does not safely handle booking-registration data on sites us…● PoC 2026-07-22 CVE-2026-14322 N/A Timetics — The Timetics WordPress plugin before 1.0.57 does not enforce a pending or unpaid status for new bookings crea…● PoC 2026-07-22 CVE-2026-11767 HIGH 8.8 Free Theme Builder For Elementor — The Free Builder for Elementor WordPress plugin before 1.6.7 does not sanitise submitted contact form field …● PoC 2026-07-21 CVE-2026-13693 MEDIUM 5.9 Bit Form — The Bit Form WordPress plugin before 3.1.0 does not restrict a form file-field value to a safe path before re…● PoC 2026-07-21 CVE-2026-13694 MEDIUM 6.5 Bit Form — The Bit Form WordPress plugin before 3.1.0 does not properly validate its workflow-trigger token once the ass…● PoC 2026-07-21 CVE-2026-14183 MEDIUM 4.3 Classified Listing — The Classified Listing WordPress plugin before 5.3.9 does not verify that the order targeted by its payment-r…● PoC 2026-07-21 CVE-2026-14184 MEDIUM 5.4 Academy Lms — The Academy LMS WordPress plugin before 3.8.1 does not verify ownership of a user-supplied user identifier in …● PoC 2026-07-21 CVE-2026-14185 MEDIUM 4.3 Wpbot — The WPBot WordPress plugin before 8.2.0 does not perform a capability or nonce check in one of its retrieval-…● PoC 2026-07-21 CVE-2026-8082 HIGH 7.5 Bpost Shipping Platform — The bpost-shipping-platform WordPress plugin before 3.2.3 does not properly sanitize a parameter before using …● PoC 2026-07-21 CVE-2026-10081 HIGH 8.8 Unlimited Elements For Elementor — The Unlimited Elements For Elementor WordPress plugin before 2.0.11 does not sanitize or escape Google review …● PoC 2026-07-20 CVE-2026-10724 MEDIUM 4.8 Reviews Feed — The Reviews Feed WordPress plugin before 2.6.5 does not neutralize WordPress shortcodes contained in third-pa…● PoC 2026-07-20 CVE-2026-10755 LOW 2.7 All In One Seo — The All in One SEO WordPress plugin before 4.9.9 does not correctly restrict access to some of its AI integra…● PoC 2026-07-20 CVE-2026-11349 HIGH 8.6 Modern Event Calendar Pro — The Modern Event Calendar Pro WordPress plugin before 7.34.0, Modern Events Calendar Lite WordPress plugin bef…● PoC 2026-07-20 CVE-2026-11868 MEDIUM 5.3 Wp Travel — The WP Travel WordPress plugin before 11.7.1 does not perform capability or ownership checks on its booking c…● PoC 2026-07-20 CVE-2026-12592 HIGH 7.5 Slimstat Analytics — The SlimStat Analytics WordPress plugin before 5.5.0 does not escape a visitor-controlled geolocation value be…● PoC 2026-07-20 CVE-2026-12723 MEDIUM 5.3 Kirki — The Kirki WordPress plugin before 6.0.12 does not perform any authorisation check on one of its REST routes, …● PoC 2026-07-20 CVE-2026-12724 MEDIUM 4.3 Kirki — The Kirki WordPress plugin before 6.0.12 does not sanitise or escape the email subject and body values suppli…● PoC 2026-07-20 CVE-2026-12898 MEDIUM 6.5 All In One Wp Migration And Backup — The All-in-One WP Migration and Backup WordPress plugin before 7.106 does not properly sanitise a user-supplie…● PoC 2026-07-20 CVE-2026-12970 HIGH 7.1 Learnpress — The LearnPress WordPress plugin before 4.4.1 does not escape a search parameter before reflecting it into an …● PoC 2026-07-20 CVE-2026-12972 MEDIUM 5.3 Payplus Payment Gateway — The PayPlus Payment Gateway WordPress plugin before 8.2.2 does not perform authorization or order-ownership va…● PoC 2026-07-20 