1432 Total CVEs
1428 AI Analyzed
2 CISA KEV
436 Critical
All Vendors
Showing 1-1432 of 1432 CVEs
CVE-2026-9860
Analyzed
8.8
WordPress Offload, AI & Optimize with Cloudflare Images

The Offload, AI & Optimize with Cloudflare Images plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 1

2026-06-18
CVE-2026-9843
Analyzed
8.1
WordPress Database for Contact Form 7, WPforms, Elementor forms plugin

The Database for Contact Form 7, WPforms, Elementor forms plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path...

2026-06-21
CVE-2026-9833
Analyzed
7.1
WordPress Tag Groups is the Advanced Way to Display Your Taxonomy Terms

The Tag Groups is the Advanced Way to Display Your Taxonomy Terms WordPress plugin before 2.2.0 does not properly escape one of its AJAX parameters be...

2026-07-23
CVE-2026-9830
Analyzed
8.2
WordPress BookingPress Appointment Booking Pro

The bookingpress-appointment-booking-pro WordPress plugin before 5

2026-07-28
CVE-2026-9810
Analyzed
9.8
WordPress AI Copilot (WordPress Plugin)

The AI Copilot WordPress plugin fails to bind OAuth tokens to specific users, allowing unauthenticated attackers to impersonate administrators and exe...

2026-07-18
CVE-2026-9725
Analyzed
9.1
WordPress Printcart Web to Print Product Designer for WooCommerce

The Printcart Web to Print Product Designer for WooCommerce plugin for WordPress is vulnerable to unauthenticated arbitrary file deletion via improper...

2026-07-03
CVE-2026-9711
Analyzed
9.8
WordPress EventON (Pro) - WordPress Virtual Event Calendar Plugin

The EventON WordPress plugin is vulnerable to unauthenticated SQL injection via the search parameter due to insufficient input escaping and lack of pa...

2026-07-01
CVE-2026-9701
Analyzed
9.8
WordPress Eventer

The Eventer WordPress plugin stores password reset keys in plaintext, allowing unauthenticated attackers to hijack user accounts.

2026-07-08
CVE-2026-9662
Analyzed
8.1
WordPress Recover Exit For WooCommerce Plugin

The Recover Exit For WooCommerce plugin for WordPress is vulnerable to Local File Inclusion in all versions up to and including 1

2026-06-09
CVE-2026-9282
Analyzed
7.5
WordPress W3 Total Cache

The W3 Total Cache plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 2

2026-07-11
CVE-2026-9227
Analyzed
8.8
WordPress is vulnerable

The GutenBee – Gutenberg Blocks plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 2

2026-05-28
CVE-2026-9055
Analyzed
9.8
WordPress Booking for Appointments and Events Calendar – Amelia

The Amelia WordPress plugin contains a critical privilege escalation vulnerability allowing unauthenticated attackers to gain administrative access vi...

2026-09-02
CVE-2026-9018
Analyzed
8.8
WordPress is vulnerable

The Easy Elements for Elementor – Addons & Website Templates plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and inc...

2026-05-22
CVE-2026-9010
Analyzed
7.5
WordPress is vulnerable

The Boost plugin for WordPress is vulnerable to time-based SQL Injection via the 'current_url' and 'user_name' parameters in versions up to, and inclu...

2026-05-20
CVE-2026-9009
Analyzed
8.8
WordPress is vulnerable

The Crawlomatic Multipage Scraper Post Generator plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 2

2026-05-28
CVE-2026-8935
Analyzed
9.8
WordPress WP MAPS PRO Plugin

The WP MAPS PRO WordPress plugin allows unauthenticated attackers to create administrator accounts via an improperly secured AJAX action.

2026-06-16
CVE-2026-8912
Analyzed
7.5
WordPress is vulnerable

The Contest Gallery plugin for WordPress is vulnerable to SQL Injection via the 'form_input' parameter in versions up to, and including, 28

2026-05-20
CVE-2026-8832
Analyzed
8.8
WordPress Code Manager Plugin

The WPCode - Insert Headers and Footers + Custom Code Snippets - WordPress Code Manager plugin for WordPress is vulnerable to Remote Code Execution in...

2026-05-27
CVE-2026-8809
Analyzed
9.8
WordPress Advanced Custom Fields: Extended Plugin

The Advanced Custom Fields: Extended plugin for WordPress contains a validation bypass vulnerability that allows unauthenticated attackers to create n...

2026-05-29
CVE-2026-8789
Analyzed
8.1
WordPress Easy Appointments

The Easy Appointments plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check and missing nonce veri...

2026-07-25
CVE-2026-8787
Analyzed
8.8
WordPress Support & Chat Management Plugin

The Firebase Support & Chat Management plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 3

2026-05-27
CVE-2026-8761
Analyzed
8.8
WordPress AI Powered WooCommerce Multivendor Marketplace Solution

The Dokan plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 5

2026-08-05
CVE-2026-8760
Analyzed
9.8
WordPress Login with OTP

The WordPress "Login with OTP" plugin is vulnerable to authentication bypass via brute-forcing of the 6-digit OTP, which lacks expiration and rate-lim...

2026-05-27
CVE-2026-8732
Analyzed
9.8
WordPress is vulnerable

The WP Maps Pro plugin for WordPress is vulnerable to Privilege Escalation via Administrator Account Creation in all versions up to, and including, 6....

2026-05-29
CVE-2026-8719
Analyzed
8.8
WordPress plugin for

The AI Engine – The Chatbot, AI Framework & MCP for WordPress plugin for WordPress is vulnerable to Privilege Escalation in version 3

2026-05-17
CVE-2026-84814
Analyzed
9.8
WordPress Bricksforge

The Bricksforge WordPress plugin contains a vulnerability that allows unauthenticated subscribers to escalate their privileges, potentially gaining ad...

2026-09-04
CVE-2026-84779
Analyzed
8.1
WordPress Agentimus – AI SEO, llms.txt & MCP for AI Agents

Subscriber Broken Access Control in Agentimus – AI SEO, llms.txt &amp; MCP for AI Agents <= 1.51.0 versions.

2026-09-04
CVE-2026-84770
Analyzed
8.8
WordPress Mang Board WP

Unauthenticated Cross Site Request Forgery (CSRF) in Mang Board WP <= 2.3.8 versions.

2026-09-03
CVE-2026-84764
Analyzed
8.8
WordPress Simply Schedule Appointments

Unauthenticated Cross Site Request Forgery (CSRF) in Simply Schedule Appointments <= 1.6.12.23 versions.

2026-09-03
CVE-2026-84757
Analyzed
8.2
WordPress WP Compress

Unauthenticated Settings Change in WP Compress <= 7.21.28 versions.

2026-09-04
CVE-2026-8444
Analyzed
8.8
WordPress WP Review Slider Pro

The WP Review Slider Pro plugin for WordPress is vulnerable to SQL Injection via the 'curselrevs[]' parameter of the wpfb_find_reviews AJAX action in...

2026-06-16
CVE-2026-8443
Analyzed
8.8
WordPress WP Review Slider Pro

The WP Review Slider Pro plugin for WordPress is vulnerable to SQL Injection via the 'stypes' and 'slocations' parameters of the wppro_get_overall_cha...

2026-06-16
CVE-2026-84238
Analyzed
9.8
WordPress Request a Quote for WooCommerce Premium

YITH Request a Quote for WooCommerce Premium versions prior to 4.46.0 contain an unauthenticated broken access control vulnerability, allowing unautho...

2026-09-04
CVE-2026-83627
Analyzed
9.8
WordPress Hummingbird Performance

The Hummingbird WordPress plugin is vulnerable to unauthenticated remote code execution due to improper sanitization of cookie data written to a web-a...

2026-09-05
CVE-2026-82970
Analyzed
10
WordPress WP Cookie Notice for GDPR, CCPA & ePrivacy Consent

A critical unrestricted file upload vulnerability in the WP Cookie Notice plugin allows unauthenticated attackers to upload and execute arbitrary mali...

2026-09-01
CVE-2026-82923
Analyzed
9.8
WordPress AI Website Builder (WordPress plugin)

The AI Website Builder WordPress plugin lacks authorization checks on REST API routes, enabling unauthenticated attackers to execute arbitrary code, m...

2026-09-05
CVE-2026-82228
Analyzed
8.1
WordPress SiteGround Security

Unauthenticated Bypass Vulnerability in SiteGround Security <= 1.6.6 versions.

2026-09-01
CVE-2026-82225
Analyzed
7.4
WordPress RegistrationMagic

Unauthenticated Broken Authentication in RegistrationMagic <= 6.0.9.8 versions.

2026-09-01
CVE-2026-82222
Analyzed
10
WordPress GiveWP

A deserialization of untrusted data vulnerability in the GiveWP WordPress plugin allows unauthenticated attackers to perform remote code execution via...

2026-08-29
CVE-2026-82183
Analyzed
8.1
WordPress OAuth Single Sign On

The OAuth Single Sign On WordPress plugin before 7.0.1 does not verify the identity assertion returned by its Steam single sign-on flow, allowing una...

2026-09-05
CVE-2026-8206
Analyzed
9.8
WordPress Kirki Plugin

The Kirki plugin for WordPress is vulnerable to unauthenticated privilege escalation via an account takeover flaw in the password reset process.

2026-06-02
CVE-2026-81807
Analyzed
8.8
WordPress Simple Ajax Chat

The Simple Ajax Chat WordPress plugin before 20260827 does not escape chat message content before rendering it, allowing unauthenticated users to inj...

2026-09-03
CVE-2026-81780
Analyzed
10
WordPress Hash Form

A critical vulnerability in the Hash Form WordPress plugin allows unauthenticated attackers to perform arbitrary file uploads, potentially leading to...

2026-09-01
CVE-2026-81779
Analyzed
10
WordPress Newspapers X

A critical input validation vulnerability in the Silk Themes Newspapers X WordPress theme allows for the installation of malicious software.

2026-09-01
CVE-2026-81769
Analyzed
8.8
WordPress Booking Hub

Incorrect Privilege Assignment vulnerability in LiquidThemes Booking Hub allows Privilege Escalation. This issue affects Booking Hub: from n/a throug...

2026-09-03
CVE-2026-81767
Analyzed
7.5
WordPress Simple Payment

Unauthenticated Broken Access Control in Simple Payment <= 2.5.2 versions.

2026-08-30
CVE-2026-81763
Analyzed
9.3
WordPress Throws SPAM Away

The Throws SPAM Away WordPress plugin contains an unauthenticated SQL injection vulnerability in versions 3.8.2 and earlier, allowing remote attackers...

2026-09-01
CVE-2026-81756
Analyzed
9.3
WordPress Smart Marketing SMS and Newsletters Forms

A critical SQL injection vulnerability in the Smart Marketing SMS and Newsletters Forms plugin allows unauthenticated attackers to query the database.

2026-09-01
CVE-2026-81737
Analyzed
8.8
WordPress FAQ Builder AYS

The FAQ Builder AYS WordPress plugin before 1.8.5 does not sanitize or escape content submitted by unauthenticated visitors before storing it and outp...

2026-09-03
CVE-2026-81660
Analyzed
8.8
WordPress CRM, Newsletters, and Marketing Automation

The Groundhogg — CRM, Newsletters, and Marketing Automation WordPress plugin before 4.5.13 does not validate or escape values submitted to some option...

2026-09-03
CVE-2026-8163
Analyzed
8.8
WordPress Infility Global Plugin

The Infility Global WordPress plugin before 2

2026-06-24
CVE-2026-8157
Analyzed
8.8
WordPress Vitepos

The Vitepos WordPress plugin before 3

2026-06-23
CVE-2026-81543
Analyzed
8.8
WordPress Abandoned Cart Pro for WooCommerce

The Abandoned Cart Pro for WooCommerce plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 10.7.1. This i...

2026-09-05
CVE-2026-81297
Analyzed
7.5
WordPress Fluent Forms Pro Add On Pack

Subscriber Privilege Escalation in Fluent Forms Pro Add On Pack <= 6.2.12 versions.

2026-09-01
CVE-2026-81296
Analyzed
7.5
WordPress Fluent Forms Pro Add On Pack

Unauthenticated Broken Access Control in Fluent Forms Pro Add On Pack <= 6.2.12 versions.

2026-09-01
CVE-2026-81294
Analyzed
9.8
WordPress Authorizer

The Authorizer plugin for WordPress contains an unauthenticated privilege escalation vulnerability due to incorrect privilege assignment, allowing una...

2026-09-03
CVE-2026-81293
Analyzed
9.3
WordPress WP Data Access

An unauthenticated SQL injection vulnerability in the WP Data Access plugin allows remote attackers to execute arbitrary SQL commands.

2026-09-01
CVE-2026-81287
Analyzed
8.5
WordPress Charitable

Subscriber SQL Injection in Charitable <= 1.8.12.1 versions.

2026-09-01
CVE-2026-81286
Analyzed
9.3
WordPress WCFM Marketplace

WCFM Marketplace for WordPress contains an unauthenticated SQL injection vulnerability in versions 3.8.1 and earlier, allowing attackers to extract se...

2026-09-03
CVE-2026-81285
Analyzed
7.5
WordPress Smush Image Compression and Optimization

Unauthenticated Denial of Service Attack in Smush Image Compression and Optimization <= 4.2.0 versions.

2026-08-30
CVE-2026-81277
Analyzed
8.5
WordPress Suggestion Engine for WooCommerce

Contributor SQL Injection in Suggestion Engine for WooCommerce <= 2.0.11 versions.

2026-08-28
CVE-2026-81273
Analyzed
8.1
WordPress FluentBooking Pro

Unauthenticated Cross Site Request Forgery (CSRF) in FluentBooking Pro <= 2.2.4 versions.

2026-08-28
CVE-2026-81271
Analyzed
8.8
WordPress GeoDirectory

Unauthenticated Cross Site Request Forgery (CSRF) in GeoDirectory <= 2.8.176 versions.

2026-08-28
CVE-2026-8095
Analyzed
8.1
WordPress Frontend File Manager Plugin

The Frontend File Manager Plugin plugin for WordPress is vulnerable to Authenticated Arbitrary File Deletion in versions up to and including 23

2026-06-28
CVE-2026-8082
Analyzed
7.5
WordPress bpost-shipping-platform

The bpost-shipping-platform WordPress plugin before 3.2.3 does not properly sanitize a parameter before using it in a SQL query during WooCommerce ord...

2026-07-26
CVE-2026-8073
Analyzed
7.5
WordPress is vulnerable

The Kirki – Freeform Page Builder, Website Builder & Customizer plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file...

2026-05-20
CVE-2026-8071
Analyzed
8.8
WordPress Anti-Spam by CleanTalk plugin

The Anti-Spam by CleanTalk

2026-06-11
CVE-2026-80467
Analyzed
8.1
WordPress Advanced Custom Fields: Extended

The Advanced Custom Fields: Extended WordPress plugin before 0.9.2.7 does not restrict the role submitted through its front-end user forms to the role...

2026-09-05
CVE-2026-78657
Analyzed
9.8
WordPress SigmaForms Pro – AI Generated Forms

The SigmaForms Pro WordPress plugin is vulnerable to unauthenticated arbitrary file deletion via path traversal, which can lead to remote code executi...

2026-09-02
CVE-2026-7862
Analyzed
8.6
WordPress plugin before

The Eupago Gateway For Woocommerce WordPress plugin before 4

2026-05-29
CVE-2026-78570
Analyzed
9.8
WordPress Total Donations

The Total Donations plugin for WordPress is vulnerable to unauthenticated privilege escalation, allowing remote attackers to gain administrative acces...

2026-08-26
CVE-2026-78568
Analyzed
9.8
WordPress Total Donations

The Total Donations plugin for WordPress contains an SQL injection vulnerability that allows unauthenticated attackers to extract sensitive database i...

2026-08-25
CVE-2026-78566
Analyzed
8.1
WordPress Shuffle

The Shuffle theme for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1

2026-08-25
CVE-2026-78562
Analyzed
8.1
WordPress Verdure Core

The Verdure Core plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1

2026-08-25
CVE-2026-78478
Analyzed
8.1
WordPress Mane

The Mane theme for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1

2026-08-25
CVE-2026-78477
Analyzed
9.8
WordPress Jawn

The Jawn theme for WordPress is susceptible to an unauthenticated privilege escalation vulnerability, allowing attackers to gain administrative contro...

2026-08-25
CVE-2026-78333
Analyzed
8.8
WordPress 12 Step Meeting List

The 12 Step Meeting List WordPress plugin before 3.19.17 does not sanitise and escape a value submitted by unauthenticated users before storing it in...

2026-08-28
CVE-2026-78285
Analyzed
8.5
WordPress Like Button Rating

Subscriber SQL Injection in Like Button Rating <= 2.6.61 versions.

2026-08-28
CVE-2026-78284
Analyzed
8.6
WordPress MasterStudy LMS

Unauthenticated Arbitrary File Deletion in MasterStudy LMS <= 3

2026-08-25
CVE-2026-78270
Analyzed
7.6
WordPress FluentCRM Pro

Author SQL Injection in FluentCRM Pro <= 3

2026-08-25
CVE-2026-78268
Analyzed
7.5
WordPress Lead Generation Contact Widget & AI Chatbot (SiteLeads)

Unauthenticated Sensitive Data Exposure in Lead Generation Contact Widget &amp; AI Chatbot: Chat Button, Phone Call, Telegram, Email – SiteLeads <= 1

2026-08-25
CVE-2026-78267
Analyzed
9.8
WordPress TranslatePress

The TranslatePress WordPress plugin contains an unauthenticated privilege escalation vulnerability, allowing remote attackers to gain unauthorized adm...

2026-08-25
CVE-2026-78137
Analyzed
7.5
WordPress StoreGrowth (WordPress Plugin)

The StoreGrowth WordPress plugin before 2.1.2 does not validate a browser-supplied product price on two of its unauthenticated actions, allowing unau...

2026-09-02
CVE-2026-7802
Analyzed
8.8
WordPress is vulnerable

The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 3

2026-05-28
CVE-2026-78003
Analyzed
9.8
WordPress Mailgun for WordPress

A Server-Side Request Forgery (SSRF) vulnerability in the Mailgun for WordPress plugin allows unauthenticated attackers to perform unauthorized API ac...

2026-08-22
CVE-2026-77693
Analyzed
8.7
WordPress Order Tip for WooCommerce

The Order Tip for WooCommerce WordPress plugin before 1

2026-08-27
CVE-2026-7761
Analyzed
8.8
WordPress Ultimate Member Plugin

The Ultimate Member plugin for WordPress is vulnerable to Account Takeover via Password Reset Link Disclosure in all versions up to and including 2

2026-06-24
CVE-2026-77264
Analyzed
9.8
WordPress Automation Web Platform – Notifications and OTP for WooCommerce, Advanced Country Code

The Automation Web Platform plugin for WordPress is vulnerable to an authentication bypass, allowing unauthenticated attackers to log in as any user,...

2026-08-21
CVE-2026-77115
Analyzed
7.1
WordPress Popup Builder

Brave Popup Builder (brave-popup-builder) up to version 0

2026-08-24
CVE-2026-77018
Analyzed
8.8
WordPress Workeera

The Workeera WordPress plugin before 1.0.6 does not restrict which profile values a candidate may submit, nor validate the type of the file it subseq...

2026-08-28
CVE-2026-77017
Analyzed
7.7
WordPress Workeera WordPress plugin

The Workeera WordPress plugin before 1.0.6 does not restrict which profile values a candidate may submit, nor confine the stored file location to an...

2026-09-03
CVE-2026-77016
Analyzed
9.6
WordPress Workeera WordPress plugin

The Workeera WordPress plugin contains a flaw allowing authenticated subscribers to delete arbitrary files on the server due to insufficient path vali...

2026-09-03
CVE-2026-77012
Analyzed
9.3
WordPress 数据采集和发布插件 (Data Collection and Publishing Plugin)

The 爱采集 WordPress plugin allows unauthenticated attackers to perform arbitrary file reads, server-side request forgery, and arbitrary file writes due...

2026-08-30
CVE-2026-77007
Analyzed
7.5
WordPress HEL Online Classroom: AI-powered Online Classrooms

The HEL Online Classroom: AI-powered Online Classrooms WordPress plugin through 1.0.3 does not perform any authorisation check on one of its REST API...

