Unknown
153 CVEsCVE IDSeverityProduct / summaryPublished
CVE-2026-12968
N/A
Product Addons And Product Options With Custom Fields — The Product Addons and Product Options With Custom Fields WordPress plugin before 1.6.15 does not restrict an…● PoC
2026-07-22
CVE-2026-12987
N/A
Events Manager — The Events Manager WordPress plugin before 7.3.7 does not safely handle booking-registration data on sites us…● PoC
2026-07-22
CVE-2026-14322
N/A
Timetics — The Timetics WordPress plugin before 1.0.57 does not enforce a pending or unpaid status for new bookings crea…● PoC
2026-07-22
CVE-2026-11767
HIGH 8.8
Free Theme Builder For Elementor — The Free Builder for Elementor WordPress plugin before 1.6.7 does not sanitise submitted contact form field …● PoC
2026-07-21
CVE-2026-13693
MEDIUM 5.9
Bit Form — The Bit Form WordPress plugin before 3.1.0 does not restrict a form file-field value to a safe path before re…● PoC
2026-07-21
CVE-2026-13694
MEDIUM 6.5
Bit Form — The Bit Form WordPress plugin before 3.1.0 does not properly validate its workflow-trigger token once the ass…● PoC
2026-07-21
CVE-2026-14183
MEDIUM 4.3
Classified Listing — The Classified Listing WordPress plugin before 5.3.9 does not verify that the order targeted by its payment-r…● PoC
2026-07-21
CVE-2026-14184
MEDIUM 5.4
Academy Lms — The Academy LMS WordPress plugin before 3.8.1 does not verify ownership of a user-supplied user identifier in …● PoC
2026-07-21
CVE-2026-14185
MEDIUM 4.3
Wpbot — The WPBot WordPress plugin before 8.2.0 does not perform a capability or nonce check in one of its retrieval-…● PoC
2026-07-21
CVE-2026-8082
HIGH 7.5
Bpost Shipping Platform — The bpost-shipping-platform WordPress plugin before 3.2.3 does not properly sanitize a parameter before using …● PoC
2026-07-21
CVE-2026-10081
HIGH 8.8
Unlimited Elements For Elementor — The Unlimited Elements For Elementor WordPress plugin before 2.0.11 does not sanitize or escape Google review …● PoC
2026-07-20
CVE-2026-10724
MEDIUM 4.8
Reviews Feed — The Reviews Feed WordPress plugin before 2.6.5 does not neutralize WordPress shortcodes contained in third-pa…● PoC
2026-07-20
CVE-2026-10755
LOW 2.7
All In One Seo — The All in One SEO WordPress plugin before 4.9.9 does not correctly restrict access to some of its AI integra…● PoC
2026-07-20
CVE-2026-11349
HIGH 8.6
Modern Event Calendar Pro — The Modern Event Calendar Pro WordPress plugin before 7.34.0, Modern Events Calendar Lite WordPress plugin bef…● PoC
2026-07-20
CVE-2026-11868
MEDIUM 5.3
Wp Travel — The WP Travel WordPress plugin before 11.7.1 does not perform capability or ownership checks on its booking c…● PoC
2026-07-20
CVE-2026-12592
HIGH 7.5
Slimstat Analytics — The SlimStat Analytics WordPress plugin before 5.5.0 does not escape a visitor-controlled geolocation value be…● PoC
2026-07-20
CVE-2026-12723
MEDIUM 5.3
Kirki — The Kirki WordPress plugin before 6.0.12 does not perform any authorisation check on one of its REST routes, …● PoC
2026-07-20
CVE-2026-12724
MEDIUM 4.3
Kirki — The Kirki WordPress plugin before 6.0.12 does not sanitise or escape the email subject and body values suppli…● PoC
2026-07-20
CVE-2026-12898
MEDIUM 6.5
All In One Wp Migration And Backup — The All-in-One WP Migration and Backup WordPress plugin before 7.106 does not properly sanitise a user-supplie…● PoC
2026-07-20
CVE-2026-12970
HIGH 7.1