CVE-2026-12973 MEDIUM 6.5 Payplus Payment Gateway — The PayPlus Payment Gateway WordPress plugin before 8.2.2 does not perform authorization or order-ownership va…● PoC 2026-07-20 CVE-2026-13142 HIGH 8.1 Social Login, Passkeys, Magic Link & Email Otp — The Social Login, Passkeys, Magic Link & Email OTP WordPress plugin before 1.4.1 does not enforce rate limiti…● PoC 2026-07-20 CVE-2026-13147 CRITICAL 9.1 Kirki — The Kirki WordPress plugin before 6.0.12 does not validate a user-supplied URL before requesting it server-si…● PoC 2026-07-20 CVE-2026-13156 MEDIUM 5.4 Mailersend — The MailerSend WordPress plugin before 1.0.8 does not perform a nonce check on its configuration-delete actio…● PoC 2026-07-20 CVE-2026-13432 MEDIUM 5.4 Thumbpress — The ThumbPress WordPress plugin before 6.2.2 does not perform a capability check on one of its AJAX actions, …● PoC 2026-07-20 CVE-2026-8825 MEDIUM 4.9 Elementor Website Builder — The Elementor Website Builder WordPress plugin before 4.1.4 does not properly check user permissions before r…● PoC 2026-07-20 CVE-2026-9833 HIGH 7.1 Tag Groups Is The Advanced Way To Display Your Taxonomy Terms — The Tag Groups is the Advanced Way to Display Your Taxonomy Terms WordPress plugin before 2.2.0 does not prope…● PoC 2026-07-20 CVE-2026-10525 MEDIUM 6.1 Nex Forms — The NEX-Forms WordPress plugin before 9.2.3 does not sanitise and escape some submitted form data before stor…● PoC 2026-07-17 CVE-2026-11575 HIGH 7.5 Phonepe Payment Solutions — The PhonePe Payment Solutions WordPress plugin before 3.1.0 does not properly verify the authenticity of incom…● PoC 2026-07-17 CVE-2026-11961 HIGH 8.1 User Registration & Membership — The User Registration & Membership WordPress plugin before 5.2.3 does not validate that the membership tier s…● PoC 2026-07-17 CVE-2026-11966 MEDIUM 5.3 User Registration & Membership — The User Registration & Membership WordPress plugin before 5.2.3 does not perform a capability check for unau…● PoC 2026-07-17 CVE-2026-12393 MEDIUM 5.4 Wps Bookings For Woocommerce — The WPS Bookings for WooCommerce WordPress plugin before 3.11.7 does not verify that a booking order belongs t…● PoC 2026-07-17 CVE-2026-13402 MEDIUM 5.3 Royal Addons For Elementor — The Royal Addons for Elementor WordPress plugin before 1.7.1063 does not check the post status of menu items …● PoC 2026-07-17 CVE-2026-9810 CRITICAL 9.8 Ai Copilot — The AI Copilot WordPress plugin before 1.5.4 does not bind OAuth access tokens to a WordPress user, and accep…● PoC 2026-07-17 CVE-2026-11371 MEDIUM 6.1 Betterdocs — The BetterDocs WordPress plugin before 4.5.5 does not sanitise an AI-generated documentation summary before s…● PoC 2026-07-16 CVE-2026-11866 MEDIUM 5.4 Appointment Booking Plugin — The Appointment Booking Plugin WordPress plugin before 5.6.3 does not validate a CSRF nonce on several state-…● PoC 2026-07-16 CVE-2026-12395 MEDIUM 6.5 Wp Job Portal — The WP Job Portal WordPress plugin before 2.5.5 does not properly sanitize and escape a parameter before usin…● PoC 2026-07-16 CVE-2026-12492 CRITICAL 9.8 Happy Coders Otp Login For Woocommerce — The Happy Coders OTP Login for WooCommerce WordPress plugin before 2.8 does not verify that a one-time passwor…● PoC 2026-07-16 CVE-2026-12510 MEDIUM 5.9 Ai Engine — The AI Engine WordPress plugin before 3.5.5 