2026-08-30
CVE-2026-77002
Analyzed
9.8
WordPress Selfie Login

The SmilePass Selfie Login WordPress plugin fails to perform server-side identity verification, allowing unauthenticated attackers to hijack any user...

2026-08-29
CVE-2026-76789
Analyzed
8.8
WordPress Slider Hero with Video Background, Animation

The Slider Hero with Video Background, Animation WordPress plugin before 9.1.3 does not have authorisation and nonce checks on two of its request hand...

2026-08-29
CVE-2026-76586
Analyzed
7.5
WordPress Appointment Booking Calendar Plugin and Scheduling Plugin

The Appointment Booking Calendar Plugin and Scheduling Plugin WordPress plugin before 1.6.3 does not verify the amount actually paid against the serv...

2026-08-30
CVE-2026-76585
Analyzed
8.8
WordPress Customer Reviews for WooCommerce

The Customer Reviews for WooCommerce WordPress plugin before 5.118.0 does not sanitise and escape the content of customer reviews received via one of...

2026-09-04
CVE-2026-76581
Analyzed
9.8
WordPress WPMU DEV Dashboard

The WPMU DEV Dashboard plugin for WordPress contains an authentication bypass vulnerability due to improper HMAC signature verification in its SSO AJA...

2026-08-28
CVE-2026-7655
Analyzed
8.1
WordPress SureCart

The SureCart plugin for WordPress is vulnerable to privilege escalation via account takeover in versions up to, and including, 4

2026-07-11
CVE-2026-76548
Analyzed
8.2
WordPress User Profile Builder

The User Profile Builder WordPress plugin before 4.0.1 does not properly restrict its front-end file upload feature, granting unauthenticated visitor...

2026-08-30
CVE-2026-7649
Analyzed
7.5
WordPress is vulnerable

The ARMember – Membership Plugin, Content Restriction, Member Levels, User Profile & User signup plugin for WordPress is vulnerable to time-based blin...

2026-05-02
CVE-2026-7641
Analyzed
8.8
WordPress is vulnerable

The Import and export users and customers plugin for WordPress is vulnerable to Privilege Escalation in all versions up to and including 2

2026-05-02
CVE-2026-75977
Analyzed
8.8
WordPress Mang Board WP

The Mang Board WP plugin for WordPress is vulnerable to Missing Authorization via Authentication Cookie Forgery in all versions up to, and including,...

2026-08-26
CVE-2026-75865
Analyzed
9.8
WordPress WPLP Cookie Consent – Cookie Banner & Consent Management for GDPR, CCPA & Google Consent Mode

The WPLP Cookie Consent plugin for WordPress is vulnerable to unauthenticated arbitrary file uploads via the saas_upload_logo function, potentially le...

2026-09-01
CVE-2026-75807
Analyzed
7.5
WordPress SAML Single Sign On – SSO Login

The SAML Single Sign On – SSO Login plugin for WordPress is vulnerable to Authentication Bypass in versions up to, and including, 5.4.6. This is due t...

2026-08-30
CVE-2026-7567
Analyzed
9.8
WordPress is vulnerable

The Temporary Login plugin for WordPress is vulnerable to authentication bypass, allowing unauthenticated attackers to log in as any temporary user.

2026-05-02
CVE-2026-7522
Analyzed
8.8
WordPress is vulnerable

The Advanced Database Cleaner – Premium plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 4

2026-05-20
CVE-2026-7520
Analyzed
8.1
WordPress Mailmunch Forms for Mailchimp

The MailChimp Forms by MailMunch plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the `sig...

2026-08-05
CVE-2026-75133
Analyzed
7.5
WordPress Keep Backup Daily

Keep Backup Daily plugin for WordPress before 2.1.4 contains a sensitive information exposure vulnerability that allows unauthenticated attackers to t...

2026-09-01
CVE-2026-74928
Analyzed
7.5
WordPress Project Manager

The Project Manager WordPress plugin before 4.0.7 does not have any authorisation check on its import routes, allowing unauthenticated users to creat...

2026-09-01
CVE-2026-7467
Analyzed
8.8
WordPress is vulnerable

The Read More & Accordion plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 3

2026-05-20
CVE-2026-7465
Analyzed
8.8
WordPress is vulnerable

The Spectra Gutenberg Blocks – Website Builder for the Block Editor plugin for WordPress is vulnerable to Remote Code Execution in all versions up to,...

2026-05-31
CVE-2026-7458
Analyzed
9.8
WordPress is vulnerable

The User Verification plugin for WordPress is vulnerable to authentication bypass due to loose comparison of OTP codes, allowing unauthenticated login...

2026-05-02
CVE-2026-7448
Analyzed
7.2
WordPress is vulnerable

The LatePoint – Calendar Booking Plugin for Appointments and Events plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'first_n...

2026-05-06
CVE-2026-7444
Analyzed
8.1
WordPress Search Analytics for WP

The Search Analytics for WP plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1

2026-08-05
CVE-2026-74016
Analyzed
9.9
WordPress Smart Cleaning

The Smart Cleaning WordPress theme is vulnerable to an arbitrary file upload flaw, enabling authenticated subscribers to upload malicious content to t...

2026-08-21
CVE-2026-74014
Analyzed
9.9
WordPress IT Residence

The IT Residence WordPress theme contains an arbitrary file upload vulnerability that allows authenticated subscribers to upload malicious files to th...

2026-08-21
CVE-2026-74013
Analyzed
8.5
WordPress eShipper Commerce

Subscriber SQL Injection in eShipper Commerce <= 2

2026-08-22
CVE-2026-73992
Analyzed
9.9
WordPress Query Wrangler

A remote code execution vulnerability exists in the Query Wrangler WordPress plugin, allowing authenticated subscribers to execute arbitrary code.

2026-08-21
CVE-2026-73343
Analyzed
10
WordPress WP Compress

An unauthenticated remote code execution vulnerability exists in the WP Compress WordPress plugin due to improper control of code generation, allowing...

2026-08-19
CVE-2026-7332
Analyzed
7.2
WordPress is vulnerable

The LatePoint – Calendar Booking Plugin for Appointments and Events plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'booking...

2026-05-06
CVE-2026-7311
Analyzed
8.1
WordPress JPEG, PNG & WebP image compression plugin

The TinyPNG – JPEG, PNG & WebP image compression plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validatio...

2026-07-03
CVE-2026-7284
Analyzed
9.8
WordPress is vulnerable

The Easy Elements for Elementor plugin is vulnerable to privilege escalation, allowing unauthenticated users to register as administrators.

2026-05-20
CVE-2026-7252
Analyzed
8.1
WordPress is vulnerable

The WP-Optimize – Cache, Compress images, Minify & Clean database to boost page speed & performance plugin for WordPress is vulnerable to arbitrary fi...

2026-05-07
CVE-2026-7106
Analyzed
8.8
WordPress is vulnerable

The Highland Software Custom Role Manager plugin for WordPress is vulnerable to Privilege Escalation in versions up to and including 1

2026-04-27
CVE-2026-6963
Analyzed
8.8
WordPress is vulnerable

The WP Mail Gateway plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the wmg_save_provider_config AJAX a...

2026-05-02
CVE-2026-6960
Analyzed
9.8
WordPress BookingPress Pro

The BookingPress Pro plugin for WordPress is vulnerable to arbitrary file uploads, potentially allowing unauthenticated remote code execution.

2026-05-22
CVE-2026-6939
Analyzed
7.2
WordPress CorvusPay WooCommerce Payment Gateway

The CorvusPay WooCommerce Payment Gateway plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'approval_code' parameter in all v...

2026-07-12
CVE-2026-6933
Analyzed
8.8
WordPress Dev Tools

The Premmerce Dev Tools plugin for WordPress is vulnerable to Remote Code Execution via missing authorization in versions up to and including 2

2026-06-16
CVE-2026-6898
Analyzed
8.8
WordPress WishList Member

The Wishlist Member plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'WishListMember3_...

2026-05-27
CVE-2026-6897
Analyzed
8.8
WordPress WishList Member

The Wishlist Member plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'WishListMember\F...

2026-05-27
CVE-2026-6895
Analyzed
8.8
WordPress WishList Member

The WishList Member plugin for WordPress is vulnerable to Missing Authorization leading to Sensitive Information Disclosure and Privilege Escalation i...

2026-05-27
CVE-2026-6858
Analyzed
7.1
WordPress Webpay WordPress Plugin

The Transbank Webpay WordPress plugin before 1

2026-06-23
CVE-2026-6741
Analyzed
8.8
WordPress is vulnerable

The LatePoint – Calendar Booking Plugin for Appointments and Events plugin for WordPress is vulnerable to Privilege Escalation in versions up to and i...

2026-04-28
CVE-2026-6692
Analyzed
8.8
WordPress is vulnerable

The Slider Revolution plugin for WordPress is vulnerable to Arbitrary File Upload in versions 7

2026-05-07
CVE-2026-66708
Analyzed
8.2
WordPress Total Upkeep

Unauthenticated Broken Access Control in Total Upkeep <= 1

2026-08-06
CVE-2026-66691
Analyzed
9.8
WordPress Nokri

A critical broken access control vulnerability exists in the scriptsbundle Nokri WordPress theme, which allows unauthenticated attackers to manipulate...

2026-08-14
CVE-2026-66671
Analyzed
8.1
WordPress Verdure Core

Unauthenticated Local File Inclusion in Verdure Core <= 1

2026-08-25
CVE-2026-66665
Analyzed
10
WordPress Type Hub

An unauthenticated arbitrary file upload vulnerability exists in the Brandexponents Type Hub plugin for WordPress, allowing remote code execution.

2026-08-06
CVE-2026-66662
Analyzed
9.8
WordPress Frontend Admin by DynamiApps

The Frontend Admin by DynamiApps plugin for WordPress contains an unauthenticated privilege escalation vulnerability caused by incorrect privilege ass...

2026-08-06
CVE-2026-66648
Analyzed
9.8
WordPress Jawn

A critical privilege escalation vulnerability exists in MVPThemes Jawn up to version 1.4.2, allowing unauthenticated attackers to gain unauthorized ad...

2026-08-25
CVE-2026-66627
Analyzed
9.9
WordPress GP Premium

GP Premium allows authenticated contributors to perform arbitrary file uploads, potentially leading to remote code execution.

2026-08-19
CVE-2026-66602
Analyzed
8.8
WordPress HashBar – WordPress Notification Bar

Cross-Site Request Forgery (CSRF) vulnerability in DevItems HashBar – WordPress Notification Bar allows Cross Site Request Forgery

2026-08-19
CVE-2026-66594
Analyzed
8.5
WordPress Persistent Login

Subscriber SQL Injection in WordPress Persistent Login <= 3

2026-08-22
CVE-2026-66473
Analyzed
7.5
WordPress Xendit Payment

Unauthenticated Broken Access Control in Xendit Payment <= 7

2026-07-28
CVE-2026-66465
Analyzed
9.8
WordPress Cartify

A critical broken authentication vulnerability in the AgniHD Cartify WordPress theme allows unauthenticated attackers to perform account takeover oper...

2026-08-14
CVE-2026-66453
Analyzed
9.8
WordPress Salon booking system

A critical authentication bypass vulnerability exists in the Dimitri Grassi Salon booking system plugin for WordPress, allowing unauthenticated attack...

2026-08-14
CVE-2026-66424
Analyzed
9.8
WordPress SMS Alert Order Notifications

An unauthenticated privilege escalation vulnerability in the SMS Alert Order Notifications plugin for WordPress versions 3.9.7 and below allows attack...

2026-08-14
CVE-2026-6627
Analyzed
8.2
WordPress WPFormify

The WPFormify – Stripe Payments with Form and Checkout plugin for WordPress is vulnerable to unauthorized modification and deletion of Stripe payment...

2026-08-05
CVE-2026-65640
Analyzed
8.8
WordPress WordPress

WordPress is vulnerable to a remote code execution vulnerability via malicious Postscript file upload by an Author level user or higher

2026-08-18
CVE-2026-65570
Analyzed
8.1
WordPress Login with phone number

Unauthenticated Bypass Vulnerability in Login with phone number <= 1

2026-08-06
CVE-2026-65569
Analyzed
8.5
WordPress WP Job Portal

Subscriber SQL Injection in WP Job Portal <= 2

2026-08-06
CVE-2026-65553
Analyzed
10
WordPress Spider Analyser

The Spider Analyser WordPress plugin contains an unauthenticated Remote Code Execution vulnerability, allowing attackers to execute arbitrary code on...

2026-08-06
CVE-2026-6555
Analyzed
9.8
WordPress is vulnerable

The ProSolution WP Client WordPress plugin is vulnerable to arbitrary file upload due to improper validation of the upload array, allowing remote code...

2026-05-20
CVE-2026-65548
Analyzed
9.9
WordPress Betheme

A critical remote code execution vulnerability exists in the Betheme WordPress theme, allowing authenticated contributors to execute arbitrary code on...

2026-08-06
CVE-2026-65547
Analyzed
8.5
WordPress Creative Mail

Subscriber SQL Injection in Creative Mail <= 1

2026-08-06
CVE-2026-65542
Analyzed
8.8
WordPress Super Socializer

Unauthenticated Broken Authentication in Super Socializer <= 7

2026-08-06
CVE-2026-65526
Analyzed
8.5
WordPress Visualizer

Contributor SQL Injection in Visualizer <= 4

2026-07-24
CVE-2026-65507
Analyzed
9.8
WordPress AIWU

The AIWU plugin for WordPress is susceptible to an unauthenticated privilege escalation vulnerability due to incorrect privilege assignment.

2026-08-06
CVE-2026-65471
Analyzed
9.6
WordPress Avada Core

Avada Core versions 5.15.6 and below are vulnerable to an unauthenticated Cross-Site Request Forgery (CSRF) attack, potentially leading to unauthorize...

2026-07-24
CVE-2026-65462
Analyzed
7.6
WordPress Uncanny Automator

Administrator SQL Injection in Uncanny Automator <= 7

2026-07-24
CVE-2026-65454
Analyzed
8.5
WordPress Quiz And Survey Master

Contributor SQL Injection in Quiz And Survey Master <= 11

2026-07-24
CVE-2026-65451
Analyzed
8.5
WordPress MapSVG

Contributor SQL Injection in MapSVG <= 8

2026-07-24
CVE-2026-65450
Analyzed
8.5
WordPress MapSVG

Contributor SQL Injection in MapSVG <= 8

2026-07-24
CVE-2026-65442
Analyzed
7.2
WordPress FormCraft

Unauthenticated Server Side Request Forgery (SSRF) in FormCraft <= 3

2026-07-28
CVE-2026-6518
Analyzed
8.8
WordPress is vulnerable

The CMP – Coming Soon & Maintenance Plugin by NiteoThemes plugin for WordPress is vulnerable to arbitrary file upload and remote code execution in all...

2026-04-18
CVE-2026-6512
Analyzed
9.1
WordPress is vulnerable

The InfusedWoo Pro plugin for WordPress is vulnerable to an authorization bypass that allows unauthenticated attackers to perform destructive actions...

2026-05-15
CVE-2026-6510
Analyzed
9.8
WordPress is vulnerable

The InfusedWoo Pro WordPress plugin is vulnerable to authentication bypass and privilege escalation via an insecure AJAX handler.

2026-05-14
CVE-2026-6506
Analyzed
8.8
WordPress is vulnerable

The InfusedWoo Pro plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 5

2026-05-14
CVE-2026-6495
Analyzed
7.1
WordPress plugin before

The Ajax Load More WordPress plugin before 7

2026-05-19
CVE-2026-64638
Analyzed
8.9
WordPress WordPress

WordPress is vulnerable to a pre-auth reflected XSS vulnerability on the login screen

2026-08-08
CVE-2026-6456
Analyzed
8.8
WordPress is vulnerable

The Account Switcher plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1

2026-05-20
CVE-2026-6443
Analyzed
9.8
WordPress is vulnerable

The Accordion and Accordion Slider plugin for WordPress version 1.4.6 contains a malicious backdoor injected by threat actors.

2026-04-17
CVE-2026-6419
Analyzed
8.8
WordPress WishList Member

The WishList Member plugin for WordPress is vulnerable to Privilege Escalation via Missing Authorization in versions up to and including 3

2026-05-27
CVE-2026-6403
Analyzed
7.5
WordPress is vulnerable

The Quick Playground plugin for WordPress is vulnerable to Path Traversal in versions up to and including 1

2026-05-17
CVE-2026-6382
Analyzed
9.1
WordPress FileOrganizer, Advanced File Manager, File Manager Pro, File Manager

Several WordPress file management plugins are vulnerable to OS Command Injection when processing images, allowing authenticated users with administrat...

2026-07-07
CVE-2026-6381
Analyzed
7.5
WordPress plugin before

The WP Maps WordPress plugin before 4

2026-05-19
CVE-2026-6379
Analyzed
8.6
WordPress plugin before

The WP Photo Album Plus WordPress plugin before 9

2026-05-19
CVE-2026-6320
Analyzed
7.5
WordPress is vulnerable

The Salon Booking System – Free Version plugin for WordPress is vulnerable to Arbitrary File Read in versions up to, and including, 10

2026-05-03
CVE-2026-63030
KEV Analyzed
9.8
WordPress WordPress

WordPress is affected by a REST API batch endpoint route confusion issue which, when combined with other vulnerabilities, can lead to SQL injection an...

2026-07-18
CVE-2026-6271
Analyzed
9.8
WordPress is vulnerable

The Career Section WordPress plugin is vulnerable to arbitrary file upload due to missing file type validation, enabling remote code execution.

2026-05-14
CVE-2026-6261
Analyzed
8.8
WordPress is vulnerable

The Betheme theme for WordPress is vulnerable to Arbitrary File Upload in versions up to, and including, 28

2026-05-06
CVE-2026-6248
Analyzed
8.1
WordPress is vulnerable

The wpForo Forum plugin for WordPress is vulnerable to Arbitrary File Deletion in versions up to and including 3

2026-04-21
CVE-2026-6235
Analyzed
9.8
WordPress plugin for

The Sendmachine for WordPress plugin is vulnerable to an authorization bypass, allowing unauthenticated attackers to modify SMTP configurations.

2026-04-23
CVE-2026-6228
Analyzed
8.8
WordPress is vulnerable

The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to Privilege Escalation in versions up to and including 3

2026-05-15
CVE-2026-6227
Analyzed
7.2
WordPress is vulnerable

The BackWPup plugin for WordPress is vulnerable to Local File Inclusion via the `block_name` parameter of the `/wp-json/backwpup/v1/getblock` REST end...

2026-04-14
CVE-2026-6226
Analyzed
8.8
WordPress is vulnerable

The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to unauthenticated privilege escalation in versions up to and including 3

2026-05-29
CVE-2026-61967
Analyzed
9.8
WordPress miniorange otp verification

An unauthenticated privilege escalation vulnerability in the miniOrange OTP Verification plugin for WordPress versions 5.5.1 and below allows attacker...

2026-08-14
CVE-2026-61962
Analyzed
10
WordPress WP BASE Booking

The WP BASE Booking plugin for WordPress contains an unauthenticated arbitrary code execution vulnerability, allowing remote attackers to execute mali...

2026-08-14
CVE-2026-61955
Analyzed
7.6
WordPress گرویتی فرم فارسی (Persian Gravity Forms)

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Hannan گرویتی فرم فارسی persian-gravity-forms al...

2026-07-14
CVE-2026-61953
Analyzed
7.2
WordPress Simple Link Directory Pro

Unauthenticated Server Side Request Forgery (SSRF) in Simple Link Directory Pro <= 15

2026-07-28
CVE-2026-61951
Analyzed
9.8
WordPress TrueBooker

TrueBooker for WordPress is vulnerable to an unauthenticated privilege escalation, allowing unauthorized users to gain elevated access.

2026-07-24
CVE-2026-61950
Analyzed
9.3
WordPress TrueBooker

The TrueBooker plugin for WordPress is vulnerable to an unauthenticated SQL injection, allowing remote attackers to extract sensitive data via crafted...