Learnpress — The LearnPress WordPress plugin before 4.4.1 does not escape a search parameter before reflecting it into an …● PoC
2026-07-20
CVE-2026-12972
MEDIUM 5.3
Payplus Payment Gateway — The PayPlus Payment Gateway WordPress plugin before 8.2.2 does not perform authorization or order-ownership va…● PoC
2026-07-20
CVE-2026-12973
MEDIUM 6.5
Payplus Payment Gateway — The PayPlus Payment Gateway WordPress plugin before 8.2.2 does not perform authorization or order-ownership va…● PoC
2026-07-20
CVE-2026-13142
HIGH 8.1
Social Login, Passkeys, Magic Link & Email Otp — The Social Login, Passkeys, Magic Link & Email OTP WordPress plugin before 1.4.1 does not enforce rate limiti…● PoC
2026-07-20
CVE-2026-13147
CRITICAL 9.1
Kirki — The Kirki WordPress plugin before 6.0.12 does not validate a user-supplied URL before requesting it server-si…● PoC
2026-07-20
CVE-2026-13156
MEDIUM 5.4
Mailersend — The MailerSend WordPress plugin before 1.0.8 does not perform a nonce check on its configuration-delete actio…● PoC
2026-07-20
CVE-2026-13432
MEDIUM 5.4
Thumbpress — The ThumbPress WordPress plugin before 6.2.2 does not perform a capability check on one of its AJAX actions, …● PoC
2026-07-20
CVE-2026-8825
MEDIUM 4.9
Elementor Website Builder — The Elementor Website Builder WordPress plugin before 4.1.4 does not properly check user permissions before r…● PoC
2026-07-20
CVE-2026-9833
HIGH 7.1
Tag Groups Is The Advanced Way To Display Your Taxonomy Terms — The Tag Groups is the Advanced Way to Display Your Taxonomy Terms WordPress plugin before 2.2.0 does not prope…● PoC
2026-07-20
CVE-2026-10525
MEDIUM 6.1
Nex Forms — The NEX-Forms WordPress plugin before 9.2.3 does not sanitise and escape some submitted form data before stor…● PoC
2026-07-17
CVE-2026-11575
HIGH 7.5
Phonepe Payment Solutions — The PhonePe Payment Solutions WordPress plugin before 3.1.0 does not properly verify the authenticity of incom…● PoC
2026-07-17
CVE-2026-11961
HIGH 8.1
User Registration & Membership — The User Registration & Membership WordPress plugin before 5.2.3 does not validate that the membership tier s…● PoC
2026-07-17
CVE-2026-11966
MEDIUM 5.3
User Registration & Membership — The User Registration & Membership WordPress plugin before 5.2.3 does not perform a capability check for unau…● PoC
2026-07-17
CVE-2026-12393
MEDIUM 5.4
Wps Bookings For Woocommerce — The WPS Bookings for WooCommerce WordPress plugin before 3.11.7 does not verify that a booking order belongs t…● PoC
2026-07-17
CVE-2026-13402
MEDIUM 5.3
Royal Addons For Elementor — The Royal Addons for Elementor WordPress plugin before 1.7.1063 does not check the post status of menu items …● PoC
2026-07-17
CVE-2026-9810
CRITICAL 9.8
Ai Copilot — The AI Copilot WordPress plugin before 1.5.4 does not bind OAuth access tokens to a WordPress user, and accep…● PoC
2026-07-17
CVE-2026-11371
MEDIUM 6.1
Betterdocs — The BetterDocs WordPress plugin before 4.5.5 does not sanitise an AI-generated documentation summary before s…● PoC
2026-07-16
CVE-2026-11866
MEDIUM 5.4
Appointment Booking Plugin — The Appointment Booking Plugin WordPress plugin before 5.6.3 does not validate a CSRF nonce on several state-…● PoC
2026-07-16
CVE-2026-12395
MEDIUM 6.5
Wp Job Portal — The WP Job Portal WordPress plugin before 2.5.5 does not properly sanitize and escape a parameter before usin…● PoC
2026-07-16
CVE-2026-12492
CRITICAL 9.8
