Unknown
300 CVEsCVE IDSeverityProduct / summaryPublished
CVE-2026-15247
N/A
Search Atlas Seo — The Search Atlas SEO WordPress plugin before 2.6.24 does not perform a nonce or capability check before proce…● PoC
2026-09-05
CVE-2026-19858
N/A
Jetformbuilder — Dynamic Blocks Form Builder — The JetFormBuilder — Dynamic Blocks Form Builder WordPress plugin before 3.6.5.2 does not perform authorisatio…● PoC
2026-09-05
CVE-2026-19861
N/A
Jetformbuilder — Dynamic Blocks Form Builder — The JetFormBuilder — Dynamic Blocks Form Builder WordPress plugin before 3.6.5.2 does not properly sanitise an…● PoC
2026-09-05
CVE-2026-77826
N/A
Registrationmagic — The RegistrationMagic WordPress plugin before 6.0.9.9 does not verify which application a Facebook access tok…● PoC
2026-09-05
CVE-2026-78149
N/A
Smart Post — The Smart Post WordPress plugin before 4.0.8 does not check whether a post is password protected before retur…● PoC
2026-09-05
CVE-2026-78150
N/A
Smart Post — The Smart Post WordPress plugin before 4.0.8 does not check the type, ownership or status of the post it is a…● PoC
2026-09-05
CVE-2026-78362
N/A
Seo Flow By Lupsonline — The SEO Flow by LupsOnline WordPress plugin before 3.0.3 does not correctly validate the credential supplied w…● PoC
2026-09-05
CVE-2026-81348
N/A
My Private Site — The My Private Site WordPress plugin before 4.2.3 does not apply its site-privacy access control to certain u…● PoC
2026-09-05
CVE-2026-81404
N/A
Ipgp Visitors Origin — The IPGP Visitors Origin WordPress plugin before 1.6 does not sanitise or escape user input before reflecting …● PoC
2026-09-05
CVE-2026-81423
N/A
Accept Stripe Payments — The Accept Stripe Payments WordPress plugin before 2.1.4 does not validate a user-supplied URL before using it…● PoC
2026-09-05
CVE-2026-81424
N/A
Accept Stripe Payments — The Accept Stripe Payments WordPress plugin before 2.1.4 does not verify that the product fulfilled when a che…● PoC
2026-09-05
CVE-2026-82304
N/A
Music Store — The Music Store WordPress plugin before 1.4.5 does not sanitise and escape user input before using it in a SQ…● PoC
2026-09-05
CVE-2026-82846
N/A
Masteriyo Lms — The Masteriyo LMS WordPress plugin before 3.4.0 does not sanitise and escape some course settings before outp…● PoC
2026-09-05
CVE-2026-83543
N/A
Greenshift — The Greenshift WordPress plugin before 13.2.0 does not validate a user-supplied URL before fetching it server…● PoC
2026-09-05
CVE-2026-83544
N/A
Greenshift — The Greenshift WordPress plugin before 13.2.0 does not properly escape a block animation attribute before out…● PoC
2026-09-05
CVE-2026-84021
N/A
Bold Page Builder — The Bold Page Builder WordPress plugin before 5.9.8 does not properly validate a link URL before outputting it…● PoC
2026-09-05
CVE-2026-84022
N/A
Bold Page Builder — The Bold Page Builder WordPress plugin before 5.9.8 does not sanitise and escape several shortcode attributes …● PoC
2026-09-05
CVE-2026-84221
N/A
Kirki — The Kirki WordPress plugin before 6.3.0 does not escape a user-supplied identifier before using it in a SQL q…● PoC
2026-09-05
CVE-2026-84225
N/A
Kirki — The Kirki WordPress plugin before 6.3.0 does not check that a user is allowed to act on a collaboration comme…● PoC
2026-09-05
CVE-2026-84745
N/A
The Events Calendar — The Events Calendar WordPress plugin before 6.17.3.1 does not restrict non-public content to the users entitle…● PoC
2026-09-05
CVE-2026-84896
N/A
King Addons For Elementor — The King Addons for Elementor WordPress plugin before 51.1.77 does not escape a widget display-style setting …● PoC
2026-09-05
CVE-2026-84898
N/A
Eventin — The Eventin WordPress plugin before 4.1.21 does not properly validate a template path value before using it t…● PoC
2026-09-05
CVE-2026-84899
N/A
Vikwidgetsloader — The VikWidgetsLoader WordPress plugin before 1.12.0 does not sanitise or escape a block attribute before outp…● PoC
2026-09-05
CVE-2026-84901
N/A
Eventin — The Eventin WordPress plugin before 4.1.22 does not properly check authorization on several of its event-mana…● PoC
2026-09-05
CVE-2026-84926
N/A
Embedpress — The EmbedPress WordPress plugin before 4.6.4 does not correctly restrict access to one of its Google Reviews …● PoC
2026-09-05
CVE-2026-84927
N/A
Embedpress — The EmbedPress WordPress plugin before 4.6.4 does not perform a sufficient authorization check on one of its …● PoC
2026-09-05
CVE-2026-84930
N/A
Catfolders Document Gallery & Pdf Library — The CatFolders Document Gallery & PDF Library WordPress plugin before 2.0.7 does not properly validate a block…● PoC
2026-09-05
CVE-2026-84931
N/A
Joli Table Of Contents — The Joli Table Of Contents WordPress plugin before 3.0.3 does not sanitise or escape a shortcode attribute val…● PoC
2026-09-05
CVE-2026-84934
N/A
Jch Optimize — The JCH Optimize WordPress plugin before 6.0.1 does not perform a capability check on one of its authenticated…● PoC
2026-09-05
CVE-2026-84935
N/A
Ht Menu — The HT Menu WordPress plugin before 1.2.7 does not perform any capability or object-ownership check when savi…● PoC
2026-09-05
CVE-2026-84936
N/A
Embedpress — The EmbedPress WordPress plugin before 4.6.4 does not have proper authorization on a public review-loading ac…● PoC
2026-09-05
CVE-2026-84937
N/A
Video Player For Youtube — The Video Player for YouTube WordPress plugin before 2.1.0 does not properly sanitise and escape user-supplie…● PoC
2026-09-05
CVE-2025-15693
N/A
Jch Optimize — The JCH Optimize WordPress plugin before 5.0.1 does not properly restrict a directory path provided to one of …● PoC
2026-09-05
CVE-2025-15694
N/A
Joli Table Of Contents — The Joli Table Of Contents WordPress plugin before 2.8.1 does not sanitise and escape some of its settings bef…● PoC
2026-09-05
CVE-2026-16281
HIGH 7.1
Classified Listing — The Classified Listing WordPress plugin before 6.1.1 does not verify that the caller owns or can edit the tar…● PoC
2026-09-04
CVE-2026-17517
MEDIUM 5.3
Content Views — The Content Views WordPress plugin before 4.5.1.2 does not check whether the user requesting a view is allowe…● PoC
2026-09-04
CVE-2026-19224
HIGH 7.2
Hummingbird Performance — The Hummingbird Performance WordPress plugin before 3.21.2 does not restrict a network-wide setting to networ…● PoC
2026-09-04
CVE-2026-74853
MEDIUM 6.8
Pods — The Pods WordPress plugin before 3.3.9.2 does not restrict which functions a display callback may resolve to,…● PoC
2026-09-04
CVE-2026-79630
MEDIUM 5.3
Wpfunnels — The WPFunnels WordPress plugin before 3.13.0 does not verify that the product requested through a checkout or…● PoC
2026-09-04
CVE-2026-79631
MEDIUM 5.3