2026-07-24
CVE-2026-61949
Analyzed
9.3
WordPress Bookly

The Bookly WordPress plugin contains an unauthenticated SQL injection vulnerability in versions 27.7 and prior, enabling attackers to execute arbitrar...

2026-07-24
CVE-2026-61948
Analyzed
9.3
WordPress WPDM – Premium Packages

The WPDM Premium Packages WordPress plugin contains an unauthenticated SQL injection vulnerability in versions 6.2.0 and prior, permitting remote data...

2026-07-24
CVE-2026-6147
Analyzed
8.8
WordPress LightSync Pro

The LightSync Pro plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the rest_replace_media() functio...

2026-08-05
CVE-2026-6070
Analyzed
9.1
WordPress WP-BusinessDirectory

The WP-BusinessDirectory plugin for WordPress contains an unauthenticated arbitrary file deletion vulnerability due to insufficient path validation in...

2026-07-01
CVE-2026-60137
KEV Analyzed
9.5
WordPress Core

WordPress Core is affected by a SQL injection vulnerability that allows unauthenticated attackers to execute unauthorized database queries.

2026-07-22
CVE-2026-59555
Analyzed
10
WordPress Participants Database

The Roland Barker Participants Database plugin for WordPress contains an unauthenticated arbitrary file deletion vulnerability due to improper path va...

2026-07-24
CVE-2026-59551
Analyzed
8.5
WordPress rtMedia for WordPress, BuddyPress and bbPress

Subscriber SQL Injection in rtMedia for WordPress, BuddyPress and bbPress <= 4

2026-07-28
CVE-2026-59550
Analyzed
9.3
WordPress AWP Classifieds

An unauthenticated SQL injection vulnerability in AWP Classifieds allows remote attackers to execute arbitrary SQL commands via the plugin, potentiall...

2026-07-28
CVE-2026-59549
Analyzed
9.3
WordPress rtMedia for WordPress, BuddyPress and bbPress

An unauthenticated SQL injection vulnerability exists in the rtMedia for WordPress plugin, allowing attackers to manipulate database queries via vulne...

2026-07-28
CVE-2026-59548
Analyzed
7.5
WordPress Byteflows Travel & Hotel Booking

Unauthenticated Sensitive Data Exposure in Byteflows Travel &amp; Hotel Booking <= 1

2026-07-28
CVE-2026-59546
Analyzed
7.4
WordPress Hide My WP Ghost

Subscriber Broken Authentication in Hide My WP Ghost <= 7

2026-07-28
CVE-2026-59543
Analyzed
9.9
WordPress Advanced Views

The WPLake Advanced Views WordPress plugin contains a code injection vulnerability allowing remote code execution for authenticated subscribers.

2026-07-24
CVE-2026-59542
Analyzed
7.7
WordPress Kali Forms

Subscriber Arbitrary File Deletion in Kali Forms <= 2

2026-07-24
CVE-2026-59541
Analyzed
8.8
WordPress WP BASE Booking

Subscriber Privilege Escalation in WP BASE Booking <= 6

2026-07-24
CVE-2026-59540
Analyzed
9.8
WordPress SMS Alert Order Notifications

The SMS Alert Order Notifications WordPress plugin contains an unauthenticated privilege escalation vulnerability that allows attackers to gain unauth...

2026-07-24
CVE-2026-59539
Analyzed
7.5
WordPress Paid Member Subscriptions

Subscriber Insecure Direct Object References (IDOR) in Paid Member Subscriptions <= 3

2026-07-28
CVE-2026-59537
Analyzed
7.6
WordPress Sender – Newsletter, SMS and Email Marketing Automation for WooCommerce

Administrator SQL Injection in Sender – Newsletter, SMS and Email Marketing Automation for WooCommerce <= 2

2026-07-28
CVE-2026-59536
Analyzed
7.5
WordPress CoCart – Headless ecommerce

Unauthenticated Broken Access Control in CoCart – Headless ecommerce <= 4

2026-07-28
CVE-2026-59535
Analyzed
7.3
WordPress Thrive Product Manager

Unauthenticated Broken Access Control in Thrive Product Manager <= 10

2026-07-28
CVE-2026-59534
Analyzed
7.5
WordPress Post My CF7 Form

Unauthenticated Broken Access Control in Post My CF7 Form <= 6

2026-07-28
CVE-2026-59533
Analyzed
9.3
WordPress Relevanssi Light

An unauthenticated SQL injection vulnerability in the Relevanssi Light WordPress plugin allows remote attackers to compromise the database.

2026-07-28
CVE-2026-59532
Analyzed
7.5
WordPress Booking and Rental Manager

Unauthenticated Other Vulnerability Type in Booking and Rental Manager <= 2

2026-07-28
CVE-2026-59531
Analyzed
7.5
WordPress Falcon – WordPress Optimizations & Tweaks

Unauthenticated Unknown in Falcon – WordPress Optimizations & Tweaks <= 2

2026-07-28
CVE-2026-59530
Analyzed
7.5
WordPress Stripe For WooCommerce

Unauthenticated Broken Access Control in Stripe For WooCommerce <= 4

2026-07-28
CVE-2026-59529
Analyzed
7.5
WordPress Ebook Store

Unauthenticated Sensitive Data Exposure in Ebook Store <= 6

2026-07-28
CVE-2026-59528
Analyzed
7.5
WordPress Discounted Shipping Rates

Subscriber Sensitive Data Exposure in ShipTime: Discounted Shipping Rates <= 1

2026-07-28
CVE-2026-59527
Analyzed
9.3
WordPress MapSVG

A critical SQL injection vulnerability in the MapSVG plugin for WordPress allows unauthenticated attackers to execute arbitrary SQL commands.

2026-07-28
CVE-2026-59526
Analyzed
9.3
WordPress MapSVG

MapSVG contains an unauthenticated SQL injection vulnerability in versions 8.14.0 and prior, allowing remote attackers to execute arbitrary database q...

2026-07-24
CVE-2026-59525
Analyzed
9.3
WordPress Participants Database

The Participants Database WordPress plugin before version 2.7.8.4 is susceptible to an unauthenticated SQL injection vulnerability.

2026-07-24
CVE-2026-59515
Analyzed
9.3
WordPress AIWU

The Sergey AIWU WordPress plugin contains a Blind SQL Injection vulnerability, permitting unauthenticated attackers to execute malicious database quer...

2026-07-14
CVE-2026-59514
Analyzed
9.3
WordPress BuddyBoss Platform

The BuddyBoss Platform plugin for WordPress contains an unauthenticated SQL injection vulnerability that allows attackers to execute arbitrary databas...

2026-07-24
CVE-2026-58480
Analyzed
9.8
WordPress Blocksy Companion

The Blocksy Companion WordPress plugin is vulnerable to unauthenticated arbitrary file uploads via the save_attachments function, enabling remote code...

2026-07-09
CVE-2026-5821
Analyzed
8.1
WordPress Image Optimizer – Optimize Images and Convert to WebP or AVIF

The Image Optimizer plugin for WordPress is vulnerable to arbitrary file deletion in versions up to and including 1

2026-07-03
CVE-2026-5809
Analyzed
7.1
WordPress is vulnerable

The wpForo Forum plugin for WordPress is vulnerable to Arbitrary File Deletion in versions up to and including 3

2026-04-12
CVE-2026-57813
Analyzed
9.8
WordPress MailOptin

The MailOptin plugin for WordPress contains an incorrect privilege assignment vulnerability, allowing unauthenticated attackers to escalate their priv...

2026-07-14
CVE-2026-57811
Analyzed
10
WordPress Realtyna Organic IDX plugin

The Realtyna Organic IDX plugin for WordPress contains a Code Injection vulnerability, allowing unauthenticated remote code execution.

2026-07-14
CVE-2026-57810
Analyzed
8.5
WordPress APIExperts Square for WooCommerce

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Saad Iqbal APIExperts Square for WooCommerce woo...

2026-07-14
CVE-2026-57807
Analyzed
9.8
WordPress OAuth Single Sign On - SSO (OAuth Client)

An authentication bypass vulnerability in the miniOrange OAuth Single Sign On plugin allows unauthorized attackers to exploit password recovery mechan...

2026-07-11
CVE-2026-57787
Analyzed
8.5
WordPress CWS SVGicons

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in CreativeWS CWS SVGicons cws-svgicons allows Blin...

2026-07-14
CVE-2026-57786
Analyzed
8.8
WordPress WorkScout-Core

Cross-Site Request Forgery (CSRF) vulnerability in purethemes WorkScout-Core workscout-core allows Authentication Bypass

2026-07-14
CVE-2026-57785
Analyzed
8.8
WordPress ApusListing

Unauthenticated Cross Site Request Forgery (CSRF) in ApusListing <= 1

2026-07-24
CVE-2026-57784
Analyzed
9.6
WordPress Ninja Forms File Uploads Extension

The Ninja Forms File Uploads Extension for WordPress contains a Cross Site Request Forgery (CSRF) vulnerability that may allow an attacker to perform...

2026-07-24
CVE-2026-57771
Analyzed
8.5
WordPress GD Rating System

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Milan Petrovic GD Rating System gd-rating-system...

2026-07-14
CVE-2026-57768
Analyzed
8.2
WordPress Houzez Login Register

Incorrect Privilege Assignment vulnerability in favethemes Houzez Login Register houzez-login-register allows Privilege Escalation

2026-07-14
CVE-2026-57766
Analyzed
8.8
WordPress File Manager & Code Editor

Unauthenticated Cross Site Request Forgery (CSRF) in WPIDE – File Manager & Code Editor <= 3

2026-07-03
CVE-2026-57739
Analyzed
9.3
WordPress AcyMailing SMTP Newsletter

The AcyMailing SMTP Newsletter plugin for WordPress contains a Blind SQL Injection vulnerability allowing unauthenticated attackers to extract databas...

2026-07-14
CVE-2026-57726
Analyzed
9.3
WordPress Kirki

Themeum Kirki is susceptible to a Blind SQL Injection vulnerability, allowing unauthenticated attackers to manipulate SQL queries.

2026-07-14
CVE-2026-57719
Analyzed
10
WordPress Aimogen Pro

CodeRevolution Aimogen Pro for WordPress is vulnerable to an unrestricted file upload flaw, allowing unauthenticated attackers to upload malicious fil...

2026-07-14
CVE-2026-57714
Analyzed
9.3
WordPress LatePoint

The LatePoint WordPress plugin is susceptible to Blind SQL Injection, enabling unauthenticated remote attackers to execute malicious database queries.

2026-07-14
CVE-2026-57707
Analyzed
9.3
WordPress Simple Business Directory Pro

The Simple Business Directory Pro plugin for WordPress is vulnerable to SQL injection, allowing unauthenticated attackers to execute arbitrary databas...

2026-07-14
CVE-2026-57702
Analyzed
9.3
WordPress Amelia

The Amelia WordPress plugin contains a Blind SQL Injection vulnerability, allowing unauthenticated attackers to execute arbitrary SQL commands.

2026-07-14
CVE-2026-57697
Analyzed
7.5
WordPress ProfileGrid

Authentication Bypass Using an Alternate Path or Channel vulnerability in Metagauss ProfileGrid profilegrid-user-profiles-groups-and-communities allo...

2026-07-14
CVE-2026-57692
Analyzed
9.8
WordPress PrivateContent

LCweb PrivateContent is vulnerable to an incorrect privilege assignment flaw, potentially allowing an attacker to escalate privileges within the appli...

2026-07-02
CVE-2026-57683
Analyzed
9.3
WordPress WP Fast Total Search

An unauthenticated SQL injection vulnerability exists in Epsiloncool WP Fast Total Search versions 1.80.280 and earlier, allowing remote attackers to...

2026-07-03
CVE-2026-57667
Analyzed
8.5
WordPress Groundhogg

Sales Representative SQL Injection in Groundhogg <= 4

2026-06-27
CVE-2026-57663
Analyzed
8.5
WordPress Recipe Maker For Your Food Blog

Contributor SQL Injection in Recipe Maker For Your Food Blog from Zip Recipes <= 8

2026-06-27
CVE-2026-57655
Analyzed
8.2
WordPress Child Theme Wizard

Unauthenticated Cross Site Request Forgery (CSRF) in Child Theme Wizard <= 1

2026-06-27
CVE-2026-57653
Analyzed
8.5
WordPress WP Job Portal

Contributor SQL Injection in WP Job Portal <= 2

2026-06-27
CVE-2026-57644
Analyzed
8.5
WordPress Restaurant Menu

Contributor SQL Injection in Restaurant Menu by MotoPress <= 2

2026-06-27
CVE-2026-57636
Analyzed
8.5
WordPress wpForo Forum

Contributor SQL Injection in wpForo Forum <= 3

2026-06-27
CVE-2026-57628
Analyzed
7.6
WordPress WP All Import

Administrator SQL Injection in WP All Import <= 4

2026-06-28
CVE-2026-57410
Analyzed
8.8
WordPress MailerPress

Incorrect Privilege Assignment vulnerability in MailerPress Team MailerPress mailerpress allows Privilege Escalation

2026-07-14
CVE-2026-57389
Analyzed
8.6
WordPress Groundhogg

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Adrian Tobey Groundhogg groundhogg allows Path Travers...

2026-07-14
CVE-2026-57386
Analyzed
8.8
WordPress aBlocks

Incorrect Privilege Assignment vulnerability in Kodezen LLC aBlocks ablocks allows Privilege Escalation

2026-07-14
CVE-2026-57385
Analyzed
8.5
WordPress Vitepos

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in appsbd Vitepos vitepos-lite allows Blind SQL Inj...

2026-07-14
CVE-2026-57378
Analyzed
7.5
WordPress Advanced Forms

Missing Authorization vulnerability in Phil Kurth Advanced Forms advanced-forms allows Exploiting Incorrectly Configured Access Control Security Level...

2026-07-14
CVE-2026-57315
Analyzed
8.5
WordPress Blocksy Companion Pro

Contributor Remote Code Execution (RCE) in Blocksy Companion Pro <= 2

2026-06-27
CVE-2026-5722
Analyzed
9.8
WordPress is vulnerable

An authentication bypass vulnerability in MoreConvert Pro for WordPress allows unauthenticated attackers to hijack administrator accounts by manipulat...

2026-05-05
CVE-2026-5718
Analyzed
8.1
WordPress is vulnerable

The Drag and Drop Multiple File Upload for Contact Form 7 plugin for WordPress is vulnerable to arbitrary file upload in versions up to, and including...

2026-04-18
CVE-2026-5710
Analyzed
7.5
WordPress is vulnerable

The Drag and Drop Multiple File Upload for Contact Form 7 plugin for WordPress is vulnerable to Path Traversal leading to Arbitrary File Read in versi...

2026-04-18
CVE-2026-5617
Analyzed
8.8
WordPress is vulnerable

The Login as User plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1

2026-04-16
CVE-2026-56070
Analyzed
9.3
WordPress Advance Product Search

The Advance Product Search plugin for WordPress is susceptible to an unauthenticated SQL injection vulnerability in versions 1.4.4 and earlier.

2026-06-27
CVE-2026-56068
Analyzed
9.3
WordPress JetEngine

JetEngine versions 3.8.10.2 and earlier are vulnerable to an unauthenticated SQL injection, potentially allowing remote attackers to manipulate databa...

2026-06-27
CVE-2026-56063
Analyzed
8.3
WordPress MailChimp Block

Unauthenticated Broken Access Control in MailChimp Block <= 1

2026-06-27
CVE-2026-56059
Analyzed
9.9
WordPress Travel Booking

The Travel Booking WordPress plugin contains an arbitrary file upload vulnerability exploitable by authenticated subscribers.

2026-06-27
CVE-2026-56058
Analyzed
9.9
WordPress Quform

The Quform WordPress plugin is susceptible to an arbitrary file upload vulnerability exploitable by authenticated subscribers.

2026-06-27
CVE-2026-56049
Analyzed
8.5
WordPress Post Snippets

Contributor Remote Code Execution (RCE) in Post Snippets <= 4

2026-06-26
CVE-2026-56037
Analyzed
8.8
WordPress Themify Popup

Deserialization of Untrusted Data vulnerability in Themify Themify Popup allows Object Injection

2026-07-03
CVE-2026-56036
Analyzed
9.3
WordPress 워드프레스 결제 심플페이 (WordPress Simple Pay)

An unauthenticated SQL injection vulnerability exists in the Codemstory 워드프레스 결제 심플페이 plugin, allowing remote attackers to execute arbitrary database...

2026-06-27
CVE-2026-56030
Analyzed
9.8
WordPress Paytium

A critical unauthenticated privilege escalation vulnerability in the Paytium plugin allows remote attackers to gain unauthorized administrative privil...

2026-06-27
CVE-2026-56028
Analyzed
9.8
WordPress Easy Elements for Elementor

A critical unauthenticated privilege escalation vulnerability exists in the Easy Elements for Elementor plugin, allowing attackers to elevate their ac...

2026-06-27
CVE-2026-56027
Analyzed
9.9
WordPress Booster for WooCommerce

Booster for WooCommerce contains an arbitrary file upload vulnerability allowing unauthenticated remote code execution.

2026-06-27
CVE-2026-56010
Analyzed
8.8
WordPress Abandoned Cart Pro for WooCommerce

Subscriber Privilege Escalation in Abandoned Cart Pro for WooCommerce <= 10

2026-06-27
CVE-2026-56008
Analyzed
8.8
WordPress Fusion Builder

Contributor Privilege Escalation in Fusion Builder <= 3

2026-06-27
CVE-2026-5524
Analyzed
9.8
WordPress Divi Form Builder

The Divi Form Builder plugin for WordPress contains an arbitrary file upload vulnerability allowing unauthenticated remote code execution via insuffic...

2026-07-03
CVE-2026-5523
Analyzed
8.8
WordPress Divi Form Builder

The Divi Form Builder plugin for WordPress is vulnerable to Missing Authorization in versions up to, and including, 5

2026-07-09
CVE-2026-5513
Analyzed
7.2
WordPress Online Scheduling and Appointment Booking System

The Online Scheduling and Appointment Booking System – Bookly plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'bookly-custom...

2026-06-15
CVE-2026-54849
Analyzed
9.3
WordPress Wishlist for WooCommerce

Premmerce Wishlist for WooCommerce contains an unauthenticated SQL injection vulnerability that allows remote attackers to manipulate database queries...

2026-06-26
CVE-2026-54843
Analyzed
9.3
WordPress MDTF

The MDTF plugin for WordPress contains an unauthenticated SQL injection vulnerability in versions 1.3.7 and earlier, allowing remote attackers to exec...

2026-06-26
CVE-2026-54842
Analyzed
8.1
WordPress Royal MCP

Missing Authorization vulnerability in Royal Plugins Royal MCP allows Exploiting Incorrectly Configured Access Control Security Levels

2026-06-27
CVE-2026-54838
Analyzed
8.5
WordPress WC Vendors Marketplace

Subscriber SQL Injection in WC Vendors Marketplace <= 2

2026-06-26
CVE-2026-54832
Analyzed
7.5
WordPress Gutenverse Companion

Unauthenticated Broken Access Control in Gutenverse Companion <= 2

2026-06-28
CVE-2026-54831
Analyzed
9.3
WordPress GeoDirectory

GeoDirectory versions 2.8.162 and earlier are susceptible to an unauthenticated SQL injection vulnerability, enabling database manipulation by remote...

2026-06-27
CVE-2026-54827
Analyzed
9.3
WordPress Real Estate 7

Real Estate 7 contains an unauthenticated SQL injection vulnerability in versions 3.5.9 and earlier, allowing remote attackers to manipulate database...

2026-06-27
CVE-2026-54825
Analyzed
9.3
WordPress wpDataTables

The wpDataTables plugin for WordPress contains an unauthenticated SQL injection vulnerability that enables remote attackers to manipulate database que...

2026-06-27
CVE-2026-54824
Analyzed
7.5
WordPress Ads by WPQuads

Unauthenticated Sensitive Data Exposure in Ads by WPQuads <= 3

2026-06-28
CVE-2026-54820
Analyzed
9.3
WordPress JetBooking

An unauthenticated SQL injection vulnerability in the JetBooking plugin for WordPress allows remote attackers to execute arbitrary SQL queries and acc...