does not verify that a user owns the chatbot conversation referen…● PoC 2026-07-16 CVE-2026-12525 HIGH 8.8 Redux Framework — The Redux Framework WordPress plugin before 4.5.13 does not restrict which user meta keys can be written when …● PoC 2026-07-16 CVE-2026-12585 HIGH 8.1 Abandoned Cart Lite For Woocommerce — The Abandoned Cart Lite for WooCommerce WordPress plugin before 6.8.2 does not protect the integrity of its ca…● PoC 2026-07-16 CVE-2026-12684 MEDIUM 6.5 Customer Reviews For Woocommerce — The Customer Reviews for WooCommerce WordPress plugin before 5.113.0 does not perform authentication, capabili…● PoC 2026-07-16 CVE-2026-12869 MEDIUM 6.1 Header Footer Builder For Elementor — The Header Footer Builder for Elementor WordPress plugin before 1.2.1 does not require an administrative capab…● PoC 2026-07-16 CVE-2026-12906 LOW 2.7 Rtmkit — The RTMKit WordPress plugin before 2.0.9 does not perform a capability check in one of its AJAX actions and re…● PoC 2026-07-16 CVE-2026-12907 LOW 2.7 Rtmkit — The RTMKit WordPress plugin before 2.0.9 does not perform a proper capability check on one of its -builder AJA…● PoC 2026-07-16 CVE-2026-12978 HIGH 7.1 Funnelkit — The FunnelKit WordPress plugin before 3.15.0.6 does not escape a user-supplied parameter before reflecting it…● PoC 2026-07-16 CVE-2026-12979 MEDIUM 5.5 Funnelkit — The FunnelKit WordPress plugin before 3.15.0.6 does not validate a user-supplied path before deleting a file …● PoC 2026-07-16 CVE-2026-11579 MEDIUM 5.3 Kali Forms — Contact Form & Drag And Drop Builder — The Kali Forms — Contact Form & Drag-and-Drop Builder WordPress plugin before 2.4.17 does not verify that a fi…● PoC 2026-07-15 CVE-2026-11580 MEDIUM 5.5 Kali Forms — Contact Form & Drag And Drop Builder — The Kali Forms — Contact Form & Drag-and-Drop Builder WordPress plugin before 2.4.17 does not perform a per-ob…● PoC 2026-07-15 CVE-2026-12281 HIGH 8.1 Shibboleth — The Shibboleth WordPress plugin before 2.5.4 does not fail closed when its HTTP header identity mode is enable…● PoC 2026-07-15 CVE-2026-12512 HIGH 8.6 Quotes Llama — The Quotes llama WordPress plugin before 3.1.6 does not properly sanitize and escape a user-supplied parameter…● PoC 2026-07-15 CVE-2026-11563 CRITICAL 9.6 Word Count And Social Shares — The Word Count and Social Shares WordPress plugin through 1.0 does not validate a user-supplied file path befo…● PoC 2026-07-14 CVE-2026-11567 MEDIUM 5.9 Sureforms — The SureForms WordPress plugin before 2.11.1 does not properly validate the payment amount on forms that use …● PoC 2026-07-14 CVE-2026-12511 HIGH 8.1 Ai Engine — The AI Engine WordPress plugin before 3.5.5 does not sanitize a user-supplied filename before using it to wri…● PoC 2026-07-14 CVE-2026-12583 HIGH 8.1 Newsletters — The Newsletters WordPress plugin before 4.15 does not prevent deserialization of untrusted input that is store…● PoC 2026-07-14 CVE-2026-12988 MEDIUM 6.4 Wp 2fa — The WP 2FA WordPress plugin before 3.1.1.2 does not verify that the email address supplied during two-factor …● PoC 2026-07-14 CVE-2025-15665 MEDIUM 5.4 Ultimate Before After Image Slider & Gallery — The Ultimate Before After Image Slider & Gallery WordPress plugin before 4.7.1 does not escape the value of t…● PoC 2026-07-14 CVE-2026-10551 MEDIUM 6.1 Breeze Cache — The Breeze Cache