Wpfunnels — The WPFunnels WordPress plugin before 3.13.0 does not restrict access to the log files it writes to a predict…● PoC
2026-09-04
CVE-2026-79632
MEDIUM 5.3
Wpfunnels — The WPFunnels WordPress plugin before 3.13.0 does not perform any authorisation or nonce check in one of its …● PoC
2026-09-04
CVE-2026-80438
MEDIUM 5.9
Ninja Forms — The Ninja Forms WordPress plugin before 3.15.2 does not restrict its REST abilities to administrators, accept…● PoC
2026-09-04
CVE-2026-81347
MEDIUM 5.9
Frontend Admin By Dynamiapps — The Frontend Admin by DynamiApps WordPress plugin before 3.29.13 does not properly validate a user-controllabl…● PoC
2026-09-04
CVE-2026-82186
MEDIUM 4.1
Wplp Cookie Consent — The WPLP Cookie Consent WordPress plugin before 4.4.2 does not properly validate a pagination parameter befor…● PoC
2026-09-04
CVE-2026-82193
MEDIUM 5.5
Wpvivid — Backup, Migration & Staging — The WPvivid — Backup, Migration & Staging WordPress plugin before 0.9.134 does not validate a user supplied fi…● PoC
2026-09-04
CVE-2026-82194
MEDIUM 5.5
Wpvivid — Backup, Migration & Staging — The WPvivid — Backup, Migration & Staging WordPress plugin before 0.9.134 does not validate a user supplied pa…● PoC
2026-09-04
CVE-2026-82923
CRITICAL 9.8
Ai Website Builder (Github Build) — The AI Website Builder WordPress plugin (GitHub build) 1.0.0 does not perform any authorisation or nonce check…● PoC
2026-09-04
CVE-2026-84043
MEDIUM 5.3
Epayco Payment Gateway For Woocommerce — The ePayco Payment Gateway for WooCommerce WordPress plugin before 8.4.7 does not properly verify the authenti…● PoC
2026-09-04
CVE-2026-84044
MEDIUM 5.3
Restaurant Menu And Food Ordering — The Restaurant Menu and Food Ordering WordPress plugin before 2.4.12 does not verify that a PayPal payment not…● PoC
2026-09-04
CVE-2026-84045
MEDIUM 5.3
E Cab Taxi Booking Manager For Woocommerce — The E-cab Taxi Booking Manager for Woocommerce WordPress plugin before 2.0.5 does not validate a client-suppli…● PoC
2026-09-04
CVE-2026-84066
LOW 3.1
Directorist: Ai Powered Business Directory, Listings & Classified Ads — The Directorist: AI-Powered Business Directory, Listings & Classified Ads WordPress plugin before 8.9 does not…● PoC
2026-09-04
CVE-2026-84146
MEDIUM 5.3
Xpro Addons — 140+ Widgets For Elementor — The Xpro Addons — 140+ Widgets for Elementor WordPress plugin before 1.7.8 does not perform any capability or …● PoC
2026-09-04
CVE-2025-15691
MEDIUM 5.3
Wpfunnels — The WPFunnels WordPress plugin before 3.13.0 does not check whether user registration is enabled on the site …● PoC
2026-09-04
CVE-2026-10821
MEDIUM 6.6
Yoast Seo Premium — The Yoast SEO Premium WordPress plugin before 27.6.1 does not sanitize control characters from redirect origin…● PoC
2026-09-02
CVE-2026-12526
HIGH 8.1
Advanced Custom Fields: Extended — The Advanced Custom Fields: Extended WordPress plugin before 0.9.2.7 does not verify that the requester is aut…● PoC
2026-09-02
CVE-2026-12865
HIGH 7.1
Photo Gallery By 10web — The Photo Gallery by 10Web WordPress plugin before 1.8.44 does not escape two request parameters before refle…● PoC
2026-09-02
CVE-2026-14215
MEDIUM 6.5
Booking For Appointments And Events Calendar — The Booking for Appointments and Events Calendar WordPress plugin before 2.4.9 does not require authenticatio…● PoC
2026-09-02
CVE-2026-14326
LOW 3.8
Timetics — The Timetics WordPress plugin through 1.0.61 does not enforce per-object ownership when updating appointments …● PoC
2026-09-02
CVE-2026-15232
MEDIUM 5.3
Motopress Appointment Booking — The MotoPress Appointment Booking WordPress plugin before 2.4.8 does not perform an authorization or ownership…● PoC
2026-09-02
CVE-2026-16966
MEDIUM 5.3
Solace Extra — The Solace Extra WordPress plugin before 1.7.0 does not perform any authorization or post-status checks in one…● PoC
2026-09-02
CVE-2026-16983
MEDIUM 4.3
Gutentor — The Gutentor WordPress plugin before 4.0.6 does not apply the correct context restriction to one of its REST …● PoC
2026-09-02
CVE-2026-17563
MEDIUM 5.3
User Frontend — The User Frontend WordPress plugin before 4.3.11 does not enforce its subscription-purchase requirement when p…● PoC
2026-09-02
CVE-2026-19116
HIGH 8.8
User Frontend — The User Frontend WordPress plugin before 4.3.11 does not prevent user-supplied field values from being deser…● PoC
2026-09-02
CVE-2026-19251
MEDIUM 5.3
Ultimate Member — The Ultimate Member WordPress plugin before 2.13.0 does not check whether a comment has been approved, or whe…● PoC
2026-09-02
CVE-2026-19453
HIGH 7.1
Jetbackup — The JetBackup WordPress plugin before 3.1.23.5 does not verify the role or capabilities of the account it pre…● PoC
2026-09-02
CVE-2026-19698
LOW 3.5
Gutenkit — The GutenKit WordPress plugin before 2.5.1 does not validate or escape style settings saved against a post bef…● PoC
2026-09-02
CVE-2026-19704
MEDIUM 5.3
Comments — The Comments WordPress plugin before 7.6.66 does not validate a value used to build a database query, allowin…● PoC
2026-09-02
CVE-2026-19719
MEDIUM 6.8
Social Media Share Buttons & Social Sharing Icons — The Social Media Share Buttons & Social Sharing Icons WordPress plugin before 3.0.1 does not escape the post t…● PoC
2026-09-02
CVE-2026-19723
HIGH 7.1
Social Media Share Buttons & Social Sharing Icons — The Social Media Share Buttons & Social Sharing Icons WordPress plugin before 3.0.1 does not properly escape a…● PoC
2026-09-02
CVE-2026-2688
MEDIUM 6.5
Hipaa Forms — The HIPAA FORMS WordPress plugin before 3.2.0 contains a hardcoded authentication bypass via a hardcoded param…● PoC
2026-09-02
CVE-2026-2811
MEDIUM 5.4
Ajaxify Comments — The Ajaxify Comments WordPress plugin before 3.2 is vulnerable to HTTP Header Injection due to insufficient in…● PoC
2026-09-02
CVE-2026-4357
CRITICAL 10
Embed Html5 Game — The Embed HTML5 Game WordPress plugin through 1.3 does not properly restrict who can upload files via the plug…● PoC
2026-09-02
CVE-2026-74927
MEDIUM 5.3
Multivendorx — The MultiVendorX WordPress plugin before 5.0.15 does not have proper authorisation controls on one of its RES…● PoC
2026-09-02
CVE-2026-77009
CRITICAL 9.9
Watchman Site7 — The WatchMan-Site7 WordPress plugin through 4.2.0 does not restrict access to its debugging console, which exe…● PoC
2026-09-02
CVE-2026-77764
MEDIUM 4.3
Gamipress — The GamiPress WordPress plugin before 7.9.9.6 does not properly restrict its video watch-tracking functionali…● PoC
2026-09-02
CVE-2026-77782
MEDIUM 5.3
Rank Math Seo — The Rank Math SEO WordPress plugin before 1.0.277.1 does not check whether a post is password protected befor…● PoC
2026-09-02
CVE-2026-77783
LOW 3.7
