← Browse

Unknown

300 CVEs
CVE IDSeverityProduct / summaryPublished
CVE-2026-15247 N/A Search Atlas Seo — The Search Atlas SEO WordPress plugin before 2.6.24 does not perform a nonce or capability check before proce…● PoC 2026-09-05 CVE-2026-19858 N/A Jetformbuilder — Dynamic Blocks Form Builder — The JetFormBuilder — Dynamic Blocks Form Builder WordPress plugin before 3.6.5.2 does not perform authorisatio…● PoC 2026-09-05 CVE-2026-19861 N/A Jetformbuilder — Dynamic Blocks Form Builder — The JetFormBuilder — Dynamic Blocks Form Builder WordPress plugin before 3.6.5.2 does not properly sanitise an…● PoC 2026-09-05 CVE-2026-77826 N/A Registrationmagic — The RegistrationMagic WordPress plugin before 6.0.9.9 does not verify which application a Facebook access tok…● PoC 2026-09-05 CVE-2026-78149 N/A Smart Post — The Smart Post WordPress plugin before 4.0.8 does not check whether a post is password protected before retur…● PoC 2026-09-05 CVE-2026-78150 N/A Smart Post — The Smart Post WordPress plugin before 4.0.8 does not check the type, ownership or status of the post it is a…● PoC 2026-09-05 CVE-2026-78362 N/A Seo Flow By Lupsonline — The SEO Flow by LupsOnline WordPress plugin before 3.0.3 does not correctly validate the credential supplied w…● PoC 2026-09-05 CVE-2026-81348 N/A My Private Site — The My Private Site WordPress plugin before 4.2.3 does not apply its site-privacy access control to certain u…● PoC 2026-09-05 CVE-2026-81404 N/A Ipgp Visitors Origin — The IPGP Visitors Origin WordPress plugin before 1.6 does not sanitise or escape user input before reflecting …● PoC 2026-09-05 CVE-2026-81423 N/A Accept Stripe Payments — The Accept Stripe Payments WordPress plugin before 2.1.4 does not validate a user-supplied URL before using it…● PoC 2026-09-05 CVE-2026-81424 N/A Accept Stripe Payments — The Accept Stripe Payments WordPress plugin before 2.1.4 does not verify that the product fulfilled when a che…● PoC 2026-09-05 CVE-2026-82304 N/A Music Store — The Music Store WordPress plugin before 1.4.5 does not sanitise and escape user input before using it in a SQ…● PoC 2026-09-05 CVE-2026-82846 N/A Masteriyo Lms — The Masteriyo LMS WordPress plugin before 3.4.0 does not sanitise and escape some course settings before outp…● PoC 2026-09-05 CVE-2026-83543 N/A Greenshift — The Greenshift WordPress plugin before 13.2.0 does not validate a user-supplied URL before fetching it server…● PoC 2026-09-05 CVE-2026-83544 N/A Greenshift — The Greenshift WordPress plugin before 13.2.0 does not properly escape a block animation attribute before out…● PoC 2026-09-05 CVE-2026-84021 N/A Bold Page Builder — The Bold Page Builder WordPress plugin before 5.9.8 does not properly validate a link URL before outputting it…● PoC 2026-09-05 CVE-2026-84022 N/A Bold Page Builder — The Bold Page Builder WordPress plugin before 5.9.8 does not sanitise and escape several shortcode attributes …● PoC 2026-09-05 CVE-2026-84221 N/A Kirki — The Kirki WordPress plugin before 6.3.0 does not escape a user-supplied identifier before using it in a SQL q…● PoC 2026-09-05 CVE-2026-84225 N/A Kirki — The Kirki WordPress plugin before 6.3.0 does not check that a user is allowed to act on a collaboration comme…● PoC 2026-09-05 CVE-2026-84745 N/A The Events Calendar — The Events Calendar WordPress plugin before 6.17.3.1 does not restrict non-public content to the users entitle…● PoC 2026-09-05 CVE-2026-84896 N/A King Addons For Elementor — The King Addons for Elementor WordPress plugin before 51.1.77 does not escape a widget display-style setting …● PoC 2026-09-05 CVE-2026-84898 N/A Eventin — The Eventin WordPress plugin before 4.1.21 does not properly validate a template path value before using it t…● PoC 2026-09-05 CVE-2026-84899 N/A Vikwidgetsloader — The VikWidgetsLoader WordPress plugin before 1.12.0 does not sanitise or escape a block attribute before outp…● PoC 2026-09-05 CVE-2026-84901 N/A Eventin — The Eventin WordPress plugin before 4.1.22 does not properly check authorization on several of its event-mana…● PoC 2026-09-05 CVE-2026-84926 N/A Embedpress — The EmbedPress WordPress plugin before 4.6.4 does not correctly restrict access to one of its Google Reviews …● PoC 2026-09-05 CVE-2026-84927 N/A Embedpress — The EmbedPress WordPress plugin before 4.6.4 does not perform a sufficient authorization check on one of its …● PoC 2026-09-05 CVE-2026-84930 N/A Catfolders Document Gallery & Pdf Library — The CatFolders Document Gallery & PDF Library WordPress plugin before 2.0.7 does not properly validate a block…● PoC 2026-09-05 CVE-2026-84931 N/A Joli Table Of Contents — The Joli Table Of Contents WordPress plugin before 3.0.3 does not sanitise or escape a shortcode attribute val…● PoC 2026-09-05 CVE-2026-84934 N/A Jch Optimize — The JCH Optimize WordPress plugin before 6.0.1 does not perform a capability check on one of its authenticated…● PoC 2026-09-05 CVE-2026-84935 N/A Ht Menu — The HT Menu WordPress plugin before 1.2.7 does not perform any capability or object-ownership check when savi…● PoC 2026-09-05 CVE-2026-84936 N/A Embedpress — The EmbedPress WordPress plugin before 4.6.4 does not have proper authorization on a public review-loading ac…● PoC 2026-09-05 CVE-2026-84937 N/A Video Player For Youtube — The Video Player for YouTube WordPress plugin before 2.1.0 does not properly sanitise and escape user-supplie…● PoC 2026-09-05 CVE-2025-15693 N/A Jch Optimize — The JCH Optimize WordPress plugin before 5.0.1 does not properly restrict a directory path provided to one of …● PoC 2026-09-05 CVE-2025-15694 N/A Joli Table Of Contents — The Joli Table Of Contents WordPress plugin before 2.8.1 does not sanitise and escape some of its settings bef…● PoC 2026-09-05 CVE-2026-16281 HIGH 7.1 Classified Listing — The Classified Listing WordPress plugin before 6.1.1 does not verify that the caller owns or can edit the tar…● PoC 2026-09-04 CVE-2026-17517 MEDIUM 5.3 Content Views — The Content Views WordPress plugin before 4.5.1.2 does not check whether the user requesting a view is allowe…● PoC 2026-09-04 CVE-2026-19224 HIGH 7.2 Hummingbird Performance — The Hummingbird Performance WordPress plugin before 3.21.2 does not restrict a network-wide setting to networ…● PoC 2026-09-04 CVE-2026-74853 MEDIUM 6.8 Pods — The Pods WordPress plugin before 3.3.9.2 does not restrict which functions a display callback may resolve to,…● PoC 2026-09-04 CVE-2026-79630 MEDIUM 5.3 Wpfunnels — The WPFunnels WordPress plugin before 3.13.0 does not verify that the product requested through a checkout or…● PoC 2026-09-04 CVE-2026-79631 MEDIUM 5.3 Wpfunnels — The WPFunnels WordPress plugin before 3.13.0 does not restrict access to the log files it writes to a predict…● PoC 2026-09-04 CVE-2026-79632 MEDIUM 5.3 Wpfunnels — The WPFunnels WordPress plugin before 3.13.0 does not perform any authorisation or nonce check in one of its …● PoC 2026-09-04 CVE-2026-80438 MEDIUM 5.9 Ninja Forms — The Ninja Forms WordPress plugin before 3.15.2 does not restrict its REST abilities to administrators, accept…● PoC 2026-09-04 CVE-2026-81347 MEDIUM 5.9 Frontend Admin By Dynamiapps — The Frontend Admin by DynamiApps WordPress plugin before 3.29.13 does not properly validate a user-controllabl…● PoC 2026-09-04 CVE-2026-82186 MEDIUM 4.1 Wplp Cookie Consent — The WPLP Cookie Consent WordPress plugin before 4.4.2 does not properly validate a pagination parameter befor…● PoC 2026-09-04 CVE-2026-82193 MEDIUM 5.5 Wpvivid — Backup, Migration & Staging — The WPvivid — Backup, Migration & Staging WordPress plugin before 0.9.134 does not validate a user supplied fi…● PoC 2026-09-04 CVE-2026-82194 MEDIUM 5.5 Wpvivid — Backup, Migration & Staging — The WPvivid — Backup, Migration & Staging WordPress plugin before 0.9.134 does not validate a user supplied pa…● PoC 2026-09-04 CVE-2026-82923 CRITICAL 9.8 Ai Website Builder (Github Build) — The AI Website Builder WordPress plugin (GitHub build) 1.0.0 does not perform any authorisation or nonce check…● PoC 2026-09-04 CVE-2026-84043 MEDIUM 5.3 Epayco Payment Gateway For Woocommerce — The ePayco Payment Gateway for WooCommerce WordPress plugin before 8.4.7 does not properly verify the authenti…● PoC 2026-09-04 CVE-2026-84044 MEDIUM 5.3 Restaurant Menu And Food Ordering — The Restaurant Menu and Food Ordering WordPress plugin before 2.4.12 does not verify that a PayPal payment not…● PoC 2026-09-04 CVE-2026-84045 MEDIUM 5.3 E Cab Taxi Booking Manager For Woocommerce — The E-cab Taxi Booking Manager for Woocommerce WordPress plugin before 2.0.5 does not validate a client-suppli…● PoC 2026-09-04 CVE-2026-84066 LOW 3.1 Directorist: Ai Powered Business Directory, Listings & Classified Ads — The Directorist: AI-Powered Business Directory, Listings & Classified Ads WordPress plugin before 8.9 does not…● PoC 2026-09-04 CVE-2026-84146 MEDIUM 5.3 Xpro Addons — 140+ Widgets For Elementor — The Xpro Addons — 140+ Widgets for Elementor WordPress plugin before 1.7.8 does not perform any capability or …● PoC 2026-09-04 CVE-2025-15691 MEDIUM 5.3 Wpfunnels — The WPFunnels WordPress plugin before 3.13.0 does not check whether user registration is enabled on the site …● PoC 2026-09-04 CVE-2026-10821 MEDIUM 6.6 Yoast Seo Premium — The Yoast SEO Premium WordPress plugin before 27.6.1 does not sanitize control characters from redirect origin…● PoC 2026-09-02 CVE-2026-12526 HIGH 8.1 Advanced Custom Fields: Extended — The Advanced Custom Fields: Extended WordPress plugin before 0.9.2.7 does not verify that the requester is aut…● PoC 2026-09-02 CVE-2026-12865 HIGH 7.1 Photo Gallery By 10web — The Photo Gallery by 10Web WordPress plugin before 1.8.44 does not escape two request parameters before refle…● PoC 2026-09-02 CVE-2026-14215 MEDIUM 6.5 Booking For Appointments And Events Calendar — The Booking for Appointments and Events Calendar WordPress plugin before 2.4.9 does not require authenticatio…● PoC 2026-09-02 CVE-2026-14326 LOW 3.8 Timetics — The Timetics WordPress plugin through 1.0.61 does not enforce per-object ownership when updating appointments …● PoC 2026-09-02 CVE-2026-15232 MEDIUM 5.3 Motopress Appointment Booking — The MotoPress Appointment Booking WordPress plugin before 2.4.8 does not perform an authorization or ownership…● PoC 2026-09-02 CVE-2026-16966 MEDIUM 5.3 Solace Extra — The Solace Extra WordPress plugin before 1.7.0 does not perform any authorization or post-status checks in one…● PoC 2026-09-02 CVE-2026-16983 MEDIUM 4.3 Gutentor — The Gutentor WordPress plugin before 4.0.6 does not apply the correct context restriction to one of its REST …● PoC 2026-09-02 CVE-2026-17563 MEDIUM 5.3 User Frontend — The User Frontend WordPress plugin before 4.3.11 does not enforce its subscription-purchase requirement when p…● PoC 2026-09-02 CVE-2026-19116 HIGH 8.8 User Frontend — The User Frontend WordPress plugin before 4.3.11 does not prevent user-supplied field values from being deser…● PoC 2026-09-02 CVE-2026-19251 MEDIUM 5.3 Ultimate Member — The Ultimate Member WordPress plugin before 2.13.0 does not check whether a comment has been approved, or whe…● PoC 2026-09-02 CVE-2026-19453 HIGH 7.1 Jetbackup — The JetBackup WordPress plugin before 3.1.23.5 does not verify the role or capabilities of the account it pre…● PoC 2026-09-02 CVE-2026-19698 LOW 3.5 Gutenkit — The GutenKit WordPress plugin before 2.5.1 does not validate or escape style settings saved against a post bef…● PoC 2026-09-02 CVE-2026-19704 MEDIUM 5.3 Comments — The Comments WordPress plugin before 7.6.66 does not validate a value used to build a database query, allowin…● PoC 2026-09-02 CVE-2026-19719 MEDIUM 6.8 Social Media Share Buttons & Social Sharing Icons — The Social Media Share Buttons & Social Sharing Icons WordPress plugin before 3.0.1 does not escape the post t…● PoC 2026-09-02 CVE-2026-19723 HIGH 7.1 Social Media Share Buttons & Social Sharing Icons — The Social Media Share Buttons & Social Sharing Icons WordPress plugin before 3.0.1 does not properly escape a…● PoC 2026-09-02 CVE-2026-2688 MEDIUM 6.5 Hipaa Forms — The HIPAA FORMS WordPress plugin before 3.2.0 contains a hardcoded authentication bypass via a hardcoded param…● PoC 2026-09-02 CVE-2026-2811 MEDIUM 5.4 Ajaxify Comments — The Ajaxify Comments WordPress plugin before 3.2 is vulnerable to HTTP Header Injection due to insufficient in…● PoC 2026-09-02 CVE-2026-4357 CRITICAL 10 Embed Html5 Game — The Embed HTML5 Game WordPress plugin through 1.3 does not properly restrict who can upload files via the plug…● PoC 2026-09-02 CVE-2026-74927 MEDIUM 5.3 Multivendorx — The MultiVendorX WordPress plugin before 5.0.15 does not have proper authorisation controls on one of its RES…● PoC 2026-09-02 CVE-2026-77009 CRITICAL 9.9 Watchman Site7 — The WatchMan-Site7 WordPress plugin through 4.2.0 does not restrict access to its debugging console, which exe…● PoC 2026-09-02 CVE-2026-77764 MEDIUM 4.3 Gamipress — The GamiPress WordPress plugin before 7.9.9.6 does not properly restrict its video watch-tracking functionali…● PoC 2026-09-02 CVE-2026-77782 MEDIUM 5.3 Rank Math Seo — The Rank Math SEO WordPress plugin before 1.0.277.1 does not check whether a post is password protected befor…● PoC 2026-09-02 CVE-2026-77783 LOW 3.7 