Happy Coders Otp Login For Woocommerce — The Happy Coders OTP Login for WooCommerce WordPress plugin before 2.8 does not verify that a one-time passwor…● PoC
2026-07-16
CVE-2026-12510
MEDIUM 5.9
Ai Engine — The AI Engine WordPress plugin before 3.5.5 does not verify that a user owns the chatbot conversation referen…● PoC
2026-07-16
CVE-2026-12525
HIGH 8.8
Redux Framework — The Redux Framework WordPress plugin before 4.5.13 does not restrict which user meta keys can be written when …● PoC
2026-07-16
CVE-2026-12585
HIGH 8.1
Abandoned Cart Lite For Woocommerce — The Abandoned Cart Lite for WooCommerce WordPress plugin before 6.8.2 does not protect the integrity of its ca…● PoC
2026-07-16
CVE-2026-12684
MEDIUM 6.5
Customer Reviews For Woocommerce — The Customer Reviews for WooCommerce WordPress plugin before 5.113.0 does not perform authentication, capabili…● PoC
2026-07-16
CVE-2026-12869
MEDIUM 6.1
Header Footer Builder For Elementor — The Header Footer Builder for Elementor WordPress plugin before 1.2.1 does not require an administrative capab…● PoC
2026-07-16
CVE-2026-12906
LOW 2.7
Rtmkit — The RTMKit WordPress plugin before 2.0.9 does not perform a capability check in one of its AJAX actions and re…● PoC
2026-07-16
CVE-2026-12907
LOW 2.7
Rtmkit — The RTMKit WordPress plugin before 2.0.9 does not perform a proper capability check on one of its -builder AJA…● PoC
2026-07-16
CVE-2026-12978
HIGH 7.1
Funnelkit — The FunnelKit WordPress plugin before 3.15.0.6 does not escape a user-supplied parameter before reflecting it…● PoC
2026-07-16
CVE-2026-12979
MEDIUM 5.5
Funnelkit — The FunnelKit WordPress plugin before 3.15.0.6 does not validate a user-supplied path before deleting a file …● PoC
2026-07-16
CVE-2026-11579
MEDIUM 5.3
Kali Forms — Contact Form & Drag And Drop Builder — The Kali Forms — Contact Form & Drag-and-Drop Builder WordPress plugin before 2.4.17 does not verify that a fi…● PoC
2026-07-15
CVE-2026-11580
MEDIUM 5.5
Kali Forms — Contact Form & Drag And Drop Builder — The Kali Forms — Contact Form & Drag-and-Drop Builder WordPress plugin before 2.4.17 does not perform a per-ob…● PoC
2026-07-15
CVE-2026-12281
HIGH 8.1
Shibboleth — The Shibboleth WordPress plugin before 2.5.4 does not fail closed when its HTTP header identity mode is enable…● PoC
2026-07-15
CVE-2026-12512
HIGH 8.6
Quotes Llama — The Quotes llama WordPress plugin before 3.1.6 does not properly sanitize and escape a user-supplied parameter…● PoC
2026-07-15
CVE-2026-11563
CRITICAL 9.6
Word Count And Social Shares — The Word Count and Social Shares WordPress plugin through 1.0 does not validate a user-supplied file path befo…● PoC
2026-07-14
CVE-2026-11567
MEDIUM 5.9
Sureforms — The SureForms WordPress plugin before 2.11.1 does not properly validate the payment amount on forms that use …● PoC
2026-07-14
CVE-2026-12511
HIGH 8.1
Ai Engine — The AI Engine WordPress plugin before 3.5.5 does not sanitize a user-supplied filename before using it to wri…● PoC
2026-07-14
CVE-2026-12583
HIGH 8.1
Newsletters — The Newsletters WordPress plugin before 4.15 does not prevent deserialization of untrusted input that is store…● PoC
2026-07-14
CVE-2026-12988
MEDIUM 6.4
Wp 2fa — The WP 2FA WordPress plugin before 3.1.1.2 does not verify that the email address supplied during two-factor …● PoC
2026-07-14
CVE-2025-15665
MEDIUM 5.4