2026-06-27
CVE-2026-5478
Analyzed
8.1
WordPress is vulnerable

The Everest Forms plugin for WordPress is vulnerable to Arbitrary File Read and Deletion in all versions up to, and including, 3

2026-04-21
CVE-2026-5465
Analyzed
8.8
WordPress is vulnerable

The Booking for Appointments and Events Calendar – Amelia plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to...

2026-04-07
CVE-2026-5436
Analyzed
8.1
WordPress is vulnerable

The MW WP Form plugin for WordPress is vulnerable to Arbitrary File Move/Read in all versions up to and including 5

2026-04-09
CVE-2026-5425
Analyzed
7.2
WordPress is vulnerable

The Widgets for Social Photo Feed plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'feed_data' parameter keys in all versions...

2026-04-05
CVE-2026-5396
Analyzed
8.2
WordPress is vulnerable

The Fluent Forms plugin for WordPress is vulnerable to Authorization Bypass Through User-Controlled Key in all versions up to, and including, 6

2026-05-14
CVE-2026-5395
Analyzed
8.2
WordPress is vulnerable

The Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder plugin for WordPress is vulnerable to Insecure Direct Objec...

2026-05-14
CVE-2026-5364
Analyzed
8.1
WordPress is vulnerable

The Drag and Drop File Upload for Contact Form 7 plugin for WordPress is vulnerable to arbitrary file upload in versions up to, and including, 1

2026-04-24
CVE-2026-5324
Analyzed
7.2
WordPress is vulnerable

The Brizy – Page Builder plugin for WordPress is vulnerable to Unauthenticated Stored Cross-Site Scripting in all versions up to, and including, 2

2026-05-04
CVE-2026-5305
Analyzed
8.8
WordPress Email Address Encoder

The Email Address Encoder WordPress plugin before 1

2026-06-26
CVE-2026-5294
Analyzed
9.8
WordPress is vulnerable

The Geeky Bot plugin for WordPress contains a missing authorization vulnerability that allows unauthenticated attackers to achieve remote code executi...

2026-05-05
CVE-2026-52703
Analyzed
9.6
WordPress FastDup

An unauthenticated path traversal vulnerability exists in the FastDup plugin for WordPress, allowing attackers to access sensitive files.

2026-06-16
CVE-2026-5231
Analyzed
7.2
WordPress is vulnerable

The WP Statistics plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'utm_source' parameter in all versions up to, and includin...

2026-04-18
CVE-2026-5229
Analyzed
9.8
WordPress is vulnerable

The Form Notify plugin for WordPress suffers from an authentication bypass vulnerability due to improper verification of user-controlled cookie data d...

2026-05-15
CVE-2026-5217
Analyzed
7.2
WordPress is vulnerable

The Optimole – Optimize Images | Convert WebP & AVIF | CDN & Lazy Load | Image Optimization plugin for WordPress is vulnerable to Stored Cross-Site Sc...

2026-04-12
CVE-2026-5200
Analyzed
8.8
WordPress plugin for

The AcyMailing – An Ultimate Newsletter Plugin and Marketing Automation Solution for WordPress plugin for WordPress is vulnerable to Missing Authoriza...

2026-05-20
CVE-2026-5192
Analyzed
7.5
WordPress is vulnerable

The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is vulnerable to Path Traversal in versions up to, and in...

2026-05-05
CVE-2026-5144
Analyzed
8.8
WordPress is vulnerable

The BuddyPress Groupblog plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1

2026-04-11
CVE-2026-5130
Analyzed
8.8
WordPress was vulnerable

The Debugger & Troubleshooter plugin for WordPress was vulnerable to Unauthenticated Privilege Escalation in versions up to and including 1

2026-03-31
CVE-2026-5127
Analyzed
8.8
WordPress is vulnerable

The User Frontend: AI Powered Frontend Posting, User Directory, Profile, Membership & User Registration plugin for WordPress is vulnerable to Deserial...

2026-05-08
CVE-2026-5118
Analyzed
9.8
WordPress Divi Form Builder

The Divi Form Builder plugin for WordPress is vulnerable to privilege escalation, allowing unauthenticated users to register as administrators.

2026-05-22
CVE-2026-5113
Analyzed
7.2
WordPress is vulnerable

The Gravity Forms plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Consent field hidden inputs in versions up to and including 2

2026-05-02
CVE-2026-5112
Analyzed
7.2
WordPress is vulnerable

The Gravity Forms plugin for WordPress is vulnerable to Unauthenticated Stored Cross-Site Scripting in versions up to and including 2

2026-05-02
CVE-2026-5111
Analyzed
7.2
WordPress is vulnerable

The Gravity Forms plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to and including 2

2026-05-02
CVE-2026-5110
Analyzed
7.2
WordPress is vulnerable

The Gravity Forms plugin for WordPress is vulnerable to Unauthenticated Stored Cross-Site Scripting in versions up to and including 2

2026-05-02
CVE-2026-5109
Analyzed
7.2
WordPress is vulnerable

The Gravity Forms plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to and including 2

2026-05-02
CVE-2026-5100
Analyzed
7.5
WordPress is vulnerable

The AWP Classifieds plugin for WordPress is vulnerable to SQL Injection via the 'regions' parameter array keys in versions up to, and including, 4

2026-05-05
CVE-2026-5076
Analyzed
9.8
WordPress ARMember Premium Plugin

The ARMember Premium plugin for WordPress stores plaintext password reset keys, allowing unauthenticated attackers to reset user passwords and hijack...

2026-06-03
CVE-2026-5063
Analyzed
7.2
WordPress plugin for

The NEX-Forms – Ultimate Forms Plugin for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via POST parameter key names in...

2026-05-04
CVE-2026-5032
Analyzed
7.5
WordPress is vulnerable

The W3 Total Cache plugin for WordPress is vulnerable to information exposure in all versions up to, and including, 2

2026-04-03
CVE-2026-4987
Analyzed
7.5
WordPress is vulnerable

The SureForms – Contact Form, Payment Form & Other Custom Form Builder plugin for WordPress is vulnerable to Payment Amount Bypass in all versions up...

2026-03-29
CVE-2026-49780
Analyzed
8.8
WordPress Dokan Plugin

Customer Privilege Escalation in Dokan <= 5

2026-06-16
CVE-2026-49777
Analyzed
10
WordPress Product Slider Pro for WooCommerce

An improper validation vulnerability in ShapedPlugin Product Slider Pro for WooCommerce allows unauthenticated attackers to perform malicious software...

2026-06-06
CVE-2026-49766
Analyzed
9.9
WordPress WP User Manager

An arbitrary file deletion vulnerability in the WP User Manager plugin for WordPress allows authenticated users to delete sensitive system files.

2026-06-16
CVE-2026-49764
Analyzed
9.8
WordPress RegistrationMagic

A broken authentication vulnerability in the RegistrationMagic plugin for WordPress allows unauthenticated attackers to bypass security controls.

2026-06-16
CVE-2026-4935
Analyzed
8.6
WordPress plugin before

The OttoKit: All-in-One Automation Platform WordPress plugin before 1

2026-05-09
CVE-2026-49111
Analyzed
8.8
WordPress Masteriyo - LMS

Incorrect Privilege Assignment vulnerability in ThemeGrill Masteriyo - LMS allows Privilege Escalation

2026-06-16
CVE-2026-48970
Analyzed
8.1
WordPress Really Simple SSL

Unauthenticated Broken Authentication in Really Simple SSL <= 9

2026-06-16
CVE-2026-48967
Analyzed
8.5
WordPress Geo Mashup Plugin

Subscriber SQL Injection in Geo Mashup <= 1

2026-06-18
CVE-2026-48964
Analyzed
8.5
WordPress HelpDesk & Customer Ticketing System

Subscriber SQL Injection in ELEX WordPress HelpDesk & Customer Ticketing System <= 3

2026-06-16
CVE-2026-4896
Analyzed
8.1
WordPress is vulnerable

The WCFM – Frontend Manager for WooCommerce along with Bookings Subscription Listings Compatible plugin for WordPress is vulnerable to Insecure Direct...

2026-04-04
CVE-2026-48889
Analyzed
8.8
WordPress Amelia Plugin

Subscriber Privilege Escalation in Amelia <= 2

2026-06-16
CVE-2026-48882
Analyzed
8.5
WordPress WP Time Slots Booking Form

Subscriber SQL Injection in WP Time Slots Booking Form <= 1

2026-06-16
CVE-2026-48879
Analyzed
9.8
WordPress AIWU

The AIWU plugin for WordPress is vulnerable to privilege escalation due to incorrect privilege assignment.

2026-06-02
CVE-2026-48874
Analyzed
8.5
WordPress GamiPress

Subscriber SQL Injection in GamiPress <= 7

2026-06-16
CVE-2026-4885
Analyzed
9.8
WordPress is vulnerable

The Piotnet Addons for Elementor Pro plugin for WordPress is vulnerable to arbitrary file upload due to insufficient extension filtering, enabling una...

2026-05-19
CVE-2026-4883
Analyzed
9.8
WordPress is vulnerable

The Piotnet Forms plugin for WordPress is vulnerable to arbitrary file upload due to insufficient file extension blacklisting, enabling remote code ex...

2026-05-20
CVE-2026-4882
Analyzed
9.8
WordPress is vulnerable

The User Registration Advanced Fields plugin for WordPress is vulnerable to arbitrary file uploads, potentially leading to remote code execution.

2026-05-02
CVE-2026-4880
Analyzed
9.8
WordPress is vulnerable

The Barcode Scanner (+Mobile App) – Inventory manager, Order fulfillment system, POS (Point of Sale) plugin for WordPress is vulnerable to privilege e...

2026-04-16
CVE-2026-4834
Analyzed
7.5
WordPress is vulnerable

The WP ERP Pro plugin for WordPress is vulnerable to SQL Injection via the 'search_key' parameter in all versions up to, and including, 1

2026-05-22
CVE-2026-4803
Analyzed
7.2
WordPress is vulnerable

The Royal Elementor Addons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'status' parameter in the wpr_update_form_action_...

2026-05-05
CVE-2026-4758
Analyzed
8.8
WordPress is vulnerable

The WP Job Portal plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the 'WPJOBPORTALcustomfiel...

2026-03-26
CVE-2026-47365
Analyzed
9.9
WordPress WordPress Toolkit

An argument injection vulnerability in WordPress Toolkit allows authenticated users to bypass cross-tenant authorization and execute arbitrary CLI com...

2026-06-12
CVE-2026-4662
Analyzed
7.5
WordPress is vulnerable

The JetEngine plugin for WordPress is vulnerable to SQL Injection via the `listing_load_more` AJAX action in all versions up to, and including, 3

2026-03-24
CVE-2026-4661
Analyzed
7.5
WordPress WP CTA – Call Now Button, Sticky Button & Call to Action Builder

The WP CTA – Sticky CTA Builder, Generate Leads, Promote Sales plugin for WordPress is vulnerable to time-based blind SQL Injection via the 'fildname'...

2026-07-11
CVE-2026-4659
Analyzed
7.5
WordPress is vulnerable

The Unlimited Elements for Elementor plugin for WordPress is vulnerable to Arbitrary File Read via the Repeater JSON/CSV URL parameter in versions up...

2026-04-17
CVE-2026-4484
Analyzed
9.8
WordPress is vulnerable

The Masteriyo LMS plugin for WordPress allows authenticated Student-level users to escalate their privileges to Administrator via the InstructorsContr...

2026-03-26
CVE-2026-4388
Analyzed
7.2
WordPress is vulnerable

The Form Maker by 10Web plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Matrix field (Text Box input type) in form submissio...

2026-04-14
CVE-2026-4375
Analyzed
9
WordPress DoLeads Integrator and wp2epub

The DoLeads Integrator and wp2epub WordPress plugins are susceptible to code injection, allowing unauthorized users to achieve remote code execution.

2026-07-08
CVE-2026-4373
Analyzed
7.5
WordPress is vulnerable

The JetFormBuilder plugin for WordPress is vulnerable to arbitrary file read via path traversal in all versions up to, and including, 3

2026-03-22
CVE-2026-4365
Analyzed
9.1
WordPress is vulnerable

The LearnPress plugin for WordPress is vulnerable to unauthorized data deletion due to a missing capability check on the `delete_question_answer()` fu...

2026-04-14
CVE-2026-4352
Analyzed
7.5
WordPress is vulnerable

The JetEngine plugin for WordPress is vulnerable to SQL Injection via the Custom Content Type (CCT) REST API search endpoint in all versions up to, an...

2026-04-14
CVE-2026-4351
Analyzed
8.1
WordPress is vulnerable

The Perfmatters plugin for WordPress is vulnerable to arbitrary file overwrite via path traversal in all versions up to, and including, 2

2026-04-10
CVE-2026-4350
Analyzed
8.1
WordPress is vulnerable

The Perfmatters plugin for WordPress is vulnerable to arbitrary file deletion via path traversal in all versions up to, and including, 2

2026-04-03
CVE-2026-4347
Analyzed
8.1
WordPress is vulnerable

The MW WP Form plugin for WordPress is vulnerable to arbitrary file moving due to insufficient file path validation via the 'generate_user_filepath' f...

2026-04-02
CVE-2026-4326
Analyzed
8.8
WordPress is vulnerable

The Vertex Addons for Elementor plugin for WordPress is vulnerable to Missing Authorization in all versions up to and including 1

2026-04-09
CVE-2026-4314
Analyzed
8.8
WordPress Toolkit

The 'The Ultimate WordPress Toolkit – WP Extended' plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 3

2026-03-22
CVE-2026-4306
Analyzed
7.5
WordPress is vulnerable

The WP Job Portal plugin for WordPress is vulnerable to SQL Injection via the 'radius' parameter in all versions up to, and including, 2

2026-03-24
CVE-2026-4304
Analyzed
7.5
WordPress is vulnerable

The WeePie Cookie Allow plugin for WordPress is vulnerable to SQL Injection via the 'consent' parameter in all versions up to, and including, 3

2026-05-06
CVE-2026-4302
Analyzed
7.2
WordPress is vulnerable

The WowOptin: Next-Gen Popup Maker plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 1

2026-03-22
CVE-2026-4297
Analyzed
8.8
WordPress Welcome Software Publishing Plugin

The Welcome Software Publishing plugin for WordPress is vulnerable to Arbitrary Options Update in all versions up to and including 0

2026-06-24
CVE-2026-4283
Analyzed
9.1
WordPress is vulnerable

The WP DSGVO Tools (GDPR) plugin for WordPress allows unauthenticated attackers to permanently destroy non-administrator accounts by bypassing the ema...

2026-03-24
CVE-2026-4275
Analyzed
8.8
WordPress Divi Torque Lite – Divi Modules for the Divi Builder & Theme

The Divi Torque Lite – Divi Theme, Divi Builder & Extra Theme plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to,...

2026-07-10
CVE-2026-42680
Analyzed
9.8
WordPress Contest Gallery Pro

Contest Gallery Pro for WordPress contains an incorrect privilege assignment vulnerability that allows privilege escalation.

2026-06-02
CVE-2026-4267
Analyzed
7.2
WordPress plugin for

The Query Monitor – The developer tools panel for WordPress plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘$_SERVER['RE...

2026-04-01
CVE-2026-42629
Analyzed
8.8
WordPress PowerPack Pro for Elementor

Unauthenticated Broken Authentication in PowerPack Pro for Elementor < v2

2026-06-18
CVE-2026-4261
Analyzed
8.8
WordPress is vulnerable

The Expire Users plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1

2026-03-21
CVE-2026-4259
Analyzed
7.1
WordPress Ultimate WooCommerce Auction Pro

The ultimate-woocommerce-auction-pro WordPress plugin through 2

2026-06-23
CVE-2026-4257
Analyzed
9.8
WordPress is vulnerable

The Contact Form by Supsystic plugin for WordPress is vulnerable to unauthenticated Remote Code Execution via Server-Side Template Injection in the Tw...

2026-03-31
CVE-2026-4248
Analyzed
8
WordPress is vulnerable

The Ultimate Member plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2

2026-03-28
CVE-2026-42411
Analyzed
8.1
WordPress CloudSecure WP Security

Unauthenticated Broken Authentication in CloudSecure WP Security <= 1

2026-06-16
CVE-2026-4162
Analyzed
7.1
WordPress is vulnerable

The Gravity SMTP plugin for WordPress is vulnerable to Missing Authorization in versions up to, and including, 2

2026-04-12
CVE-2026-41471
Analyzed
7.5
WordPress versions

Easy PayPal Events & Tickets plugin for WordPress versions 1

2026-05-05
CVE-2026-4132
Analyzed
7.2
WordPress is vulnerable

The HTTP Headers plugin for WordPress is vulnerable to External Control of File Name or Path leading to Remote Code Execution in all versions up to an...

2026-04-24
CVE-2026-4119
Analyzed
9.1
WordPress is vulnerable

The Create DB Tables plugin for WordPress is vulnerable to authorization bypass, allowing authenticated attackers to drop or create database tables.

2026-04-23
CVE-2026-4100
Analyzed
7.1
WordPress is vulnerable

The Paid Memberships Pro plugin for WordPress is vulnerable to unauthorized modification and disruption of Stripe webhook configuration in all version...

2026-05-04
CVE-2026-4094
Analyzed
8.1
WordPress is vulnerable

The FOX – Currency Switcher Professional for WooCommerce plugin for WordPress is vulnerable to unauthorized data loss due to a missing capability chec...

2026-05-16
CVE-2026-40772
Analyzed
10
WordPress GeekyBot Plugin

The GeekyBot WordPress plugin is susceptible to an unauthenticated arbitrary file upload vulnerability, which can lead to remote code execution.

2026-06-16
CVE-2026-4062
Analyzed
7.5
WordPress is vulnerable

The Geo Mashup plugin for WordPress is vulnerable to Time-Based SQL Injection via the 'object_ids' and 'exclude_object_ids' parameters in all versions...

2026-05-03
CVE-2026-4061
Analyzed
7.5
WordPress is vulnerable

The Geo Mashup plugin for WordPress is vulnerable to Time-Based SQL Injection via the 'map_post_type' parameter in all versions up to, and including,...

2026-05-03
CVE-2026-4060
Analyzed
7.5
WordPress is vulnerable

The Geo Mashup plugin for WordPress is vulnerable to Time-Based SQL Injection via the 'sort' parameter in all versions up to, and including, 1

2026-05-03
CVE-2026-4038
Analyzed
9.8
WordPress is vulnerable

The Aimogen Pro plugin for WordPress allows unauthenticated arbitrary function calls. Attackers can exploit this to change the default user role to ad...

2026-03-20
CVE-2026-4030
Analyzed
8.1
WordPress plugin for

The Database Backup for WordPress plugin for WordPress is vulnerable to unauthorized arbitrary file read and deletion in all versions up to, and inclu...

2026-05-16
CVE-2026-4021
Analyzed
8.1
WordPress is vulnerable

The Contest Gallery plugin for WordPress is vulnerable to an authentication bypass leading to admin account takeover in all versions up to, and includ...

2026-03-24
CVE-2026-4020
Analyzed
7.5
WordPress is vulnerable

The Gravity SMTP plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2

2026-03-31
CVE-2026-4003
Analyzed
9.8
WordPress is vulnerable

The Users manager – PN WordPress plugin contains a privilege escalation flaw allowing unauthenticated attackers to modify arbitrary user metadata.

2026-04-08
CVE-2026-3985
Analyzed
7.5
WordPress is vulnerable

The Creative Mail – Easier WordPress & WooCommerce Email Marketing plugin for WordPress is vulnerable to SQL Injection via the 'checkout_uuid' paramet...

2026-05-20
CVE-2026-39591
Analyzed
9.9
WordPress WP-BusinessDirectory

An arbitrary file upload vulnerability exists in the WP-BusinessDirectory plugin for WordPress, allowing attackers to upload malicious files.

2026-06-16
CVE-2026-39587
Analyzed
8.1
WordPress WP BASE Booking

Unauthenticated Privilege Escalation in WP BASE Booking <= 5

2026-06-16
CVE-2026-39583
Analyzed
9.8
WordPress Ecommerce Delivery

An unauthenticated privilege escalation vulnerability exists in the Datalogics Ecommerce Delivery WordPress plugin, allowing attackers to gain adminis...