Rank Math Seo — The Rank Math SEO WordPress plugin before 1.0.277 does not verify that the post whose schema it renders on th…● PoC 2026-09-02 CVE-2026-77784 LOW 2.7 Rank Math Seo — The Rank Math SEO WordPress plugin before 1.0.277 does not verify that a user is allowed to edit the object b…● PoC 2026-09-02 CVE-2026-77785 LOW 2.7 Rank Math Seo — The Rank Math SEO WordPress plugin before 1.0.277 does not verify that the requesting user is permitted to re…● PoC 2026-09-02 CVE-2026-77787 LOW 2.7 Rank Math Seo — The Rank Math SEO WordPress plugin before 1.0.277 does not perform a capability check when bulk metadata upda…● PoC 2026-09-02 CVE-2026-77788 MEDIUM 4.9 Rank Math Seo — The Rank Math SEO WordPress plugin before 1.0.277 does not verify that the metadata row being updated belongs…● PoC 2026-09-02 CVE-2026-77792 HIGH 7.5 Registrationmagic — The RegistrationMagic WordPress plugin before 6.0.9.9 does not escape a registration form field value before …● PoC 2026-09-02 CVE-2026-77793 MEDIUM 5.3 Registrationmagic — The RegistrationMagic WordPress plugin before 6.0.9.9 does not validate the total price of a paid registration…● PoC 2026-09-02 CVE-2026-77794 MEDIUM 5.3 Registrationmagic — The RegistrationMagic WordPress plugin before 6.0.9.9 does not validate a client-supplied quantity multiplier …● PoC 2026-09-02 CVE-2026-78151 MEDIUM 5.3 Formlayer — The FormLayer WordPress plugin before 1.0.9 does not perform any authorization check before returning a form's…● PoC 2026-09-02 CVE-2026-78153 MEDIUM 5.3 Restrict User Access — The Restrict User Access WordPress plugin before 2.8.1 does not normalise the REST API route before checking i…● PoC 2026-09-02 CVE-2026-79621 MEDIUM 4.3 Catalogx — The CatalogX WordPress plugin before 6.1.3 does not sanitise or escape content that an unauthenticated user c…● PoC 2026-09-02 CVE-2026-80467 HIGH 8.1 Advanced Custom Fields: Extended — The Advanced Custom Fields: Extended WordPress plugin before 0.9.2.7 does not restrict the role submitted thro…● PoC 2026-09-02 CVE-2026-81194 MEDIUM 4.3 Masterstudy Lms Wordpress Plugin — The MasterStudy LMS WordPress Plugin WordPress plugin before 3.7.46 does not properly verify authorization wh…● PoC 2026-09-02 CVE-2026-81195 MEDIUM 5.3 Masterstudy Lms Wordpress Plugin — The MasterStudy LMS WordPress Plugin WordPress plugin before 3.7.46 does not perform an authorization check b…● PoC 2026-09-02 CVE-2026-81196 LOW 2.7 Masterstudy Lms Wordpress Plugin — The MasterStudy LMS WordPress Plugin WordPress plugin before 3.7.46 does not properly verify ownership of qui…● PoC 2026-09-02 CVE-2026-81197 MEDIUM 5.3 Masterstudy Lms Wordpress Plugin — The MasterStudy LMS WordPress Plugin WordPress plugin before 3.7.46 does not restrict access to a REST route …● PoC 2026-09-02 CVE-2026-81198 LOW 3.8 Masterstudy Lms Wordpress Plugin — The MasterStudy LMS WordPress Plugin WordPress plugin before 3.7.46 does not properly verify ownership of a c…● PoC 2026-09-02 CVE-2026-81199 MEDIUM 5.3 Masterstudy Lms Wordpress Plugin — The MasterStudy LMS WordPress Plugin WordPress plugin before 3.7.46 does not perform an authorization check b…● PoC 2026-09-02 CVE-2026-81426 MEDIUM 4.3 Wc Vendors — The WC Vendors WordPress plugin before 2.7.2.1 does not have CSRF protection on some of its front-end order s…● PoC 2026-09-02 CVE-2026-81427 MEDIUM 4.3 Wc Vendors — The WC Vendors WordPress plugin before 2.7.2.1 does not verify that the vendor submitting a front-end order s…● PoC 2026-09-02 CVE-2026-81428 MEDIUM 6.5 Wc Vendors — The WC Vendors WordPress plugin before 2.7.2.1 does not verify ownership or the object type of user-supplied …● PoC 2026-09-02 CVE-2026-81432 MEDIUM 4.3 Jetstylemanager For Gutenberg — The JetStyleManager for Gutenberg WordPress plugin before 1.3.9 does not have CSRF protection on some of its A…● PoC 2026-09-02 CVE-2026-81571 MEDIUM 4.8 Brave — The Brave WordPress plugin before 0.8.8 does not prevent a URL parameter used to pre-fill a form field from be…● PoC 2026-09-02 CVE-2026-81583 MEDIUM 5.4 Theme My Login — The My Login WordPress plugin before 7.2.0 does not enforce the network's registration setting when processin…● PoC 2026-09-02 CVE-2026-81737 HIGH 8.8 Faq Builder Ays — The FAQ Builder AYS WordPress plugin before 1.8.5 does not sanitize or escape content submitted by unauthentic…● PoC 2026-09-02 CVE-2026-81807 HIGH 8.8 Simple Ajax Chat — The Simple Ajax Chat WordPress plugin before 20260827 does not escape chat message content before rendering i…● PoC 2026-09-02 CVE-2026-82182 MEDIUM 4.1 Wpvivid — Backup, Migration & Staging — The WPvivid — Backup, Migration & Staging WordPress plugin before 0.9.133 does not sanitise a user supplied li…● PoC 2026-09-02 CVE-2026-82183 HIGH 8.1 Oauth Single Sign On — The OAuth Single Sign On WordPress plugin before 7.0.1 does not verify the identity assertion returned by its…● PoC 2026-09-02 CVE-2026-82884 MEDIUM 6.8 All In One Seo — The All in One SEO WordPress plugin before 5.0.0.1 does not sanitise and escape some content stored in posts b…● PoC 2026-09-02 CVE-2026-83533 MEDIUM 5.3 Wp Express Checkout — The WP Express Checkout WordPress plugin before 2.4.9 does not verify server-side that a payment was actually …● PoC 2026-09-02 CVE-2026-83547 MEDIUM 6.8 Xpro Addons — The Xpro Addons WordPress plugin before 1.7.4 does not properly escape some of its widgets' settings before ou…● PoC 2026-09-02 CVE-2026-8151 MEDIUM 5.4 Simple Membership Mailchimp Integration — The Simple Membership MailChimp Integration WordPress plugin before 1.9.8 does not have CSRF checks in its set…● PoC 2026-09-02 CVE-2025-15481 MEDIUM 5.3 Notification Bar For Wordpress — The Notification Bar for WordPress plugin through 1.1.8 exposes an unauthenticated CSV export script that disc…● PoC 2026-09-02 CVE-2025-15485 HIGH 8.2 Auto X Line — The Auto x LINE WordPress plugin through 1.0.0 does not have authorization checks in some of its REST endpoint…● PoC 2026-09-02 CVE-2025-15489 MEDIUM 5.3 Passster — The Passster WordPress plugin before 4.2.24 does not handle input properly in an AJAX action, allowing unauthe…● PoC 2026-09-02 CVE-2025-15490 MEDIUM 5.3 Passster — The Passster WordPress plugin before 4.2.26 has a flaw in its global protection checks, allowing unauthenticat…● PoC 2026-09-02 CVE-2025-15663 MEDIUM 6.8 Ultimate Before After Image Slider & Gallery — The Ultimate Before After Image Slider & Gallery WordPress plugin before 4.7.19 does not properly escape the …● PoC 2026-09-02 CVE-2025-15664 MEDIUM 6.8 Ultimate Before After Image Slider & Gallery — The Ultimate Before After Image Slider & Gallery WordPress plugin before 