5.1

CVSS4.0

CVE-2026-33273 -

Unrestricted upload of file with dangerous type issue exists in MATCHA INVOICE 2.6.6 and earlier. If this vulnerability is exploited, an arbitrary file may be created by an administrator of the product. As a result, arbitrary code may be executed on the server.

📅 Published: April 8, 2026, 5:11 a.m. 🔄 Last Modified: April 8, 2026, 7:33 p.m.

8.7

CVSS4.0

CVE-2026-24913 -

SQL Injection vulnerability exists in MATCHA INVOICE 2.6.6 and earlier. If this vulnerability is exploited, information stored in the database may be obtained or altered by a user who can log in to the product.

📅 Published: April 8, 2026, 5:10 a.m. 🔄 Last Modified: April 8, 2026, 7:33 p.m.

6.4

CVSS3.1

CVE-2026-3239 - Strong Testimonials <= 3.2.21 - Authenticated (Contributor+) Stored Cross-Site Scripting via testim…

The Strong Testimonials plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's testimonial_view shortcode in all versions up to, and including, 3.2.21 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authe…

📅 Published: April 8, 2026, 4:27 a.m. 🔄 Last Modified: April 8, 2026, 7:33 p.m.

6.4

CVSS3.1

CVE-2026-3600 - Investi <= 1.0.26 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'maximum-num-years…

The Investi plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'investi-announcements-accordion' shortcode's 'maximum-num-years' attribute in all versions up to, and including, 1.0.26. This is due to insufficient input sanitization and output escaping on user-supplied shortco…

📅 Published: April 8, 2026, 4:27 a.m. 🔄 Last Modified: April 8, 2026, 7:33 p.m.

5.3

CVSS3.1

CVE-2026-3646 - LTL Freight Quotes – R+L Carriers Edition <= 3.3.13 - Missing Authorization to Unauthenticated Sett…

The LTL Freight Quotes – R+L Carriers Edition plugin for WordPress is vulnerable to Missing Authorization via the plugin's webhook handler in all versions up to, and including, 3.3.13. This is due to missing authentication, authorization, and nonce verification on a standalone PHP file that directl…

📅 Published: April 8, 2026, 3:36 a.m. 🔄 Last Modified: April 8, 2026, 9:26 p.m.

5.3

CVSS3.1

CVE-2026-4299 - MainWP Child Reports <= 2.2.6 - Missing Authorization to Authenticated (Subscriber+) Information Di…

The MainWP Child Reports plugin for WordPress is vulnerable to Missing Authorization in all versions up to and including 2.2.6. This is due to a missing capability check in the heartbeat_received() function in the Live_Update class. This makes it possible for authenticated attackers, with Subscribe…

📅 Published: April 8, 2026, 3:36 a.m. 🔄 Last Modified: April 8, 2026, 7:33 p.m.

6.4

CVSS3.1

CVE-2026-4785 - LatePoint <= 5.3.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode

The LatePoint – Calendar Booking Plugin for Appointments and Events plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'button_caption' parameter in the [latepoint_resources] shortcode in versions up to and including 5.3.0. This is due to insufficient output escaping when the…

📅 Published: April 8, 2026, 3:36 a.m. 🔄 Last Modified: April 8, 2026, 7:33 p.m.

6.4

CVSS3.1

CVE-2026-4341 - Prime Slider <= 4.1.10 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'follow_us_te…

The Prime Slider – Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'follow_us_text' setting of the Mount widget in all versions up to, and including, 4.1.10. This is due to insufficient input sanitization and output escaping. Specifically, the `render_…

📅 Published: April 8, 2026, 3:36 a.m. 🔄 Last Modified: April 8, 2026, 7:33 p.m.

6.4

CVSS3.1

CVE-2026-3513 - TableOn – WordPress Posts Table Filterable <= 1.0.4.4 - Authenticated (Contributor+) Stored Cross-S…

The TableOn – WordPress Posts Table Filterable plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'tableon_button' shortcode in all versions up to and including 1.0.4.4. This is due to insufficient input sanitization and output escaping on user-supplied shortcode attributes s…

📅 Published: April 8, 2026, 3:36 a.m. 🔄 Last Modified: April 8, 2026, 7:44 p.m.

9.8

CVSS3.1

CVE-2026-4003 - Users manager – PN <= 1.1.15 - Unauthenticated Privilege Escalation via Account Takeover via 'users…

The Users manager – PN plugin for WordPress is vulnerable to Privilege Escalation via Arbitrary User Meta Update in all versions up to and including 1.1.15. This is due to a flawed authorization logic check in the userspn_ajax_nopriv_server() function within the 'userspn_form_save' case. The condit…

📅 Published: April 8, 2026, 3:36 a.m. 🔄 Last Modified: April 8, 2026, 7:33 p.m.
Total resulsts: 344009
Page 100 of 34,401
« previous page » next page
Filters