2026-06-16
CVE-2026-39581
Analyzed
8.5
WordPress WP Sessions Time Monitoring Full Automatic

Subscriber SQL Injection in WP Sessions Time Monitoring Full Automatic <= 1

2026-06-17
CVE-2026-39579
Analyzed
8.8
WordPress B Blocks

Contributor Privilege Escalation in B Blocks <= 2

2026-06-16
CVE-2026-39531
Analyzed
9.3
WordPress WP Directory Kit

The WP Directory Kit plugin for WordPress is vulnerable to Blind SQL Injection, allowing attackers to extract sensitive database information.

2026-05-22
CVE-2026-39502
Analyzed
9.3
WordPress Form Maker

The Form Maker by 10Web plugin for WordPress is vulnerable to unauthenticated SQL injection, allowing attackers to extract information from the databa...

2026-06-16
CVE-2026-39492
Analyzed
9.3
WordPress WP Maps Plugin

The WP Maps plugin for WordPress is vulnerable to unauthenticated SQL injection, enabling attackers to extract sensitive information from the database...

2026-06-16
CVE-2026-39441
Analyzed
9.3
WordPress Feed KuantoKusta for WooCommerce

The Feed KuantoKusta for WooCommerce plugin contains an unauthenticated SQL injection vulnerability that allows remote attackers to manipulate databas...

2026-06-16
CVE-2026-3891
Analyzed
9.8
WordPress is vulnerable

The Pix for WooCommerce WordPress plugin (up to 1.5.0) is vulnerable to unauthenticated arbitrary file uploads due to missing capability checks and fi...

2026-03-14
CVE-2026-3844
Analyzed
9.8
WordPress is vulnerable

The Breeze Cache plugin for WordPress is vulnerable to unauthenticated arbitrary file uploads via the Gravatar fetching function.

2026-04-23
CVE-2026-3830
Analyzed
8.6
WordPress plugin before

The Product Filter for WooCommerce by WBW WordPress plugin before 3

2026-04-14
CVE-2026-3772
Analyzed
8.8
WordPress is vulnerable

The WP Editor plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1

2026-05-02
CVE-2026-3688
Analyzed
8.1
WordPress WCFM Membership – WooCommerce Memberships for Multivendor Marketplace

The WCFM Membership – WooCommerce Memberships for Multivendor Marketplace plugin for WordPress is vulnerable to Insecure Direct Object Reference in al...

2026-07-09
CVE-2026-3666
Analyzed
8.8
WordPress is vulnerable

The wpForo Forum plugin for WordPress is vulnerable to arbitrary file deletion in all versions up to, and including, 2

2026-04-05
CVE-2026-3658
Analyzed
7.5
WordPress is vulnerable

The Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin plugin for WordPress is vulnerable to SQL Injection via the 'fields' pa...

2026-03-20
CVE-2026-3655
Analyzed
9.8
WordPress OTP Login With Phone Number, OTP Verification Plugin

The OTP Login With Phone Number plugin for WordPress is vulnerable to authentication bypass, allowing unauthenticated attackers to hijack user account...

2026-05-29
CVE-2026-3643
Analyzed
7.2
WordPress is vulnerable

The Accessibly plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the REST API in all versions up to, and including, 3

2026-04-17
CVE-2026-3629
Analyzed
8.1
WordPress is vulnerable

The Import and export users and customers plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 1

2026-03-22
CVE-2026-3614
Analyzed
8.8
WordPress is vulnerable

The AcyMailing plugin for WordPress is vulnerable to privilege escalation in all versions From 9

2026-04-16
CVE-2026-3599
Analyzed
7.5
WordPress is vulnerable

The Riaxe Product Customizer plugin for WordPress is vulnerable to SQL Injection via the 'options' parameter keys within 'product_data' of the /wp-jso...

2026-04-17
CVE-2026-3596
Analyzed
9.8
WordPress is vulnerable

The Riaxe Product Customizer plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 2.1.2. The plugin regist...

2026-04-16
CVE-2026-3589
Analyzed
7.5
WordPress plugin from

The WooCommerce WordPress plugin from versions 5

2026-03-07
CVE-2026-3584
Analyzed
9.8
WordPress is vulnerable

The Kali Forms WordPress plugin is vulnerable to Remote Code Execution (RCE) via the form_process function, allowing unauthenticated attackers to exec...

2026-03-21
CVE-2026-3576
Analyzed
7.2
WordPress Planyo Online Reservation System

The Planyo Online Reservation System plugin for WordPress is vulnerable to Server-Side Request Forgery leading to Local File Inclusion in all versions...

2026-07-12
CVE-2026-3533
Analyzed
8.8
WordPress is vulnerable

The Jupiter X Core plugin for WordPress is vulnerable to limited file uploads due to missing authorization on import_popup_templates() function as wel...

2026-03-24
CVE-2026-3499
Analyzed
8.8
WordPress is vulnerable

The Product Feed PRO for WooCommerce by AdTribes – Product Feeds for WooCommerce plugin for WordPress is vulnerable to Cross-Site Request Forgery in v...

2026-04-08
CVE-2026-34901
Analyzed
9.8
WordPress iControlWP

iControlWP contains an unauthenticated privilege escalation vulnerability that allows remote attackers to gain elevated access to the system.

2026-06-16
CVE-2026-3489
Analyzed
7.5
WordPress is vulnerable

The DirectoryPress – Business Directory And Classified Ad Listing plugin for WordPress is vulnerable to SQL Injection via the 'packages' parameter in...

2026-04-17
CVE-2026-3478
Analyzed
7.2
WordPress is vulnerable

The Content Syndication Toolkit plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 1

2026-03-22
CVE-2026-3464
Analyzed
8.8
WordPress is vulnerable

The WP Customer Area plugin for WordPress is vulnerable to arbitrary file read and deletion due to insufficient file path validation in the 'ajax_atta...

2026-04-18
CVE-2026-3461
Analyzed
9.8
WordPress is vulnerable

The Visa Acceptance Solutions plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 2.1.0. This is due to...

2026-04-16
CVE-2026-3459
Analyzed
8.1
WordPress is vulnerable

The Drag and Drop Multiple File Upload - Contact Form 7 plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient file type val...

2026-03-06
CVE-2026-3456
Analyzed
7.5
WordPress is vulnerable

The GeekyBot — Generate AI Content Without Prompt, Chatbot and Lead Generation plugin for WordPress is vulnerable to SQL Injection via the 'attributek...

2026-05-05
CVE-2026-3453
Analyzed
8.1
WordPress is vulnerable

The ProfilePress plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 4

2026-03-11
CVE-2026-3445
Analyzed
7.1
WordPress is vulnerable

The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress plugin for WordPress is vuln...

2026-04-05
CVE-2026-34424
Analyzed
9.8
WordPress and Joomla

Smart Slider 3 Pro 3.5.1.35 contains a critical remote access toolkit vulnerability that allows unauthenticated attackers to execute arbitrary code an...

2026-04-10
CVE-2026-3430
Analyzed
8.6
WordPress Creative Mail

The Creative Mail WordPress plugin from 1

2026-08-08
CVE-2026-3425
Analyzed
8.8
WordPress is vulnerable

The RTMKit Addons for Elementor plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 2

2026-05-14
CVE-2026-3368
Analyzed
7.2
WordPress is vulnerable

The Injection Guard plugin for WordPress is vulnerable to Stored Cross-Site Scripting via malicious query parameter names in all versions up to and in...

2026-03-22
CVE-2026-3360
Analyzed
7.5
WordPress is vulnerable

The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to an Insecure Direct Object Reference in all versions up to,...

2026-04-11
CVE-2026-3359
Analyzed
7.5
WordPress is vulnerable

The Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder plugin for WordPress is vulnerable to SQL Injection via the 'inputs' parame...

2026-05-06
CVE-2026-3334
Analyzed
8.8
WordPress is vulnerable

The CMS Commander plugin for WordPress is vulnerable to SQL Injection via the 'or_blogname', 'or_blogdescription', and 'or_admin_email' parameters in...

2026-03-21
CVE-2026-3326
Analyzed
8.6
WordPress Xstore WordPress theme

The Xstore WordPress theme before 9

2026-06-11
CVE-2026-32834
Analyzed
7.5
WordPress version

Easy PayPal Events & Tickets plugin for WordPress version 1

2026-05-05
CVE-2026-32573
Analyzed
9.1
WordPress Nelio AB Testing

Nelio AB Testing plugin for WordPress contains a code injection vulnerability. This allows remote attackers to execute arbitrary code by exploiting im...

2026-03-26
CVE-2026-32566
Analyzed
9.8
WordPress ACPT (Pro) - Custom Post Types Plugin for WordPress

A critical privilege escalation vulnerability in the ACPT (Pro) WordPress plugin allows unauthenticated attackers to gain unauthorized administrative...

2026-08-28
CVE-2026-32564
Analyzed
8.5
WordPress ACPT (Pro) - Custom Post Types Plugin

Subscriber SQL Injection in ACPT (Pro) - Custom Post Types Plugin for WordPress <= 2.0.63 versions.

2026-08-28
CVE-2026-32561
Analyzed
8.8
WordPress Booking Hub

Subscriber Privilege Escalation in Booking Hub <= 1

2026-08-25
CVE-2026-32560
Analyzed
8.8
WordPress MagicAI for WordPress

Subscriber Local File Inclusion in MagicAI for WordPress - AI Text, Image, Chat, Code, and Voice Generator <= 1

2026-08-25
CVE-2026-32558
Analyzed
9.8
WordPress Affiliate Pro - Affiliate Program for WooCommerce & WordPress

An unauthenticated privilege escalation vulnerability exists in the Affiliate Pro plugin for WordPress, allowing unauthorized users to elevate their a...

2026-08-25
CVE-2026-32551
Analyzed
9.3
WordPress Woo Essential

A critical SQL injection vulnerability in the DiviNext Woo Essential plugin allows unauthenticated attackers to execute arbitrary database queries.

2026-08-25
CVE-2026-32550
Analyzed
8.5
WordPress Kadence Shop Kit

Subscriber SQL Injection in Kadence Shop Kit <= 3.0.6 versions.

2026-08-28
CVE-2026-32477
Analyzed
8.6
WordPress ShopBuilder Pro – Elementor WooCommerce Builder Addons

Unauthenticated Arbitrary File Deletion in ShopBuilder Pro – Elementor WooCommerce Builder Addons <= 2

2026-08-25
CVE-2026-32474
Analyzed
9.9
WordPress Templatiq

The Templatiq WordPress plugin is vulnerable to an arbitrary file upload flaw, allowing authenticated contributors to execute malicious code on the se...

2026-08-19
CVE-2026-32471
Analyzed
8.5
WordPress ProLancer Element

Subscriber SQL Injection in ProLancer Element <= 1

2026-08-25
CVE-2026-32463
Analyzed
9.9
WordPress Sync Post With Other Site

The Sync Post With Other Site WordPress plugin is vulnerable to an arbitrary file upload flaw, allowing authenticated contributors to execute maliciou...

2026-08-19
CVE-2026-32444
Analyzed
9.9
WordPress Cwicly

A remote code execution vulnerability exists in the Cwicly plugin for WordPress, allowing authenticated users with contributor-level access to execute...

2026-08-19
CVE-2026-3243
Analyzed
8.8
WordPress is vulnerable

The Advanced Members for ACF plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the create_crop...

2026-04-09
CVE-2026-3220
Analyzed
8.8
WordPress plugin before

The Autoptimize WordPress plugin before 3

2026-05-19
CVE-2026-3180
Analyzed
7.5
WordPress is vulnerable

The Contest Gallery – Upload & Vote Photos, Media, Sell with PayPal & Stripe plugin for WordPress is vulnerable to blind SQL Injection via the ‘cgLost...

2026-03-03
CVE-2026-3132
Analyzed
8.8
WordPress is vulnerable

The Master Addons for Elementor Premium plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 2

2026-03-03
CVE-2026-3124
Analyzed
7.5
WordPress is vulnerable

The Download Monitor plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 5

2026-03-30
CVE-2026-3090
Analyzed
7.2
WordPress is vulnerable

The Post SMTP – Complete Email Deliverability and SMTP Solution with Email Logs, Alerts, Backup SMTP & Mobile App plugin for WordPress is vulnerable t...

2026-03-19
CVE-2026-3045
Analyzed
7.5
WordPress is vulnerable

The Appointment Booking Calendar — Simply Schedule Appointments plugin for WordPress is vulnerable to unauthorized access of sensitive data in all ver...

2026-03-14
CVE-2026-3003
Analyzed
7.2
WordPress is vulnerable

The Vagaro Booking Widget plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘vagaro_code’ parameter in all versions up to, and...

2026-03-22
CVE-2026-2996
Analyzed
7.5
WordPress Advanced Product Fields (Product Addons) for WooCommerce

The Advanced Product Fields (Product Addons) for WooCommerce plugin for WordPress is vulnerable to Improper Input Validation in all versions up to, an...

2026-08-23
CVE-2026-2992
Analyzed
8.2
WordPress is vulnerable

The KiviCare – Clinic & Patient Management System (EHR) plugin for WordPress is vulnerable to Privilege Escalation due to missing authorization on the...

2026-03-19
CVE-2026-2991
Analyzed
9.8
WordPress is vulnerable

The KiviCare EHR plugin for WordPress suffers from an authentication bypass in its social login function, allowing unauthenticated attackers to log in...

2026-03-19
CVE-2026-2942
Analyzed
9.8
WordPress is vulnerable

The ProSolution WP Client plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation, enabling potential Remote...

2026-04-09
CVE-2026-2941
Analyzed
8.8
WordPress is vulnerable

The Linksy Search and Replace plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'linksy...

2026-03-21
CVE-2026-2936
Analyzed
7.2
WordPress is vulnerable

The Visitor Traffic Real Time Statistics plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'page_title' parameter in all versi...

2026-04-05
CVE-2026-2931
Analyzed
8.8
WordPress is vulnerable

The Amelia Booking plugin for WordPress is vulnerable to Insecure Direct Object References in versions up to, and including, 9

2026-03-26
CVE-2026-2892
Analyzed
7.5
WordPress is vulnerable

The Otter Blocks plugin for WordPress is vulnerable to Purchase Verification Bypass in all versions up to, and including, 3

2026-05-01
CVE-2026-2890
Analyzed
7.5
WordPress is vulnerable

The Formidable Forms plugin for WordPress is vulnerable to a payment integrity bypass in all versions up to, and including, 6

2026-03-14
CVE-2026-28562
Analyzed
8.2
WordPress database

wpForo 2

2026-03-01
CVE-2026-28171
Analyzed
8.6
WordPress WooCommerce File Approval

Unauthenticated Arbitrary File Deletion in WooCommerce File Approval <= 10

2026-08-25
CVE-2026-28165
Analyzed
9.8
WordPress Digits

The Digits WordPress plugin is affected by an unauthenticated privilege escalation vulnerability, enabling remote attackers to gain unauthorized eleva...

2026-08-25
CVE-2026-28161
Analyzed
8.8
WordPress Service Finder Booking

Subscriber Privilege Escalation in Service Finder Booking <= 6

2026-08-14
CVE-2026-28152
Analyzed
8.1
WordPress Tonda Core

Unauthenticated Local File Inclusion in Tonda Core < 2

2026-08-25
CVE-2026-28148
Analyzed
9.8
WordPress Headless Single Sign On

The miniOrange Headless Single Sign On plugin for WordPress contains an unauthenticated bypass vulnerability due to improper cryptographic signature v...

2026-08-14
CVE-2026-28111
Analyzed
8.8
WordPress Forminator

Contributor Privilege Escalation in Forminator <= 1

2026-08-06
CVE-2026-28008
Analyzed
9.8
WordPress OAuth Single Sign On – SSO (OAuth Client)

The miniOrange OAuth Single Sign On plugin for WordPress contains an unauthenticated authentication bypass vulnerability that allows attackers to spoo...

2026-08-14
CVE-2026-28005
Analyzed
9.8
WordPress Kadence WooCommerce Email Designer

The Kadence WooCommerce Email Designer plugin for WordPress contains a missing authorization vulnerability that allows unauthenticated attackers to es...

2026-08-06
CVE-2026-27938
Analyzed
7.7
WordPress sites

WPGraphQL provides a GraphQL API for WordPress sites

2026-02-26
CVE-2026-27544
Analyzed
10
WordPress QA Analytics

QuarkA QA Analytics plugin for WordPress contains an unauthenticated remote code execution vulnerability due to improper control of code generation.

2026-08-14
CVE-2026-27542
Analyzed
9.8
WordPress Woocommerce Wholesale Lead Capture

The Woocommerce Wholesale Lead Capture plugin is vulnerable to incorrect privilege assignment, which allows attackers to escalate their privileges wit...

2026-03-19
CVE-2026-27419
Analyzed
9.9
WordPress Zegen

An arbitrary file upload vulnerability in Zozothemes Zegen allows authenticated attackers to execute malicious code.

2026-07-03
CVE-2026-27096
Analyzed
8.1
WordPress Theme allows

Deserialization of Untrusted Data vulnerability in BuddhaThemes ColorFolio - Freelance Designer WordPress Theme allows Object Injection

2026-03-19
CVE-2026-2631
Analyzed
9.8
WordPress plugin before

The Datalogics Ecommerce Delivery plugin for WordPress before 2.6.60 contains an unauthenticated REST endpoint vulnerability allowing remote attackers...

2026-03-12
CVE-2026-2626
Analyzed
8.1
WordPress plugin before

The divi-booster WordPress plugin before 5

2026-03-12
CVE-2026-2592
Analyzed
7.7
WordPress is vulnerable

The Zarinpal Gateway for WooCommerce plugin for WordPress is vulnerable to Improper Access Control to Payment Status Update in all versions up to and...

2026-02-17
CVE-2026-25863
Analyzed
7.5
WordPress plugin through

Conditional Fields for Contact Form 7 WordPress plugin through version 2

2026-05-05
CVE-2026-2579
Analyzed
7.5
WordPress is vulnerable

The WowStore – Store Builder & Product Blocks for WooCommerce plugin for WordPress is vulnerable to SQL Injection via the ‘search’ parameter in all ve...

2026-03-17
CVE-2026-2576
Analyzed
7.5
WordPress plugin for

The Business Directory Plugin – Easy Listing Directories for WordPress plugin for WordPress is vulnerable to time-based SQL Injection via the 'payment...

2026-02-18
CVE-2026-2568
Analyzed
7.2
WordPress is vulnerable

The WP Zendesk for Contact Form 7, WPForms, Elementor, Formidable and Ninja Forms plugin for WordPress is vulnerable to Stored Cross-Site Scripting vi...

2026-03-04
CVE-2026-2554
Analyzed
8.1
WordPress is vulnerable

The WCFM – Frontend Manager for WooCommerce along with Bookings Subscription Listings Compatible plugin for WordPress is vulnerable to Insecure Direct...

2026-05-03
CVE-2026-25470
Analyzed
10
WordPress ACPT (Pro) - Custom Post Types Plugin

An improper code injection vulnerability in the ACPT (Pro) plugin for WordPress allows unauthenticated remote attackers to execute arbitrary code.

2026-06-18
CVE-2026-25405
Analyzed
8.5
WordPress eRoom

Contributor SQL Injection in eRoom <= 1

2026-07-24
CVE-2026-2511
Analyzed
7.5
WordPress is vulnerable

The JS Help Desk – AI-Powered Support & Ticketing System plugin for WordPress is vulnerable to SQL Injection via the `multiformid` parameter in the `s...

2026-03-28
CVE-2026-2497
Analyzed
7.2
WordPress Gallery by BestWebSoft

The Gallery by BestWebSoft plugin for WordPress is vulnerable to SQL Injection via the '_gallery_order_{post_id}' parameter array keys in all versions...

2026-08-16
CVE-2026-2495
Analyzed
7.5
WordPress is vulnerable

The WPNakama – Team and multi-Client Collaboration, Editorial and Project Management plugin for WordPress is vulnerable to SQL Injection via the 'orde...