4.7.19 does not properly escape the …● PoC 2026-09-02 CVE-2025-15692 LOW 3.5 Icegram Express — The Icegram Express WordPress plugin before 5.8.6 does not properly escape a list description setting before o…● PoC 2026-09-02 CVE-2025-8945 MEDIUM 5.3 Wp Edit Password Protected — The Wp Edit Password Protected WordPress plugin before 1.3.5 allows protecting page content, but this protecti…● PoC 2026-09-02 CVE-2025-9314 CRITICAL 9.8 Developer Tools — The Developer Tools WordPress plugin through 1.1.3 contains an unauthenticated arbitrary file upload vulnerabi…● PoC 2026-09-02 CVE-2026-13611 MEDIUM 5.3 Kivicare — The KiviCare WordPress plugin before 4.5.5 does not perform authorization checks on some of its REST endpoints…● PoC 2026-09-01 CVE-2026-74916 MEDIUM 6.5 Wp Fastest Cache — The WP Fastest Cache WordPress plugin before 1.5.1 does not include a set of tracking-related query parameters…● PoC 2026-09-01 CVE-2026-78363 MEDIUM 4.8 Mw Wp Form — The MW WP Form WordPress plugin before 5.1.5 does not prevent shortcodes in user-submitted values from being e…● PoC 2026-09-01 CVE-2026-77013 MEDIUM 5.3 爱采集数据采集和发布插件 — The 爱采集数据采集和发布插件 WordPress plugin through 1.0.0 does not restrict which of its handler methods a request may i…● PoC 2026-08-31 CVE-2026-14307 HIGH 7.1 Geotargetingwp — The geotargetingwp WordPress plugin before 3.5.6.2 does not sanitise or escape several parameters before refle…● PoC 2026-08-30 CVE-2026-14835 MEDIUM 6.8 Sogo Add Script To Individual Pages Header Footer — The SOGO Add Script to Individual Pages Header Footer WordPress plugin through 3.9 does not sanitise or escape…● PoC 2026-08-30 CVE-2026-19722 MEDIUM 6.6 Wpvivid — Backup, Migration & Staging — The WPvivid — Backup, Migration & Staging WordPress plugin before 0.9.133 does not validate the destination of…● PoC 2026-08-30 CVE-2026-76585 HIGH 8.8 Customer Reviews For Woocommerce — The Customer Reviews for WooCommerce WordPress plugin before 5.118.0 does not sanitise and escape the content …● PoC 2026-08-30 CVE-2026-78364 LOW 3.5 Mw Wp Form — The MW WP Form WordPress plugin before 5.1.6 does not sanitise and escape some of its form settings before out…● PoC 2026-08-30 CVE-2026-81660 HIGH 8.8 Groundhogg — Crm, Newsletters, And Marketing Automation — The Groundhogg — CRM, Newsletters, and Marketing Automation WordPress plugin before 4.5.13 does not validate o…● PoC 2026-08-30 CVE-2026-81766 MEDIUM 6.6 Really Simple Security — The Really Simple Security WordPress plugin before 9.8.0 does not check that the user is allowed to install R…● PoC 2026-08-30 CVE-2026-10522 CRITICAL 9.8 Memberhero — The MemberHero WordPress plugin through 6.9 does not restrict which account fields can be supplied during its…● PoC 2026-08-29 CVE-2026-16061 HIGH 8.6 Rest Routes — The Rest Routes WordPress plugin through 5.5.5 does not sanitize and validate a value taken from the URL of o…● PoC 2026-08-29 CVE-2026-16259 CRITICAL 9.8 Uix Usercenter — The Uix UserCenter WordPress plugin through 1.0.3 does not verify that the account being modified through an u…● PoC 2026-08-29 CVE-2026-16600 HIGH 7.7 Smartaipress — The SmartAIPress WordPress plugin through 1.2.0 does not perform a capability check on one of its AJAX actions…● PoC 2026-08-29 CVE-2026-16947 CRITICAL 9.1 Total Processing Card Payments For Woocommerce — The Total processing card payments for WooCommerce WordPress plugin through 7.3 does not validate a user-suppl…● PoC 2026-08-29 CVE-2026-17520 MEDIUM 4.8 Newsletters — The Newsletters WordPress plugin before 4.17 does not generate its API key using a sufficiently random source,…● PoC 2026-08-29 CVE-2026-17522 MEDIUM 5.4 Newsletters — The Newsletters WordPress plugin before 4.17 does not perform any nonce or capability check when saving one of…● PoC 2026-08-29 CVE-2026-18233 MEDIUM 6.5 Mstore Api — The MStore API WordPress plugin before 4.21.1 does not verify that the order targeted by one of its delivery …● PoC 2026-08-29 CVE-2026-18234 MEDIUM 6.5 Mstore Api — The MStore API WordPress plugin before 4.21.1 does not verify that the order targeted by its wallet payment h…● PoC 2026-08-29 CVE-2026-19430 MEDIUM 5.3 Catfolders Document Gallery Pro — The Catfolders Document Gallery Pro WordPress plugin before 2.0.7 does not authorise some of its REST API rout…● PoC 2026-08-29 CVE-2026-76546 MEDIUM 6.8 User Profile Builder — The User Profile Builder WordPress plugin before 4.0.1 does not escape the output of one of its optional shor…● PoC 2026-08-29 CVE-2026-76547 MEDIUM 6.6 User Profile Builder — The User Profile Builder WordPress plugin before 4.0.1 does not validate the type of data being deserialized …● PoC 2026-08-29 CVE-2026-76548 HIGH 8.2 User Profile Builder — The User Profile Builder WordPress plugin before 4.0.1 does not properly restrict its front-end file upload f…● PoC 2026-08-29 CVE-2026-76586 HIGH 7.5 Appointment Booking Calendar Plugin And Scheduling Plugin — The Appointment Booking Calendar Plugin and Scheduling Plugin WordPress plugin before 1.6.3 does not verify t…● PoC 2026-08-29 CVE-2026-77007 HIGH 7.5 Hel Online Classroom: Ai Powered Online Classrooms — The HEL Online Classroom: AI-powered Online Classrooms WordPress plugin through 1.0.3 does not perform any aut…● PoC 2026-08-29 CVE-2026-77008 MEDIUM 6.5 Hel Online Classroom: Ai Powered Online Classrooms — The HEL Online Classroom: AI-powered Online Classrooms WordPress plugin through 1.0.3 does not have any author…● PoC 2026-08-29 CVE-2026-77010 MEDIUM 6.5 Hel Online Classroom: Ai Powered Online Classrooms — The HEL Online Classroom: AI-powered Online Classrooms WordPress plugin through 1.0.3 does not perform authori…● PoC 2026-08-29 CVE-2026-77012 CRITICAL 9.3 爱采集数据采集和发布插件 — The 爱采集数据采集和发布插件 WordPress plugin through 1.0.0 does not require a per-install secret for one of its unauthent…● PoC 2026-08-29 CVE-2026-77704 LOW 2.7 Booking For Appointments And Events Calendar — The Booking for Appointments and Events Calendar WordPress plugin before 2.4.9 does not check that a user hol…● PoC 2026-08-29 CVE-2026-77786 MEDIUM 4.9 Rank Math Seo — The Rank Math SEO WordPress plugin before 1.0.277 does not check that the user requesting an automated SEO fi…● PoC 2026-08-29 CVE-2026-80311 MEDIUM 4.3 Stripe Payment Forms By Wp Full Pay — The Stripe Payment Forms by WP Full Pay WordPress plugin before 8.5.5 does not verify that a subscription bel…● PoC 2026-08-29 CVE-2026-80488 MEDIUM 4.1 Wp Ultimate Csv Importer — The WP Ultimate CSV Importer WordPress plugin before 9.0 does not properly sanitise and escape imported field…● PoC 2026-08-29 CVE-2026-81026 MEDIUM 4.8 Masterstudy Lms