Unknown
300 CVEsCVE IDSeverityProduct / summaryPublished
CVE-2026-14187
N/A
Tutor Lms — The Tutor LMS WordPress plugin before 4.0.6 does not enforce per-object ownership checks on its course conten…● PoC
2026-08-22
CVE-2026-16260
N/A
Post Grid, Slider & Carousel Ultimate — The Post Grid, Slider & Carousel Ultimate WordPress plugin before 1.8.1 does not sanitise and escape one of i…● PoC
2026-08-22
CVE-2026-16612
N/A
Fibosearch — The FiboSearch WordPress plugin before 1.34.1 does not consistently exclude password-protected products from …● PoC
2026-08-22
CVE-2026-16738
N/A
Conekta Payment Gateway — The Conekta Payment Gateway WordPress plugin before 6.2.2 does not verify the authenticity of incoming payment…● PoC
2026-08-22
CVE-2026-18052
N/A
Managewp Worker — The ManageWP Worker WordPress plugin before 4.9.37 does not bind the account being logged in to the signature …● PoC
2026-08-22
CVE-2026-19093
N/A
Tutor Lms — The Tutor LMS WordPress plugin before 4.0.6 does not validate a stored file path before using it to stream me…● PoC
2026-08-22
CVE-2026-19221
N/A
Forminator Forms — The Forminator Forms WordPress plugin before 1.57.0.5 does not restrict a network-wide setting to network adm…● PoC
2026-08-22
CVE-2026-19222
N/A
Forminator Forms — The Forminator Forms WordPress plugin before 1.57.0.7 does not consistently enforce the role restriction it a…● PoC
2026-08-22
CVE-2026-76789
N/A
Slider Hero With Video Background, Animation — The Slider Hero with Video Background, Animation WordPress plugin before 9.1.3 does not have authorisation and…● PoC
2026-08-22
CVE-2026-76793
N/A
Firebase Authentication — The Firebase Authentication WordPress plugin before 1.7.1 does not require the email address in an authenticat…● PoC
2026-08-22
CVE-2026-77000
N/A
Wp Social Media Login — The WP Social Media Login WordPress plugin through 1.0.6 does not verify that a social login was actually comp…● PoC
2026-08-22
CVE-2026-77001
N/A
Social Login & Sharing Buttons With Analytics By Soclever — The Social Login & Sharing buttons with Analytics By SoClever WordPress plugin through 1.2.0 does not perform …● PoC
2026-08-22
CVE-2026-77002
N/A
Smilepass Selfie Login — The SmilePass Selfie Login WordPress plugin through 1.0.2 does not perform any server-side verification of the…● PoC
2026-08-22
CVE-2026-13176
LOW 2.7
Eventin — The Eventin WordPress plugin before 4.1.21 does not validate a user-supplied webhook URL stored on events nor …● PoC
2026-08-21
CVE-2026-13736
MEDIUM 5.3
Newpath Wildapricotpress Add On — The NewPath WildApricotPress Add-on WordPress plugin through 1.0.0 does not enforce its members-only field pr…● PoC
2026-08-21
CVE-2026-14325
LOW 3.5
Drag And Drop Multiple File Upload For Contact Form 7 — The Drag and Drop Multiple File Upload for Contact Form 7 WordPress plugin before 1.3.9.9 does not escape one …● PoC
2026-08-21
CVE-2026-14601
MEDIUM 6.8
Link Whisper Free — The Link Whisper Free WordPress plugin before 0.9.7 does not properly sanitize and escape a parameter before u…● PoC
2026-08-21
CVE-2026-15046
MEDIUM 4.2
Litextension — The LitExtension WordPress plugin through 1.2.5 does not verify a nonce before an administrative action that o…● PoC
2026-08-21
CVE-2026-15150
MEDIUM 5.3
Mycred — The myCred WordPress plugin before 3.2.5 does not verify that the receiver of an incoming payment gateway noti…● PoC
2026-08-21
CVE-2026-16575
MEDIUM 5.3
Dokan: Ai Powered Woocommerce Multivendor Marketplace Solution — The Dokan: AI Powered WooCommerce Multivendor Marketplace Solution WordPress plugin before 5.0.14 does not re…● PoC
2026-08-21
CVE-2026-16576
HIGH 7.2
Dokan: Ai Powered Woocommerce Multivendor Marketplace Solution — The Dokan: AI Powered WooCommerce Multivendor Marketplace Solution WordPress plugin before 5.0.14 does not co…● PoC
2026-08-21
CVE-2026-16577
LOW 2.7
Dokan: Ai Powered Woocommerce Multivendor Marketplace Solution — The Dokan: AI Powered WooCommerce Multivendor Marketplace Solution WordPress plugin before 5.0.14 does not va…● PoC
2026-08-21
CVE-2026-16650
MEDIUM 5.3
Charitable — The Charitable WordPress plugin before 1.8.12 does not verify the authenticity of incoming Square payment webh…● PoC
2026-08-21
CVE-2026-16959
MEDIUM 6.8
Media Library Assistant — The Media Library Assistant WordPress plugin before 3.40 does not validate a search parameter before concatena…● PoC
2026-08-21
CVE-2026-16962
MEDIUM 5.3
Tamara Checkout — The Tamara Checkout WordPress plugin through 1.9.9.20 does not verify the order key, a nonce, or any capabilit…● PoC
2026-08-21
CVE-2026-17559
MEDIUM 5.3
Passster — The Passster WordPress plugin before 4.3.9 does not correctly match its own public endpoint paths when decidin…● PoC
2026-08-21
CVE-2026-18356
LOW 3.7
Limit Login Attempts Security — The Limit Login Attempts Reloaded WordPress plugin before 3.3.5 does not compare logins against its username d…● PoC
2026-08-21
CVE-2026-18781
HIGH 8.1
Drag And Drop Multiple File Upload For Contact Form 7 — The Drag and Drop Multiple File Upload for Contact Form 7 WordPress plugin before 1.3.9.9 does not validate th…● PoC
2026-08-21
CVE-2026-19085
LOW 2.7
Duplicate Post — The Duplicate Post WordPress plugin before 1.5.6 does not check that a user may read the content of a post bef…● PoC
2026-08-21
CVE-2026-19435
LOW 2.7
Duplicate Post — The Duplicate Post WordPress plugin before 1.5.6 does not check the user's capabilities before returning post …● PoC
2026-08-21
CVE-2026-19848
MEDIUM 6.5
Profilepress — The ProfilePress WordPress plugin before 4.17.1 does not strip shortcodes from two of its profile fields befor…● PoC
2026-08-21
CVE-2026-75796
HIGH 7.2
Ai Engine — The AI Engine WordPress plugin before 3.6.1 does not verify that the requesting user is authorized to act on …● PoC
2026-08-21
CVE-2025-15671
MEDIUM 5.4
Welcart E Commerce — The Welcart e-Commerce WordPress plugin before 2.12.1 does not regenerate the session identifier on authentica…● PoC
2026-08-21
CVE-2026-13405
MEDIUM 6.6
Royal Addons For Elementor — The Royal Addons for Elementor WordPress plugin before 1.7.1066 does not correctly sanitise custom widget mar…● PoC
2026-08-20
CVE-2026-15049
HIGH 7.2
Depicter — Popup & Slider Builder — The Depicter — Popup & Slider Builder WordPress plugin before 4.8.0 does not validate the type of a file uploa…● PoC
2026-08-20
CVE-2026-19615
MEDIUM 6.8
Admin And Site Enhancements (Ase) — The Admin and Site Enhancements (ASE) WordPress plugin before 9.0.1 does not sanitise uploaded SVG files on ev…● PoC
2026-08-20
CVE-2026-19697
MEDIUM 6.8
Gutenkit — The GutenKit WordPress plugin before 2.5.0 does not sanitise uploaded SVG files on all of the upload paths it…● PoC