2026-02-18
CVE-2026-2468
Analyzed
7.5
WordPress is vulnerable

The Quentn WP plugin for WordPress is vulnerable to SQL Injection via the 'qntn_wp_access' cookie in all versions up to, and including, 1

2026-03-22
CVE-2026-24552
Analyzed
8.5
WordPress Create by Mediavine

Contributor SQL Injection in Create by Mediavine <= 2

2026-07-24
CVE-2026-2448
Analyzed
8.8
WordPress is vulnerable

The Page Builder by SiteOrigin plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 2

2026-03-03
CVE-2026-2446
Analyzed
9.8
WordPress plugin before

The PowerPack for LearnDash WordPress plugin before 1.3.0 lacks authorization and CSRF checks in an AJAX action, allowing unauthenticated users to cre...

2026-03-07
CVE-2026-2440
Analyzed
7.2
WordPress is vulnerable

The SurveyJS plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 2

2026-03-22
CVE-2026-2428
Analyzed
7.5
WordPress is vulnerable

The Fluent Forms Pro Add On Pack plugin for WordPress is vulnerable to Insufficient Verification of Data Authenticity in all versions up to, and inclu...

2026-02-27
CVE-2026-2416
Analyzed
7.5
WordPress is vulnerable

The Geo Mashup plugin for WordPress is vulnerable to SQL Injection via the 'sort' parameter in all versions up to, and including, 1

2026-02-25
CVE-2026-23693
Analyzed
10
WordPress plugin versions

The ElementsKit Lite plugin for WordPress exposes a REST endpoint without authentication, allowing unauthenticated attackers to use the site as an ope...

2026-02-24
CVE-2026-2365
Analyzed
7.2
WordPress is vulnerable

The Fluent Forms Pro plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `fluentform_step_form_save_data` AJAX action in all ver...

2026-03-05
CVE-2026-2354
Analyzed
8.8
WordPress Swiss Toolkit For WP

The Swiss Toolkit For WP plugin for WordPress is vulnerable to arbitrary file upload due to a flawed file type validation bypass in the `upload_extens...

2026-07-11
CVE-2026-2296
Analyzed
7.2
WordPress is vulnerable

The Product Addons for Woocommerce – Product Options with Custom Fields plugin for WordPress is vulnerable to Code Injection in all versions up to, an...

2026-02-18
CVE-2026-22850
Analyzed
8.3
WordPress Multiple Products

Koko Analytics is an open-source analytics plugin for WordPress

2026-01-20
CVE-2026-2279
Analyzed
7.2
WordPress is vulnerable

The myLinksDump plugin for WordPress is vulnerable to SQL Injection via the 'sort_by' and 'sort_order' parameters in all versions up to, and including...

2026-03-22
CVE-2026-2269
Analyzed
7.2
WordPress is vulnerable

The Uncanny Automator – Easy Automation, Integration, Webhooks & Workflow Builder Plugin plugin for WordPress is vulnerable to Server-Side Request For...

2026-03-03
CVE-2026-2262
Analyzed
7.5
WordPress is vulnerable

The Easy Appointments plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3

2026-04-18
CVE-2026-22383
Analyzed
7.5
WordPress Theme pawfriends

Authorization Bypass Through User-Controlled Key vulnerability in Mikado-Themes PawFriends - Pet Shop and Veterinary WordPress Theme pawfriends allows...

2026-02-21
CVE-2026-22343
Analyzed
8.6
WordPress Dating Theme

Unauthenticated Broken Access Control in WordPress Dating Theme <= 11

2026-06-18
CVE-2026-22342
Analyzed
8.8
WordPress Dating Theme

Unauthenticated Cross Site Request Forgery (CSRF) in WordPress Dating Theme <= 11

2026-06-18
CVE-2026-2232
Analyzed
7.5
WordPress is vulnerable

The Product Table and List Builder for WooCommerce Lite plugin for WordPress is vulnerable to time-based SQL Injection via the 'search' parameter in a...

2026-02-20
CVE-2026-2144
Analyzed
8.1
WordPress is vulnerable

The Magic Login Mail or QR Code plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 2

2026-02-14
CVE-2026-2052
Analyzed
8.8
WordPress is vulnerable

The Widget Options – Advanced Conditional Visibility for Gutenberg Blocks & Classic Widgets plugin for WordPress is vulnerable to Remote Code Executio...

2026-05-02
CVE-2026-2025
Analyzed
7.5
WordPress plugin before

The Mail Mint WordPress plugin before 1

2026-03-05
CVE-2026-2024
Analyzed
7.5
WordPress is vulnerable

The PhotoStack Gallery plugin for WordPress is vulnerable to SQL Injection via the 'postid' parameter in all versions up to, and including, 0

2026-02-14
CVE-2026-2019
Analyzed
7.2
WordPress is vulnerable

The Cart All In One For WooCommerce plugin for WordPress is vulnerable to Code Injection in all versions up to, and including, 1

2026-02-18
CVE-2026-2001
Analyzed
8.8
WordPress is vulnerable

The WowRevenue plugin for WordPress is vulnerable to unauthorized plugin installation due to a missing capability check in the 'Notice::install_activa...

2026-02-17
CVE-2026-19949
Analyzed
8.8
WordPress All-in-One WP Migration and Backup

The All-in-One WP Migration and Backup plugin for WordPress is vulnerable to SQL Injection via archive restore functionality in all versions up to, an...

2026-08-26
CVE-2026-1994
Analyzed
9.8
WordPress is vulnerable

The s2Member plugin for WordPress allows unauthenticated privilege escalation via account takeover due to insufficient identity validation during pass...

2026-02-20
CVE-2026-19892
Analyzed
8.8
WordPress InfusedWoo Pro

The InfusedWoo Pro plugin for WordPress is vulnerable to Privilege Escalation via Account Takeover in all versions up to, and including, 5

2026-08-25
CVE-2026-19883
Analyzed
8.8
WordPress WPeMatico RSS Feed Fetcher

The WPeMatico RSS Feed Fetcher plugin for WordPress is vulnerable to unauthorized modification of data that can lead to privilege escalation due to a...

2026-08-22
CVE-2026-1988
Analyzed
7.5
WordPress is vulnerable

The Flexi Product Slider and Grid for WooCommerce plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1

2026-02-14
CVE-2026-19842
Analyzed
8.8
WordPress SAML Single Sign On

The SAML Single Sign On WordPress plugin before 5

2026-08-20
CVE-2026-19728
Analyzed
7.5
WordPress Extra Product Options Builder

The Extra Product Options Builder for WooCommerce WordPress plugin before 1.2.176 does not verify that the requester is entitled to a customer-uploade...

2026-08-25
CVE-2026-19725
Analyzed
9.1
WordPress Backup, Migration & Staging

The WPvivid Backup, Migration & Staging plugin contains an arbitrary file creation vulnerability due to improper sanitization of log file paths provid...

2026-08-25
CVE-2026-19718
Analyzed
8.1
WordPress BlogVault Backup & Staging, MalCare WordPress Security Plugin, and The WP Remote WordPress Plugin

The BlogVault Backup & Staging WordPress plugin before 6.65, MalCare WordPress Security Plugin WordPress plugin before 6.65, The WP Remote WordPress...

2026-09-02
CVE-2026-19717
Analyzed
7.5
WordPress Document Gallery & PDF Library

The CatFolders Document Gallery & PDF Library WordPress plugin before 2.0.7 does not have authorisation checks in some of its REST API endpoints, allo...

2026-08-25
CVE-2026-19715
Analyzed
7.5
WordPress WP OAuth Server ( Login with WordPress )

The WP OAuth Server ( Login with WordPress ) WordPress plugin before 6.3.1 does not restrict access to the debug log it writes, which is stored at a f...

2026-09-03
CVE-2026-19632
Analyzed
9.8
WordPress TranslatePress

The TranslatePress plugin for WordPress is vulnerable to sensitive information exposure via an AJAX action, allowing unauthenticated attackers to stea...

2026-08-26
CVE-2026-19598
Analyzed
9.8
WordPress Pods – Custom Content Types and Fields

The Pods WordPress plugin is vulnerable to unauthenticated privilege escalation due to an authorization bypass in the AJAX router.

2026-08-16
CVE-2026-1947
Analyzed
7.5
WordPress plugin for

The NEX-Forms – Ultimate Forms Plugin for WordPress plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and...

2026-03-17
CVE-2026-1945
Analyzed
7.2
WordPress is vulnerable

The WPBookit plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'wpb_user_name' and 'wpb_user_email' parameters in all versions...

2026-03-04
CVE-2026-19423
Analyzed
8.1
WordPress Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin

The Ultimate Member WordPress plugin before 2.13.0 does not validate a submitted role selection when it cannot resolve the set of roles a profile for...

2026-09-04
CVE-2026-1937
Analyzed
9.8
WordPress is vulnerable

The YayMail plugin for WordPress is vulnerable to privilege escalation due to a missing capability check on an AJAX action, allowing authenticated att...

2026-02-18
CVE-2026-1931
Analyzed
7.2
WordPress is vulnerable

The Rent Fetch plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'keyword' parameter in all versions up to, and including, 0

2026-02-18
CVE-2026-1929
Analyzed
8.8
WordPress is vulnerable

The Advanced Woo Labels plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 2

2026-02-25
CVE-2026-1916
Analyzed
7.5
WordPress is vulnerable

The WPGSI: Spreadsheet Integration plugin for WordPress is vulnerable to unauthorized modification and loss of data due to missing capability checks a...

2026-02-25
CVE-2026-19084
Analyzed
7.5
WordPress shared-files-pro

The shared-files-pro WordPress plugin before 1.7.70 does not validate the file path supplied when creating a featured image, allowing unauthenticated...

2026-09-04
CVE-2026-19053
Analyzed
9.1
WordPress ProSolution WP Client

The ProSolution WP Client WordPress plugin is vulnerable to unauthenticated blind SQL injection due to improper sanitization of user-supplied paramete...

2026-08-27
CVE-2026-18946
Analyzed
7.5
WordPress Contact Form to Any API

The Contact Form to Any API WordPress plugin before 3

2026-08-11
CVE-2026-18945
Analyzed
8.2
WordPress WP Helper Premium

The WP Helper Premium WordPress plugin before 4.7.6 does not verify the order key when rendering its custom order confirmation page or when handling t...

2026-08-22
CVE-2026-18855
Analyzed
9.1
WordPress Link Library

The Link Library WordPress plugin contains a path traversal vulnerability in the ll_delete_link_fields function, allowing unauthenticated attackers to...

2026-08-16
CVE-2026-18786
Analyzed
8.8
WordPress CheckView

The CheckView WordPress plugin before 2.3.2 does not restrict its REST API authentication filter to its own routes and unconditionally discards the a...

2026-08-27
CVE-2026-18781
Analyzed
8.1
WordPress Drag and Drop Multiple File Upload for Contact Form 7

The Drag and Drop Multiple File Upload for Contact Form 7 WordPress plugin before 1

2026-08-22
CVE-2026-18653
Analyzed
7.2
WordPress WP Directory Kit

The WP Directory Kit WordPress plugin before 1.5.7 does not sanitise and escape a parameter before using it in a SQL statement, allowing administrator...

2026-08-25
CVE-2026-18550
Analyzed
9.8
WordPress Nokri – Job Board WordPress Theme

The Nokri WordPress theme is vulnerable to unauthenticated account takeover due to improper validation of password reset tokens, allowing unauthorized...

2026-09-02
CVE-2026-18473
Analyzed
9.1
WordPress WP Directory Kit

The WP Directory Kit WordPress plugin before 1.5.5 contains a SQL injection vulnerability that allows unauthenticated users to execute arbitrary datab...

2026-08-17
CVE-2026-18470
Analyzed
7.5
WordPress Login & Register Forms

The Login & Register Forms WordPress plugin before 4

2026-08-11
CVE-2026-18469
Analyzed
8.1
WordPress Login & Register Forms

The Login & Register Forms WordPress plugin before 4.0.2 does not enforce its password reset attempt limit against a server-derived value, keying bot...

2026-08-19
CVE-2026-18468
Analyzed
8.1
WordPress Login & Register Forms

The Login & Register Forms WordPress plugin before 4.0.2 does not bind the password reset verification state to the account being reset or to the par...

2026-08-16
CVE-2026-18464
Analyzed
7.5
WordPress WP MAPS PRO

The WP MAPS PRO WordPress plugin before 6.1.3 does not perform a capability check in one of its AJAX actions, which is also available to unauthenticat...

2026-08-16
CVE-2026-18438
Analyzed
8.8
WordPress Templately – Elementor & Gutenberg Template Library

The Templately – Elementor & Gutenberg Template Library: 6500+ Free & Pro Ready Templates And Cloud! plugin for WordPress is vulnerable to Remote Code...

2026-08-16
CVE-2026-18432
Analyzed
9.8
WordPress Frontend Admin by DynamiApps

The Frontend Admin by DynamiApps plugin for WordPress contains a privilege escalation vulnerability due to an improper authorization check, allowing u...

2026-08-16
CVE-2026-18431
Analyzed
9.8
WordPress Avada (Fusion) Builder

An arbitrary file write vulnerability in the Avada theme and Fusion Builder plugin for WordPress allows unauthenticated attackers to achieve remote co...

2026-08-26
CVE-2026-1843
Analyzed
7.2
WordPress is vulnerable

The Super Page Cache plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Activity Log in all versions up to, and including, 5

2026-02-14
CVE-2026-18366
Analyzed
9.8
WordPress Events Manager

The Events Manager WordPress plugin fails to properly scope capability checks, allowing unauthenticated users to perform privileged account actions if...

2026-08-13
CVE-2026-18357
Analyzed
7.5
WordPress WPC Order Tip for WooCommerce

The WPC Order Tip for WooCommerce WordPress plugin before 3.3.1 does not perform authorisation or nonce checks in one of its reporting features, allow...

2026-08-17
CVE-2026-18352
Analyzed
7.5
WordPress User Access Manager

The User Access Manager plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 2

2026-08-02
CVE-2026-18322
Analyzed
8.8
WordPress Smart Popup by Supsystic

The Smart Popup by Supsystic plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1

2026-08-05
CVE-2026-18316
Analyzed
9.1
WordPress Solace Extra

The Solace Extra plugin for WordPress is vulnerable to unauthorized data modification and loss due to a missing capability check on the import_zip() f...

2026-08-16
CVE-2026-1830
Analyzed
9.8
WordPress is vulnerable

The Quick Playground plugin for WordPress contains an RCE vulnerability due to insufficient authorization on REST API endpoints, allowing unauthentica...

2026-04-09
CVE-2026-1829
Analyzed
8.8
WordPress Content Visibility for Divi Builder

The Content Visibility for Divi Builder plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 4

2026-06-03
CVE-2026-18080
Analyzed
9.8
WordPress ERP: Complete HR, Accounting & CRM Suite Built for WooCommerce

The ERP: Complete HR, Accounting & CRM Suite plugin for WordPress is vulnerable to unauthenticated remote code execution via unrestricted file uploads...

2026-08-27
CVE-2026-18072
Analyzed
9.8
WordPress Advanced Responsive Video Embedder

A hardcoded backdoor in the Advanced Responsive Video Embedder WordPress plugin allows unauthenticated attackers to authenticate as an administrator u...

2026-07-29
CVE-2026-18057
Analyzed
8.1
WordPress Events Manager – Calendar, Bookings, Tickets, and more!

The Events Manager WordPress plugin before 7.4.1 does not sanitise and escape a user-controlled value before using it in a SQL statement, allowing us...

2026-08-21
CVE-2026-18051
Analyzed
10
WordPress W3 Total Cache

The W3 Total Cache WordPress plugin contains a path traversal vulnerability that allows unauthenticated attackers to write or overwrite arbitrary file...

2026-08-20
CVE-2026-18049
Analyzed
7.5
WordPress WP Photo Album Plus

The WP Photo Album Plus WordPress plugin before 9.2.07.002 does not perform any capability or nonce check on one of its public endpoint actions and bu...

2026-08-27
CVE-2026-18048
Analyzed
7.5
WordPress WP Photo Album Plus

The WP Photo Album Plus WordPress plugin before 9.2.07.002 does not validate a client-controlled value used to build a file path in one of its public...

2026-08-21
CVE-2026-18032
Analyzed
7.5
WordPress WP Data Access – App Builder for Tables, Forms, Charts, Maps & Dashboards

The WP Data Access WordPress plugin before 5.5.79 does not validate the column names it accepts on one of its unauthenticated AJAX actions, and the n...

2026-08-27
CVE-2026-18030
Analyzed
8.1
WordPress BricksForge

The BricksForge WordPress plugin before 3.1.8.8 does not verify the identity of the requester when processing a password change submitted through one...

2026-08-16
CVE-2026-1800
Analyzed
7.5
WordPress is vulnerable

The Fonts Manager | Custom Fonts plugin for WordPress is vulnerable to time-based SQL Injection via the ‘fmcfIdSelectedFnt’ parameter in all versions...

2026-03-22
CVE-2026-1779
Analyzed
8.1
WordPress is vulnerable

The User Registration & Membership plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 5

2026-02-26
CVE-2026-17581
Analyzed
7.2
WordPress WCPOS – Point of Sale (POS) plugin for WooCommerce

The WCPOS – Point of Sale (POS) plugin for WooCommerce plugin for WordPress is vulnerable to Code Injection via the 'thermal' Template Engine in all v...

2026-08-16
CVE-2026-1756
Analyzed
8.8
WordPress is vulnerable

The WP FOFT Loader plugin for WordPress is vulnerable to arbitrary file uploads due to incorrect file type validation in the 'WP_FOFT_Loader_Mimes::fi...

2026-02-04
CVE-2026-17542
Analyzed
7.5
WordPress File Manager

The File Manager WordPress plugin before 6

2026-08-11
CVE-2026-17541
Analyzed
7.5
WordPress File Manager

The File Manager WordPress plugin before 6

2026-08-11
CVE-2026-17540
Analyzed
8.8
WordPress File Manager plugin

The File Manager WordPress plugin before 6.9.1 does not properly authorise its file management commands, allowing any authenticated user, such as a su...

2026-08-18
CVE-2026-1750
Analyzed
8.8
WordPress is vulnerable

The Ecwid by Lightspeed Ecommerce Shopping Cart plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 7

2026-02-15
CVE-2026-1730
Analyzed
8.8
WordPress Multiple Products

The OS DataHub Maps plugin for WordPress is vulnerable to arbitrary file uploads due to incorrect file type validation in the 'OS_DataHub_Maps_Admin::...

2026-02-03
CVE-2026-1729
Analyzed
9.8
WordPress is vulnerable

The AdForest WordPress theme (<= 6.0.12) is vulnerable to authentication bypass via the sb_login_user_with_otp_fun function, allowing attackers to log...

2026-02-12
CVE-2026-1720
Analyzed
8.8
WordPress is vulnerable

The WowOptin: Next-Gen Popup Maker – Create Stunning Popups and Optins for Lead Generation plugin for WordPress is vulnerable to unauthorized arbitrar...

2026-03-06
CVE-2026-1719
Analyzed
7.5
WordPress is vulnerable

The Gravity Bookings Premium plugin for WordPress is vulnerable to SQL Injection in all versions up to, and including, 2

2026-05-06
CVE-2026-1714
Analyzed
8.6
WordPress is vulnerable

The ShopLentor – WooCommerce Builder for Elementor & Gutenberg +21 Modules – All in One Solution plugin for WordPress is vulnerable to Email Relay Abu...

2026-02-18
CVE-2026-17123
Analyzed
8.8
WordPress Royal Addons for Elementor

The Royal Elementor Addons plugin for WordPress is vulnerable to Server-Side Request Forgery in versions up to, and including, 1

2026-08-16
CVE-2026-17087
Analyzed
7.5
WordPress WP Travel Engine – Tour Booking Plugin – Tour Operator Software

The WP Travel Engine – Tour Booking Plugin – Tour Operator Software plugin for WordPress is vulnerable to authorization bypass in all versions up to,...

2026-08-16
CVE-2026-17044
Analyzed
8.6
WordPress File Upload WordPress plugin

The Iptanus File Upload WordPress plugin before 5.1.8 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to...