WordPress plugin before 2.5.6 is vulnerable to unauthenticated Stored Cross-Site Scripting (X…● PoC 2026-07-13 CVE-2026-11963 HIGH 8.1 User Registration & Membership — The User Registration & Membership WordPress plugin before 5.2.2 does not perform an authorization check on a…● PoC 2026-07-13 CVE-2026-11964 CRITICAL 9.1 User Registration & Membership — The User Registration & Membership WordPress plugin before 5.2.2 does not verify the authenticity of incoming…● PoC 2026-07-13 CVE-2026-12081 MEDIUM 5 Database For Contact Form 7, Wpforms, Elementor Forms — The Database for Contact Form 7, WPforms, Elementor forms WordPress plugin before 1.5.2 does not restrict the …● PoC 2026-07-13 CVE-2026-12271 MEDIUM 5.4 Tutor Lms — The Tutor LMS WordPress plugin before 3.9.13 does not verify ownership of the targeted quiz attempt before wr…● PoC 2026-07-13 CVE-2026-12273 MEDIUM 4.3 Tutor Lms — The Tutor LMS WordPress plugin before 3.9.13 does not perform any authorization or post-target validation bef…● PoC 2026-07-13 CVE-2026-12274 MEDIUM 6.5 Tutor Lms — The Tutor LMS WordPress plugin before 3.9.13 does not verify that the requesting user is allowed to edit a ta…● PoC 2026-07-13 CVE-2026-12275 HIGH 7.1 Tutor Lms — The Tutor LMS WordPress plugin before 3.9.13 does not, in its Droip and Kirki page-builder integration, perfo…● PoC 2026-07-13 CVE-2026-12396 MEDIUM 5.4 Wp Job Portal — The WP Job Portal WordPress plugin before 2.5.5 does not perform capability or ownership checks before allowi…● PoC 2026-07-13 CVE-2026-12397 MEDIUM 4.3 Wp Job Portal — The WP Job Portal WordPress plugin before 2.5.5 does not verify ownership when returning an employer's contac…● PoC 2026-07-13 CVE-2026-12582 HIGH 8.6 Library Management System — The Library Management System WordPress plugin before 3.5.8 does not sanitize and escape a user-supplied param…● PoC 2026-07-13 CVE-2026-12276 MEDIUM 5.3 La Studio Element Kit For Elementor — The LA-Studio Element Kit for Elementor WordPress plugin before 1.6.1 does not check whether user registration…● PoC 2026-07-10 CVE-2026-12685 HIGH 7.5 Escortwp — The EscortWP escortwp WordPress theme through 3.6.2 was distributed with a vendor-authored, obfuscated backdoo…● PoC 2026-07-10 CVE-2026-11571 HIGH 7.5 Everest Forms — The Everest Forms WordPress plugin before 3.5.0 does not reliably delete temporary CSV files generated during…● PoC 2026-07-09 CVE-2026-11869 MEDIUM 5.3 Wp Dsgvo Tools (Gdpr) — The WP DSGVO Tools (GDPR) WordPress plugin before 3.1.40 does not perform an authorization check on the immedi…● PoC 2026-07-09 CVE-2026-11875 MEDIUM 5.3 Wp Support Plus Responsive Ticket System — The WP Support Plus Responsive Ticket System WordPress plugin through 9.1.2 does not sign or verify its guest-…● PoC 2026-07-09 CVE-2026-12270 MEDIUM 6.5 Everest Forms — The Everest Forms WordPress plugin before 3.5.0 does not correctly restrict access to several REST API endpoi…● PoC 2026-07-09 CVE-2026-12516 MEDIUM 5.3 Fediverse Embeds — The Fediverse Embeds WordPress plugin before 1.5.8 does not validate the destination of the server-side reques…● PoC 2026-07-09 CVE-2026-12517 MEDIUM 5.3 Fediverse Embeds — The Fediverse Embeds WordPress plugin before 1.5.8 does not validate the destination of the server-side reques…● PoC 2026-07-09 CVE-2026-12378 HIGH 8.1 Appointment Booking