2026-08-20
CVE-2026-19699
LOW 2.7
Gutenkit — The GutenKit WordPress plugin before 2.5.0 does not have a sufficient capability check on some of its REST AP…● PoC
2026-08-20
CVE-2026-74992
MEDIUM 6.8
Kirki — The Kirki WordPress plugin before 6.2.3 does not properly validate the files contained in archives uploaded b…● PoC
2026-08-20
CVE-2026-75860
CRITICAL 9.8
Json Options — The JSON Options WordPress plugin through 0.0.4 does not have any capability check or nonce verification on on…● PoC
2026-08-20
CVE-2026-11565
HIGH 8.5
Advanced File Manager — The Advanced File Manager WordPress plugin before 5.4.13 does not perform capability checks in several of its…● PoC
2026-08-19
CVE-2026-12983
HIGH 8.6
Dinatur — The Dinatur WordPress plugin through 1.18 does not sanitize and escape user input before using it in a SQL que…● PoC
2026-08-19
CVE-2026-13169
HIGH 8.1
Eventin — The Eventin WordPress plugin before 4.1.21 does not properly verify ownership of events before allowing them …● PoC
2026-08-19
CVE-2026-13173
LOW 2.7
Eventin — The Eventin WordPress plugin before 4.1.21 does not verify the current user's permission to edit other users …● PoC
2026-08-19
CVE-2026-13174
HIGH 7.2
Eventin — The Eventin WordPress plugin before 4.1.21 does not verify ownership or capability before deleting user accou…● PoC
2026-08-19
CVE-2026-13175
MEDIUM 6.5
Eventin — The Eventin WordPress plugin before 4.1.21 does not verify ownership before allowing schedule records to be m…● PoC
2026-08-19
CVE-2026-14196
MEDIUM 4.3
Wcfm Marketplace — The WCFM Marketplace WordPress plugin before 3.8.1 does not verify that a marketplace vendor owns a review be…● PoC
2026-08-19
CVE-2026-14287
MEDIUM 4.7
10web Booster — The 10Web Booster WordPress plugin before 2.33.5 does not correctly validate an access token on an unauthenti…● PoC
2026-08-19
CVE-2026-14334
HIGH 8.8
Booking Calendar, Appointment Booking System — The Booking calendar, Appointment Booking System WordPress plugin through 3.2.36 does not properly sanitize up…● PoC
2026-08-19
CVE-2026-14825
LOW 2.7
Quiz And Survey Master (Qsm) — The Quiz and Survey Master (QSM) WordPress plugin before 11.2.4 does not perform a per-object ownership check…● PoC
2026-08-19
CVE-2026-14826
LOW 2.7
Quiz And Survey Master (Qsm) — The Quiz and Survey Master (QSM) WordPress plugin before 11.2.4 does not perform a per-object ownership check…● PoC
2026-08-19
CVE-2026-14861
HIGH 7.5
User Verification By Pickplugins — The User Verification by PickPlugins WordPress plugin through 2.0.47 does not verify that a request to resend …● PoC
2026-08-19
CVE-2026-15253
MEDIUM 6.8
Easy Media Replace — The Easy Media Replace WordPress plugin through 0.2.0 does not sanitise and escape an attachment title before …● PoC
2026-08-19
CVE-2026-16058
MEDIUM 5.3
Yaycurrency — The YayCurrency WordPress plugin before 3.3.5 does not perform any capability or ownership check on several o…● PoC
2026-08-19
CVE-2026-16570
HIGH 7.1
Nextscripts: Social Networks Auto Poster — The NextScripts: Social Networks Auto-Poster WordPress plugin before 4.4.8 does not escape some of the query-s…● PoC
2026-08-19
CVE-2026-16616
HIGH 8.6
Simple File List — The Simple File List WordPress plugin through 6.3.11 does not validate the source path of a file-move operatio…● PoC
2026-08-19
CVE-2026-16617
HIGH 8.8
Simple File List — The Simple File List WordPress plugin through 6.3.11 does not properly sanitise and escape a file's descriptio…● PoC
2026-08-19
CVE-2026-16950
HIGH 8.6
Product Shortlist — The Product Shortlist WordPress plugin through 1.0.4 does not properly sanitise and escape a parameter before …● PoC
2026-08-19
CVE-2026-16979
MEDIUM 4.3
Smartcrawl Seo Checker, Analyzer & Optimizer — The SmartCrawl SEO checker, analyzer & optimizer WordPress plugin before 3.16.3 does not perform capability ch…● PoC
2026-08-19
CVE-2026-17565
HIGH 7.2
Animation Addons For Elementor — The Animation Addons for Elementor WordPress plugin before 2.7.2 does not validate a user-supplied value befo…● PoC
2026-08-19
CVE-2026-18031
CRITICAL 9.8
Tabapay Gateway — The TabaPay Gateway WordPress plugin through 1.4.0 does not validate the payment callback before establishing …● PoC
2026-08-19
CVE-2026-18051
CRITICAL 10
W3 Total Cache — The W3 Total Cache WordPress plugin before 2.10.5 does not properly validate the request path it uses to build…● PoC
2026-08-19
CVE-2026-18202
MEDIUM 6.8
Jetengine — The JetEngine WordPress plugin before 3.8.14 adds SVG to the site-wide list of allowed upload types without sa…● PoC
2026-08-19
CVE-2026-18231
MEDIUM 5.3
Wp Directory Kit — The WP Directory Kit WordPress plugin before 1.5.7 does not perform any authorization check on one of its publ…● PoC
2026-08-19
CVE-2026-18466
MEDIUM 5.4
Wp Maps — The WP Maps WordPress plugin before 4.9.8 does not perform a capability check, nor validate a nonce, in one o…● PoC
2026-08-19
CVE-2026-18776
CRITICAL 9.8
Truebooker — The TrueBooker WordPress plugin before 1.2.7 does not have proper authorisation checks in some of its AJAX ac…● PoC
2026-08-19
CVE-2026-18777
MEDIUM 5.3
Truebooker — The TrueBooker WordPress plugin before 1.2.7 does not have proper authorisation checks in one of its AJAX act…● PoC
2026-08-19
CVE-2026-18778
MEDIUM 5.3
Truebooker — The TrueBooker WordPress plugin before 1.2.7 does not have proper authorisation checks in some of its AJAX ac…● PoC
2026-08-19
CVE-2026-18779
MEDIUM 5.3
Truebooker — The TrueBooker WordPress plugin before 1.2.7 does not have proper authorisation checks in one of its AJAX act…● PoC
2026-08-19
CVE-2026-18937
CRITICAL 9
Broken Link Checker — The Broken Link Checker WordPress plugin before 2.4.12 does not limit which query variables it accepts from us…● PoC
2026-08-19
CVE-2026-19055
HIGH 7.1
Prosolution Wp Client — The ProSolution WP Client WordPress plugin before 2.0.11 does not sanitise and escape several parameters befor…● PoC
2026-08-19
CVE-2026-19056
HIGH 7.1
Prosolution Wp Client — The ProSolution WP Client WordPress plugin before 2.0.11 does not sanitise and escape a parameter before refle…● PoC
2026-08-19
CVE-2026-19406
LOW 2.7
Easy Appointments — The Easy Appointments WordPress plugin before 4.0.1 does not restrict one of its appointment-listing REST endp…● PoC
2026-08-19
CVE-2026-19416
MEDIUM 4.3
Kivicare — The KiviCare WordPress plugin before 4.5.4 does not verify that the requesting user owns the appointment bein…● PoC
2026-08-19
CVE-2026-19417
MEDIUM 6.5
Kivicare — The KiviCare WordPress plugin before 4.5.4 does not verify that the requesting user is entitled to the media …● PoC
2026-08-19