Ultimate Before After Image Slider & Gallery — The Ultimate Before After Image Slider & Gallery WordPress plugin before 4.7.1 does not escape the value of t…● PoC
2026-07-14
CVE-2026-10551
MEDIUM 6.1
Breeze Cache — The Breeze Cache WordPress plugin before 2.5.6 is vulnerable to unauthenticated Stored Cross-Site Scripting (X…● PoC
2026-07-13
CVE-2026-11963
HIGH 8.1
User Registration & Membership — The User Registration & Membership WordPress plugin before 5.2.2 does not perform an authorization check on a…● PoC
2026-07-13
CVE-2026-11964
CRITICAL 9.1
User Registration & Membership — The User Registration & Membership WordPress plugin before 5.2.2 does not verify the authenticity of incoming…● PoC
2026-07-13
CVE-2026-12081
MEDIUM 5
Database For Contact Form 7, Wpforms, Elementor Forms — The Database for Contact Form 7, WPforms, Elementor forms WordPress plugin before 1.5.2 does not restrict the …● PoC
2026-07-13
CVE-2026-12271
MEDIUM 5.4
Tutor Lms — The Tutor LMS WordPress plugin before 3.9.13 does not verify ownership of the targeted quiz attempt before wr…● PoC
2026-07-13
CVE-2026-12273
MEDIUM 4.3
Tutor Lms — The Tutor LMS WordPress plugin before 3.9.13 does not perform any authorization or post-target validation bef…● PoC
2026-07-13
CVE-2026-12274
MEDIUM 6.5
Tutor Lms — The Tutor LMS WordPress plugin before 3.9.13 does not verify that the requesting user is allowed to edit a ta…● PoC
2026-07-13
CVE-2026-12275
HIGH 7.1
Tutor Lms — The Tutor LMS WordPress plugin before 3.9.13 does not, in its Droip and Kirki page-builder integration, perfo…● PoC
2026-07-13
CVE-2026-12396
MEDIUM 5.4
Wp Job Portal — The WP Job Portal WordPress plugin before 2.5.5 does not perform capability or ownership checks before allowi…● PoC
2026-07-13
CVE-2026-12397
MEDIUM 4.3
Wp Job Portal — The WP Job Portal WordPress plugin before 2.5.5 does not verify ownership when returning an employer's contac…● PoC
2026-07-13
CVE-2026-12582
HIGH 8.6
Library Management System — The Library Management System WordPress plugin before 3.5.8 does not sanitize and escape a user-supplied param…● PoC
2026-07-13
CVE-2026-12276
MEDIUM 5.3
La Studio Element Kit For Elementor — The LA-Studio Element Kit for Elementor WordPress plugin before 1.6.1 does not check whether user registration…● PoC
2026-07-10
CVE-2026-12685
HIGH 7.5
Escortwp — The EscortWP escortwp WordPress theme through 3.6.2 was distributed with a vendor-authored, obfuscated backdoo…● PoC
2026-07-10
CVE-2026-11571
HIGH 7.5
Everest Forms — The Everest Forms WordPress plugin before 3.5.0 does not reliably delete temporary CSV files generated during…● PoC
2026-07-09
CVE-2026-11869
MEDIUM 5.3
Wp Dsgvo Tools (Gdpr) — The WP DSGVO Tools (GDPR) WordPress plugin before 3.1.40 does not perform an authorization check on the immedi…● PoC
2026-07-09
CVE-2026-11875
MEDIUM 5.3
Wp Support Plus Responsive Ticket System — The WP Support Plus Responsive Ticket System WordPress plugin through 9.1.2 does not sign or verify its guest-…● PoC
2026-07-09
CVE-2026-12270
MEDIUM 6.5
Everest Forms — The Everest Forms WordPress plugin before 3.5.0 does not correctly restrict access to several REST API endpoi…● PoC
2026-07-09
CVE-2026-12516
MEDIUM 5.3
Fediverse Embeds — The Fediverse Embeds WordPress plugin before 1.5.8 does not validate the destination of the server-side reques…● PoC
2026-07-09
CVE-2026-12517
MEDIUM 5.3