Rank Math Seo — The Rank Math SEO WordPress plugin before 1.0.277 does not verify that the post whose schema it renders on th…● PoC
2026-09-02
CVE-2026-77784
LOW 2.7
Rank Math Seo — The Rank Math SEO WordPress plugin before 1.0.277 does not verify that a user is allowed to edit the object b…● PoC
2026-09-02
CVE-2026-77785
LOW 2.7
Rank Math Seo — The Rank Math SEO WordPress plugin before 1.0.277 does not verify that the requesting user is permitted to re…● PoC
2026-09-02
CVE-2026-77787
LOW 2.7
Rank Math Seo — The Rank Math SEO WordPress plugin before 1.0.277 does not perform a capability check when bulk metadata upda…● PoC
2026-09-02
CVE-2026-77788
MEDIUM 4.9
Rank Math Seo — The Rank Math SEO WordPress plugin before 1.0.277 does not verify that the metadata row being updated belongs…● PoC
2026-09-02
CVE-2026-77792
HIGH 7.5
Registrationmagic — The RegistrationMagic WordPress plugin before 6.0.9.9 does not escape a registration form field value before …● PoC
2026-09-02
CVE-2026-77793
MEDIUM 5.3
Registrationmagic — The RegistrationMagic WordPress plugin before 6.0.9.9 does not validate the total price of a paid registration…● PoC
2026-09-02
CVE-2026-77794
MEDIUM 5.3
Registrationmagic — The RegistrationMagic WordPress plugin before 6.0.9.9 does not validate a client-supplied quantity multiplier …● PoC
2026-09-02
CVE-2026-78151
MEDIUM 5.3
Formlayer — The FormLayer WordPress plugin before 1.0.9 does not perform any authorization check before returning a form's…● PoC
2026-09-02
CVE-2026-78153
MEDIUM 5.3
Restrict User Access — The Restrict User Access WordPress plugin before 2.8.1 does not normalise the REST API route before checking i…● PoC
2026-09-02
CVE-2026-79621
MEDIUM 4.3
Catalogx — The CatalogX WordPress plugin before 6.1.3 does not sanitise or escape content that an unauthenticated user c…● PoC
2026-09-02
CVE-2026-80467
HIGH 8.1
Advanced Custom Fields: Extended — The Advanced Custom Fields: Extended WordPress plugin before 0.9.2.7 does not restrict the role submitted thro…● PoC
2026-09-02
CVE-2026-81194
MEDIUM 4.3
Masterstudy Lms Wordpress Plugin — The MasterStudy LMS WordPress Plugin WordPress plugin before 3.7.46 does not properly verify authorization wh…● PoC
2026-09-02
CVE-2026-81195
MEDIUM 5.3
Masterstudy Lms Wordpress Plugin — The MasterStudy LMS WordPress Plugin WordPress plugin before 3.7.46 does not perform an authorization check b…● PoC
2026-09-02
CVE-2026-81196
LOW 2.7
Masterstudy Lms Wordpress Plugin — The MasterStudy LMS WordPress Plugin WordPress plugin before 3.7.46 does not properly verify ownership of qui…● PoC
2026-09-02
CVE-2026-81197
MEDIUM 5.3
Masterstudy Lms Wordpress Plugin — The MasterStudy LMS WordPress Plugin WordPress plugin before 3.7.46 does not restrict access to a REST route …● PoC
2026-09-02
CVE-2026-81198
LOW 3.8
Masterstudy Lms Wordpress Plugin — The MasterStudy LMS WordPress Plugin WordPress plugin before 3.7.46 does not properly verify ownership of a c…● PoC
2026-09-02
CVE-2026-81199
MEDIUM 5.3
Masterstudy Lms Wordpress Plugin — The MasterStudy LMS WordPress Plugin WordPress plugin before 3.7.46 does not perform an authorization check b…● PoC
2026-09-02
CVE-2026-81426
MEDIUM 4.3
Wc Vendors — The WC Vendors WordPress plugin before 2.7.2.1 does not have CSRF protection on some of its front-end order s…● PoC
2026-09-02
CVE-2026-81427
MEDIUM 4.3
Wc Vendors — The WC Vendors WordPress plugin before 2.7.2.1 does not verify that the vendor submitting a front-end order s…● PoC
2026-09-02
CVE-2026-81428
MEDIUM 6.5
Wc Vendors — The WC Vendors WordPress plugin before 2.7.2.1 does not verify ownership or the object type of user-supplied …● PoC
2026-09-02
CVE-2026-81432
MEDIUM 4.3
Jetstylemanager For Gutenberg — The JetStyleManager for Gutenberg WordPress plugin before 1.3.9 does not have CSRF protection on some of its A…● PoC
2026-09-02
CVE-2026-81571
MEDIUM 4.8
Brave — The Brave WordPress plugin before 0.8.8 does not prevent a URL parameter used to pre-fill a form field from be…● PoC
2026-09-02
CVE-2026-81583
MEDIUM 5.4
Theme My Login — The My Login WordPress plugin before 7.2.0 does not enforce the network's registration setting when processin…● PoC
2026-09-02
CVE-2026-81737
HIGH 8.8
Faq Builder Ays — The FAQ Builder AYS WordPress plugin before 1.8.5 does not sanitize or escape content submitted by unauthentic…● PoC
2026-09-02
CVE-2026-81807
HIGH 8.8
Simple Ajax Chat — The Simple Ajax Chat WordPress plugin before 20260827 does not escape chat message content before rendering i…● PoC
2026-09-02
CVE-2026-82182
MEDIUM 4.1
Wpvivid — Backup, Migration & Staging — The WPvivid — Backup, Migration & Staging WordPress plugin before 0.9.133 does not sanitise a user supplied li…● PoC
2026-09-02
CVE-2026-82183
HIGH 8.1
Oauth Single Sign On — The OAuth Single Sign On WordPress plugin before 7.0.1 does not verify the identity assertion returned by its…● PoC
2026-09-02
CVE-2026-82884
MEDIUM 6.8
All In One Seo — The All in One SEO WordPress plugin before 5.0.0.1 does not sanitise and escape some content stored in posts b…● PoC
2026-09-02
CVE-2026-83533
MEDIUM 5.3
Wp Express Checkout — The WP Express Checkout WordPress plugin before 2.4.9 does not verify server-side that a payment was actually …● PoC
2026-09-02
CVE-2026-83547
MEDIUM 6.8
Xpro Addons — The Xpro Addons WordPress plugin before 1.7.4 does not properly escape some of its widgets' settings before ou…● PoC
2026-09-02
CVE-2026-8151
MEDIUM 5.4
Simple Membership Mailchimp Integration — The Simple Membership MailChimp Integration WordPress plugin before 1.9.8 does not have CSRF checks in its set…● PoC
2026-09-02
CVE-2025-15481
MEDIUM 5.3
Notification Bar For Wordpress — The Notification Bar for WordPress plugin through 1.1.8 exposes an unauthenticated CSV export script that disc…● PoC
2026-09-02
CVE-2025-15485
HIGH 8.2
Auto X Line — The Auto x LINE WordPress plugin through 1.0.0 does not have authorization checks in some of its REST endpoint…● PoC
2026-09-02
CVE-2025-15489
MEDIUM 5.3
Passster — The Passster WordPress plugin before 4.2.24 does not handle input properly in an AJAX action, allowing unauthe…● PoC
2026-09-02
CVE-2025-15490
MEDIUM 5.3
Passster — The Passster WordPress plugin before 4.2.26 has a flaw in its global protection checks, allowing unauthenticat…● PoC
2026-09-02
CVE-2025-15663
MEDIUM 6.8
Ultimate Before After Image Slider & Gallery — The Ultimate Before After Image Slider & Gallery WordPress plugin before 4.7.19 does not properly escape the …● PoC
2026-09-02
CVE-2025-15664
MEDIUM 6.8
Ultimate Before After Image Slider & Gallery — The Ultimate Before After Image Slider & Gallery WordPress plugin before 4.7.19 does not properly escape the …● PoC