CVE-2026-19709
MEDIUM 5.3
Membership For Woocommerce — The Membership For WooCommerce WordPress plugin before 3.1.2 does not check that an API consumer secret has ac…● PoC
2026-08-19
CVE-2026-19782
MEDIUM 5.4
Wps Bidouille — The WPS Bidouille WordPress plugin before 1.33.5 does not have proper authorisation checks in an AJAX action, …● PoC
2026-08-19
CVE-2026-19842
HIGH 8.8
Saml Single Sign On — The SAML Single Sign On WordPress plugin before 5.4.7 does not verify the signature of a SAML response before…● PoC
2026-08-19
CVE-2026-13700
MEDIUM 5.9
Wooms — The WooMS WordPress plugin through 9.14 does not validate a user-supplied URL before using it in a server-side…● PoC
2026-08-17
CVE-2026-14832
MEDIUM 5.3
Shopsmart Loyalty For Woocommerce — The ShopSmart Loyalty for WooCommerce WordPress plugin through 1.0.0 does not perform any authorization or own…● PoC
2026-08-17
CVE-2026-13712
MEDIUM 5.4
Divi — The Divi WordPress theme before 5.9.0 does not properly escape some of its Social Media Follow module settings…● PoC
2026-08-16
CVE-2026-15384
MEDIUM 5.7
Manual Image Crop — The Manual Image Crop WordPress plugin before 1.15 does not perform any capability check or nonce verification…● PoC
2026-08-16
CVE-2026-17533
HIGH 7.2
All In One Wp Migration And Backup — The All-in-One WP Migration and Backup WordPress plugin before 7.108 does not restrict its migration import fu…● PoC
2026-08-16
CVE-2026-18653
HIGH 7.2
Wp Directory Kit — The WP Directory Kit WordPress plugin before 1.5.7 does not sanitise and escape a parameter before using it in…● PoC
2026-08-16
CVE-2026-19613
MEDIUM 6.5
Ecs — The ECS WordPress plugin before 4.3.10 does not perform ownership or post-status checks when one of its dynam…● PoC
2026-08-16
CVE-2026-19711
MEDIUM 6.5
Premium Packages — The Premium Packages WordPress plugin before 7.0.7 does not validate a withdrawal request against the request…● PoC
2026-08-16
CVE-2026-19712
MEDIUM 6.1
Masteriyo Lms — The Masteriyo LMS WordPress plugin before 2.3.3 does not sanitise and escape a quiz field before outputting i…● PoC
2026-08-16
CVE-2026-19714
CRITICAL 9.1
Simple Jwt Login — The Simple JWT Login WordPress plugin before 3.6.8 does not validate the audience of the Google identity toke…● PoC
2026-08-16
CVE-2026-19717
HIGH 7.5
Catfolders Document Gallery & Pdf Library — The CatFolders Document Gallery & PDF Library WordPress plugin before 2.0.7 does not have authorisation checks…● PoC
2026-08-16
CVE-2026-19725
CRITICAL 9.1
Wpvivid — Backup, Migration & Staging — The WPvivid — Backup, Migration & Staging WordPress plugin before 0.9.131 does not sanitise a value taken from…● PoC
2026-08-16
CVE-2026-19726
MEDIUM 6.5
Visualizer — The Visualizer WordPress plugin before 4.0.7 does not properly authorise access to the configuration of its c…● PoC
2026-08-16
CVE-2026-19728
HIGH 7.5
Extra Product Options Builder For Woocommerce — The Extra Product Options Builder for WooCommerce WordPress plugin before 1.2.176 does not verify that the req…● PoC
2026-08-16
CVE-2026-14229
MEDIUM 5.3
Ecs — The ECS WordPress plugin before 4.3.8 does not check the post status or any capability when rendering an Elem…● PoC
2026-08-15
CVE-2026-14230
MEDIUM 5.4
Ecs — The ECS WordPress plugin before 4.3.8 does not perform capability or object-ownership checks on its Dynamic R…● PoC
2026-08-15
CVE-2026-16541
MEDIUM 6.5
Simply Schedule Appointments — The Simply Schedule Appointments WordPress plugin before 1.6.12.17 does not restrict the user records returned…● PoC
2026-08-15
CVE-2026-16611
HIGH 7.5
Product Feed Pro For Woocommerce By Adtribes — The Product Feed PRO for WooCommerce by AdTribes WordPress plugin before 13.5.7 does not perform an authoriza…● PoC
2026-08-15
CVE-2026-18216
MEDIUM 6.5
Backup Migration — The Backup Migration WordPress plugin before 2.1.7 does not properly restrict a post-restore automatic login m…● PoC
2026-08-15
CVE-2026-18807
MEDIUM 4.3
Ecs — The ECS WordPress plugin before 4.3.8 does not have capability or ownership checks on its dynamic repeater ac…● PoC
2026-08-15
CVE-2026-14290
MEDIUM 6.8
Embed Google Photos Album — The Embed Google Photos album WordPress plugin through 2.2.1 does not escape a shortcode attribute value befor…● PoC
2026-08-14
CVE-2026-15205
HIGH 8.6
Paymob For Woocommerce — The Paymob for WooCommerce WordPress plugin before 4.1.9 does not properly sanitise a client-supplied identifi…● PoC
2026-08-14
CVE-2026-16739
MEDIUM 5.9
Epeken All Kurir For Woocommerce — The Epeken All Kurir for Woocommerce WordPress plugin through 2.1.2 does not verify that a payment-confirmatio…● PoC
2026-08-14
CVE-2026-18039
HIGH 8.1
Essential Addons For Elementor — The Essential Addons for Elementor WordPress plugin before 6.7.2 does not prevent user-supplied registration …● PoC
2026-08-14
CVE-2026-13328
MEDIUM 5.3
Food Menu — The Food Menu WordPress plugin before 6.0.2 does not perform any capability or ownership check on its reserva…● PoC
2026-08-13
CVE-2026-13610
HIGH 7.5
Kivicare — The KiviCare WordPress plugin before 4.5.2 does not restrict the roles assignable through its unauthenticated…● PoC
2026-08-13
CVE-2026-14182
CRITICAL 9.8
Customer Email Verification For Woocommerce — The Customer Email Verification for WooCommerce WordPress plugin before 3.2.6 does not correctly validate the …● PoC
2026-08-13
CVE-2026-14213
LOW 3.7
Booking For Appointments And Events Calendar — The Booking for Appointments and Events Calendar WordPress plugin before 2.4.6 does not verify that an authen…● PoC
2026-08-13
CVE-2026-14332
MEDIUM 5.4
Ecwid By Lightspeed Ecommerce Shopping Cart — The Ecwid by Lightspeed Ecommerce Shopping Cart WordPress plugin before 7.0.9 does not perform a capability ch…● PoC
2026-08-13
CVE-2026-15413
CRITICAL 10
Link Factory — The Link Factory WordPress plugin is a backdoor. Distributed as a "homepage sentence publisher", it exposes an…● PoC
2026-08-13
CVE-2026-18945
HIGH 8.2
Wp Helper Premium — The WP Helper Premium WordPress plugin before 4.7.6 does not verify the order key when rendering its custom or…● PoC
2026-08-13
CVE-2026-19088
MEDIUM 5.4
Shopengine Elementor Woocommerce Builder Addon — The ShopEngine Elementor WooCommerce Builder Addon WordPress plugin before 4.9.3 does not protect one of its …● PoC
2026-08-13
CVE-2026-12976
MEDIUM 6.5
Learnpress — The LearnPress WordPress plugin before 4.4.4 does not verify that a user is enrolled in a course before proce…● PoC
2026-08-12
CVE-2026-13168
MEDIUM 6.5
Eventin — The Eventin WordPress plugin before 4.1.20 does not properly restrict access to stored customer records, allo…● PoC
2026-08-12
CVE-2026-13171
HIGH 8.2