Wordpress Plugin — The MasterStudy LMS WordPress Plugin WordPress plugin before 3.7.40 does not verify the amount, receiver, cur…● PoC 2026-08-29 CVE-2026-81200 LOW 2.7 Masterstudy Lms Wordpress Plugin — The MasterStudy LMS WordPress Plugin WordPress plugin before 3.7.42 does not correctly restrict access to ord…● PoC 2026-08-29 CVE-2026-81342 MEDIUM 4.7 Masterstudy Lms Wordpress Plugin — The MasterStudy LMS WordPress Plugin WordPress plugin before 3.7.43 does not validate a redirect parameter su…● PoC 2026-08-29 CVE-2026-81346 MEDIUM 4.3 Frontend Admin By Dynamiapps — The Frontend Admin by DynamiApps WordPress plugin before 3.29.11 does not perform a capability check on one of…● PoC 2026-08-29 CVE-2026-12513 MEDIUM 6.8 Shared Files — The Shared Files WordPress plugin before 1.7.67, shared-files-pro WordPress plugin before 1.7.68 do not prope…● PoC 2026-08-28 CVE-2026-12514 MEDIUM 5.3 Shared Files — The Shared Files WordPress plugin before 1.7.67, shared-files-pro WordPress plugin before 1.7.70 do not perfo…● PoC 2026-08-28 CVE-2026-14558 HIGH 7.2 User Frontend — The User Frontend WordPress plugin before 4.3.10 does not properly validate field type definitions and deseri…● PoC 2026-08-28 CVE-2026-14567 MEDIUM 5.3 User Frontend — The User Frontend WordPress plugin before 4.3.10 does not restrict access to its user directory search endpoi…● PoC 2026-08-28 CVE-2026-19084 HIGH 7.5 Shared Files Pro — The shared-files-pro WordPress plugin before 1.7.70 does not validate the file path supplied when creating a f…● PoC 2026-08-28 CVE-2026-19423 HIGH 8.1 Ultimate Member — The Ultimate Member WordPress plugin before 2.13.0 does not validate a submitted role selection when it canno…● PoC 2026-08-28 CVE-2026-77701 MEDIUM 5.3 Wcfm Marketplace — The WCFM Marketplace WordPress plugin before 3.8.2 does not correctly verify that the person requesting a ref…● PoC 2026-08-28 CVE-2026-79615 LOW 2.7 Quiz And Survey Master (Qsm) — The Quiz and Survey Master (QSM) WordPress plugin before 11.2.4 does not check authorisation when returning q…● PoC 2026-08-28 CVE-2026-79706 MEDIUM 5.3 Breeze Cache — The Breeze Cache WordPress plugin before 2.5.13 does not sanitise a value taken from the request before using …● PoC 2026-08-28 CVE-2026-79995 MEDIUM 4.3 User Registration & Membership — The User Registration & Membership WordPress plugin before 5.2.5 does not verify that the account whose pendi…● PoC 2026-08-28 CVE-2026-79996 HIGH 7.2 User Registration & Membership — The User Registration & Membership WordPress plugin before 5.2.6 does not perform a capability check when sav…● PoC 2026-08-28 CVE-2026-13414 MEDIUM 4.8 Cmp — The CMP WordPress plugin before 4.1.18 does not perform authorization checks on one of its AJAX actions and r…● PoC 2026-08-27 CVE-2026-13415 HIGH 7.2 Cmp — The CMP WordPress plugin before 4.1.18 does not enforce an option-name allow-list when importing settings via…● PoC 2026-08-27 CVE-2026-13416 LOW 3.5 Cmp — The CMP WordPress plugin before 4.1.18 does not sanitise and escape a settings value before outputting it on …● PoC 2026-08-27 CVE-2026-16567 MEDIUM 5.3 Document Embedder — The Document Embedder WordPress plugin before 2.3.1 does not check a document's status before issuing a downl…● PoC 2026-08-27 CVE-2026-16568 MEDIUM 4.3 Mobile App For Woocommerce: Shopapper Mobile App Builder Service For Woocommerce — The Mobile App for WooCommerce: ShopApper Mobile App Builder Service for WooCommerce WordPress plugin through …● PoC 2026-08-27 CVE-2026-16569 MEDIUM 4.3 Mobile App For Woocommerce: Shopapper Mobile App Builder Service For Woocommerce — The Mobile App for WooCommerce: ShopApper Mobile App Builder Service for WooCommerce WordPress plugin through …● PoC 2026-08-27 CVE-2026-19092 CRITICAL 9.8 Tutor Lms — The Tutor LMS WordPress plugin before 4.0.6 does not prevent request data from overwriting internal variables …● PoC 2026-08-27 CVE-2026-19223 HIGH 7.2 Smush — The Smush WordPress plugin before 4.3.2 does not restrict a network-wide setting to network administrators, a…● PoC 2026-08-27 CVE-2026-19225 MEDIUM 6.6 Defender Security — The Defender Security WordPress plugin before 6.2.0 does not restrict a network-wide setting to network admin…● PoC 2026-08-27 CVE-2026-19454 MEDIUM 4.4 Jetbackup — The JetBackup WordPress plugin before 3.1.23.5 does not perform its multisite authorisation check before serv…● PoC 2026-08-27 CVE-2026-19715 HIGH 7.5 Wp Oauth Server ( Login With Wordpress ) — The WP OAuth Server ( Login with WordPress ) WordPress plugin before 6.3.1 does not restrict access to the deb…● PoC 2026-08-27 CVE-2026-74232 CRITICAL 9.3 L3 V2 8 — Zbtlink L3_V2_8 firmware 3.0.0.4.528, Zbtlink WE826-T2 firmware 19.1101, Zbtlink ZBT-7628 firmware 1.0.0.2.007…● PoC 2026-08-27 CVE-2026-74233 CRITICAL 9.3 We1326 — Zbtlink WE1326, WE357, WE5926, WE5926-WD, WE826-Q, WE826-T2, WE826-WD, WG108, and WG3526 firmware 19.1101, Zbt…● PoC 2026-08-27 CVE-2026-76549 MEDIUM 5.9 Updraftplus: Wp Backup & Migration Plugin — The UpdraftPlus: WP Backup & Migration Plugin WordPress plugin before 1.26.7 does not have CSRF checks in one …● PoC 2026-08-27 CVE-2026-77016 CRITICAL 9.6 Workeera — The Workeera WordPress plugin before 1.0.6 does not restrict which values may be written to a user's own cand…● PoC 2026-08-27 CVE-2026-77017 HIGH 7.7 Workeera — The Workeera WordPress plugin before 1.0.6 does not restrict which profile values a candidate may submit, nor…● PoC 2026-08-27 CVE-2026-77018 HIGH 8.8 Workeera — The Workeera WordPress plugin before 1.0.6 does not restrict which profile values a candidate may submit, nor…● PoC 2026-08-27 CVE-2026-78125 MEDIUM 5.3 Learnpress — The LearnPress WordPress plugin before 4.0.3 does not perform any authorization check on one of its REST endp…● PoC 2026-08-27 CVE-2026-78137 HIGH 7.5 Storegrowth — The StoreGrowth WordPress plugin before 2.1.2 does not validate a browser-supplied product price on two of it…● PoC 2026-08-27 CVE-2026-78138 MEDIUM 4.3 Finale Lite — The Finale Lite WordPress plugin before 2.21.0 does not perform a capability check on an AJAX action that ret…● PoC 2026-08-27 CVE-2026-78139 MEDIUM 4.3 Notifima — The Notifima WordPress plugin before 3.1.4 does not verify that the caller owns the subscription being modifi…● PoC 2026-08-27 CVE-2026-78333 HIGH 8.8 12 Step Meeting List — The 12 Step Meeting List WordPress plugin before 3.19.17 does not sanitise and escape a value submitted by una…● PoC 2026-08-27 CVE-2026-13172 MEDIUM 5.3 Eventin — The Eventin WordPress plugin before 4.1.22 does not restrict access to non-published content by status or own…● PoC 2026-08-26 