2026-09-02
CVE-2025-15692
LOW 3.5
Icegram Express — The Icegram Express WordPress plugin before 5.8.6 does not properly escape a list description setting before o…● PoC
2026-09-02
CVE-2025-8945
MEDIUM 5.3
Wp Edit Password Protected — The Wp Edit Password Protected WordPress plugin before 1.3.5 allows protecting page content, but this protecti…● PoC
2026-09-02
CVE-2025-9314
CRITICAL 9.8
Developer Tools — The Developer Tools WordPress plugin through 1.1.3 contains an unauthenticated arbitrary file upload vulnerabi…● PoC
2026-09-02
CVE-2026-13611
MEDIUM 5.3
Kivicare — The KiviCare WordPress plugin before 4.5.5 does not perform authorization checks on some of its REST endpoints…● PoC
2026-09-01
CVE-2026-74916
MEDIUM 6.5
Wp Fastest Cache — The WP Fastest Cache WordPress plugin before 1.5.1 does not include a set of tracking-related query parameters…● PoC
2026-09-01
CVE-2026-78363
MEDIUM 4.8
Mw Wp Form — The MW WP Form WordPress plugin before 5.1.5 does not prevent shortcodes in user-submitted values from being e…● PoC
2026-09-01
CVE-2026-77013
MEDIUM 5.3
爱采集数据采集和发布插件 — The 爱采集数据采集和发布插件 WordPress plugin through 1.0.0 does not restrict which of its handler methods a request may i…● PoC
2026-08-31
CVE-2026-14307
HIGH 7.1
Geotargetingwp — The geotargetingwp WordPress plugin before 3.5.6.2 does not sanitise or escape several parameters before refle…● PoC
2026-08-30
CVE-2026-14835
MEDIUM 6.8
Sogo Add Script To Individual Pages Header Footer — The SOGO Add Script to Individual Pages Header Footer WordPress plugin through 3.9 does not sanitise or escape…● PoC
2026-08-30
CVE-2026-19722
MEDIUM 6.6
Wpvivid — Backup, Migration & Staging — The WPvivid — Backup, Migration & Staging WordPress plugin before 0.9.133 does not validate the destination of…● PoC
2026-08-30
CVE-2026-76585
HIGH 8.8
Customer Reviews For Woocommerce — The Customer Reviews for WooCommerce WordPress plugin before 5.118.0 does not sanitise and escape the content …● PoC
2026-08-30
CVE-2026-78364
LOW 3.5
Mw Wp Form — The MW WP Form WordPress plugin before 5.1.6 does not sanitise and escape some of its form settings before out…● PoC
2026-08-30
CVE-2026-81660
HIGH 8.8
Groundhogg — Crm, Newsletters, And Marketing Automation — The Groundhogg — CRM, Newsletters, and Marketing Automation WordPress plugin before 4.5.13 does not validate o…● PoC
2026-08-30
CVE-2026-81766
MEDIUM 6.6
Really Simple Security — The Really Simple Security WordPress plugin before 9.8.0 does not check that the user is allowed to install R…● PoC
2026-08-30
CVE-2026-10522
CRITICAL 9.8
Memberhero — The MemberHero WordPress plugin through 6.9 does not restrict which account fields can be supplied during its…● PoC
2026-08-29
CVE-2026-16061
HIGH 8.6
Rest Routes — The Rest Routes WordPress plugin through 5.5.5 does not sanitize and validate a value taken from the URL of o…● PoC
2026-08-29
CVE-2026-16259
CRITICAL 9.8
Uix Usercenter — The Uix UserCenter WordPress plugin through 1.0.3 does not verify that the account being modified through an u…● PoC
2026-08-29
CVE-2026-16600
HIGH 7.7
Smartaipress — The SmartAIPress WordPress plugin through 1.2.0 does not perform a capability check on one of its AJAX actions…● PoC
2026-08-29
CVE-2026-16947
CRITICAL 9.1
Total Processing Card Payments For Woocommerce — The Total processing card payments for WooCommerce WordPress plugin through 7.3 does not validate a user-suppl…● PoC
2026-08-29
CVE-2026-17520
MEDIUM 4.8
Newsletters — The Newsletters WordPress plugin before 4.17 does not generate its API key using a sufficiently random source,…● PoC
2026-08-29
CVE-2026-17522
MEDIUM 5.4
Newsletters — The Newsletters WordPress plugin before 4.17 does not perform any nonce or capability check when saving one of…● PoC
2026-08-29
CVE-2026-18233
MEDIUM 6.5
Mstore Api — The MStore API WordPress plugin before 4.21.1 does not verify that the order targeted by one of its delivery …● PoC
2026-08-29
CVE-2026-18234
MEDIUM 6.5
Mstore Api — The MStore API WordPress plugin before 4.21.1 does not verify that the order targeted by its wallet payment h…● PoC
2026-08-29
CVE-2026-19430
MEDIUM 5.3
Catfolders Document Gallery Pro — The Catfolders Document Gallery Pro WordPress plugin before 2.0.7 does not authorise some of its REST API rout…● PoC
2026-08-29
CVE-2026-76546
MEDIUM 6.8
User Profile Builder — The User Profile Builder WordPress plugin before 4.0.1 does not escape the output of one of its optional shor…● PoC
2026-08-29
CVE-2026-76547
MEDIUM 6.6
User Profile Builder — The User Profile Builder WordPress plugin before 4.0.1 does not validate the type of data being deserialized …● PoC
2026-08-29
CVE-2026-76548
HIGH 8.2
User Profile Builder — The User Profile Builder WordPress plugin before 4.0.1 does not properly restrict its front-end file upload f…● PoC
2026-08-29
CVE-2026-76586
HIGH 7.5
Appointment Booking Calendar Plugin And Scheduling Plugin — The Appointment Booking Calendar Plugin and Scheduling Plugin WordPress plugin before 1.6.3 does not verify t…● PoC
2026-08-29
CVE-2026-77007
HIGH 7.5
Hel Online Classroom: Ai Powered Online Classrooms — The HEL Online Classroom: AI-powered Online Classrooms WordPress plugin through 1.0.3 does not perform any aut…● PoC
2026-08-29
CVE-2026-77008
MEDIUM 6.5
Hel Online Classroom: Ai Powered Online Classrooms — The HEL Online Classroom: AI-powered Online Classrooms WordPress plugin through 1.0.3 does not have any author…● PoC
2026-08-29
CVE-2026-77010
MEDIUM 6.5
Hel Online Classroom: Ai Powered Online Classrooms — The HEL Online Classroom: AI-powered Online Classrooms WordPress plugin through 1.0.3 does not perform authori…● PoC
2026-08-29
CVE-2026-77012
CRITICAL 9.3
爱采集数据采集和发布插件 — The 爱采集数据采集和发布插件 WordPress plugin through 1.0.0 does not require a per-install secret for one of its unauthent…● PoC
2026-08-29
CVE-2026-77704
LOW 2.7
Booking For Appointments And Events Calendar — The Booking for Appointments and Events Calendar WordPress plugin before 2.4.9 does not check that a user hol…● PoC
2026-08-29
CVE-2026-77786
MEDIUM 4.9
Rank Math Seo — The Rank Math SEO WordPress plugin before 1.0.277 does not check that the user requesting an automated SEO fi…● PoC
2026-08-29
CVE-2026-80311
MEDIUM 4.3
Stripe Payment Forms By Wp Full Pay — The Stripe Payment Forms by WP Full Pay WordPress plugin before 8.5.5 does not verify that a subscription bel…● PoC
2026-08-29
CVE-2026-80488
MEDIUM 4.1
Wp Ultimate Csv Importer — The WP Ultimate CSV Importer WordPress plugin before 9.0 does not properly sanitise and escape imported field…● PoC
2026-08-29
CVE-2026-81026
MEDIUM 4.8