Eventin — The Eventin WordPress plugin before 4.1.20 does not perform an authorization check on its waiting-list regist…● PoC
2026-08-12
CVE-2026-13177
MEDIUM 4.3
Eventin — The Eventin WordPress plugin before 4.1.20 does not properly restrict access to individual order records, all…● PoC
2026-08-12
CVE-2026-13612
MEDIUM 4.3
Kivicare — The KiviCare WordPress plugin before 4.5.2 does not verify that the requesting user owns the records being ac…● PoC
2026-08-12
CVE-2026-13613
HIGH 8.8
Kivicare — The KiviCare WordPress plugin before 4.5.2 does not properly sanitise and escape user-supplied parameters bef…● PoC
2026-08-12
CVE-2026-14857
MEDIUM 4.3
Wp Crowdfunding — The WP Crowdfunding WordPress plugin before 2.2.1 does not verify ownership of a campaign before allowing its …● PoC
2026-08-12
CVE-2026-14858
MEDIUM 4.3
Wp Crowdfunding — The WP Crowdfunding WordPress plugin before 2.2.1 does not verify order ownership before returning order detai…● PoC
2026-08-12
CVE-2026-14859
MEDIUM 4.3
Wp Crowdfunding — The WP Crowdfunding WordPress plugin before 2.2.1 does not check the campaign-submission capability in one of …● PoC
2026-08-12
CVE-2026-14925
HIGH 7.5
Import Wp — The Import WP WordPress plugin before 2.14.23 does not perform any authorization check on one of its export-f…● PoC
2026-08-12
CVE-2026-15039
CRITICAL 9.8
Giftware — The giftware WordPress plugin before 4.2.10 does not validate the type of uploaded files in one of its upload …● PoC
2026-08-12
CVE-2026-15045
MEDIUM 6.5
Wallet System For Woocommerce — The Wallet System for WooCommerce WordPress plugin before 2.7.10 does not validate a user-supplied wallet amou…● PoC
2026-08-12
CVE-2026-15213
MEDIUM 5.3
Welcart E Commerce — The Welcart e-Commerce WordPress plugin before 2.11.33 does not verify the authenticity of its convenience-sto…● PoC
2026-08-12
CVE-2026-15249
MEDIUM 5.4
Patterns Kit — The Patterns Kit WordPress plugin through 1.0.3 does not escape a link attribute before its client-side script…● PoC
2026-08-12
CVE-2026-15388
MEDIUM 4.3
Cookie Consent — The Cookie Consent WordPress plugin before 0.0.10 does not correctly enforce its intended administrator-only …● PoC
2026-08-12
CVE-2026-16051
CRITICAL 9.8
Wpmudev Updates — The wpmudev-updates WordPress plugin before 5.0.1 does not verify the integrity of the packages installed thro…● PoC
2026-08-12
CVE-2026-16066
MEDIUM 5.4
Welcart E Commerce — The Welcart e-Commerce WordPress plugin before 2.11.34 does not sanitise or escape a product field before outp…● PoC
2026-08-12
CVE-2026-16253
HIGH 7.5
Total Upkeep — The Total Upkeep WordPress plugin before 1.17.3 does not adequately protect the secret that authorizes its ba…● PoC
2026-08-12
CVE-2026-16294
HIGH 7.1
Powerpress Podcasting Plugin By Blubrry — The PowerPress Podcasting plugin by Blubrry WordPress plugin before 11.17.1 does not validate one of its Podca…● PoC
2026-08-12
CVE-2026-16538
CRITICAL 9.1
Wallet For Woocommerce — The Wallet for WooCommerce WordPress plugin before 1.6.10 does not verify the amount actually collected for a …● PoC
2026-08-12
CVE-2026-16621
MEDIUM 5.3
Payment Gateway For Paypal On Woocommerce — The Payment Gateway for PayPal on WooCommerce WordPress plugin before 9.2.1 does not verify that payment actua…● PoC
2026-08-12
CVE-2026-16737
MEDIUM 5.3
Wp Travel Engine — The WP Travel Engine WordPress plugin before 6.8.5 does not perform authorization or ownership checks when lo…● PoC
2026-08-12
CVE-2026-16747
MEDIUM 6.5
Kirki — The Kirki WordPress plugin before 6.2.1 does not properly authorise its front-end form submission REST routes …● PoC
2026-08-12
CVE-2026-16977
HIGH 8.1
Form Maker By 10web — The Form Maker by 10Web WordPress plugin before 1.15.45 does not properly parameterize a user-controlled valu…● PoC
2026-08-12
CVE-2026-16990
MEDIUM 5.3
Payment Button For Paypal — The Payment Button for PayPal WordPress plugin through 1.2.3.44 does not enforce the merchant-configured price…● PoC
2026-08-12
CVE-2026-17008
MEDIUM 5.3
Quick Paypal Payments — The Quick Paypal Payments WordPress plugin through 5.7.50 does not verify the paid amount, receiver, or paymen…● PoC
2026-08-12
CVE-2026-17013
MEDIUM 6.1
Wp Photo Album Plus — The WP Photo Album Plus WordPress plugin before 9.2.07.002 does not sanitise and escape a parameter before ref…● PoC
2026-08-12
CVE-2026-18035
MEDIUM 5.3
User Access Manager — The User Access Manager WordPress plugin before 2.3.15 does not apply its access restrictions to REST API requ…● PoC
2026-08-12
CVE-2026-18044
LOW 3.7
Estatik Real Estate Plugin — The Estatik Real Estate Plugin WordPress plugin before 4.3.4 does not validate the same recipient list that it…● PoC
2026-08-12
CVE-2026-18046
MEDIUM 4.3
Cookie Consent — The Cookie Consent WordPress plugin before 0.0.10 does not correctly enforce its intended administrator-only …● PoC
2026-08-12
CVE-2026-18048
HIGH 7.5
Wp Photo Album Plus — The WP Photo Album Plus WordPress plugin before 9.2.07.002 does not validate a client-controlled value used to…● PoC
2026-08-12
CVE-2026-18049
HIGH 7.5
Wp Photo Album Plus — The WP Photo Album Plus WordPress plugin before 9.2.07.002 does not perform any capability or nonce check on o…● PoC
2026-08-12
CVE-2026-18057
HIGH 8.1
Events Manager — The Events Manager WordPress plugin before 7.4.1 does not sanitise and escape a user-controlled value before …● PoC
2026-08-12
CVE-2026-18230
HIGH 8.1
Wp Directory Kit — The WP Directory Kit WordPress plugin before 1.5.6 does not sanitise and escape a parameter before using it in…● PoC
2026-08-12
CVE-2026-18366
CRITICAL 9.8
Events Manager — The Events Manager WordPress plugin before 7.4.1 does not properly scope its capability mapping, discarding t…● PoC
2026-08-12
CVE-2026-18391
CRITICAL 9.8
Woocommerce Subscriptions — The WooCommerce Subscriptions WordPress plugin before 9.1.0 does not validate user input before unserializing …● PoC
2026-08-12
CVE-2026-18474
HIGH 8.6
Wp Directory Kit — The WP Directory Kit WordPress plugin before 1.5.6 does not sanitise and escape a parameter before using it in…● PoC
2026-08-12
CVE-2026-18789
HIGH 7.5
Ezoic — The Ezoic WordPress plugin before 2.23.1 does not properly restrict access to some of its content export funct…● PoC
2026-08-12
CVE-2026-18943
MEDIUM 6.5
Wpc Admin Columns — The WPC Admin Columns WordPress plugin before 2.3.4 does not have authorisation checks in one of its AJAX acti…● PoC
2026-08-12
CVE-2026-18962
MEDIUM 4.3
Wp Photo Album Plus — The WP Photo Album Plus WordPress plugin before 9.2.09.002 does not check that the current user is allowed to …● PoC
2026-08-12
CVE-2026-19050
MEDIUM 6.4