Fediverse Embeds — The Fediverse Embeds WordPress plugin before 1.5.8 does not validate the destination of the server-side reques…● PoC
2026-07-09
CVE-2026-12378
HIGH 8.1
Appointment Booking Calendar Plugin And Scheduling Plugin — The Appointment Booking Calendar Plugin and Scheduling Plugin WordPress plugin through 1.1.28 does not valida…● PoC
2026-07-08
CVE-2026-10834
MEDIUM 4.6
Wp Travel Engine — The WP Travel Engine WordPress plugin before 6.8.1 does not properly validate the source of a user-supplied p…● PoC
2026-07-07
CVE-2026-12277
HIGH 8.7
Frontend File Manager Plugin — The Frontend File Manager Plugin WordPress plugin through 23.6 does not validate a file path derived from user…● PoC
2026-07-07
CVE-2026-12375
CRITICAL 9.8
Uncanny Automator Pro — The uncanny-automator-pro WordPress plugin before 7.3.0.6 was distributed with malicious code after the vendor…● PoC
2026-07-07
CVE-2026-4375
CRITICAL 9
Doleads Integrator — The DoLeads Integrator WordPress plugin through 0.65, wp2epub WordPress plugin through 0.65 have been seen to …● PoC
2026-07-07
CVE-2026-10830
HIGH 8.8
Allcoach — The AllCoach WordPress plugin before 1.0.2 does not verify that an email address submitted to a public accoun…● PoC
2026-07-06
CVE-2026-11766
HIGH 8
Ultimate Member — The Ultimate Member WordPress plugin before 2.12.0 does not properly sanitise and escape the value of custom …● PoC
2026-07-06
CVE-2026-11855
HIGH 8.8
Simple Membership — The Simple Membership WordPress plugin before 4.7.5 does not verify the authenticity of Stripe webhook request…● PoC
2026-07-06
CVE-2026-11962
HIGH 8.8
Fileorganizer — The FileOrganizer WordPress plugin before 1.2.0 does not validate the file type on several of its file-manage…● PoC
2026-07-06
CVE-2026-12083
HIGH 8.1
Admin And Site Enhancements (Ase) — The Admin and Site Enhancements (ASE) WordPress plugin before 8.8.4, admin-site-enhancements-pro WordPress plu…● PoC
2026-07-06
CVE-2026-6382
CRITICAL 9.1
Fileorganizer — The FileOrganizer WordPress plugin before 1.1.9, Advanced File Manager WordPress plugin before 5.4.12, File …● PoC
2026-07-06
CVE-2026-10077
MEDIUM 6.8
Yootheme — The yootheme WordPress theme before 5.0.35 does not prevent its bundled front-end framework from treating cert…● PoC
2026-07-02
CVE-2026-11578
LOW 2.7
Fluent Forms — The Fluent Forms WordPress plugin before 6.2.5 does not properly restrict the deletion of form submission ent…● PoC
2026-07-02
CVE-2026-11781
LOW 2.7
Adminify — The Adminify WordPress plugin before 4.2.10 does not perform per-user read-capability checks on the results r…● PoC
2026-07-02
CVE-2026-11965
MEDIUM 6.5
User Registration & Membership — The User Registration & Membership WordPress plugin before 5.2.0 does not enforce payment completion before a…● PoC
2026-07-02
CVE-2026-10750
HIGH 8.1
Royal Mcp — The Royal MCP WordPress plugin before 1.4.26 does not perform capability checks on the majority of its MCP to…● PoC
2026-07-01
CVE-2026-11562
MEDIUM 4.3
Ws Form Lite — The WS Form LITE WordPress plugin before 1.11.8 does not have a capability check on one of its settings-updat…● PoC
2026-07-01
CVE-2026-11568
HIGH 7.5
Product Configurator For Woocommerce — The Product Configurator for WooCommerce WordPress plugin before 1.7.3 does not perform any authorisation or p…● PoC
2026-07-01
CVE-2026-11570
MEDIUM 4.2