Calendar Plugin And Scheduling Plugin — The Appointment Booking Calendar Plugin and Scheduling Plugin WordPress plugin through 1.1.28 does not valida…● PoC 2026-07-08 CVE-2026-10834 MEDIUM 4.6 Wp Travel Engine — The WP Travel Engine WordPress plugin before 6.8.1 does not properly validate the source of a user-supplied p…● PoC 2026-07-07 CVE-2026-12277 HIGH 8.7 Frontend File Manager Plugin — The Frontend File Manager Plugin WordPress plugin through 23.6 does not validate a file path derived from user…● PoC 2026-07-07 CVE-2026-12375 CRITICAL 9.8 Uncanny Automator Pro — The uncanny-automator-pro WordPress plugin before 7.3.0.6 was distributed with malicious code after the vendor…● PoC 2026-07-07 CVE-2026-4375 CRITICAL 9 Doleads Integrator — The DoLeads Integrator WordPress plugin through 0.65, wp2epub WordPress plugin through 0.65 have been seen to …● PoC 2026-07-07 CVE-2026-10830 HIGH 8.8 Allcoach — The AllCoach WordPress plugin before 1.0.2 does not verify that an email address submitted to a public accoun…● PoC 2026-07-06 CVE-2026-11766 HIGH 8 Ultimate Member — The Ultimate Member WordPress plugin before 2.12.0 does not properly sanitise and escape the value of custom …● PoC 2026-07-06 CVE-2026-11855 HIGH 8.8 Simple Membership — The Simple Membership WordPress plugin before 4.7.5 does not verify the authenticity of Stripe webhook request…● PoC 2026-07-06 CVE-2026-11962 HIGH 8.8 Fileorganizer — The FileOrganizer WordPress plugin before 1.2.0 does not validate the file type on several of its file-manage…● PoC 2026-07-06 CVE-2026-12083 HIGH 8.1 Admin And Site Enhancements (Ase) — The Admin and Site Enhancements (ASE) WordPress plugin before 8.8.4, admin-site-enhancements-pro WordPress plu…● PoC 2026-07-06 CVE-2026-6382 CRITICAL 9.1 Fileorganizer — The FileOrganizer WordPress plugin before 1.1.9, Advanced File Manager WordPress plugin before 5.4.12, File …● PoC 2026-07-06 CVE-2026-10077 MEDIUM 6.8 Yootheme — The yootheme WordPress theme before 5.0.35 does not prevent its bundled front-end framework from treating cert…● PoC 2026-07-02 CVE-2026-11578 LOW 2.7 Fluent Forms — The Fluent Forms WordPress plugin before 6.2.5 does not properly restrict the deletion of form submission ent…● PoC 2026-07-02 CVE-2026-11781 LOW 2.7 Adminify — The Adminify WordPress plugin before 4.2.10 does not perform per-user read-capability checks on the results r…● PoC 2026-07-02 CVE-2026-11965 MEDIUM 6.5 User Registration & Membership — The User Registration & Membership WordPress plugin before 5.2.0 does not enforce payment completion before a…● PoC 2026-07-02 CVE-2026-10750 HIGH 8.1 Royal Mcp — The Royal MCP WordPress plugin before 1.4.26 does not perform capability checks on the majority of its MCP to…● PoC 2026-07-01 CVE-2026-11562 MEDIUM 4.3 Ws Form Lite — The WS Form LITE WordPress plugin before 1.11.8 does not have a capability check on one of its settings-updat…● PoC 2026-07-01 CVE-2026-11568 HIGH 7.5 Product Configurator For Woocommerce — The Product Configurator for WooCommerce WordPress plugin before 1.7.3 does not perform any authorisation or p…● PoC 2026-07-01 CVE-2026-11570 MEDIUM 4.2 User Submitted Posts — The User Submitted Posts WordPress plugin before 20260608 does not escape a submitted value before outputting…● PoC 2026-07-01 CVE-2026-11794 HIGH 8.1 Advanced Form Integration — Connect Forms To 200+ Apps — The Advanced Form Integration — Connect Forms to 200+ Apps WordPress plugin before 2.1.1 does not restrict the…● PoC 2026-07-01 CVE-2026-11880 LOW 3.1 Fluent Forms — The Fluent Forms WordPress plugin before 6.2.1 does not properly verify ownership before processing a subscri…● PoC 2026-07-01 CVE-2026-11883 HIGH 7.2 Webauthn Provider For Two Factor — The WebAuthn Provider for Two Factor WordPress plugin before 2.5.6 does not correctly validate the second-fact…● PoC 2026-07-01 CVE-2026-11887 MEDIUM 4.3 Salon Booking System — The Salon Booking System WordPress plugin before 10.30.20 does not have proper authorisation checks on one of…● PoC 2026-07-01 CVE-2026-11581 MEDIUM 5.9 Kali Forms — Contact Form & Drag And Drop Builder — The Kali Forms — Contact Form & Drag-and-Drop Builder WordPress plugin before 2.4.13 does not sanitise a form …● PoC 2026-06-30 CVE-2026-11589 HIGH 8.8 Wp Support Plus Responsive Ticket System — The WP Support Plus Responsive Ticket System WordPress plugin through 9.1.2 does not properly validate uploade…● PoC 2026-06-30 CVE-2026-11590 HIGH 8.6 Wp Support Plus Responsive Ticket System — The WP Support Plus Responsive Ticket System WordPress plugin through 9.1.2 does not sanitize user-supplied ar…● PoC 2026-06-30 CVE-2026-9576 MEDIUM 4.9 Fluent Booking — The Fluent Booking WordPress plugin before 2.1.2 does not verify ownership of the requested group_id before e…● PoC 2026-06-30 CVE-2026-10083 HIGH 7.5 Apcu Manager — The APCu Manager WordPress plugin before 4.5.0 does not escape APCu object-cache keys before rendering them in…● PoC 2026-06-29 CVE-2026-9676 MEDIUM 4.3 F4 Post Tree — The F4 Post Tree WordPress plugin before 2.0.5 does not perform capability checks or CSRF/nonce verification o…● PoC 2026-06-29 CVE-2026-10820 HIGH 8.1 Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content — The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content Wo…● PoC 2026-06-27 CVE-2026-9677 MEDIUM 4.8 Shariff For Wordpress — The Shariff for WordPress Shariff for WordPress plugin through 1.0.11 does not sanitize or escape the shariff_…● PoC 2026-06-27 CVE-2026-10823 HIGH 7.5 Ymc Filter — The YMC Filter WordPress plugin before 3.11.3 does not properly authorize access to one of its REST API endpoi…● PoC 2026-06-26 CVE-2026-10835 HIGH 7.7 Salesmanago & Leadoo — The SALESmanago & Leadoo WordPress plugin before 3.11.3 does not properly sanitise and escape a parameter pass…● PoC 2026-06-26 CVE-2026-8380 MEDIUM 6.5 Frontend File Manager Plugin — The Frontend File Manager Plugin WordPress plugin through 23.6 does not properly verify ownership of every tar…● PoC 2026-06-26 CVE-2025-10268 MEDIUM 5.3 Printcart Web To Print Product Designer For Woocommerce — The Printcart Web to Print Product Designer for WooCommerce WordPress plugin through 2.4.8 is vulnerable to pa…● PoC 2026-06-26 CVE-2026-10824 MEDIUM 6.5 Masteriyo Lms — The Masteriyo LMS WordPress plugin before 2.2.1 does not perform authorization checks in a course-progress RE…● PoC 2026-06-25 CVE-2026-5305 HIGH 8.8 Email Address Encoder — The Email Address Encoder WordPress plugin before 1.0.25, email-encoder-premium WordPress plugin before 0.3.12…● PoC 2026-06-25 CVE-2026-9702 HIGH 7.5 Inpost Pl — The InPost PL WordPress plugin before 1.9.1 does not verify that