Prosolution Wp Client — The ProSolution WP Client WordPress plugin before 2.0.9 does not validate a user-supplied URL, and does not ch…● PoC
2026-08-12
CVE-2026-19052
MEDIUM 4.3
Prosolution Wp Client — The ProSolution WP Client WordPress plugin before 2.0.9 does not perform capability checks on two administrati…● PoC
2026-08-12
CVE-2026-19073
MEDIUM 5.3
Order Sync With Zendesk For Woocommerce — The Order Sync with Zendesk for WooCommerce WordPress plugin before 2.2.3 does not perform any capability chec…● PoC
2026-08-12
CVE-2026-19217
MEDIUM 5.4
Royal Addons For Elementor — The Royal Addons for Elementor WordPress plugin before 1.7.1065 does not validate a widget setting used to bu…● PoC
2026-08-12
CVE-2026-14548
MEDIUM 6.5
Ray Enterprise Translation — The Ray Enterprise Translation WordPress plugin through 1.7.3 does not perform any capability or nonce checks …● PoC
2026-08-11
CVE-2026-14549
MEDIUM 4.3
Ray Enterprise Translation — The Ray Enterprise Translation WordPress plugin through 1.7.3 does not perform any capability or nonce checks …● PoC
2026-08-11
CVE-2026-12971
LOW 2.2
Learnpress — The LearnPress WordPress plugin before 4.4.4 does not validate a user-supplied URL before the server fetches …● PoC
2026-08-10
CVE-2026-13170
HIGH 7.2
Eventin — The Eventin WordPress plugin before 4.1.20 does not properly validate a template path setting before using it…● PoC
2026-08-10
CVE-2026-13600
HIGH 8.1
Autonettv Relay — The AutoNetTV Relay WordPress plugin before 3.0.14 does not perform any capability or authentication check bef…● PoC
2026-08-10
CVE-2026-13701
MEDIUM 4.8
Advanced Excerpt — The Advanced Excerpt WordPress plugin before 4.5 does not sanitise and escape one of its settings before outpu…● PoC
2026-08-10
CVE-2026-14206
HIGH 7.5
Ht Contact Form — The HT Contact Form WordPress plugin before 2.9.3 does not perform any authorization check on the endpoint th…● PoC
2026-08-10
CVE-2026-14211
LOW 3.8
Booking For Appointments And Events Calendar — The Booking for Appointments and Events Calendar WordPress plugin before 9.7 does not verify that an authenti…● PoC
2026-08-10
CVE-2026-14237
HIGH 7.2
Vitepos — The vitepos WordPress plugin before 3.6.0, Vitepos WordPress plugin before 3.5.0 do not perform a per-target …● PoC
2026-08-10
CVE-2026-14238
MEDIUM 4.1
Vitepos — The vitepos WordPress plugin before 3.6.0 does not sanitize or parameterize an identifier taken from a REST re…● PoC
2026-08-10
CVE-2026-14293
HIGH 8.8
Autopay — The Autopay WordPress plugin before 5.0.1 does not perform any capability or nonce check before saving a styli…● PoC
2026-08-10
CVE-2026-14860
MEDIUM 5.3
Podcast Player — The Podcast Player WordPress plugin before 8.3.1 does not validate the destination of a server-side request b…● PoC
2026-08-10
CVE-2026-14941
MEDIUM 5.4
Customer Reviews For Woocommerce — The Customer Reviews for WooCommerce WordPress plugin before 5.116.0 does not perform nonce or capability chec…● PoC
2026-08-10
CVE-2026-15047
MEDIUM 6.8
S2member — The s2Member WordPress plugin before 260805 does not escape several shortcode attributes before outputting th…● PoC
2026-08-10
CVE-2026-15229
MEDIUM 5.3
Pinpoint Booking System — The Pinpoint Booking System WordPress plugin through 2.9.9.7.1 does not validate the booking price on the ser…● PoC
2026-08-10
CVE-2026-15237
MEDIUM 5.3
Motopress Hotel Booking — The MotoPress Hotel Booking WordPress plugin before 6.2.3 does not perform any authorization or ownership chec…● PoC
2026-08-10
CVE-2026-15238
MEDIUM 5.4
Motopress Hotel Booking — The MotoPress Hotel Booking WordPress plugin before 6.2.3 does not verify record ownership before updating cus…● PoC
2026-08-10
CVE-2026-16257
HIGH 8.2
Arvow Ai Seo Writer — The Arvow AI SEO Writer WordPress plugin before 1.5.4 does not properly restrict access to one of its REST end…● PoC
2026-08-10
CVE-2026-16298
CRITICAL 9.8
Foodboxbooker — The FoodBoxBooker WordPress plugin before 1.0.7 does not properly validate the password reset request, allowin…● PoC
2026-08-10
CVE-2026-16299
CRITICAL 9.8
Single Sign On For Tng — The Single Sign On For TNG WordPress plugin before 2.2.0 does not properly validate a password reset request, …● PoC
2026-08-10
CVE-2026-16949
MEDIUM 5.8
Term Pages — The Term Pages WordPress plugin before 2.0.0 does not properly sanitise and escape a parameter before using it…● PoC
2026-08-10
CVE-2026-16985
HIGH 8.8
Squeeze — The Squeeze WordPress plugin before 1.7.12 does not validate the file type or extension of the per-size image…● PoC
2026-08-10
CVE-2026-17010
MEDIUM 5.4
Saitama Addon Pack — The Saitama Addon Pack WordPress plugin through 1.0.8 does not sanitise and escape certain post metadata value…● PoC
2026-08-10
CVE-2026-17012
MEDIUM 5.3
Accept Paypal & Stripe With Subscriptions For Woocommerce — The Accept PayPal & Stripe with Subscriptions for WooCommerce WordPress plugin through 3.1.0 does not verify t…● PoC
2026-08-10
CVE-2026-17016
LOW 3.7
Accept Paypal & Stripe With Subscriptions For Woocommerce — The Accept PayPal & Stripe with Subscriptions for WooCommerce WordPress plugin through 3.1.0 does not validate…● PoC
2026-08-10
CVE-2026-17018
MEDIUM 4.9
Cubewp Framework — The CubeWP Framework WordPress plugin through 1.1.30 does not perform a per-object read authorization check, n…● PoC
2026-08-10
CVE-2026-17019
MEDIUM 6.1
Jetengine — The JetEngine WordPress plugin before 3.8.13.1 does not sanitise uploaded SVG files before storing and serving…● PoC
2026-08-10
CVE-2026-17020
MEDIUM 4.3
Salon Booking System — The Salon Booking System WordPress plugin through 10.31.0 does not verify that a requested booking belongs to…● PoC
2026-08-10
CVE-2026-17021
MEDIUM 5.3
Salon Booking System — The Salon Booking System WordPress plugin before 10.30.34 does not properly restrict access to some of its boo…● PoC
2026-08-10
CVE-2026-17022
HIGH 7.5
Salon Booking System — The Salon Booking System WordPress plugin before 10.30.34 does not properly validate a booking's ownership to…● PoC
2026-08-10
CVE-2026-17023
MEDIUM 4.8
Salon Booking System — The Salon Booking System WordPress plugin through 10.30.33 does not perform any capability check or validate …● PoC
2026-08-10
CVE-2026-17540
HIGH 8.8
File Manager — The File Manager WordPress plugin before 6.9.1 does not properly authorise its file management commands, allow…● PoC
2026-08-10
CVE-2026-17541
HIGH 7.5
File Manager — The File Manager WordPress plugin before 6.9.1 does not have authorisation checks on one of its REST API route…● PoC
2026-08-10
CVE-2026-17542
HIGH 7.5
File Manager — The File Manager WordPress plugin before 6.9.1 does not perform any capability check on one of its file manage…● PoC