Masterstudy Lms Wordpress Plugin — The MasterStudy LMS WordPress Plugin WordPress plugin before 3.7.40 does not verify the amount, receiver, cur…● PoC
2026-08-29
CVE-2026-81200
LOW 2.7
Masterstudy Lms Wordpress Plugin — The MasterStudy LMS WordPress Plugin WordPress plugin before 3.7.42 does not correctly restrict access to ord…● PoC
2026-08-29
CVE-2026-81342
MEDIUM 4.7
Masterstudy Lms Wordpress Plugin — The MasterStudy LMS WordPress Plugin WordPress plugin before 3.7.43 does not validate a redirect parameter su…● PoC
2026-08-29
CVE-2026-81346
MEDIUM 4.3
Frontend Admin By Dynamiapps — The Frontend Admin by DynamiApps WordPress plugin before 3.29.11 does not perform a capability check on one of…● PoC
2026-08-29
CVE-2026-12513
MEDIUM 6.8
Shared Files — The Shared Files WordPress plugin before 1.7.67, shared-files-pro WordPress plugin before 1.7.68 do not prope…● PoC
2026-08-28
CVE-2026-12514
MEDIUM 5.3
Shared Files — The Shared Files WordPress plugin before 1.7.67, shared-files-pro WordPress plugin before 1.7.70 do not perfo…● PoC
2026-08-28
CVE-2026-14558
HIGH 7.2
User Frontend — The User Frontend WordPress plugin before 4.3.10 does not properly validate field type definitions and deseri…● PoC
2026-08-28
CVE-2026-14567
MEDIUM 5.3
User Frontend — The User Frontend WordPress plugin before 4.3.10 does not restrict access to its user directory search endpoi…● PoC
2026-08-28
CVE-2026-19084
HIGH 7.5
Shared Files Pro — The shared-files-pro WordPress plugin before 1.7.70 does not validate the file path supplied when creating a f…● PoC
2026-08-28
CVE-2026-19423
HIGH 8.1
Ultimate Member — The Ultimate Member WordPress plugin before 2.13.0 does not validate a submitted role selection when it canno…● PoC
2026-08-28
CVE-2026-77701
MEDIUM 5.3
Wcfm Marketplace — The WCFM Marketplace WordPress plugin before 3.8.2 does not correctly verify that the person requesting a ref…● PoC
2026-08-28
CVE-2026-79615
LOW 2.7
Quiz And Survey Master (Qsm) — The Quiz and Survey Master (QSM) WordPress plugin before 11.2.4 does not check authorisation when returning q…● PoC
2026-08-28
CVE-2026-79706
MEDIUM 5.3
Breeze Cache — The Breeze Cache WordPress plugin before 2.5.13 does not sanitise a value taken from the request before using …● PoC
2026-08-28
CVE-2026-79995
MEDIUM 4.3
User Registration & Membership — The User Registration & Membership WordPress plugin before 5.2.5 does not verify that the account whose pendi…● PoC
2026-08-28
CVE-2026-79996
HIGH 7.2
User Registration & Membership — The User Registration & Membership WordPress plugin before 5.2.6 does not perform a capability check when sav…● PoC
2026-08-28
CVE-2026-13414
MEDIUM 4.8
Cmp — The CMP WordPress plugin before 4.1.18 does not perform authorization checks on one of its AJAX actions and r…● PoC
2026-08-27
CVE-2026-13415
HIGH 7.2
Cmp — The CMP WordPress plugin before 4.1.18 does not enforce an option-name allow-list when importing settings via…● PoC
2026-08-27
CVE-2026-13416
LOW 3.5
Cmp — The CMP WordPress plugin before 4.1.18 does not sanitise and escape a settings value before outputting it on …● PoC
2026-08-27
CVE-2026-16567
MEDIUM 5.3
Document Embedder — The Document Embedder WordPress plugin before 2.3.1 does not check a document's status before issuing a downl…● PoC
2026-08-27
CVE-2026-16568
MEDIUM 4.3
Mobile App For Woocommerce: Shopapper Mobile App Builder Service For Woocommerce — The Mobile App for WooCommerce: ShopApper Mobile App Builder Service for WooCommerce WordPress plugin through …● PoC
2026-08-27
CVE-2026-16569
MEDIUM 4.3
Mobile App For Woocommerce: Shopapper Mobile App Builder Service For Woocommerce — The Mobile App for WooCommerce: ShopApper Mobile App Builder Service for WooCommerce WordPress plugin through …● PoC
2026-08-27
CVE-2026-19092
CRITICAL 9.8
Tutor Lms — The Tutor LMS WordPress plugin before 4.0.6 does not prevent request data from overwriting internal variables …● PoC
2026-08-27
CVE-2026-19223
HIGH 7.2
Smush — The Smush WordPress plugin before 4.3.2 does not restrict a network-wide setting to network administrators, a…● PoC
2026-08-27
CVE-2026-19225
MEDIUM 6.6
Defender Security — The Defender Security WordPress plugin before 6.2.0 does not restrict a network-wide setting to network admin…● PoC
2026-08-27
CVE-2026-19454
MEDIUM 4.4
Jetbackup — The JetBackup WordPress plugin before 3.1.23.5 does not perform its multisite authorisation check before serv…● PoC
2026-08-27
CVE-2026-19715
HIGH 7.5
Wp Oauth Server ( Login With Wordpress ) — The WP OAuth Server ( Login with WordPress ) WordPress plugin before 6.3.1 does not restrict access to the deb…● PoC
2026-08-27
CVE-2026-74232
CRITICAL 9.3
L3 V2 8 — Zbtlink L3_V2_8 firmware 3.0.0.4.528, Zbtlink WE826-T2 firmware 19.1101, Zbtlink ZBT-7628 firmware 1.0.0.2.007…● PoC
2026-08-27
CVE-2026-74233
CRITICAL 9.3
We1326 — Zbtlink WE1326, WE357, WE5926, WE5926-WD, WE826-Q, WE826-T2, WE826-WD, WG108, and WG3526 firmware 19.1101, Zbt…● PoC
2026-08-27
CVE-2026-76549
MEDIUM 5.9
Updraftplus: Wp Backup & Migration Plugin — The UpdraftPlus: WP Backup & Migration Plugin WordPress plugin before 1.26.7 does not have CSRF checks in one …● PoC
2026-08-27
CVE-2026-77016
CRITICAL 9.6
Workeera — The Workeera WordPress plugin before 1.0.6 does not restrict which values may be written to a user's own cand…● PoC
2026-08-27
CVE-2026-77017
HIGH 7.7
Workeera — The Workeera WordPress plugin before 1.0.6 does not restrict which profile values a candidate may submit, nor…● PoC
2026-08-27
CVE-2026-77018
HIGH 8.8
Workeera — The Workeera WordPress plugin before 1.0.6 does not restrict which profile values a candidate may submit, nor…● PoC
2026-08-27
CVE-2026-78125
MEDIUM 5.3
Learnpress — The LearnPress WordPress plugin before 4.0.3 does not perform any authorization check on one of its REST endp…● PoC
2026-08-27
CVE-2026-78137
HIGH 7.5
Storegrowth — The StoreGrowth WordPress plugin before 2.1.2 does not validate a browser-supplied product price on two of it…● PoC
2026-08-27
CVE-2026-78138
MEDIUM 4.3
Finale Lite — The Finale Lite WordPress plugin before 2.21.0 does not perform a capability check on an AJAX action that ret…● PoC
2026-08-27
CVE-2026-78139
MEDIUM 4.3
Notifima — The Notifima WordPress plugin before 3.1.4 does not verify that the caller owns the subscription being modifi…● PoC
2026-08-27
CVE-2026-78333
HIGH 8.8
12 Step Meeting List — The 12 Step Meeting List WordPress plugin before 3.19.17 does not sanitise and escape a value submitted by una…● PoC
2026-08-27
CVE-2026-13172
MEDIUM 5.3
Eventin — The Eventin WordPress plugin before 4.1.22 does not restrict access to non-published content by status or own…● PoC
2026-08-26