CVE-2026-13404 MEDIUM 5.3 Royal Addons For Elementor — The Royal Addons for Elementor WordPress plugin before 1.7.1066 does not perform any capability or ownership …● PoC 2026-08-26 CVE-2026-13406 MEDIUM 5.3 Royal Addons For Elementor — The Royal Addons for Elementor WordPress plugin before 1.7.1066 does not perform any capability or nonce chec…● PoC 2026-08-26 CVE-2026-14212 MEDIUM 4.7 Booking For Appointments And Events Calendar — The Booking for Appointments and Events Calendar WordPress plugin before 9.8 does not verify that an authenti…● PoC 2026-08-26 CVE-2026-14216 MEDIUM 6.5 Booking For Appointments And Events Calendar — The Booking for Appointments and Events Calendar WordPress plugin before 2.4.7 does not require authenticatio…● PoC 2026-08-26 CVE-2026-14550 MEDIUM 5.3 Wpcafe — The WPCafe WordPress plugin before 3.0.18 does not perform an authorization check when creating a reservation…● PoC 2026-08-26 CVE-2026-16984 MEDIUM 6.5 Privacy Policy Generator, Terms & Conditions, Gdpr, Ccpa, Cookie Policy & Disclaimer Templates — The Privacy Policy Generator, Terms & Conditions, GDPR, CCPA, Cookie Policy & Disclaimer Templates WordPress …● PoC 2026-08-26 CVE-2026-16986 MEDIUM 5.3 Booking Package — The Booking Package WordPress plugin before 1.7.25 does not validate the payment amount server-side against th…● PoC 2026-08-26 CVE-2026-19094 MEDIUM 5.3 Tutor Lms — The Tutor LMS WordPress plugin before 4.0.6 does not validate values used to build a database query, and does…● PoC 2026-08-26 CVE-2026-19220 LOW 3.7 Forminator Forms — The Forminator Forms WordPress plugin before 1.57.1 does not verify that site registration is enabled on the …● PoC 2026-08-26 CVE-2026-19226 MEDIUM 6.8 Royal Addons For Elementor — The Royal Addons for Elementor WordPress plugin before 1.7.1066 does not validate some widget settings before…● PoC 2026-08-26 CVE-2026-19718 HIGH 8.1 Blogvault Backup & Staging — The BlogVault Backup & Staging WordPress plugin before 6.65, MalCare WordPress Security Plugin WordPress plug…● PoC 2026-08-26 CVE-2026-74851 HIGH 7.2 Pods — The Pods WordPress plugin before 3.3.9.1 does not correctly compare a display callback against its list of bl…● PoC 2026-08-26 CVE-2026-74928 HIGH 7.5 Project Manager — The Project Manager WordPress plugin before 4.0.7 does not have any authorisation check on its import routes,…● PoC 2026-08-26 CVE-2026-74929 MEDIUM 5.4 Project Manager — The Project Manager WordPress plugin before 4.0.7 does not restrict several of its REST API routes to the pro…● PoC 2026-08-26 CVE-2026-74930 MEDIUM 4.3 Project Manager — The Project Manager WordPress plugin before 4.0.7 does not check that the user whose activity is being reques…● PoC 2026-08-26 CVE-2026-75797 HIGH 7.7 Ai Engine — The AI Engine WordPress plugin before 3.7.2 does not confine a caller-supplied URL when mapping it to a local…● PoC 2026-08-26 CVE-2026-75798 MEDIUM 5.3 Ai Engine — The AI Engine WordPress plugin before 3.7.2 does not perform an authorisation check on one of its administrat…● PoC 2026-08-26 CVE-2026-77693 HIGH 8.7 Order Tip For Woocommerce — The Order Tip for WooCommerce WordPress plugin before 1.6.0 does not check the capability of the user requesti…● PoC 2026-08-26 CVE-2026-77694 MEDIUM 5.3 Eventin — The Eventin WordPress plugin before 4.1.19 does not properly restrict which changes a guest checkout token is…● PoC 2026-08-26 CVE-2026-77695 MEDIUM 6.5 Return Refund And Exchange For Woocommerce — The Return Refund and Exchange For WooCommerce WordPress plugin before 4.6.4 does not correctly verify the own…● PoC 2026-08-26 CVE-2026-77754 MEDIUM 5.3 Kirki — The Kirki WordPress plugin before 6.0.14 does not perform a capability check on some endpoints of one of its …● PoC 2026-08-26 CVE-2026-77757 MEDIUM 5.4 Directorist: Ai Powered Business Directory, Listings & Classified Ads — The Directorist: AI-Powered Business Directory, Listings & Classified Ads WordPress plugin before 8.9.3 does n…● PoC 2026-08-26 CVE-2026-77758 MEDIUM 5.3 Stripe Payment Forms By Wp Full Pay — The Stripe Payment Forms by WP Full Pay WordPress plugin before 8.5.1 does not properly verify that a custome…● PoC 2026-08-26 CVE-2026-77789 MEDIUM 4.3 Stripe Payment Forms By Wp Full Pay — The Stripe Payment Forms by WP Full Pay WordPress plugin before 8.5.1 does not verify that a subscription bel…● PoC 2026-08-26 CVE-2026-77790 MEDIUM 5.5 Registrationmagic — The RegistrationMagic WordPress plugin before 6.0.9.4 does not sanitise and escape a parameter before using i…● PoC 2026-08-26 CVE-2026-78146 MEDIUM 6.5 Simple Newsletter Plugin — The Simple Newsletter Plugin WordPress plugin before 4.3.3 does not verify that the requester is the subscrib…● PoC 2026-08-26 CVE-2026-74932 HIGH 7.5 Wp Fastest Cache — The WP Fastest Cache WordPress plugin before 1.5.1 does not validate the Host header before using it to build …● PoC 2026-08-25 CVE-2026-13598 CRITICAL 9.8 Restrictmate — The RestrictMate WordPress plugin before 1.3.0 does not restrict the user role supplied during account regist…● PoC 2026-08-23 CVE-2026-14853 MEDIUM 4.3 Woocommerce Bookings — The WooCommerce Bookings WordPress plugin before 3.9.0 does not perform a capability check on one of its AJAX …● PoC 2026-08-23 CVE-2026-77003 LOW 2.7 Content Mask — The Content Mask WordPress plugin before 1.8.5.5 does not check the capability required to publish the post ty…● PoC 2026-08-23 CVE-2026-77115 HIGH 7.1 Brave — Brave Popup Builder (brave-popup-builder) up to version 0.8.5 reflects UTM query parameters into popup form HT…● PoC 2026-08-23 CVE-2026-77116 MEDIUM 4.3 Brave — Brave Popup Builder (slug: brave-popup-builder) has a broken access control issue in versions through 0.8.5. A…● PoC 2026-08-23 CVE-2026-14187 LOW 2.7 Tutor Lms — The Tutor LMS WordPress plugin before 4.0.6 does not enforce per-object ownership checks on its course conten…● PoC 2026-08-22 CVE-2026-16260 MEDIUM 6.8 Post Grid, Slider & Carousel Ultimate — The Post Grid, Slider & Carousel Ultimate WordPress plugin before 1.8.1 does not sanitise and escape one of i…● PoC 2026-08-22 CVE-2026-16612 MEDIUM 5.3 Fibosearch — The FiboSearch WordPress plugin before 1.34.1 does not consistently exclude password-protected products from …● PoC 2026-08-22 CVE-2026-16738 MEDIUM 5.3 Conekta Payment Gateway — The Conekta Payment Gateway WordPress plugin before 6.2.2 does not verify the authenticity of incoming payment…● PoC 2026-08-22 CVE-2026-18052 HIGH 8.1 Managewp Worker — The ManageWP Worker WordPress plugin before 4.9.37 does not bind the account being logged in to the signature …● PoC 2026-08-22 CVE-2026-19093 MEDIUM 