2026-08-16
CVE-2026-17022
Analyzed
7.5
WordPress Salon Booking System

The Salon Booking System WordPress plugin through 10

2026-08-11
CVE-2026-17017
Analyzed
8.1
WordPress CubeWP Framework WordPress plugin

The CubeWP Framework WordPress plugin before 1.1.31 does not properly sanitize and escape a parameter before using it in a SQL statement through an AJ...

2026-08-16
CVE-2026-16988
Analyzed
7.5
WordPress GeoDirectory

The GeoDirectory WordPress plugin before 2.8.169 does not perform any authorization check when returning map marker data for a single requested listi...

2026-08-17
CVE-2026-16977
Analyzed
8.1
WordPress Form Maker by 10Web

The Form Maker by 10Web WordPress plugin before 1.15.45 does not properly parameterize a user-controlled value that is substituted into a dynamic SQL...

2026-08-21
CVE-2026-16948
Analyzed
8.1
WordPress Solace Extra WordPress plugin

The Solace Extra WordPress plugin before 1.6.1 does not perform capability checks in several of its AJAX actions and exposes the nonce that protects t...

2026-08-16
CVE-2026-16940
Analyzed
10
WordPress Custom Fields (WordPress Plugin)

The Custom Fields WordPress plugin before version 1.5.1 is vulnerable to path traversal, allowing unauthenticated attackers to delete arbitrary files...

2026-08-06
CVE-2026-16736
Analyzed
7.5
WordPress User Registration & Membership

The User Registration & Membership WordPress plugin before 5.2.6 does not enforce the site's registration-disabled setting when processing registrati...

2026-08-14
CVE-2026-1667
Analyzed
7.2
WordPress GEO Plugin by Squirrly SEO

The SEO Plugin by Squirrly SEO plugin for WordPress is vulnerable to Arbitrary Post Creation and Stored Cross-Site Scripting in all versions up to, an...

2026-07-12
CVE-2026-16635
Analyzed
8.8
WordPress Pronamic Pay

The Pronamic Pay plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 10

2026-08-02
CVE-2026-16623
Analyzed
8
WordPress Create Block Theme

The Create Block WordPress plugin before 2

2026-08-05
CVE-2026-16617
Analyzed
8.8
WordPress Simple File List

The Simple File List WordPress plugin through 6

2026-08-20
CVE-2026-16611
Analyzed
7.5
WordPress Product Feed PRO for WooCommerce

The Product Feed PRO for WooCommerce by AdTribes WordPress plugin before 13.5.7 does not perform an authorization check on one of its REST read route...

2026-08-24
CVE-2026-16610
Analyzed
9.8
WordPress Admin and Site Enhancements (ASE) Pro

The ASE Pro WordPress plugin is vulnerable to remote code execution due to improper input sanitization and a lack of authentication checks in its fron...

2026-07-30
CVE-2026-16605
Analyzed
7.2
WordPress MultiVendorX

The MultiVendorX WordPress plugin before 5.0.11 does not verify that the store targeted through its REST API belongs to the requesting vendor, allowi...

2026-08-14
CVE-2026-16604
Analyzed
7.5
WordPress Passster WordPress Plugin

The Passster WordPress plugin before 4.3.6 outputs password-protected block content in the public page response before verifying the password, allowi...

2026-08-10
CVE-2026-16603
Analyzed
7.5
WordPress Passster WordPress plugin

The Passster WordPress plugin before 4.3.6 does not enforce its category-based content protection on the WordPress REST API, allowing unauthenticated...

2026-08-10
CVE-2026-16602
Analyzed
7.5
WordPress Passster WordPress plugin

The Passster WordPress plugin before 4.3.6 does not perform a post-status check before returning post content from an unauthenticated REST endpoint,...

2026-08-10
CVE-2026-16601
Analyzed
8.8
WordPress CM Map Locations

The CM Map Locations – Visualize and share your locations in a few clicks plugin for WordPress is vulnerable to Limited Arbitrary File Upload in all v...

2026-08-25
CVE-2026-16600
Analyzed
7.7
WordPress SmartAIPress

The SmartAIPress WordPress plugin through 1.2.0 does not perform a capability check on one of its AJAX actions and does not validate a user-supplied U...

2026-08-30
CVE-2026-16594
Analyzed
7.5
WordPress WP Directory Kit

The WP Directory Kit WordPress plugin before 1.5.5 does not perform authorization or nonce checks on one of its authenticated AJAX actions, allowing a...

2026-08-27
CVE-2026-16589
Analyzed
7.7
WordPress WP Directory Kit

The WP Directory Kit WordPress plugin before 1.5.5 does not sanitize and escape a parameter before using it in a SQL statement through one of its auth...

2026-08-16
CVE-2026-16585
Analyzed
7.2
WordPress Better Messages – Chat Rooms, Group Chat, Private Messages & AI Chat Bots

The Better Messages – Chat Rooms, Group Chat, Private Messages & AI Chat Bots plugin for WordPress is vulnerable to arbitrary file deletion due to ins...

2026-07-28
CVE-2026-16578
Analyzed
7.5
WordPress Login Security, Limit Logins, 2FA & Brute Force Protection

The Admin Safety Guard — Login Security, Limit Logins, 2FA & Brute Force Protection WordPress plugin before 1.4.0 does not perform any capability chec...

2026-08-27
CVE-2026-16573
Analyzed
7.5
WordPress Bit Form WordPress plugin

The Bit Form WordPress plugin before 3.2.0 does not sanitize an uploaded signature image before storing it, allowing unauthenticated attackers to upl...

2026-08-10
CVE-2026-16572
Analyzed
8.6
WordPress LogMyTrip

The LogMyTrip WordPress plugin through 1

2026-08-04
CVE-2026-16561
Analyzed
7.5
WordPress Sunshine Photo Cart

The Sunshine Photo Cart WordPress plugin before 3.6.12 does not perform access control checks in one of its AJAX actions, allowing unauthenticated us...

2026-08-10
CVE-2026-16540
Analyzed
7.5
WordPress Simply Schedule Appointments

The Simply Schedule Appointments WordPress plugin before 1.6.12.6 does not correctly restrict a bulk appointment operation to the requester's own reco...

2026-08-09
CVE-2026-16539
Analyzed
8.1
WordPress sm page duplicator

The sm page duplicator WordPress plugin through 1

2026-08-04
CVE-2026-16538
Analyzed
9.1
WordPress Wallet for WooCommerce

The Wallet for WooCommerce plugin fails to verify payment completion before crediting user wallets, allowing attackers to inflate balances without pro...

2026-08-21
CVE-2026-16534
Analyzed
9.1
WordPress Import and export users and customers

A privilege management flaw in the Import and export users and customers plugin allows authenticated users to escalate their privileges to administrat...

2026-08-27
CVE-2026-16532
Analyzed
9.1
WordPress Link Library WordPress Plugin

The Link Library WordPress plugin fails to sanitize user inputs, enabling unauthenticated attackers to execute arbitrary SQL commands against the data...

2026-08-27
CVE-2026-1648
Analyzed
7.2
WordPress is vulnerable

The Performance Monitor plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 1

2026-03-22
CVE-2026-16300
Analyzed
9.8
WordPress ChamaWP

The ChamaWP WordPress plugin contains a missing authorization flaw in the password reset process, allowing unauthenticated attackers to reset the pass...

2026-08-04
CVE-2026-16299
Analyzed
9.8
WordPress Single Sign On For TNG

The Single Sign On For TNG WordPress plugin contains an improper authentication vulnerability that allows unauthenticated attackers to reset the passw...

2026-08-27
CVE-2026-16298
Analyzed
9.8
WordPress FoodBoxBooker

The FoodBoxBooker WordPress plugin fails to validate password reset requests, enabling unauthenticated attackers to reset passwords for any user, incl...

2026-08-18
CVE-2026-16294
Analyzed
7.1
WordPress PowerPress Podcasting plugin

The PowerPress Podcasting plugin by Blubrry WordPress plugin before 11.17.1 does not validate one of its Podcast Episode URL settings before performin...

2026-08-27
CVE-2026-16268
Analyzed
8.2
WordPress Newsletters

The Newsletters WordPress plugin before 4

2026-08-06
CVE-2026-16263
Analyzed
8.8
WordPress WP Maps

The WP Maps WordPress plugin before 4

2026-08-08
CVE-2026-16262
Analyzed
7.5
WordPress Estatik Real Estate Plugin

The Estatik Real Estate Plugin WordPress plugin before 4.3.3 does not bind its OAuth social login flow to the initiating user session, allowing an una...

2026-08-15
CVE-2026-16259
Analyzed
9.8
WordPress UserCenter

The Uix UserCenter WordPress plugin contains a hardcoded authentication token vulnerability, allowing unauthenticated attackers to hijack any user acc...

2026-08-30
CVE-2026-16257
Analyzed
8.2
WordPress AI SEO Writer

The Arvow AI SEO Writer WordPress plugin before 1.5.4 does not properly restrict access to one of its REST endpoints, whose only access control can be...

2026-08-17
CVE-2026-16236
Analyzed
8.8
WordPress Organic IDX plugin + WPL Real Estate

The Realtyna Organic IDX plugin for WordPress is vulnerable to Arbitrary File Upload in versions up to, and including, 5

2026-07-31
CVE-2026-16230
Analyzed
9.8
WordPress Formidable Digital Signatures

The Formidable Digital Signatures plugin for WordPress up to 3.0.6 contains a path traversal vulnerability that allows unauthenticated attackers to de...

2026-08-12
CVE-2026-1620
Analyzed
8.8
WordPress is vulnerable

The Livemesh Addons for Elementor plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 9

2026-04-16
CVE-2026-16149
Analyzed
8.8
WordPress Security Hardener

The Security Hardener plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 2

2026-08-23
CVE-2026-16145
Analyzed
7.2
WordPress Invisible Anti-Spam & CAPTCHA

The Invisible Anti-Spam & CAPTCHA — reCAPTCHA Alternative for All Forms plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'act...

2026-08-16
CVE-2026-16144
Analyzed
8.1
WordPress Kali Forms

The Kali Forms — Contact Form & Drag-and-Drop Builder plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including...

2026-08-01
CVE-2026-16142
Analyzed
9.8
WordPress TrueBooker – Appointment Booking and Scheduler System

The TrueBooker WordPress plugin is vulnerable to account takeover due to an insecure AJAX handler that allows unauthenticated users to modify any acco...

2026-08-15
CVE-2026-16099
Analyzed
8.8
WordPress Podlove Podcast Publisher

The Podlove Podcast Publisher plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the create_lin...

2026-08-16
CVE-2026-16098
Analyzed
9.8
WordPress ProSolution WP Client

The ProSolution WP Client WordPress plugin is vulnerable to unauthenticated arbitrary file upload due to insufficient validation of file extensions an...

2026-08-16
CVE-2026-16061
Analyzed
8.6
WordPress Rest Routes

The Rest Routes WordPress plugin through 5.5.5 does not sanitize and validate a value taken from the URL of one of its public REST routes before usin...

2026-08-30
CVE-2026-16060
Analyzed
9.8
WordPress Insert or Embed Articulate Content into WordPress

The Insert or Embed Articulate Content into WordPress plugin fails to properly validate uploaded archives, allowing malicious file uploads and potenti...

2026-08-11
CVE-2026-16055
Analyzed
7.5
WordPress Contest Gallery

The Contest Gallery WordPress plugin before 30.0.7 does not route its front-end login through the standard WordPress authentication flow, issuing an...

2026-08-10
CVE-2026-16054
Analyzed
9.1
WordPress Drag and Drop Multiple File Upload for WooCommerce

An unauthenticated file deletion vulnerability in the Drag and Drop Multiple File Upload for WooCommerce plugin allows anonymous attackers to destroy...

2026-08-27
CVE-2026-16051
Analyzed
9.8
WordPress wpmudev-updates

The wpmudev-updates WordPress plugin fails to verify the integrity of installed packages and lacks replay protection, enabling unauthenticated remote...

2026-08-13
CVE-2026-16041
Analyzed
7.5
WordPress MStore API

The MStore API WordPress plugin before 4.21.0 does not perform authorization or purchase-ownership checks on its REST product-review creation route,...

2026-08-27
CVE-2026-16038
Analyzed
9.1
WordPress MStore API

The MStore API WordPress plugin fails to validate payments with the gateway before marking orders as paid, allowing unauthenticated attackers to obtai...

2026-08-15
CVE-2026-16036
Analyzed
7.5
WordPress 2FA

The miniOrange 2FA WordPress plugin before 6.2.7 does not bind the second factor being configured during the pre-login two-factor challenge to the ta...

2026-08-10
CVE-2026-16030
Analyzed
8.1
WordPress MStore API

The MStore API WordPress plugin before 4

2026-08-08
CVE-2026-15992
Analyzed
8.8
WordPress WP Password Policy

The WP Password Policy plugin for WordPress is vulnerable to Privilege Escalation in all versions up to and including 3

2026-07-29
CVE-2026-15991
Analyzed
8.8
WordPress File Manager

The File Manager plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the connector function in a...

2026-08-06
CVE-2026-15988
Analyzed
8.8
WordPress AI Engine – The Chatbot, AI Framework & MCP for WordPress

The AI Engine – The Chatbot, AI Framework & MCP for WordPress plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to,...

2026-08-01
CVE-2026-15981
Analyzed
9.8
WordPress SAML Single Sign On – SSO Login

The SAML Single Sign On plugin for WordPress contains an authentication bypass flaw that allows unauthenticated users to gain access to any account, i...

2026-07-24
CVE-2026-15980
Analyzed
9.8
WordPress MyHome Core

The MyHome Core WordPress plugin contains an authentication bypass flaw in its AJAX handlers, allowing unauthenticated attackers to hijack user accoun...

2026-08-30
CVE-2026-15965
Analyzed
8.8
WordPress MaxUpload – Big File Uploads – Increase Maximum File Upload Size

The MaxUpload – Big File Uploads – Increase Maximum File Upload Size plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to...

2026-08-15
CVE-2026-15964
Analyzed
9.8
WordPress Single Sign On For TNG

The Single Sign On For TNG WordPress plugin suffers from an unauthenticated password reset vulnerability due to insufficient validation of AJAX reques...

2026-08-02
CVE-2026-15958
Analyzed
9.3
WordPress Easy Integration for Dropbox – File Manager

The Easy Integration for Dropbox WordPress plugin fails to perform authorization checks on AJAX actions, allowing unauthenticated attackers to manipul...

2026-08-27
CVE-2026-15930
Analyzed
9.4
WordPress Simple Membership WordPress plugin

The Simple Membership WordPress plugin contains an authorization bypass vulnerability allowing unauthenticated attackers to overwrite administrator ac...

2026-08-04
CVE-2026-15826
Analyzed
9.8
WordPress User Profile Builder

The User Profile Builder plugin for WordPress is vulnerable to an authentication bypass via type confusion, allowing unauthenticated attackers to log...

2026-08-15
CVE-2026-1581
Analyzed
7.5
WordPress is vulnerable

The wpForo Forum plugin for WordPress is vulnerable to time-based SQL Injection via the 'wpfob' parameter in all versions up to, and including, 2

2026-02-20
CVE-2026-15748
Analyzed
9.8
WordPress Forminator Forms

The Forminator Forms plugin for WordPress is vulnerable to unauthenticated arbitrary file uploads via the handle_file_upload function, potentially lea...

2026-08-18
CVE-2026-1566
Analyzed
8.8
WordPress is vulnerable

The LatePoint – Calendar Booking Plugin for Appointments and Events plugin for WordPress is vulnerable to privilege escalation via password reset in a...

2026-03-03
CVE-2026-1565
Analyzed
8.8
WordPress is vulnerable

The User Frontend: AI Powered Frontend Posting, User Directory, Profile, Membership & User Registration plugin for WordPress is vulnerable to arbitrar...

2026-02-27
CVE-2026-15606
Analyzed
8.8
WordPress Frontend Admin by DynamiApps

The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 3

2026-08-12
CVE-2026-1560
Analyzed
8.8
WordPress is vulnerable

The Custom Block Builder – Lazy Blocks plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 4

2026-02-11
CVE-2026-1557
Analyzed
7.5
WordPress is vulnerable

The WP Responsive Images plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 1

2026-02-26
CVE-2026-1555
Analyzed
9.8
WordPress is vulnerable

The WebStack theme for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the io_img_upload() function in all ve...

2026-04-16
CVE-2026-15459
Analyzed
8.1
WordPress WPMU DEV Dashboard

The WPMU DEV Dashboard plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 5

2026-08-06
CVE-2026-15450
Analyzed
8.1
WordPress NEX-Forms – Ultimate Forms Plugin for WordPress

The Nex Forms – Ultimate Form Builder – Lite plugin for WordPress is vulnerable to arbitrary file deletion via path traversal in versions up to, and i...

2026-08-01
CVE-2026-15426
Analyzed
8.8
WordPress AcyMailing

The AcyMailing – An Ultimate Newsletter Plugin and Marketing Automation Solution for WordPress plugin for WordPress is vulnerable to authorization byp...

2026-08-12
CVE-2026-15414
Analyzed
8.8
WordPress Subscriptions for WooCommerce

The Subscriptions for WooCommerce plugin for WordPress is vulnerable to Privilege Escalation in versions up to, and including, 2

2026-08-01
CVE-2026-15413
Analyzed
10
WordPress Link Factory

The Link Factory WordPress plugin is a malicious backdoor that exposes a hardcoded REST API, allowing unauthorized operators to interact with the site...

2026-08-13
CVE-2026-15401
Analyzed
7.2
WordPress VikBooking Hotel Booking Engine & PMS

The VikBooking Hotel Booking Engine & PMS plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'vbfX' parameter in all versions u...

2026-07-26
CVE-2026-15372
Analyzed
7.5
WordPress WP 2FA

The WP 2FA WordPress plugin before 4.1.0 does not validate the second authentication factor when one of its supported methods is selected at login, a...

2026-08-10
CVE-2026-15369
Analyzed
9.8
WordPress Custom User Registration Fields for WooCommerce

An unauthenticated privilege escalation vulnerability in the Addify Custom User Registration Fields for WooCommerce plugin allows attackers to gain ad...

2026-08-30
CVE-2026-15361
Analyzed
8.1
WordPress Content Views

The Content Views WordPress plugin before 4

2026-08-08
CVE-2026-15360
Analyzed
9.1
WordPress Ajax Load More

The Ajax Load More WordPress plugin before 8.0.1 contains a SQL injection vulnerability allowing unauthenticated attackers to extract sensitive databa...

2026-08-10
CVE-2026-15354
Analyzed
9.8
WordPress ACPT (Premium)

The ACPT (Premium) WordPress plugin allows unauthenticated attackers to perform privilege escalation and account takeover by manipulating user IDs in...

2026-09-04
CVE-2026-15341
Analyzed
9.8
WordPress User Session Synchronizer

The User Session Synchronizer plugin for WordPress is vulnerable to an authentication bypass via improper cryptographic validation, allowing unauthent...

2026-08-15
CVE-2026-15338
Analyzed
7.5
WordPress LA-Studio Element Kit for Elementor

The LA-Studio Element Kit for Elementor plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1

2026-07-11
CVE-2026-15335
Analyzed
7.5
WordPress Booking Package

The Booking Package plugin for WordPress is vulnerable to generic SQL Injection via 'email' Form Parameter (form<N>) in all versions up to, and includ...

2026-07-11
CVE-2026-15312
Analyzed
8.8
WordPress Propovoice: All-in-One Client Management System

The Propovoice: All-in-One Client Management System plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1

2026-08-15
CVE-2026-15303
Analyzed
9.8
WordPress 6Storage Rentals

The 6Storage Rentals plugin for WordPress contains an authentication bypass vulnerability that allows unauthenticated attackers to log in as any user,...

2026-08-15
CVE-2026-15300
Analyzed
9.1
WordPress GEO my WP

The GEO my WP WordPress plugin is vulnerable to unauthenticated SQL injection via the 'distance', 'lat', and 'lng' parameters due to improper sanitiza...

2026-07-10
CVE-2026-15282
Analyzed
9.8
WordPress Instant Appointment

The Instant Appointment WordPress plugin is vulnerable to unauthenticated arbitrary file uploads, potentially leading to remote code execution.