CVE-2026-13404
MEDIUM 5.3
Royal Addons For Elementor — The Royal Addons for Elementor WordPress plugin before 1.7.1066 does not perform any capability or ownership …● PoC
2026-08-26
CVE-2026-13406
MEDIUM 5.3
Royal Addons For Elementor — The Royal Addons for Elementor WordPress plugin before 1.7.1066 does not perform any capability or nonce chec…● PoC
2026-08-26
CVE-2026-14212
MEDIUM 4.7
Booking For Appointments And Events Calendar — The Booking for Appointments and Events Calendar WordPress plugin before 9.8 does not verify that an authenti…● PoC
2026-08-26
CVE-2026-14216
MEDIUM 6.5
Booking For Appointments And Events Calendar — The Booking for Appointments and Events Calendar WordPress plugin before 2.4.7 does not require authenticatio…● PoC
2026-08-26
CVE-2026-14550
MEDIUM 5.3
Wpcafe — The WPCafe WordPress plugin before 3.0.18 does not perform an authorization check when creating a reservation…● PoC
2026-08-26
CVE-2026-16984
MEDIUM 6.5
Privacy Policy Generator, Terms & Conditions, Gdpr, Ccpa, Cookie Policy & Disclaimer Templates — The Privacy Policy Generator, Terms & Conditions, GDPR, CCPA, Cookie Policy & Disclaimer Templates WordPress …● PoC
2026-08-26
CVE-2026-16986
MEDIUM 5.3
Booking Package — The Booking Package WordPress plugin before 1.7.25 does not validate the payment amount server-side against th…● PoC
2026-08-26
CVE-2026-19094
MEDIUM 5.3
Tutor Lms — The Tutor LMS WordPress plugin before 4.0.6 does not validate values used to build a database query, and does…● PoC
2026-08-26
CVE-2026-19220
LOW 3.7
Forminator Forms — The Forminator Forms WordPress plugin before 1.57.1 does not verify that site registration is enabled on the …● PoC
2026-08-26
CVE-2026-19226
MEDIUM 6.8
Royal Addons For Elementor — The Royal Addons for Elementor WordPress plugin before 1.7.1066 does not validate some widget settings before…● PoC
2026-08-26
CVE-2026-19718
HIGH 8.1
Blogvault Backup & Staging — The BlogVault Backup & Staging WordPress plugin before 6.65, MalCare WordPress Security Plugin WordPress plug…● PoC
2026-08-26
CVE-2026-74851
HIGH 7.2
Pods — The Pods WordPress plugin before 3.3.9.1 does not correctly compare a display callback against its list of bl…● PoC
2026-08-26
CVE-2026-74928
HIGH 7.5
Project Manager — The Project Manager WordPress plugin before 4.0.7 does not have any authorisation check on its import routes,…● PoC
2026-08-26
CVE-2026-74929
MEDIUM 5.4
Project Manager — The Project Manager WordPress plugin before 4.0.7 does not restrict several of its REST API routes to the pro…● PoC
2026-08-26
CVE-2026-74930
MEDIUM 4.3
Project Manager — The Project Manager WordPress plugin before 4.0.7 does not check that the user whose activity is being reques…● PoC
2026-08-26
CVE-2026-75797
HIGH 7.7
Ai Engine — The AI Engine WordPress plugin before 3.7.2 does not confine a caller-supplied URL when mapping it to a local…● PoC
2026-08-26
CVE-2026-75798
MEDIUM 5.3
Ai Engine — The AI Engine WordPress plugin before 3.7.2 does not perform an authorisation check on one of its administrat…● PoC
2026-08-26
CVE-2026-77693
HIGH 8.7
Order Tip For Woocommerce — The Order Tip for WooCommerce WordPress plugin before 1.6.0 does not check the capability of the user requesti…● PoC
2026-08-26
CVE-2026-77694
MEDIUM 5.3
Eventin — The Eventin WordPress plugin before 4.1.19 does not properly restrict which changes a guest checkout token is…● PoC
2026-08-26
CVE-2026-77695
MEDIUM 6.5
Return Refund And Exchange For Woocommerce — The Return Refund and Exchange For WooCommerce WordPress plugin before 4.6.4 does not correctly verify the own…● PoC
2026-08-26
CVE-2026-77754
MEDIUM 5.3
Kirki — The Kirki WordPress plugin before 6.0.14 does not perform a capability check on some endpoints of one of its …● PoC
2026-08-26
CVE-2026-77757
MEDIUM 5.4
Directorist: Ai Powered Business Directory, Listings & Classified Ads — The Directorist: AI-Powered Business Directory, Listings & Classified Ads WordPress plugin before 8.9.3 does n…● PoC
2026-08-26
CVE-2026-77758
MEDIUM 5.3
Stripe Payment Forms By Wp Full Pay — The Stripe Payment Forms by WP Full Pay WordPress plugin before 8.5.1 does not properly verify that a custome…● PoC
2026-08-26
CVE-2026-77789
MEDIUM 4.3
Stripe Payment Forms By Wp Full Pay — The Stripe Payment Forms by WP Full Pay WordPress plugin before 8.5.1 does not verify that a subscription bel…● PoC
2026-08-26
CVE-2026-77790
MEDIUM 5.5
Registrationmagic — The RegistrationMagic WordPress plugin before 6.0.9.4 does not sanitise and escape a parameter before using i…● PoC
2026-08-26
CVE-2026-78146
MEDIUM 6.5
Simple Newsletter Plugin — The Simple Newsletter Plugin WordPress plugin before 4.3.3 does not verify that the requester is the subscrib…● PoC
2026-08-26
CVE-2026-74932
HIGH 7.5
Wp Fastest Cache — The WP Fastest Cache WordPress plugin before 1.5.1 does not validate the Host header before using it to build …● PoC
2026-08-25
CVE-2026-13598
CRITICAL 9.8
Restrictmate — The RestrictMate WordPress plugin before 1.3.0 does not restrict the user role supplied during account regist…● PoC
2026-08-23
CVE-2026-14853
MEDIUM 4.3
Woocommerce Bookings — The WooCommerce Bookings WordPress plugin before 3.9.0 does not perform a capability check on one of its AJAX …● PoC
2026-08-23
CVE-2026-77003
LOW 2.7
Content Mask — The Content Mask WordPress plugin before 1.8.5.5 does not check the capability required to publish the post ty…● PoC
2026-08-23
CVE-2026-77115
HIGH 7.1
Brave — Brave Popup Builder (brave-popup-builder) up to version 0.8.5 reflects UTM query parameters into popup form HT…● PoC
2026-08-23
CVE-2026-77116
MEDIUM 4.3
Brave — Brave Popup Builder (slug: brave-popup-builder) has a broken access control issue in versions through 0.8.5. A…● PoC
2026-08-23
CVE-2026-14187
LOW 2.7
Tutor Lms — The Tutor LMS WordPress plugin before 4.0.6 does not enforce per-object ownership checks on its course conten…● PoC
2026-08-22
CVE-2026-16260
MEDIUM 6.8
Post Grid, Slider & Carousel Ultimate — The Post Grid, Slider & Carousel Ultimate WordPress plugin before 1.8.1 does not sanitise and escape one of i…● PoC
2026-08-22
CVE-2026-16612
MEDIUM 5.3
Fibosearch — The FiboSearch WordPress plugin before 1.34.1 does not consistently exclude password-protected products from …● PoC
2026-08-22
CVE-2026-16738
MEDIUM 5.3
Conekta Payment Gateway — The Conekta Payment Gateway WordPress plugin before 6.2.2 does not verify the authenticity of incoming payment…● PoC
2026-08-22
CVE-2026-18052
HIGH 8.1
Managewp Worker — The ManageWP Worker WordPress plugin before 4.9.37 does not bind the account being logged in to the signature …● PoC
2026-08-22
CVE-2026-19093
MEDIUM 6.8