User Submitted Posts — The User Submitted Posts WordPress plugin before 20260608 does not escape a submitted value before outputting…● PoC
2026-07-01
CVE-2026-11794
HIGH 8.1
Advanced Form Integration — Connect Forms To 200+ Apps — The Advanced Form Integration — Connect Forms to 200+ Apps WordPress plugin before 2.1.1 does not restrict the…● PoC
2026-07-01
CVE-2026-11880
LOW 3.1
Fluent Forms — The Fluent Forms WordPress plugin before 6.2.1 does not properly verify ownership before processing a subscri…● PoC
2026-07-01
CVE-2026-11883
HIGH 7.2
Webauthn Provider For Two Factor — The WebAuthn Provider for Two Factor WordPress plugin before 2.5.6 does not correctly validate the second-fact…● PoC
2026-07-01
CVE-2026-11887
MEDIUM 4.3
Salon Booking System — The Salon Booking System WordPress plugin before 10.30.20 does not have proper authorisation checks on one of…● PoC
2026-07-01
CVE-2026-11581
MEDIUM 5.9
Kali Forms — Contact Form & Drag And Drop Builder — The Kali Forms — Contact Form & Drag-and-Drop Builder WordPress plugin before 2.4.13 does not sanitise a form …● PoC
2026-06-30
CVE-2026-11589
HIGH 8.8
Wp Support Plus Responsive Ticket System — The WP Support Plus Responsive Ticket System WordPress plugin through 9.1.2 does not properly validate uploade…● PoC
2026-06-30
CVE-2026-11590
HIGH 8.6
Wp Support Plus Responsive Ticket System — The WP Support Plus Responsive Ticket System WordPress plugin through 9.1.2 does not sanitize user-supplied ar…● PoC
2026-06-30
CVE-2026-9576
MEDIUM 4.9
Fluent Booking — The Fluent Booking WordPress plugin before 2.1.2 does not verify ownership of the requested group_id before e…● PoC
2026-06-30
CVE-2026-10083
HIGH 7.5
Apcu Manager — The APCu Manager WordPress plugin before 4.5.0 does not escape APCu object-cache keys before rendering them in…● PoC
2026-06-29
CVE-2026-9676
MEDIUM 4.3
F4 Post Tree — The F4 Post Tree WordPress plugin before 2.0.5 does not perform capability checks or CSRF/nonce verification o…● PoC
2026-06-29
CVE-2026-10820
HIGH 8.1
Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content — The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content Wo…● PoC
2026-06-27
CVE-2026-9677
MEDIUM 4.8
Shariff For Wordpress — The Shariff for WordPress Shariff for WordPress plugin through 1.0.11 does not sanitize or escape the shariff_…● PoC
2026-06-27
CVE-2026-10823
HIGH 7.5
Ymc Filter — The YMC Filter WordPress plugin before 3.11.3 does not properly authorize access to one of its REST API endpoi…● PoC
2026-06-26
CVE-2026-10835
HIGH 7.7
Salesmanago & Leadoo — The SALESmanago & Leadoo WordPress plugin before 3.11.3 does not properly sanitise and escape a parameter pass…● PoC
2026-06-26
CVE-2026-8380
MEDIUM 6.5
Frontend File Manager Plugin — The Frontend File Manager Plugin WordPress plugin through 23.6 does not properly verify ownership of every tar…● PoC
2026-06-26
CVE-2025-10268
MEDIUM 5.3
Printcart Web To Print Product Designer For Woocommerce — The Printcart Web to Print Product Designer for WooCommerce WordPress plugin through 2.4.8 is vulnerable to pa…● PoC
2026-06-26
CVE-2026-10824
MEDIUM 6.5
Masteriyo Lms — The Masteriyo LMS WordPress plugin before 2.2.1 does not perform authorization checks in a course-progress RE…● PoC
2026-06-25
CVE-2026-5305
HIGH 8.8
Email Address Encoder — The Email Address Encoder WordPress plugin before 1.0.25, email-encoder-premium WordPress plugin before 0.3.12…● PoC
2026-06-25
CVE-2026-9702