the request originates from the legitimate bu…● PoC 2026-06-25 CVE-2026-10531 MEDIUM 5.4 Ai Share & Summarize — The AI Share & Summarize WordPress plugin before 2.0.4 does not sanitise and escape some of its shortcode attr…● PoC 2026-06-24 CVE-2026-10735 HIGH 7.5 Smart Post Show Pro — Multiple Shapedsmart-post-show-pro WordPress plugin before 4.0.2, Real Testimonials Pro WordPress plugin befor…● PoC 2026-06-24 CVE-2026-10749 HIGH 7.2 Post Duplicator — The Post Duplicator WordPress plugin before 3.0.15 does not safely handle custom meta-data during post duplica…● PoC 2026-06-24 CVE-2026-10753 LOW 2.7 Site Kit By Google — The Site Kit by Google WordPress plugin before 1.176.0 does not properly restrict a REST API write endpoint t…● PoC 2026-06-24 CVE-2026-9709 HIGH 7.7 Cornerstone — The Cornerstone WordPress plugin before 7.8.9 does not enforce capability checks on one of its REST API routes…● PoC 2026-06-24 CVE-2026-9710 HIGH 7.7 Cornerstone — The Cornerstone WordPress plugin before 7.8.8 does not enforce capability checks on one of its CSS-preview req…● PoC 2026-06-24 CVE-2026-7842 MEDIUM 6.8 Infility Global — The Infility Global Infility Global WordPress plugin before 2.15.20 for WordPress does not sanitize or validat…● PoC 2026-06-23 CVE-2026-8163 HIGH 8.8 Infility Global — The Infility Global WordPress plugin before 2.15.19 does not properly sanitize and escape some parameters befo…● PoC 2026-06-23 CVE-2026-8172 HIGH 7.1 Simple Basic Contact Form — The Simple Basic Contact Form WordPress plugin through 20250114 does not escape user-supplied input before ref…● PoC 2026-06-23 CVE-2026-8378 MEDIUM 5.4 Frontend File Manager Plugin — The Frontend File Manager Plugin WordPress plugin through 23.6 does not sanitise nor escape a filename submitt…● PoC 2026-06-23 CVE-2026-8379 HIGH 7.5 Frontend File Manager Plugin — The Frontend File Manager Plugin WordPress plugin through 23.6 does not properly enforce its nonce check on th…● PoC 2026-06-23 CVE-2026-10530 MEDIUM 5.3 Pie Register — The Pie Register WordPress plugin before 3.8.4.10 does not use sufficiently random values when generating its…● PoC 2026-06-22 CVE-2026-4110 MEDIUM 6.1 Ultimate Woocommerce Auction Pro — The ultimate-woocommerce-auction-pro WordPress plugin through 2.4.5 does not sanitise and escape a parameter b…● PoC 2026-06-22 CVE-2026-4259 HIGH 7.1 Ultimate Woocommerce Auction Pro — The ultimate-woocommerce-auction-pro WordPress plugin through 2.4.5 does not sanitise and escape a parameter b…● PoC 2026-06-22 CVE-2026-6858 HIGH 7.1 Transbank Webpay — The Transbank Webpay WordPress plugin before 1.14.0 does not sanitize and escape logs to be displayed, allowin…● PoC 2026-06-22 CVE-2026-7859 MEDIUM 5.3 Motors — The Motors WordPress plugin before 1.4.110 does not have proper authorisation and CSRF checks on one of its A…● PoC 2026-06-22 CVE-2026-8157 HIGH 8.8 Vitepos — The Vitepos WordPress plugin before 3.4.2 does not properly restrict the roles that can be assigned when crea…● PoC 2026-06-22 CVE-2026-9822 MEDIUM 6.5 Wp Hotel Booking — The WP Hotel Booking WordPress plugin before 2.3.1 does not enforce capability checks in several of its AJAX h…● PoC 2026-06-19 CVE-2026-9815 MEDIUM 6.5 Magicform — The MagicForm WordPress plugin through 0.1.3 does not properly validate the type of files uploaded through an …● PoC 2026-06-18 CVE-2026-7850 MEDIUM 5.9 Wp Magnific Popup — The WP Magnific Popup WordPress plugin through 1.0 does not properly escape user-controlled link URLs before i…● PoC 2026-06-17 CVE-2026-8089 HIGH 7.1 Wemail: Email Marketing, Email Automation, Newsletters, Subscribers & Email Optins For Woocommerce — The weMail: Email Marketing, Email Automation, Newsletters, Subscribers & Email Optins for WooCommerce WordPre…● PoC 2026-06-17 CVE-2026-8383 MEDIUM 5.3 Learnpress — The LearnPress WordPress plugin before 4.3.7 does not gate the `edit` context on one of its REST endpoint beh…● PoC 2026-06-17 CVE-2026-9570 HIGH 7.1 Taskbuilder — The Taskbuilder WordPress plugin before 5.0.8 does not properly sanitise a URL parameter before echoing it in…● PoC 2026-06-17 CVE-2026-8385 MEDIUM 5.3 Wp Go Maps — The WP Go Maps WordPress plugin before 10.0.10 does not properly enforce the marker approval filter on the ad…● PoC 2026-06-15 CVE-2026-8386 MEDIUM 5.3 Wp Go Maps — The WP Go Maps WordPress plugin before 10.0.10 does not perform any approval-state filtering on its public si…● PoC 2026-06-15 CVE-2026-8935 CRITICAL 9.8 Wp Maps Pro — The WP MAPS PRO WordPress plugin before 6.1.1 registers an unauthenticated AJAX action which, given a valid no…● PoC 2026-06-15 CVE-2026-9278 MEDIUM 5.4 Form Builder Cp — The Form Builder CP WordPress plugin before 1.2.47 does not properly sanitize a form configuration value befor…● PoC 2026-06-15 CVE-2025-15546 MEDIUM 5.4 Iptanus File Upload — The Iptanus File Upload WordPress plugin before 5.1.7 does not implement proper file handling when the duplica…● PoC 2026-06-14 CVE-2026-9061 LOW 3.5 Store Locator Wordpress — The Store Locator WordPress plugin before 1.6.9 does not sanitize and escape store logo metadata before storin…● PoC 2026-06-13 CVE-2026-9062 LOW 3.4 Store Locator Wordpress — The Store Locator WordPress plugin before 1.6.9 does not validate a parameter before using it in a file path, …● PoC 2026-06-13 CVE-2026-9269 LOW 3.5 Secure Copy Content Protection And Content Locking — The Secure Copy Content Protection and Content Locking WordPress plugin before 5.1.5 does not sanitise and esc…● PoC 2026-06-12 CVE-2026-9271 MEDIUM 5.9 Keepinmind Dashboard Notes — Vulnerability Title● PoC 2026-06-12 CVE-2026-3326 HIGH 8.6 Xstore — The Xstore WordPress theme before 9.7.3 does not properly sanitise and escape a parameter before using it in a…● PoC 2026-06-10 CVE-2026-8071 HIGH 8.8 Anti Spam By Cleantalk. Spam Protection — The Anti-Spam by CleanTalk. Spam protection WordPress plugin before 6.79 does not properly sanitize content wi…● PoC 2026-06-10 CVE-2026-9060 LOW 3.5 Store Locator Wordpress — The Store Locator WordPress plugin before 1.6.6 does not sanitize and escape one of its settings before storin…● PoC 2026-06-10 CVE-2026-9067 CRITICAL 9.1 Schema & Structured Data For Wp & Amp — The Schema & Structured Data for WP & AMP WordPress plugin before 1.60 does not check user capabilities on its…● PoC 2026-06-10 CVE-2026-4986 MEDIUM 5.3 Wpforms — The WPForms WordPress plugin before 1.10.0.5 does not verify the authenticity of incoming PayPal webhook even…● PoC 2026-06-09 CVE-2026-8981 LOW 3.5 Custom Block Builder — The Custom Block Builder WordPress plugin before 4.3.0 does not consistently check the unfiltered_html capabi…● PoC 2026-06-09