2026-08-10
CVE-2026-18030
HIGH 8.1
Bricksforge — The BricksForge WordPress plugin before 3.1.8.8 does not verify the identity of the requester when processing …● PoC
2026-08-10
CVE-2026-18200
MEDIUM 4.3
Foodboxbooker — The FoodBoxBooker WordPress plugin before 1.0.8 does not verify that the user account being updated belongs to…● PoC
2026-08-10
CVE-2026-18468
HIGH 8.1
Login & Register Forms — The Login & Register Forms WordPress plugin before 4.0.2 does not bind the password reset verification state …● PoC
2026-08-10
CVE-2026-18469
HIGH 8.1
Login & Register Forms — The Login & Register Forms WordPress plugin before 4.0.2 does not enforce its password reset attempt limit ag…● PoC
2026-08-10
CVE-2026-18470
HIGH 7.5
Login & Register Forms — The Login & Register Forms WordPress plugin before 4.0.2 does not verify that a password reset request comes …● PoC
2026-08-10
CVE-2026-18666
MEDIUM 4.3
Library Management System — The Library Management System WordPress plugin before 3.6.7 does not sanitize and escape a user-supplied param…● PoC
2026-08-10
CVE-2026-18786
HIGH 8.8
Checkview — The CheckView WordPress plugin before 2.3.2 does not restrict its REST API authentication filter to its own r…● PoC
2026-08-10
CVE-2026-18934
MEDIUM 5.5
Rss Aggregator By Feedzy — The RSS Aggregator by Feedzy WordPress plugin before 5.2.6 does not verify that the requesting user owns or i…● PoC
2026-08-10
CVE-2026-18946
HIGH 7.5
Contact Form To Any Api — The Contact Form to Any API WordPress plugin before 3.0.7 does not use a random filename when copying files up…● PoC
2026-08-10
CVE-2026-18960
MEDIUM 5.4
Block User Account — The Block User Account WordPress plugin before 2.0.1 does not enforce its account block on every authenticatio…● PoC
2026-08-10
CVE-2026-19049
HIGH 8.6
Prosolution Wp Client — The ProSolution WP Client WordPress plugin before 2.0.9 does not sanitise a cookie value before using it in SQ…● PoC
2026-08-10
CVE-2026-19053
CRITICAL 9.1
Prosolution Wp Client — The ProSolution WP Client WordPress plugin before 2.0.6 does not sanitise and escape a parameter before using …● PoC
2026-08-10
CVE-2026-19074
MEDIUM 5.3
Advanced Classifieds & Directory Pro — The Advanced Classifieds & Directory Pro Advanced Classifieds & Directory Pro WordPress plugin before 3.4.3 (<…● PoC
2026-08-10
CVE-2026-19075
MEDIUM 5
All In One Video Gallery — All-in-One Video Gallery registers a public, unauthenticated file-download handler triggered by `?vdl=<post_id…● PoC
2026-08-10
CVE-2026-19077
MEDIUM 6.5
Duplicate Post — The Duplicate Post WordPress plugin before 1.5.5 does not perform per-object authorisation checks in its bulk …● PoC
2026-08-10
CVE-2026-19089
CRITICAL 9.8
Product Input Fields For Woocommerce — The Product Input Fields for WooCommerce WordPress plugin before 2.0.2 does not validate uploaded file types w…● PoC
2026-08-10
CVE-2026-15038
CRITICAL 9.8
Infinitewp Client — The InfiniteWP Client WordPress plugin before 1.13.6 does not properly verify the site-connection state and th…● PoC
2026-08-09
CVE-2026-16032
MEDIUM 6.1
Lws Optimize — The LWS Optimize WordPress plugin before 4.1.2 does not properly escape a value submitted through an unauthen…● PoC
2026-08-09
CVE-2026-16957
LOW 2.7
Slim Seo — The Slim SEO WordPress plugin before 4.9.11 does not restrict a post-meta preview feature to posts the user i…● PoC
2026-08-09
CVE-2026-16965
MEDIUM 4.3
Solace Extra — The Solace Extra WordPress plugin before 1.6.1 does not perform capability or nonce checks in one of its AJAX …● PoC
2026-08-09
CVE-2026-16988
HIGH 7.5
Geodirectory — The GeoDirectory WordPress plugin before 2.8.169 does not perform any authorization check when returning map …● PoC
2026-08-09
CVE-2026-16992
MEDIUM 6.5
Create — The Create WordPress plugin before 2.5.4 does not perform an authorization check before returning content over…● PoC
2026-08-09
CVE-2026-17011
LOW 3.8
Nexter Blocks — The Nexter Blocks WordPress plugin before 5.0.2 does not restrict who can save global CSS through one of its …● PoC
2026-08-09
CVE-2026-17014
MEDIUM 5.3
Wp Photo Album Plus — The WP Photo Album Plus WordPress plugin before 9.2.07.002 does not perform any capability or nonce check on o…● PoC
2026-08-09
CVE-2026-17017
HIGH 8.1
Cubewp Framework — The CubeWP Framework WordPress plugin before 1.1.31 does not properly sanitize and escape a parameter before u…● PoC
2026-08-09
CVE-2026-17044
HIGH 8.6
Iptanus File Upload — The Iptanus File Upload WordPress plugin before 5.1.8 does not properly sanitise and escape a parameter before…● PoC
2026-08-09
CVE-2026-18032
HIGH 7.5
Wp Data Access — The WP Data Access WordPress plugin before 5.5.79 does not validate the column names it accepts on one of its…● PoC
2026-08-09
CVE-2026-18037
MEDIUM 6.5
Create — The Create WordPress plugin before 2.5.4 does not perform an authorization check before rendering content over…● PoC
2026-08-09
CVE-2026-18357
HIGH 7.5
Wpc Order Tip For Woocommerce — The WPC Order Tip for WooCommerce WordPress plugin before 3.3.1 does not perform authorisation or nonce checks…● PoC
2026-08-09
CVE-2026-18464
HIGH 7.5
Wp Maps Pro — The WP MAPS PRO WordPress plugin before 6.1.3 does not perform a capability check in one of its AJAX actions, …● PoC
2026-08-09
CVE-2026-18465
MEDIUM 6.5
Wp Maps Pro — The WP MAPS PRO WordPress plugin before 6.1.3 does not perform a capability check in one of its AJAX actions, …● PoC
2026-08-09
CVE-2026-18473
CRITICAL 9.1
Wp Directory Kit — The WP Directory Kit WordPress plugin before 1.5.5 does not properly sanitise and escape a parameter before us…● PoC
2026-08-09
CVE-2026-18603
MEDIUM 6.5
Piweb Cancel Order / Refund Request For Woocommerce — The PiWeb Cancel order / Refund request for WooCommerce WordPress plugin before 1.3.4.34 does not have authori…● PoC
2026-08-09
CVE-2026-16267
HIGH 8.1
Newsletters — The Newsletters WordPress plugin before 4.16 does not restrict the classes allowed when unserialising a value …● PoC
2026-08-08
CVE-2026-16269
MEDIUM 4.8
Newsletters — The Newsletters WordPress plugin before 4.16 does not strictly compare its API authentication key, allowing un…● PoC
2026-08-08
CVE-2026-16282
MEDIUM 5.3
Appointment Hour Booking — The Appointment Hour Booking WordPress plugin before 1.5.88 does not validate a client-supplied booking price…● PoC
2026-08-08
CVE-2026-16535
MEDIUM 6.1
Link Library — The Link Library WordPress plugin before 7.9.4 does not sanitise and escape a parameter before reflecting it b…● PoC
2026-08-08
CVE-2026-16558
MEDIUM 5.4
Ymc Filter — The YMC Filter WordPress plugin before 3.12.8 does not sanitize and escape a layout builder setting before out…● PoC