HIGH 7.5
Inpost Pl — The InPost PL WordPress plugin before 1.9.1 does not verify that the request originates from the legitimate bu…● PoC
2026-06-25
CVE-2026-10531
MEDIUM 5.4
Ai Share & Summarize — The AI Share & Summarize WordPress plugin before 2.0.4 does not sanitise and escape some of its shortcode attr…● PoC
2026-06-24
CVE-2026-10735
HIGH 7.5
Smart Post Show Pro — Multiple Shapedsmart-post-show-pro WordPress plugin before 4.0.2, Real Testimonials Pro WordPress plugin befor…● PoC
2026-06-24
CVE-2026-10749
HIGH 7.2
Post Duplicator — The Post Duplicator WordPress plugin before 3.0.15 does not safely handle custom meta-data during post duplica…● PoC
2026-06-24
CVE-2026-10753
LOW 2.7
Site Kit By Google — The Site Kit by Google WordPress plugin before 1.176.0 does not properly restrict a REST API write endpoint t…● PoC
2026-06-24
CVE-2026-9709
HIGH 7.7
Cornerstone — The Cornerstone WordPress plugin before 7.8.9 does not enforce capability checks on one of its REST API routes…● PoC
2026-06-24
CVE-2026-9710
HIGH 7.7
Cornerstone — The Cornerstone WordPress plugin before 7.8.8 does not enforce capability checks on one of its CSS-preview req…● PoC
2026-06-24
CVE-2026-7842
MEDIUM 6.8
Infility Global — The Infility Global Infility Global WordPress plugin before 2.15.20 for WordPress does not sanitize or validat…● PoC
2026-06-23
CVE-2026-8163
HIGH 8.8
Infility Global — The Infility Global WordPress plugin before 2.15.19 does not properly sanitize and escape some parameters befo…● PoC
2026-06-23
CVE-2026-8172
HIGH 7.1
Simple Basic Contact Form — The Simple Basic Contact Form WordPress plugin through 20250114 does not escape user-supplied input before ref…● PoC
2026-06-23
CVE-2026-8378
MEDIUM 5.4
Frontend File Manager Plugin — The Frontend File Manager Plugin WordPress plugin through 23.6 does not sanitise nor escape a filename submitt…● PoC
2026-06-23
CVE-2026-8379
HIGH 7.5
Frontend File Manager Plugin — The Frontend File Manager Plugin WordPress plugin through 23.6 does not properly enforce its nonce check on th…● PoC
2026-06-23
CVE-2026-10530
MEDIUM 5.3
Pie Register — The Pie Register WordPress plugin before 3.8.4.10 does not use sufficiently random values when generating its…● PoC
2026-06-22
CVE-2026-4110
MEDIUM 6.1
Ultimate Woocommerce Auction Pro — The ultimate-woocommerce-auction-pro WordPress plugin through 2.4.5 does not sanitise and escape a parameter b…● PoC
2026-06-22
CVE-2026-4259
HIGH 7.1
Ultimate Woocommerce Auction Pro — The ultimate-woocommerce-auction-pro WordPress plugin through 2.4.5 does not sanitise and escape a parameter b…● PoC
2026-06-22
CVE-2026-6858
HIGH 7.1
Transbank Webpay — The Transbank Webpay WordPress plugin before 1.14.0 does not sanitize and escape logs to be displayed, allowin…● PoC
2026-06-22
CVE-2026-7859
MEDIUM 5.3
Motors — The Motors WordPress plugin before 1.4.110 does not have proper authorisation and CSRF checks on one of its A…● PoC
2026-06-22
CVE-2026-8157
HIGH 8.8
Vitepos — The Vitepos WordPress plugin before 3.4.2 does not properly restrict the roles that can be assigned when crea…● PoC
2026-06-22
CVE-2026-9822
MEDIUM 6.5
Wp Hotel Booking — The WP Hotel Booking WordPress plugin before 2.3.1 does not enforce capability checks in several of its AJAX h…● PoC
2026-06-19
CVE-2026-9815
MEDIUM 6.5
Magicform — The MagicForm WordPress plugin through 0.1.3 does not properly validate the type of files uploaded through an …● PoC