Tutor Lms — The Tutor LMS WordPress plugin before 4.0.6 does not validate a stored file path before using it to stream me…● PoC
2026-08-22
CVE-2026-19221
HIGH 7.2
Forminator Forms — The Forminator Forms WordPress plugin before 1.57.0.5 does not restrict a network-wide setting to network adm…● PoC
2026-08-22
CVE-2026-19222
MEDIUM 6.6
Forminator Forms — The Forminator Forms WordPress plugin before 1.57.0.7 does not consistently enforce the role restriction it a…● PoC
2026-08-22
CVE-2026-76789
HIGH 8.8
Slider Hero With Video Background, Animation — The Slider Hero with Video Background, Animation WordPress plugin before 9.1.3 does not have authorisation and…● PoC
2026-08-22
CVE-2026-76793
HIGH 8.1
Firebase Authentication — The Firebase Authentication WordPress plugin before 1.7.1 does not require the email address in an authenticat…● PoC
2026-08-22
CVE-2026-77000
CRITICAL 9.8
Wp Social Media Login — The WP Social Media Login WordPress plugin through 1.0.6 does not verify that a social login was actually comp…● PoC
2026-08-22
CVE-2026-77001
CRITICAL 9.8
Social Login & Sharing Buttons With Analytics By Soclever — The Social Login & Sharing buttons with Analytics By SoClever WordPress plugin through 1.2.0 does not perform …● PoC
2026-08-22
CVE-2026-77002
CRITICAL 9.8
Smilepass Selfie Login — The SmilePass Selfie Login WordPress plugin through 1.0.2 does not perform any server-side verification of the…● PoC
2026-08-22
CVE-2026-13176
LOW 2.7
Eventin — The Eventin WordPress plugin before 4.1.21 does not validate a user-supplied webhook URL stored on events nor …● PoC
2026-08-21
CVE-2026-13736
MEDIUM 5.3
Newpath Wildapricotpress Add On — The NewPath WildApricotPress Add-on WordPress plugin through 1.0.0 does not enforce its members-only field pr…● PoC
2026-08-21
CVE-2026-14325
LOW 3.5
Drag And Drop Multiple File Upload For Contact Form 7 — The Drag and Drop Multiple File Upload for Contact Form 7 WordPress plugin before 1.3.9.9 does not escape one …● PoC
2026-08-21
CVE-2026-14601
MEDIUM 6.8
Link Whisper Free — The Link Whisper Free WordPress plugin before 0.9.7 does not properly sanitize and escape a parameter before u…● PoC
2026-08-21
CVE-2026-15046
MEDIUM 4.2
Litextension — The LitExtension WordPress plugin through 1.2.5 does not verify a nonce before an administrative action that o…● PoC
2026-08-21
CVE-2026-15150
MEDIUM 5.3
Mycred — The myCred WordPress plugin before 3.2.5 does not verify that the receiver of an incoming payment gateway noti…● PoC
2026-08-21
CVE-2026-16575
MEDIUM 5.3
Dokan: Ai Powered Woocommerce Multivendor Marketplace Solution — The Dokan: AI Powered WooCommerce Multivendor Marketplace Solution WordPress plugin before 5.0.14 does not re…● PoC
2026-08-21
CVE-2026-16576
HIGH 7.2
Dokan: Ai Powered Woocommerce Multivendor Marketplace Solution — The Dokan: AI Powered WooCommerce Multivendor Marketplace Solution WordPress plugin before 5.0.14 does not co…● PoC
2026-08-21
CVE-2026-16577
LOW 2.7
Dokan: Ai Powered Woocommerce Multivendor Marketplace Solution — The Dokan: AI Powered WooCommerce Multivendor Marketplace Solution WordPress plugin before 5.0.14 does not va…● PoC
2026-08-21
CVE-2026-16650
MEDIUM 5.3
Charitable — The Charitable WordPress plugin before 1.8.12 does not verify the authenticity of incoming Square payment webh…● PoC
2026-08-21
CVE-2026-16959
MEDIUM 6.8
Media Library Assistant — The Media Library Assistant WordPress plugin before 3.40 does not validate a search parameter before concatena…● PoC
2026-08-21
CVE-2026-16962
MEDIUM 5.3
Tamara Checkout — The Tamara Checkout WordPress plugin through 1.9.9.20 does not verify the order key, a nonce, or any capabilit…● PoC
2026-08-21
CVE-2026-17559
MEDIUM 5.3
Passster — The Passster WordPress plugin before 4.3.9 does not correctly match its own public endpoint paths when decidin…● PoC
2026-08-21
CVE-2026-18356
LOW 3.7
Limit Login Attempts Security — The Limit Login Attempts Reloaded WordPress plugin before 3.3.5 does not compare logins against its username d…● PoC
2026-08-21
CVE-2026-18781
HIGH 8.1
Drag And Drop Multiple File Upload For Contact Form 7 — The Drag and Drop Multiple File Upload for Contact Form 7 WordPress plugin before 1.3.9.9 does not validate th…● PoC
2026-08-21
CVE-2026-19085
LOW 2.7
Duplicate Post — The Duplicate Post WordPress plugin before 1.5.6 does not check that a user may read the content of a post bef…● PoC
2026-08-21
CVE-2026-19435
LOW 2.7
Duplicate Post — The Duplicate Post WordPress plugin before 1.5.6 does not check the user's capabilities before returning post …● PoC
2026-08-21
CVE-2026-19848
MEDIUM 6.5
Profilepress — The ProfilePress WordPress plugin before 4.17.1 does not strip shortcodes from two of its profile fields befor…● PoC
2026-08-21
CVE-2026-75796
HIGH 7.2
Ai Engine — The AI Engine WordPress plugin before 3.6.1 does not verify that the requesting user is authorized to act on …● PoC
2026-08-21
CVE-2025-15671
MEDIUM 5.4
Welcart E Commerce — The Welcart e-Commerce WordPress plugin before 2.12.1 does not regenerate the session identifier on authentica…● PoC
2026-08-21
CVE-2026-13405
MEDIUM 6.6
Royal Addons For Elementor — The Royal Addons for Elementor WordPress plugin before 1.7.1066 does not correctly sanitise custom widget mar…● PoC
2026-08-20
CVE-2026-15049
HIGH 7.2
Depicter — Popup & Slider Builder — The Depicter — Popup & Slider Builder WordPress plugin before 4.8.0 does not validate the type of a file uploa…● PoC
2026-08-20
CVE-2026-19615
MEDIUM 6.8
Admin And Site Enhancements (Ase) — The Admin and Site Enhancements (ASE) WordPress plugin before 9.0.1 does not sanitise uploaded SVG files on ev…● PoC
2026-08-20
CVE-2026-19697
MEDIUM 6.8
Gutenkit — The GutenKit WordPress plugin before 2.5.0 does not sanitise uploaded SVG files on all of the upload paths it…● PoC
2026-08-20
CVE-2026-19699
LOW 2.7
Gutenkit — The GutenKit WordPress plugin before 2.5.0 does not have a sufficient capability check on some of its REST AP…● PoC
2026-08-20
CVE-2026-74992
MEDIUM 6.8
Kirki — The Kirki WordPress plugin before 6.2.3 does not properly validate the files contained in archives uploaded b…● PoC
2026-08-20
CVE-2026-75860
CRITICAL 9.8
Json Options — The JSON Options WordPress plugin through 0.0.4 does not have any capability check or nonce verification on on…● PoC
2026-08-20
CVE-2026-11565
HIGH 8.5
Advanced File Manager — The Advanced File Manager WordPress plugin before 5.4.13 does not perform capability checks in several of its…● PoC
2026-08-19
CVE-2026-12983
HIGH 8.6
Dinatur — The Dinatur WordPress plugin through 1.18 does not sanitize and escape user input before using it in a SQL que…● PoC