2026-08-08
CVE-2026-16559
MEDIUM 6.8
Ymc Filter — The YMC Filter WordPress plugin before 3.12.9 does not sanitize SVG files uploaded through one of its icon upl…● PoC
2026-08-08
CVE-2026-16562
MEDIUM 6.5
Wp Statistics — The WP Statistics WordPress plugin before 14.16.10 does not perform a capability check on a set of dashboard …● PoC
2026-08-08
CVE-2026-16574
MEDIUM 5.4
Dokan: Ai Powered Woocommerce Multivendor Marketplace Solution — The Dokan: AI Powered WooCommerce Multivendor Marketplace Solution WordPress plugin before 5.0.11 does not ve…● PoC
2026-08-08
CVE-2026-16578
HIGH 7.5
Admin Safety Guard — Login Security, Limit Logins, 2fa & Brute Force Protection — The Admin Safety Guard — Login Security, Limit Logins, 2FA & Brute Force Protection WordPress plugin before 1.…● PoC
2026-08-08
CVE-2026-16589
HIGH 7.7
Wp Directory Kit — The WP Directory Kit WordPress plugin before 1.5.5 does not sanitize and escape a parameter before using it in…● PoC
2026-08-08
CVE-2026-16590
MEDIUM 6.5
Wp Directory Kit — The WP Directory Kit WordPress plugin before 1.5.5 does not perform authorization or nonce checks on one of it…● PoC
2026-08-08
CVE-2026-16594
HIGH 7.5
Wp Directory Kit — The WP Directory Kit WordPress plugin before 1.5.5 does not perform authorization or nonce checks on one of it…● PoC
2026-08-08
CVE-2026-16595
MEDIUM 6.5
Wp Directory Kit — The WP Directory Kit WordPress plugin before 1.5.5 does not perform authorization or nonce checks on one of it…● PoC
2026-08-08
CVE-2026-16608
MEDIUM 5.3
Download Monitor — The Download Monitor WordPress plugin before 5.2.6 does not perform authorization checks on one of its downloa…● PoC
2026-08-08
CVE-2026-16948
HIGH 8.1
Solace Extra — The Solace Extra WordPress plugin before 1.6.1 does not perform capability checks in several of its AJAX actio…● PoC
2026-08-08
CVE-2026-16953
MEDIUM 4.8
Ai Engine — The AI Engine WordPress plugin before 3.6.4 does not verify ownership of a guest's uploaded chatbot files bef…● PoC
2026-08-08
CVE-2026-16955
MEDIUM 5
Ai Engine — The AI Engine WordPress plugin before 3.6.6 does not confine a caller-supplied file path before reading it an…● PoC
2026-08-08
CVE-2026-14205
CRITICAL 9.8
Wp Events Manager — The WP Events Manager WordPress plugin before 2.2.5 does not validate the requested quantity when registering …● PoC
2026-08-07
CVE-2026-14331
MEDIUM 6.1
Subscribe2 — The Subscribe2 WordPress plugin before 10.46 does not properly escape a user-supplied value before reflecting…● PoC
2026-08-07
CVE-2026-14943
HIGH 7.5
Password Protected — Lock Entire Site, Pages, Posts, Categories, And Partial Content — The Password Protected — Lock Entire Site, Pages, Posts, Categories, and Partial Content WordPress plugin befo…● PoC
2026-08-07
CVE-2026-15032
MEDIUM 6.1
Comments — The Comments WordPress plugin before 7.6.60 does not properly escape a user-supplied URL before outputting it…● PoC
2026-08-07
CVE-2026-15148
MEDIUM 5.3
Wp Events Manager — The WP Events Manager WordPress plugin before 2.2.5 does not verify that an incoming payment notification orig…● PoC
2026-08-07
CVE-2026-15211
MEDIUM 5.9
Subscriptions For Woocommerce — The Subscriptions for WooCommerce WordPress plugin before 2.0.1 does not validate the payment amount or bind t…● PoC
2026-08-07
CVE-2026-15214
MEDIUM 4.3
Subscriptions For Woocommerce — The Subscriptions for WooCommerce WordPress plugin before 2.0.1 does not verify that the requester owns the su…● PoC
2026-08-07
CVE-2026-15215
HIGH 8.8
Subscriptions For Woocommerce — The Subscriptions for WooCommerce WordPress plugin before 2.0.1 does not verify the user's capability before i…● PoC
2026-08-07
CVE-2026-15239
MEDIUM 5.3
Simple Captcha With Cloudflare Turnstile — The Simple CAPTCHA with Cloudflare Turnstile WordPress plugin before 1.42.0 does not bind its Turnstile valida…● PoC
2026-08-07
CVE-2026-15245
MEDIUM 5.4
Bne Testimonials — The BNE Testimonials WordPress plugin before 2.0.8.2 does not properly escape a shortcode attribute for a Java…● PoC
2026-08-07
CVE-2026-15359
MEDIUM 6.5
Templately — The Templately WordPress plugin before 3.7.1 does not have an authorisation check on one of its request handl…● PoC
2026-08-07
CVE-2026-15361
HIGH 8.1
Content Views — The Content Views WordPress plugin before 4.5 does not perform a capability check on one of its AJAX actions …● PoC
2026-08-07
CVE-2026-15386
MEDIUM 5.4
Meow Gallery — The Meow Gallery WordPress plugin before 5.5.2 does not escape an attachment's alt text before outputting it i…● PoC
2026-08-07
CVE-2026-16030
HIGH 8.1
Mstore Api — The MStore API WordPress plugin before 4.21.0 does not correctly verify the cryptographic signature of the to…● PoC
2026-08-07
CVE-2026-16038
CRITICAL 9.1
Mstore Api — The MStore API WordPress plugin before 4.21.0 does not verify the payment with the payment gateway before mar…● PoC
2026-08-07
CVE-2026-16039
MEDIUM 6.5
Mstore Api — The MStore API WordPress plugin before 4.21.0 does not restrict its vendor-orders endpoint to the caller's ow…● PoC
2026-08-07
CVE-2026-16041
HIGH 7.5
Mstore Api — The MStore API WordPress plugin before 4.21.0 does not perform authorization or purchase-ownership checks on …● PoC
2026-08-07
CVE-2026-16258
CRITICAL 9.8
Ajax Search Lite — The Ajax Search Lite WordPress plugin before 4.14.5 does not prevent the deserialization of untrusted input, …● PoC
2026-08-07
CVE-2026-16262
HIGH 7.5
Estatik Real Estate Plugin — The Estatik Real Estate Plugin WordPress plugin before 4.3.3 does not bind its OAuth social login flow to the …● PoC
2026-08-07
CVE-2026-16263
HIGH 8.8
Wp Maps — The WP Maps WordPress plugin before 4.9.7 does not perform a capability check in one of its AJAX actions and …● PoC
2026-08-07
CVE-2026-16265
MEDIUM 6.5
Wp Maps — The WP Maps WordPress plugin before 4.9.7 does not perform a capability check in one of its AJAX actions and …● PoC
2026-08-07
CVE-2026-10524
HIGH 7.5
Cocart — The CoCart WordPress plugin before 4.9.0 does not validate a user-supplied price value against the actual prod…● PoC
2026-08-06
CVE-2026-10599
HIGH 7.5
Integrate Phonepe With Woocommerce — The Integrate PhonePe with WooCommerce WordPress plugin through 1.2.1 does not validate that a verified paymen…● PoC
2026-08-06
CVE-2026-11361
MEDIUM 5.9
Formidable Forms — The Formidable Forms WordPress plugin before 6.32.1 does not properly validate the status of a PayPal subscrip…● PoC
2026-08-06
CVE-2026-11588
MEDIUM 6.1
Eonsr Aeo Agent — The EONSR AEO Agent WordPress plugin through 3.7.9 does not perform any authorisation check on one of its REST…● PoC
2026-08-06
CVE-2026-11976
CRITICAL 10
