7.1

CVSS3.1

CVE-2026-3445 - Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Cont…

The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress plugin for WordPress is vulnerable to unauthorized membership payment bypass in all versions up to, and including, 4.16.11. This is due to a missing ownership verification on th…

📅 Published: April 4, 2026, 8:25 a.m. 🔄 Last Modified: April 4, 2026, 8:25 a.m.

4.3

CVSS3.1

CVE-2026-2826 - Kadence Blocks — Page Builder Toolkit for Gutenberg Editor <= 3.6.3 - Missing Authorization to Auth…

The Kadence Blocks — Page Builder Toolkit for Gutenberg Editor plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 3.6.3. This is due to the plugin not properly verifying that a user has the `upload_files` capability in the `process_pattern` REST API end…

📅 Published: April 4, 2026, 8:25 a.m. 🔄 Last Modified: April 4, 2026, 8:25 a.m.

6.4

CVSS3.1

CVE-2026-2437 - WP Travel Engine - Travel and Tour Booking Plugin <= 6.7.5 - Authenticated (Contributor+) Stored Cr…

The WP Travel Engine – Tour Booking Plugin – Tour Operator Software plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'wte_trip_tax' shortcode in all versions up to, and including, 6.7.5 due to insufficient input sanitization and output escaping on user supplied att…

📅 Published: April 4, 2026, 8:25 a.m. 🔄 Last Modified: April 4, 2026, 8:25 a.m.

7.2

CVSS3.1

CVE-2026-5425 - Widgets for Social Photo Feed <= 1.7.9 - Unauthenticated Stored Cross-Site Scripting via feed_data

The Widgets for Social Photo Feed plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'feed_data' parameter keys in all versions up to, and including, 1.7.9 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inje…

📅 Published: April 4, 2026, 8:25 a.m. 🔄 Last Modified: April 4, 2026, 8:25 a.m.

8.1

CVSS3.1

CVE-2026-4896 - WCFM - WooCommerce Frontend Manager <= 6.7.25 - Insecure Direct Object References to Autenticated (…

The WCFM – Frontend Manager for WooCommerce along with Bookings Subscription Listings Compatible plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 6.7.25 via multiple AJAX actions including `wcfm_modify_order_status`, `delete_wcfm_article`,…

📅 Published: April 4, 2026, 7:42 a.m. 🔄 Last Modified: April 4, 2026, 8:16 a.m.
Load More Vulnerability
avatar

Mehmet Ince

@mdisec

CVE stats coming here

avatar

Nuri Çilengir

@ncilengir

CVE stats coming here

avatar

@aydinnyunus

CVE stats coming here

avatar

Onurcan Genç

@onurcangnc

CVE stats coming here

avatar

Seyit Sigirci

@h3xecute

CVE stats coming here

avatar

Ali İltizar

@iltosec

CVE stats coming here

avatar

@b3rsec

CVE stats coming here

avatar

@furkank

CVE stats coming here

avatar

kutaysec

@kutaysec

CVE stats coming here