2026-08-19
CVE-2026-13169
HIGH 8.1
Eventin — The Eventin WordPress plugin before 4.1.21 does not properly verify ownership of events before allowing them …● PoC
2026-08-19
CVE-2026-13173
LOW 2.7
Eventin — The Eventin WordPress plugin before 4.1.21 does not verify the current user's permission to edit other users …● PoC
2026-08-19
CVE-2026-13174
HIGH 7.2
Eventin — The Eventin WordPress plugin before 4.1.21 does not verify ownership or capability before deleting user accou…● PoC
2026-08-19
CVE-2026-13175
MEDIUM 6.5
Eventin — The Eventin WordPress plugin before 4.1.21 does not verify ownership before allowing schedule records to be m…● PoC
2026-08-19
CVE-2026-14196
MEDIUM 4.3
Wcfm Marketplace — The WCFM Marketplace WordPress plugin before 3.8.1 does not verify that a marketplace vendor owns a review be…● PoC
2026-08-19
CVE-2026-14287
MEDIUM 4.7
10web Booster — The 10Web Booster WordPress plugin before 2.33.5 does not correctly validate an access token on an unauthenti…● PoC
2026-08-19
CVE-2026-14334
HIGH 8.8
Booking Calendar, Appointment Booking System — The Booking calendar, Appointment Booking System WordPress plugin through 3.2.36 does not properly sanitize up…● PoC
2026-08-19
CVE-2026-14825
LOW 2.7
Quiz And Survey Master (Qsm) — The Quiz and Survey Master (QSM) WordPress plugin before 11.2.4 does not perform a per-object ownership check…● PoC
2026-08-19
CVE-2026-14826
LOW 2.7
Quiz And Survey Master (Qsm) — The Quiz and Survey Master (QSM) WordPress plugin before 11.2.4 does not perform a per-object ownership check…● PoC
2026-08-19
CVE-2026-14861
HIGH 7.5
User Verification By Pickplugins — The User Verification by PickPlugins WordPress plugin through 2.0.47 does not verify that a request to resend …● PoC
2026-08-19
CVE-2026-15253
MEDIUM 6.8
Easy Media Replace — The Easy Media Replace WordPress plugin through 0.2.0 does not sanitise and escape an attachment title before …● PoC
2026-08-19
CVE-2026-16058
MEDIUM 5.3
Yaycurrency — The YayCurrency WordPress plugin before 3.3.5 does not perform any capability or ownership check on several o…● PoC
2026-08-19
CVE-2026-16570
HIGH 7.1
Nextscripts: Social Networks Auto Poster — The NextScripts: Social Networks Auto-Poster WordPress plugin before 4.4.8 does not escape some of the query-s…● PoC
2026-08-19
CVE-2026-16616
HIGH 8.6
Simple File List — The Simple File List WordPress plugin through 6.3.11 does not validate the source path of a file-move operatio…● PoC
2026-08-19
CVE-2026-16617
HIGH 8.8
Simple File List — The Simple File List WordPress plugin through 6.3.11 does not properly sanitise and escape a file's descriptio…● PoC
2026-08-19
CVE-2026-16950
HIGH 8.6
Product Shortlist — The Product Shortlist WordPress plugin through 1.0.4 does not properly sanitise and escape a parameter before …● PoC
2026-08-19
CVE-2026-16979
MEDIUM 4.3
Smartcrawl Seo Checker, Analyzer & Optimizer — The SmartCrawl SEO checker, analyzer & optimizer WordPress plugin before 3.16.3 does not perform capability ch…● PoC
2026-08-19
CVE-2026-17565
HIGH 7.2
Animation Addons For Elementor — The Animation Addons for Elementor WordPress plugin before 2.7.2 does not validate a user-supplied value befo…● PoC
2026-08-19
CVE-2026-18031
CRITICAL 9.8
Tabapay Gateway — The TabaPay Gateway WordPress plugin through 1.4.0 does not validate the payment callback before establishing …● PoC
2026-08-19
CVE-2026-18051
CRITICAL 10
W3 Total Cache — The W3 Total Cache WordPress plugin before 2.10.5 does not properly validate the request path it uses to build…● PoC
2026-08-19
CVE-2026-18202
MEDIUM 6.8
Jetengine — The JetEngine WordPress plugin before 3.8.14 adds SVG to the site-wide list of allowed upload types without sa…● PoC
2026-08-19
CVE-2026-18231
MEDIUM 5.3
Wp Directory Kit — The WP Directory Kit WordPress plugin before 1.5.7 does not perform any authorization check on one of its publ…● PoC
2026-08-19
CVE-2026-18466
MEDIUM 5.4
Wp Maps — The WP Maps WordPress plugin before 4.9.8 does not perform a capability check, nor validate a nonce, in one o…● PoC
2026-08-19
CVE-2026-18776
CRITICAL 9.8
Truebooker — The TrueBooker WordPress plugin before 1.2.7 does not have proper authorisation checks in some of its AJAX ac…● PoC
2026-08-19
CVE-2026-18777
MEDIUM 5.3
Truebooker — The TrueBooker WordPress plugin before 1.2.7 does not have proper authorisation checks in one of its AJAX act…● PoC
2026-08-19
CVE-2026-18778
MEDIUM 5.3
Truebooker — The TrueBooker WordPress plugin before 1.2.7 does not have proper authorisation checks in some of its AJAX ac…● PoC
2026-08-19
CVE-2026-18779
MEDIUM 5.3
Truebooker — The TrueBooker WordPress plugin before 1.2.7 does not have proper authorisation checks in one of its AJAX act…● PoC
2026-08-19
CVE-2026-18937
CRITICAL 9
Broken Link Checker — The Broken Link Checker WordPress plugin before 2.4.12 does not limit which query variables it accepts from us…● PoC
2026-08-19
CVE-2026-19055
HIGH 7.1
Prosolution Wp Client — The ProSolution WP Client WordPress plugin before 2.0.11 does not sanitise and escape several parameters befor…● PoC
2026-08-19
CVE-2026-19056
HIGH 7.1
Prosolution Wp Client — The ProSolution WP Client WordPress plugin before 2.0.11 does not sanitise and escape a parameter before refle…● PoC
2026-08-19
CVE-2026-19406
LOW 2.7
Easy Appointments — The Easy Appointments WordPress plugin before 4.0.1 does not restrict one of its appointment-listing REST endp…● PoC
2026-08-19
CVE-2026-19416
MEDIUM 4.3
Kivicare — The KiviCare WordPress plugin before 4.5.4 does not verify that the requesting user owns the appointment bein…● PoC
2026-08-19
CVE-2026-19417
MEDIUM 6.5
Kivicare — The KiviCare WordPress plugin before 4.5.4 does not verify that the requesting user is entitled to the media …● PoC
2026-08-19
CVE-2026-19709
MEDIUM 5.3
Membership For Woocommerce — The Membership For WooCommerce WordPress plugin before 3.1.2 does not check that an API consumer secret has ac…● PoC
2026-08-19
CVE-2026-19782
MEDIUM 5.4
Wps Bidouille — The WPS Bidouille WordPress plugin before 1.33.5 does not have proper authorisation checks in an AJAX action, …● PoC
2026-08-19
CVE-2026-19842
HIGH 8.8
Saml Single Sign On — The SAML Single Sign On WordPress plugin before 5.4.7 does not verify the signature of a SAML response before…● PoC
2026-08-19
CVE-2026-13700
MEDIUM 5.9
Wooms — The WooMS WordPress plugin through 9.14 does not validate a user-supplied URL before using it in a server-side…● PoC
2026-08-17
CVE-2026-14832
MEDIUM 5.3
Shopsmart Loyalty For Woocommerce — The ShopSmart Loyalty for WooCommerce WordPress plugin through 1.0.0 does not perform any authorization or own…● PoC
2026-08-17