2026-07-10
CVE-2026-15258
Analyzed
8.1
WordPress Product Feed Manager For WooCommerce

The Product Feed Manager For WooCommerce WordPress plugin before 7

2026-08-01
CVE-2026-15240
Analyzed
7.5
WordPress Customer Switching

The Customer Switching WordPress plugin before 2.1.3 does not securely bind an active user-switching session to the operator who initiated it, allowin...

2026-08-23
CVE-2026-15230
Analyzed
8.1
WordPress YayPricing

The YayPricing WordPress plugin before 3.5.7 does not perform capability checks on several of its REST API routes, relying only on a shared nonce, al...

2026-08-09
CVE-2026-15215
Analyzed
8.8
WordPress Subscriptions for WooCommerce

The Subscriptions for WooCommerce WordPress plugin before 2

2026-08-08
CVE-2026-15212
Analyzed
8.8
WordPress WPO365 | SEAMLESS WORDPRESS + MICROSOFT INTEGRATION (WPO365 | LOGIN)

The WPO365 | Login plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 43

2026-07-24
CVE-2026-15210
Analyzed
9.1
WordPress OTP Login With Phone Number, OTP Verification

The OTP Login With Phone Number, OTP Verification plugin fails to limit verification attempts, allowing unauthenticated attackers to bypass authentica...

2026-08-09
CVE-2026-15205
Analyzed
8.6
WordPress Paymob for WooCommerce

The Paymob for WooCommerce WordPress plugin before 4

2026-08-15
CVE-2026-15155
Analyzed
8.8
WordPress Essential Addons for Elementor

The Essential Addons for Elementor – Popular Elementor Templates & Widgets plugin for WordPress is vulnerable to Authenticated Account Takeover via Em...

2026-07-11
CVE-2026-15142
Analyzed
7.5
WordPress Real Estate Manager Pro

The Real Estate Manager Pro plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 12

2026-08-16
CVE-2026-15103
Analyzed
8.8
WordPress WPFunnels – Funnel Builder for WooCommerce

The WPFunnels – Funnel Builder for WooCommerce with Checkout & One Click Upsell plugin for WordPress is vulnerable to Privilege Escalation via arbitra...

2026-07-16
CVE-2026-15070
Analyzed
8.8
WordPress Salon Booking System – Free Version

The Salon Booking System – Free Version plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 10

2026-07-10
CVE-2026-15052
Analyzed
7.2
WordPress MailChimp Subscribe Form, Optin Builder, PopUp Builder, Form Builder

The MailChimp Subscribe Form, Optin Builder, PopUp Builder, Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Form Fi...

2026-08-02
CVE-2026-15048
Analyzed
7.5
WordPress Geeky Bot

The Geeky Bot WordPress plugin before 1

2026-08-01
CVE-2026-15039
Analyzed
9.8
WordPress giftware

The giftware WordPress plugin contains an unrestricted file upload vulnerability, allowing unauthenticated users to upload malicious files and execute...

2026-08-13
CVE-2026-15038
Analyzed
9.8
WordPress InfiniteWP Client

The InfiniteWP Client WordPress plugin fails to verify request authenticity, allowing unauthenticated attackers to hijack administrator sessions and a...

2026-08-18
CVE-2026-15017
Analyzed
8.8
WordPress MDJM Event Management

The MDJM Event Management plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1

2026-07-24
CVE-2026-15015
Analyzed
9.8
WordPress MountDev AI MCP Connector for WordPress

The MountDev AI MCP Connector plugin for WordPress contains an authorization bypass flaw that allows unauthenticated attackers to obtain administrativ...

2026-07-24
CVE-2026-15014
Analyzed
9.8
WordPress SMS Alert – SMS & OTP for WooCommerce

The SMS Alert plugin for WordPress is vulnerable to authentication bypass and account takeover due to an insecure OTP validation process that fails to...

2026-07-28
CVE-2026-15013
Analyzed
9.8
WordPress SAML Single Sign On – SSO Login

The SAML SSO plugin for WordPress is vulnerable to signature algorithm confusion, allowing unauthenticated attackers to forge assertions and gain admi...

2026-07-16
CVE-2026-15008
Analyzed
8.1
WordPress Uncanny Automator

The Uncanny Automator – Easy Automation, Integration, Webhooks & Workflow Builder Plugin plugin for WordPress is vulnerable to arbitrary file deletion...

2026-07-17
CVE-2026-15006
Analyzed
7.5
WordPress Bit Integrations

The Bit integrations – Form Integration, Webhook, Spreadsheets, CRM, LMS & Email Automation plugin for WordPress is vulnerable to Directory Traversal...

2026-08-01
CVE-2026-15005
Analyzed
8.8
WordPress Loco Translate

The Loco Translate plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2

2026-07-16
CVE-2026-15002
Analyzed
7.2
WordPress Autopay (platnosci-online-blue-media)

The Platnosci Online Blue Media (Autopay) plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 5

2026-08-16
CVE-2026-15001
Analyzed
8.8
WordPress bLoyal: Loyalty & Promotions by bLoyal

The bLoyal: Loyalty & Promotions by bLoyal plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 3

2026-08-15
CVE-2026-1499
Analyzed
9.8
WordPress is vulnerable

The WP Duplicate plugin for WordPress allows authenticated subscribers to trigger a chain of vulnerabilities leading to unauthenticated remote code ex...

2026-02-06
CVE-2026-14956
Analyzed
9.8
WordPress Bricksforge

The Bricksforge WordPress plugin contains a privilege escalation vulnerability in the Pro Forms component, allowing unauthenticated attackers to regis...

2026-07-17
CVE-2026-14943
Analyzed
7.5
WordPress Password Protected — Lock Entire Site, Pages, Posts, Categories, and Partial Content

The Password Protected — Lock Entire Site, Pages, Posts, Categories, and Partial Content WordPress plugin before 2.8.4 does not restrict REST API acce...

2026-08-15
CVE-2026-14930
Analyzed
7.5
WordPress JS Help Desk

The JS Help Desk WordPress plugin before 3

2026-08-01
CVE-2026-14925
Analyzed
7.5
WordPress Import WP WordPress Plugin

The Import WP WordPress plugin before 2.14.23 does not perform any authorization check on one of its export-file download handlers, allowing unauthen...

2026-08-27
CVE-2026-14924
Analyzed
7.5
WordPress Tablesome Table

The Tablesome Table WordPress plugin before 1.1.31 does not perform any authentication, capability, or nonce checks in one of its AJAX actions, allow...

2026-08-04
CVE-2026-1492
Analyzed
9.8
WordPress is vulnerable

The RegistrationMagic WordPress plugin allows unauthenticated attackers to create administrator accounts by exploiting improper privilege management d...

2026-03-03
CVE-2026-14919
Analyzed
9.8
WordPress ShopMonitor.io WordPress Plugin

A critical authentication bypass in the ShopMonitor.io WordPress plugin allows unauthenticated attackers to hijack administrator accounts via email re...

2026-08-01
CVE-2026-1490
Analyzed
9.8
WordPress is vulnerable

The CleanTalk Anti-Spam plugin for WordPress allows unauthenticated attackers to install arbitrary plugins via PTR record spoofing, potentially leadin...

2026-02-15
CVE-2026-14894
Analyzed
9.8
WordPress Super Forms – Drag & Drop Form Builder

The Super Forms plugin for WordPress suffers from an unauthenticated arbitrary file upload vulnerability via the `submit_form` AJAX handler, enabling...

2026-07-10
CVE-2026-14870
Analyzed
7.1
WordPress Database for Contact Form 7, WPforms, Elementor forms

The Database for Contact Form 7, WPforms, Elementor forms WordPress plugin before 1.5.3 does not properly sanitise and escape a parameter before refle...

2026-08-18
CVE-2026-14830
Analyzed
7.5
WordPress FlxWoo

The FlxWoo WordPress plugin before 3

2026-08-01
CVE-2026-14829
Analyzed
8.2
WordPress Checkimate — WooCommerce Checkout, Abandoned Cart Recovery & Order Bumps

The Checkimate — WooCommerce Checkout, Abandoned Cart Recovery & Order Bumps WordPress plugin through 1

2026-08-06
CVE-2026-14812
Analyzed
10
WordPress Premium SEO

The Premium SEO WordPress plugin contains a malicious backdoor that enables unauthenticated attackers to create admin accounts, execute code, and inje...

2026-08-07
CVE-2026-1463
Analyzed
8.8
WordPress is vulnerable

The Photo Gallery, Sliders, Proofing and Themes – NextGEN Gallery plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, an...

2026-03-19
CVE-2026-14603
Analyzed
7.5
WordPress WowOptin: Next-Gen Popup Maker

The WowOptin: Next-Gen Popup Maker WordPress plugin before 1.4.38 does not have proper authorization on a REST endpoint, allowing unauthenticated use...

2026-08-05
CVE-2026-14557
Analyzed
9.1
WordPress Digital Marketplace WordPress plugin

The SoftMarket Digital Marketplace WordPress plugin contains an authentication bypass flaw in its email-verification flow, allowing unauthenticated us...

2026-08-11
CVE-2026-14545
Analyzed
9.8
WordPress TrueBooker WordPress Plugin

The TrueBooker WordPress plugin fails to validate account ownership during password resets, allowing unauthenticated attackers to hijack any user acco...

2026-07-29
CVE-2026-14526
Analyzed
9.8
WordPress AI Copilot – Content Generator

An authorization bypass in the AI Copilot WordPress plugin allows unauthenticated attackers to create administrator accounts and achieve full site tak...

2026-08-08
CVE-2026-14524
Analyzed
9.1
WordPress ProSolution WP Client

The ProSolution WP Client WordPress plugin is vulnerable to unauthenticated arbitrary file deletion via path traversal, potentially leading to remote...

2026-08-16
CVE-2026-14498
Analyzed
8.8
WordPress Query Wrangler

The Query Wrangler plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 1

2026-08-16
CVE-2026-14495
Analyzed
8.8
WordPress DoLogin Security

The DoLogin Security plugin for WordPress is vulnerable to Authentication Bypass via Insufficient Randomness in all versions up to, and including, 4

2026-07-08
CVE-2026-14494
Analyzed
9.8
WordPress SigmaForms Pro – AI Generated Forms

The SigmaForms Pro WordPress plugin is vulnerable to unauthenticated remote code execution due to improper file upload validation in the handle_form_s...

2026-08-30
CVE-2026-14490
Analyzed
7.5
WordPress Demi – One Click Demo Import, Backup & Site Migration

The Demi – One Click Demo Import, WP Backup & Site Migration plugin for WordPress is vulnerable to Arbitrary Directory Deletion in all versions up to,...

2026-07-28
CVE-2026-14489
Analyzed
8.8
WordPress WHMCS Bridge

The WHMCS Bridge plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the connect() function in all ver...

2026-07-08
CVE-2026-14487
Analyzed
9.1
WordPress Simple Coherent Form

The Simple Coherent Form WordPress plugin contains a path traversal vulnerability allowing unauthenticated remote file deletion and potential code exe...

2026-07-08
CVE-2026-14484
Analyzed
9.1
WordPress RapiSafe – Secure Multi File Upload for Contact Form 7

The RapiSafe WordPress plugin is vulnerable to unauthenticated arbitrary file deletion via path traversal, which may lead to remote code execution.

2026-08-16
CVE-2026-14483
Analyzed
9.8
WordPress Realtyna Organic IDX plugin + WPL Real Estate

The Realtyna Organic IDX plugin + WPL Real Estate for WordPress is vulnerable to unauthenticated arbitrary file uploads due to missing validation and...

2026-07-31
CVE-2026-14482
Analyzed
8.8
WordPress 多说社会化评论框 (Duoshuo Social Comment Box)

The 多说社会化评论框 plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1

2026-07-08
CVE-2026-14433
Analyzed
7.2
WordPress Online Booking & Scheduling Calendar for WordPress

The Online Booking & Scheduling Calendar for WordPress by vcita plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'business_id...

2026-08-16
CVE-2026-14365
Analyzed
9.8
WordPress TrueBooker – Appointment Booking and Scheduler System

The TrueBooker WordPress plugin is vulnerable to authorization bypass, allowing unauthenticated attackers to perform unauthorized actions such as chan...

2026-08-07
CVE-2026-14364
Analyzed
9.8
WordPress TrueBooker – Appointment Booking and Scheduler System

The TrueBooker WordPress plugin is vulnerable to account takeover due to improper password reset validation, allowing unauthenticated attackers to res...

2026-08-07
CVE-2026-14356
Analyzed
8.8
WordPress FleekDash V2

The FleekDash V2 plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 2

2026-07-30
CVE-2026-14345
Analyzed
9.8
WordPress WPFunnels – Funnel Builder for WooCommerce

The WPFunnels WordPress plugin is vulnerable to unauthenticated remote code execution due to improper sanitization of log data combined with unsafe fi...

2026-07-07
CVE-2026-14334
Analyzed
8.8
WordPress Booking calendar, Appointment Booking System

The Booking calendar, Appointment Booking System WordPress plugin through 3

2026-08-20
CVE-2026-14333
Analyzed
7.5
WordPress Demi

The Demi WordPress plugin before 0

2026-08-01
CVE-2026-14328
Analyzed
8.8
WordPress Eazy Plugin Manager – Powerful Plugin Management Solution for WordPress

The Eazy Plugin Manager – Powerful Plugin Management Solution for WordPress plugin for WordPress is vulnerable to Privilege Escalation in all versions...

2026-07-29
CVE-2026-14319
Analyzed
7.5
WordPress GiveWP

The GiveWP WordPress plugin before 4

2026-08-01
CVE-2026-14293
Analyzed
8.8
WordPress WordPress Plugin

The Autopay WordPress plugin before 5.0.1 does not perform any capability or nonce check before saving a styling option from a public request, and doe...

2026-08-17
CVE-2026-14291
Analyzed
7.5
WordPress security-ninja-premium

The security-ninja-premium WordPress plugin before 5.290 does not verify the second authentication factor in one of its two-factor authentication code...

2026-08-12
CVE-2026-14282
Analyzed
9.8
WordPress GoDAM – Organize WordPress Media Library & File Manager

The GoDAM WordPress plugin suffers from an unrestricted arbitrary file upload vulnerability allowing unauthenticated remote code execution via insuffi...

2026-07-24
CVE-2026-14279
Analyzed
8.8
WordPress Wholesale Market

The Wholesale Market plugin for WordPress is vulnerable to privilege escalation in versions up to, and including, 2

2026-08-15
CVE-2026-14270
Analyzed
8.8
WordPress Extra Checkout Options - addon for Extra Product Options plugin

The Extra Checkout Options (addon for Extra Product Options & Add-Ons for WooCommerce) plugin for WordPress is vulnerable to Arbitrary File Upload in...

2026-07-30
CVE-2026-14262
Analyzed
8.8
WordPress Simple JWT Login

The Simple JWT Login – Allows you to use JWT on REST endpoints

2026-07-11
CVE-2026-14245
Analyzed
9.8
WordPress miniOrange OTP Login, Verification and SMS Notifications

The miniOrange OTP Login, Verification and SMS Notifications plugin for WordPress is vulnerable to an authentication bypass that allows unauthenticate...

2026-07-09
CVE-2026-14237
Analyzed
7.2
WordPress WordPress Plugin

The vitepos WordPress plugin before 3.6.0, Vitepos WordPress plugin before 3.5.0 do not perform a per-target authorization check in their point-of-sa...

2026-08-17
CVE-2026-14235
Analyzed
7.5
WordPress Download Manager

The Download Manager WordPress plugin before 3

2026-07-28
CVE-2026-14206
Analyzed
7.5
WordPress HT Contact Form

The HT Contact Form WordPress plugin before 2

2026-08-11
CVE-2026-14205
Analyzed
9.8
WordPress WP Events Manager

The WP Events Manager WordPress plugin contains a vulnerability that allows authenticated users to bypass payment requirements when registering for pa...

2026-08-08
CVE-2026-14158
Analyzed
8.8
WordPress Widget Logic Visual

The Widget Logic Visual plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 1

2026-07-08
CVE-2026-1405
Analyzed
9.8
WordPress is vulnerable

The Slider Future plugin for WordPress allows unauthenticated arbitrary file uploads, which can be leveraged to achieve remote code execution on the s...

2026-02-20
CVE-2026-1400
Analyzed
7.2
WordPress Multiple Products

The AI Engine – The Chatbot and AI Framework for WordPress plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type valid...

2026-01-28
CVE-2026-13756
Analyzed
8.8
WordPress WP Grid Builder

The WP Grid Builder plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 2

2026-07-11
CVE-2026-1375
Analyzed
8.1
WordPress Multiple Products

The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to Insecure Direct Object References (IDOR) in all versions up...

2026-02-03
CVE-2026-13741
Analyzed
8.8
WordPress Digits: WordPress Mobile Number Signup and Login

The Digits: WordPress Mobile Number Signup and Login plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including,...

2026-07-16
CVE-2026-13726
Analyzed
7.1
WordPress MPG (Multiple Page Generator)

The MPG WordPress plugin before 4.1.8 does not sanitise and escape a parameter before reflecting it back in the response, allowing unauthenticated at...

2026-08-05
CVE-2026-13714
Analyzed
9.8
WordPress Organic IDX plugin + WPL Real Estate

The Realtyna Organic IDX plugin + WPL Real Estate for WordPress contains a critical file upload vulnerability allowing unauthenticated remote code exe...

2026-07-28
CVE-2026-13690
Analyzed
7.4
WordPress UsersWP

The UsersWP WordPress plugin before 1.2.67 does not validate the selected authentication provider in its two-factor login handler, allowing an attack...

2026-08-19
CVE-2026-1368
Analyzed
7.5
WordPress plugin before

The Video Conferencing with Zoom WordPress plugin before 4

2026-02-19
CVE-2026-13613
Analyzed
8.8
WordPress KiviCare

The KiviCare WordPress plugin before 4

2026-08-13
CVE-2026-13610
Analyzed
7.5
WordPress Clinic & Patient Management System (EHR)

The KiviCare WordPress plugin before 4.5.2 does not restrict the roles assignable through its unauthenticated registration endpoint, allowing unauthe...

2026-08-22
CVE-2026-13609
Analyzed
8.8
WordPress Frontend Admin

The Frontend Admin by DynamiApps WordPress plugin before 3

2026-08-01
CVE-2026-13600
Analyzed
8.1
WordPress AutoNetTV Relay

The AutoNetTV Relay WordPress plugin before 3.0.14 does not perform any capability or authentication check before setting a WordPress administrator au...

2026-08-16
CVE-2026-13597
Analyzed
9.1
WordPress 微信二维码登陆 (WeChat QR Login)

The 微信二维码登陆 WordPress plugin fails to validate WeChat webhook signatures, allowing unauthenticated attackers to forge login events and impersonate any...

2026-07-28
CVE-2026-1359
Analyzed
8.8
WordPress Genolve AI Business Graphics, AI Images

The Genolve – AI image AI video generation plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check o...

2026-07-11
CVE-2026-1357
Analyzed
9.8
WordPress is vulnerable

The WPvivid Backup & Migration plugin for WordPress allows unauthenticated remote code execution via arbitrary file uploads due to improper RSA error...

2026-02-11
CVE-2026-13492
Analyzed
8.8
WordPress UsersWP

The UsersWP plugin for WordPress is vulnerable to Arbitrary File Deletion in versions up to, and including, 1

2026-07-10
CVE-2026-13468
Analyzed
7.5
WordPress Visualizer

The Visualizer – Tables & Charts Manager with Built-in AI Generator plugin for WordPress is vulnerable to authorization bypass in all versions up to,...

2026-07-01
CVE-2026-13447
Analyzed
9.8
WordPress MStore API

The MStore API WordPress plugin is vulnerable to authentication bypass via JWT forgery due to missing cryptographic signature verification in the Fire...

2026-09-05
CVE-2026-13439
Analyzed
9.8
WordPress Easy Form Builder by WhiteStudio

The Easy Form Builder plugin for WordPress contains an unauthenticated privilege escalation vulnerability allowing attackers to reset any user passwor...

2026-07-21