2026-06-18
CVE-2026-7850
MEDIUM 5.9
Wp Magnific Popup — The WP Magnific Popup WordPress plugin through 1.0 does not properly escape user-controlled link URLs before i…● PoC
2026-06-17
CVE-2026-8089
HIGH 7.1
Wemail: Email Marketing, Email Automation, Newsletters, Subscribers & Email Optins For Woocommerce — The weMail: Email Marketing, Email Automation, Newsletters, Subscribers & Email Optins for WooCommerce WordPre…● PoC
2026-06-17
CVE-2026-8383
MEDIUM 5.3
Learnpress — The LearnPress WordPress plugin before 4.3.7 does not gate the `edit` context on one of its REST endpoint beh…● PoC
2026-06-17
CVE-2026-9570
HIGH 7.1
Taskbuilder — The Taskbuilder WordPress plugin before 5.0.8 does not properly sanitise a URL parameter before echoing it in…● PoC
2026-06-17
CVE-2026-8385
MEDIUM 5.3
Wp Go Maps — The WP Go Maps WordPress plugin before 10.0.10 does not properly enforce the marker approval filter on the ad…● PoC
2026-06-15
CVE-2026-8386
MEDIUM 5.3
Wp Go Maps — The WP Go Maps WordPress plugin before 10.0.10 does not perform any approval-state filtering on its public si…● PoC
2026-06-15
CVE-2026-8935
CRITICAL 9.8
Wp Maps Pro — The WP MAPS PRO WordPress plugin before 6.1.1 registers an unauthenticated AJAX action which, given a valid no…● PoC
2026-06-15
CVE-2026-9278
MEDIUM 5.4
Form Builder Cp — The Form Builder CP WordPress plugin before 1.2.47 does not properly sanitize a form configuration value befor…● PoC
2026-06-15
CVE-2025-15546
MEDIUM 5.4
Iptanus File Upload — The Iptanus File Upload WordPress plugin before 5.1.7 does not implement proper file handling when the duplica…● PoC
2026-06-14
CVE-2026-9061
LOW 3.5
Store Locator Wordpress — The Store Locator WordPress plugin before 1.6.9 does not sanitize and escape store logo metadata before storin…● PoC
2026-06-13
CVE-2026-9062
LOW 3.4
Store Locator Wordpress — The Store Locator WordPress plugin before 1.6.9 does not validate a parameter before using it in a file path, …● PoC
2026-06-13
CVE-2026-9269
LOW 3.5
Secure Copy Content Protection And Content Locking — The Secure Copy Content Protection and Content Locking WordPress plugin before 5.1.5 does not sanitise and esc…● PoC
2026-06-12
CVE-2026-9271
MEDIUM 5.9
Keepinmind Dashboard Notes — Vulnerability Title● PoC
2026-06-12
CVE-2026-3326
HIGH 8.6
Xstore — The Xstore WordPress theme before 9.7.3 does not properly sanitise and escape a parameter before using it in a…● PoC
2026-06-10
CVE-2026-8071
HIGH 8.8
Anti Spam By Cleantalk. Spam Protection — The Anti-Spam by CleanTalk. Spam protection WordPress plugin before 6.79 does not properly sanitize content wi…● PoC
2026-06-10
CVE-2026-9060
LOW 3.5
Store Locator Wordpress — The Store Locator WordPress plugin before 1.6.6 does not sanitize and escape one of its settings before storin…● PoC
2026-06-10
CVE-2026-9067
CRITICAL 9.1
Schema & Structured Data For Wp & Amp — The Schema & Structured Data for WP & AMP WordPress plugin before 1.60 does not check user capabilities on its…● PoC
2026-06-10
CVE-2026-4986
MEDIUM 5.3
Wpforms — The WPForms WordPress plugin before 1.10.0.5 does not verify the authenticity of incoming PayPal webhook even…● PoC
2026-06-09
CVE-2026-8981
LOW 3.5
Custom Block Builder — The Custom Block Builder WordPress plugin before 4.3.0 does not consistently check the unfiltered_html capabi…● PoC
2026-06-09