6.8 Tutor Lms — The Tutor LMS WordPress plugin before 4.0.6 does not validate a stored file path before using it to stream me…● PoC 2026-08-22 CVE-2026-19221 HIGH 7.2 Forminator Forms — The Forminator Forms WordPress plugin before 1.57.0.5 does not restrict a network-wide setting to network adm…● PoC 2026-08-22 CVE-2026-19222 MEDIUM 6.6 Forminator Forms — The Forminator Forms WordPress plugin before 1.57.0.7 does not consistently enforce the role restriction it a…● PoC 2026-08-22 CVE-2026-76789 HIGH 8.8 Slider Hero With Video Background, Animation — The Slider Hero with Video Background, Animation WordPress plugin before 9.1.3 does not have authorisation and…● PoC 2026-08-22 CVE-2026-76793 HIGH 8.1 Firebase Authentication — The Firebase Authentication WordPress plugin before 1.7.1 does not require the email address in an authenticat…● PoC 2026-08-22 CVE-2026-77000 CRITICAL 9.8 Wp Social Media Login — The WP Social Media Login WordPress plugin through 1.0.6 does not verify that a social login was actually comp…● PoC 2026-08-22 CVE-2026-77001 CRITICAL 9.8 Social Login & Sharing Buttons With Analytics By Soclever — The Social Login & Sharing buttons with Analytics By SoClever WordPress plugin through 1.2.0 does not perform …● PoC 2026-08-22 CVE-2026-77002 CRITICAL 9.8 Smilepass Selfie Login — The SmilePass Selfie Login WordPress plugin through 1.0.2 does not perform any server-side verification of the…● PoC 2026-08-22 CVE-2026-13176 LOW 2.7 Eventin — The Eventin WordPress plugin before 4.1.21 does not validate a user-supplied webhook URL stored on events nor …● PoC 2026-08-21 CVE-2026-13736 MEDIUM 5.3 Newpath Wildapricotpress Add On — The NewPath WildApricotPress Add-on WordPress plugin through 1.0.0 does not enforce its members-only field pr…● PoC 2026-08-21 CVE-2026-14325 LOW 3.5 Drag And Drop Multiple File Upload For Contact Form 7 — The Drag and Drop Multiple File Upload for Contact Form 7 WordPress plugin before 1.3.9.9 does not escape one …● PoC 2026-08-21 CVE-2026-14601 MEDIUM 6.8 Link Whisper Free — The Link Whisper Free WordPress plugin before 0.9.7 does not properly sanitize and escape a parameter before u…● PoC 2026-08-21 CVE-2026-15046 MEDIUM 4.2 Litextension — The LitExtension WordPress plugin through 1.2.5 does not verify a nonce before an administrative action that o…● PoC 2026-08-21 CVE-2026-15150 MEDIUM 5.3 Mycred — The myCred WordPress plugin before 3.2.5 does not verify that the receiver of an incoming payment gateway noti…● PoC 2026-08-21 CVE-2026-16575 MEDIUM 5.3 Dokan: Ai Powered Woocommerce Multivendor Marketplace Solution — The Dokan: AI Powered WooCommerce Multivendor Marketplace Solution WordPress plugin before 5.0.14 does not re…● PoC 2026-08-21 CVE-2026-16576 HIGH 7.2 Dokan: Ai Powered Woocommerce Multivendor Marketplace Solution — The Dokan: AI Powered WooCommerce Multivendor Marketplace Solution WordPress plugin before 5.0.14 does not co…● PoC 2026-08-21 CVE-2026-16577 LOW 2.7 Dokan: Ai Powered Woocommerce Multivendor Marketplace Solution — The Dokan: AI Powered WooCommerce Multivendor Marketplace Solution WordPress plugin before 5.0.14 does not va…● PoC 2026-08-21 CVE-2026-16650 MEDIUM 5.3 Charitable — The Charitable WordPress plugin before 1.8.12 does not verify the authenticity of incoming Square payment webh…● PoC 2026-08-21 CVE-2026-16959 MEDIUM 6.8 Media Library Assistant — The Media Library Assistant WordPress plugin before 3.40 does not validate a search parameter before concatena…● PoC 2026-08-21 CVE-2026-16962 MEDIUM 5.3 Tamara Checkout — The Tamara Checkout WordPress plugin through 1.9.9.20 does not verify the order key, a nonce, or any capabilit…● PoC 2026-08-21 CVE-2026-17559 MEDIUM 5.3 Passster — The Passster WordPress plugin before 4.3.9 does not correctly match its own public endpoint paths when decidin…● PoC 2026-08-21 CVE-2026-18356 LOW 3.7 Limit Login Attempts Security — The Limit Login Attempts Reloaded WordPress plugin before 3.3.5 does not compare logins against its username d…● PoC 2026-08-21 CVE-2026-18781 HIGH 8.1 Drag And Drop Multiple File Upload For Contact Form 7 — The Drag and Drop Multiple File Upload for Contact Form 7 WordPress plugin before 1.3.9.9 does not validate th…● PoC 2026-08-21 CVE-2026-19085 LOW 2.7 Duplicate Post — The Duplicate Post WordPress plugin before 1.5.6 does not check that a user may read the content of a post bef…● PoC 2026-08-21 CVE-2026-19435 LOW 2.7 Duplicate Post — The Duplicate Post WordPress plugin before 1.5.6 does not check the user's capabilities before returning post …● PoC 2026-08-21 CVE-2026-19848 MEDIUM 6.5 Profilepress — The ProfilePress WordPress plugin before 4.17.1 does not strip shortcodes from two of its profile fields befor…● PoC 2026-08-21 CVE-2026-75796 HIGH 7.2 Ai Engine — The AI Engine WordPress plugin before 3.6.1 does not verify that the requesting user is authorized to act on …● PoC 2026-08-21 CVE-2025-15671 MEDIUM 5.4 Welcart E Commerce — The Welcart e-Commerce WordPress plugin before 2.12.1 does not regenerate the session identifier on authentica…● PoC 2026-08-21 CVE-2026-13405 MEDIUM 6.6 Royal Addons For Elementor — The Royal Addons for Elementor WordPress plugin before 1.7.1066 does not correctly sanitise custom widget mar…● PoC 2026-08-20 CVE-2026-15049 HIGH 7.2 Depicter — Popup & Slider Builder — The Depicter — Popup & Slider Builder WordPress plugin before 4.8.0 does not validate the type of a file uploa…● PoC 2026-08-20 CVE-2026-19615 MEDIUM 6.8 Admin And Site Enhancements (Ase) — The Admin and Site Enhancements (ASE) WordPress plugin before 9.0.1 does not sanitise uploaded SVG files on ev…● PoC 2026-08-20 CVE-2026-19697 MEDIUM 6.8 Gutenkit — The GutenKit WordPress plugin before 2.5.0 does not sanitise uploaded SVG files on all of the upload paths it…● PoC 2026-08-20 CVE-2026-19699 LOW 2.7 Gutenkit — The GutenKit WordPress plugin before 2.5.0 does not have a sufficient capability check on some of its REST AP…● PoC 2026-08-20 CVE-2026-74992 MEDIUM 6.8 Kirki — The Kirki WordPress plugin before 6.2.3 does not properly validate the files contained in archives uploaded b…● PoC 2026-08-20 CVE-2026-75860 CRITICAL 9.8 Json Options — The JSON Options WordPress plugin through 0.0.4 does not have any capability check or nonce verification on on…● PoC 2026-08-20 CVE-2026-11565 HIGH 8.5 Advanced File Manager — The Advanced File Manager WordPress plugin before 5.4.13 does not perform capability checks in several of its…● PoC 2026-08-19 CVE-2026-12983 HIGH 8.6 Dinatur — The Dinatur WordPress plugin through 1.18 does not sanitize and escape user input before using it in a SQL