Monsterinsights Pro — The official MonsterInsights Pro update distribution bucket (`monster-insights.s3.amazonaws.com`) was compromi…● PoC
2026-08-06
CVE-2026-12501
MEDIUM 5.3
Wp Travel Engine — The WP Travel Engine WordPress plugin before 6.8.2 does not verify that an incoming PayPal payment notificatio…● PoC
2026-08-06
CVE-2026-12584
HIGH 7.5
Payment Gateway For Redsys & Woocommerce Lite — The Payment Gateway for Redsys & WooCommerce Lite WordPress plugin before 7.0.2 does not verify the authentici…● PoC
2026-08-06
CVE-2026-12713
CRITICAL 9.1
Wpcargo Track & Trace — The WPCargo Track & Trace WordPress plugin before 8.0.4 does not properly sanitise and escape a parameter befo…● PoC
2026-08-06
CVE-2026-12901
MEDIUM 5.9
Getpaid — The GetPaid WordPress plugin before 2.8.55 does not verify the authenticity of incoming Worldpay payment notif…● PoC
2026-08-06
CVE-2026-13153
HIGH 7.5
Gutenberg Essential Blocks — The Gutenberg Essential Blocks WordPress plugin before 6.4.0 does not restrict access to one of its public RE…● PoC
2026-08-06
CVE-2026-13154
HIGH 7.5
Gutenberg Essential Blocks — The Gutenberg Essential Blocks WordPress plugin before 6.4.0 does not verify that an attacker-supplied post t…● PoC
2026-08-06
CVE-2026-13342
MEDIUM 5.3
Security Optimizer — The Security Optimizer WordPress plugin from 1.5.8 to 1.6.4 does not correctly validate requests to its option…● PoC
2026-08-06
CVE-2026-13399
HIGH 7.5
Payment Plugins For Paypal Woocommerce — The Payment Plugins for PayPal WooCommerce WordPress plugin before 2.0.20 does not have proper authorization c…● PoC
2026-08-06
CVE-2026-13703
MEDIUM 5.4
Seo Redirection Plugin — The SEO Redirection Plugin WordPress plugin before 9.19 does not perform a capability check in one of its aut…● PoC
2026-08-06
CVE-2026-14204
MEDIUM 6.5
Google Authenticator — The Google Authenticator WordPress plugin before 0.56 does not verify a CSRF nonce when saving its two-factor …● PoC
2026-08-06
CVE-2026-14225
LOW 2.7
Easy Appointments — The Easy Appointments WordPress plugin before 3.12.28 does not correctly validate shortcode input in one of it…● PoC
2026-08-06
CVE-2026-14240
MEDIUM 5.3
Tourmaster — The tourmaster WordPress plugin before 5.4.9 writes its order/booking export to a fixed, predictable file insi…● PoC
2026-08-06
CVE-2026-14306
MEDIUM 4.3
Tutor Lms — The Tutor LMS WordPress plugin before 3.9.14 does not properly verify enrollment when restricting access to pr…● PoC
2026-08-06
CVE-2026-14313
MEDIUM 5.3
Peprodev Woocommerce Receipt Uploader — PeproDev WooCommerce Receipt Uploader (PeproDev WooCommerce Receipt Uploader WordPress plugin through 2.8.0 sl…● PoC
2026-08-06
CVE-2026-14314
MEDIUM 5.3
Peprodev Woocommerce Receipt Uploader — The PeproDev WooCommerce Receipt Uploader WordPress plugin through 2.8.0 does not verify that a requested atta…● PoC
2026-08-06
CVE-2026-14547
MEDIUM 5.3
Estatik Real Estate Plugin — The Estatik Real Estate Plugin WordPress plugin before 4.3.3 does not properly enforce its anti-spam check or …● PoC
2026-08-06
CVE-2026-14812
CRITICAL 10
Premium Seo — The Premium SEO WordPress plugin is malicious: it ships an unauthenticated backdoor that creates a hidden admi…● PoC
2026-08-06
CVE-2026-14829
HIGH 8.2
Checkimate — Woocommerce Checkout, Abandoned Cart Recovery & Order Bumps — The Checkimate — WooCommerce Checkout, Abandoned Cart Recovery & Order Bumps WordPress plugin through 1.0.13 d…● PoC
2026-08-06
CVE-2026-14831
MEDIUM 5.3
Easy Booking — The Easy Booking WordPress plugin before 3.5.0 does not re-enforce a bookable product's configured minimum boo…● PoC
2026-08-06
CVE-2026-14842
MEDIUM 5.3
Events Made Easy — The Events Made Easy WordPress plugin before 3.1.2 does not bind the payment authorization token to the paymen…● PoC
2026-08-06
CVE-2026-14936
MEDIUM 5.3
Simple Membership — The Simple Membership WordPress plugin before 4.7.7 does not verify that a PayPal payment notification was sen…● PoC
2026-08-06
CVE-2026-15147
MEDIUM 5.3
Five Star Restaurant Reservations — The Five Star Restaurant Reservations WordPress plugin before 2.7.23 does not verify the authenticity of incom…● PoC
2026-08-06
CVE-2026-15149
MEDIUM 5.3
Wp Hotel Booking — The WP Hotel Booking WordPress plugin before 2.3.3 does not ensure that room quantities and the resulting orde…● PoC
2026-08-06
CVE-2026-15152
MEDIUM 5.3
Wp Hotel Booking — The WP Hotel Booking WordPress plugin before 2.3.2 does not verify that a payment notification corresponds to …● PoC
2026-08-06
CVE-2026-15208
MEDIUM 5.3
Registrationmagic — The RegistrationMagic WordPress plugin before 6.0.9.5 does not compare the verified PayPal capture's amount, c…● PoC
2026-08-06
CVE-2026-15246
MEDIUM 4.3
Realhomes Memberships — The RealHomes Memberships WordPress plugin before 3.1.0 does not verify that a membership payment actually com…● PoC
2026-08-06
CVE-2026-15256
MEDIUM 4.8
Ninja Forms — The Ninja Forms WordPress plugin before 3.14.10 does not prevent user-supplied query-string input, used to pre…● PoC
2026-08-06
CVE-2026-16054
CRITICAL 9.1
Drag And Drop Multiple File Upload For Woocommerce — The Drag and Drop Multiple File Upload for WooCommerce WordPress plugin before 1.1.8 does not prevent unauthen…● PoC
2026-08-06
CVE-2026-16065
MEDIUM 6.5
Welcart E Commerce — The Welcart e-Commerce WordPress plugin before 2.11.32 does not properly sanitise a value taken from an import…● PoC
2026-08-06
CVE-2026-16067
MEDIUM 5.3
Event Booking Manager For Woocommerce (Pro) — The Event Booking Manager for WooCommerce (Pro) WordPress plugin before 5.0.3 does not validate the ticket pri…● PoC
2026-08-06
CVE-2026-16268
HIGH 8.2
Newsletters — The Newsletters WordPress plugin before 4.16 does not authenticate or validate a bounce-processing request bef…● PoC
2026-08-06
CVE-2026-16290
MEDIUM 5.3
Profilegrid — The ProfileGrid WordPress plugin before 6.0.0.0 does not perform authorization checks before returning a grou…● PoC
2026-08-06
CVE-2026-16537
MEDIUM 5.4
Slick Slider — The Slick Slider WordPress plugin before 0.5.3 does not sanitize and escape a shortcode attribute value before…● PoC
2026-08-06
CVE-2026-16619
HIGH 7.5
Miniorange 2fa — The miniOrange 2FA WordPress plugin before 6.2.8 does not correctly limit the number of second-factor verifica…● PoC
2026-08-06
CVE-2026-16620
HIGH 7.5
Wpc Name Your Price For Woocommerce — The WPC Name Your Price for WooCommerce WordPress plugin before 2.2.5 does not enforce its server-side price a…● PoC
2026-08-06
CVE-2026-16734
HIGH 7.5
Stripe Payment Forms By Wp Full Pay — The Stripe Payment Forms by WP Full Pay WordPress plugin before 8.5.2 does not verify that the caller owns th…● PoC
2026-08-06