que…● PoC 2026-08-19 CVE-2026-13169 HIGH 8.1 Eventin — The Eventin WordPress plugin before 4.1.21 does not properly verify ownership of events before allowing them …● PoC 2026-08-19 CVE-2026-13173 LOW 2.7 Eventin — The Eventin WordPress plugin before 4.1.21 does not verify the current user's permission to edit other users …● PoC 2026-08-19 CVE-2026-13174 HIGH 7.2 Eventin — The Eventin WordPress plugin before 4.1.21 does not verify ownership or capability before deleting user accou…● PoC 2026-08-19 CVE-2026-13175 MEDIUM 6.5 Eventin — The Eventin WordPress plugin before 4.1.21 does not verify ownership before allowing schedule records to be m…● PoC 2026-08-19 CVE-2026-14196 MEDIUM 4.3 Wcfm Marketplace — The WCFM Marketplace WordPress plugin before 3.8.1 does not verify that a marketplace vendor owns a review be…● PoC 2026-08-19 CVE-2026-14287 MEDIUM 4.7 10web Booster — The 10Web Booster WordPress plugin before 2.33.5 does not correctly validate an access token on an unauthenti…● PoC 2026-08-19 CVE-2026-14334 HIGH 8.8 Booking Calendar, Appointment Booking System — The Booking calendar, Appointment Booking System WordPress plugin through 3.2.36 does not properly sanitize up…● PoC 2026-08-19 CVE-2026-14825 LOW 2.7 Quiz And Survey Master (Qsm) — The Quiz and Survey Master (QSM) WordPress plugin before 11.2.4 does not perform a per-object ownership check…● PoC 2026-08-19 CVE-2026-14826 LOW 2.7 Quiz And Survey Master (Qsm) — The Quiz and Survey Master (QSM) WordPress plugin before 11.2.4 does not perform a per-object ownership check…● PoC 2026-08-19 CVE-2026-14861 HIGH 7.5 User Verification By Pickplugins — The User Verification by PickPlugins WordPress plugin through 2.0.47 does not verify that a request to resend …● PoC 2026-08-19 CVE-2026-15253 MEDIUM 6.8 Easy Media Replace — The Easy Media Replace WordPress plugin through 0.2.0 does not sanitise and escape an attachment title before …● PoC 2026-08-19 CVE-2026-16058 MEDIUM 5.3 Yaycurrency — The YayCurrency WordPress plugin before 3.3.5 does not perform any capability or ownership check on several o…● PoC 2026-08-19 CVE-2026-16570 HIGH 7.1 Nextscripts: Social Networks Auto Poster — The NextScripts: Social Networks Auto-Poster WordPress plugin before 4.4.8 does not escape some of the query-s…● PoC 2026-08-19 CVE-2026-16616 HIGH 8.6 Simple File List — The Simple File List WordPress plugin through 6.3.11 does not validate the source path of a file-move operatio…● PoC 2026-08-19 CVE-2026-16617 HIGH 8.8 Simple File List — The Simple File List WordPress plugin through 6.3.11 does not properly sanitise and escape a file's descriptio…● PoC 2026-08-19 CVE-2026-16950 HIGH 8.6 Product Shortlist — The Product Shortlist WordPress plugin through 1.0.4 does not properly sanitise and escape a parameter before …● PoC 2026-08-19 CVE-2026-16979 MEDIUM 4.3 Smartcrawl Seo Checker, Analyzer & Optimizer — The SmartCrawl SEO checker, analyzer & optimizer WordPress plugin before 3.16.3 does not perform capability ch…● PoC 2026-08-19 CVE-2026-17565 HIGH 7.2 Animation Addons For Elementor — The Animation Addons for Elementor WordPress plugin before 2.7.2 does not validate a user-supplied value befo…● PoC 2026-08-19 CVE-2026-18031 CRITICAL 9.8 Tabapay Gateway — The TabaPay Gateway WordPress plugin through 1.4.0 does not validate the payment callback before establishing …● PoC 2026-08-19 CVE-2026-18051 CRITICAL 10 W3 Total Cache — The W3 Total Cache WordPress plugin before 2.10.5 does not properly validate the request path it uses to build…● PoC 2026-08-19 CVE-2026-18202 MEDIUM 6.8 Jetengine — The JetEngine WordPress plugin before 3.8.14 adds SVG to the site-wide list of allowed upload types without sa…● PoC 2026-08-19 CVE-2026-18231 MEDIUM 5.3 Wp Directory Kit — The WP Directory Kit WordPress plugin before 1.5.7 does not perform any authorization check on one of its publ…● PoC 2026-08-19 CVE-2026-18466 MEDIUM 5.4 Wp Maps — The WP Maps WordPress plugin before 4.9.8 does not perform a capability check, nor validate a nonce, in one o…● PoC 2026-08-19 CVE-2026-18776 CRITICAL 9.8 Truebooker — The TrueBooker WordPress plugin before 1.2.7 does not have proper authorisation checks in some of its AJAX ac…● PoC 2026-08-19 CVE-2026-18777 MEDIUM 5.3 Truebooker — The TrueBooker WordPress plugin before 1.2.7 does not have proper authorisation checks in one of its AJAX act…● PoC 2026-08-19 CVE-2026-18778 MEDIUM 5.3 Truebooker — The TrueBooker WordPress plugin before 1.2.7 does not have proper authorisation checks in some of its AJAX ac…● PoC 2026-08-19 CVE-2026-18779 MEDIUM 5.3 Truebooker — The TrueBooker WordPress plugin before 1.2.7 does not have proper authorisation checks in one of its AJAX act…● PoC 2026-08-19 CVE-2026-18937 CRITICAL 9 Broken Link Checker — The Broken Link Checker WordPress plugin before 2.4.12 does not limit which query variables it accepts from us…● PoC 2026-08-19 CVE-2026-19055 HIGH 7.1 Prosolution Wp Client — The ProSolution WP Client WordPress plugin before 2.0.11 does not sanitise and escape several parameters befor…● PoC 2026-08-19 CVE-2026-19056 HIGH 7.1 Prosolution Wp Client — The ProSolution WP Client WordPress plugin before 2.0.11 does not sanitise and escape a parameter before refle…● PoC 2026-08-19 CVE-2026-19406 LOW 2.7 Easy Appointments — The Easy Appointments WordPress plugin before 4.0.1 does not restrict one of its appointment-listing REST endp…● PoC 2026-08-19 CVE-2026-19416 MEDIUM 4.3 Kivicare — The KiviCare WordPress plugin before 4.5.4 does not verify that the requesting user owns the appointment bein…● PoC 2026-08-19 CVE-2026-19417 MEDIUM 6.5 Kivicare — The KiviCare WordPress plugin before 4.5.4 does not verify that the requesting user is entitled to the media …● PoC 2026-08-19 CVE-2026-19709 MEDIUM 5.3 Membership For Woocommerce — The Membership For WooCommerce WordPress plugin before 3.1.2 does not check that an API consumer secret has ac…● PoC 2026-08-19 CVE-2026-19782 MEDIUM 5.4 Wps Bidouille — The WPS Bidouille WordPress plugin before 1.33.5 does not have proper authorisation checks in an AJAX action, …● PoC 2026-08-19 CVE-2026-19842 HIGH 8.8 Saml Single Sign On — The SAML Single Sign On WordPress plugin before 5.4.7 does not verify the signature of a SAML response before…● PoC 2026-08-19 CVE-2026-13700 MEDIUM 5.9 Wooms — The WooMS WordPress plugin through 9.14 does not validate a user-supplied URL before using it in a server-side…● PoC 2026-08-17 CVE-2026-14832 MEDIUM 5.3 Shopsmart Loyalty For Woocommerce — The ShopSmart Loyalty for WooCommerce WordPress plugin through 1.0.0 does not perform any authorization or own…● PoC 2026-08-17