7.2

CVSS3.1

CVE-2026-4803 - Royal Addons for Elementor <= 1.7.1056 - Unauthenticated Stored Cross-Site Scripting via 'status' P…

The Royal Elementor Addons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'status' parameter in the wpr_update_form_action_meta AJAX action in all versions up to, and including, 1.7.1056. This is due to insufficient input sanitization and output escaping, combined with a …

📅 Published: May 5, 2026, 3:37 a.m. 🔄 Last Modified: May 5, 2026, 3:37 a.m.

6.5

CVSS3.1

CVE-2026-5957 - EmailKit <= 1.6.5 - Authenticated (Author+) Arbitrary File Read via 'emailkit-editor-template' REST…

The EmailKit plugin for WordPress is vulnerable to Arbitrary File Read in all versions up to and including 1.6.5. This is due to a flawed path traversal validation in the create_template() method of the CheckForm class, where realpath() is called on the allowed base directory (wp-content/uploads/em…

📅 Published: May 5, 2026, 3:37 a.m. 🔄 Last Modified: May 6, 2026, 2:05 p.m.

6.4

CVSS3.1

CVE-2026-2948 - Gutenverse – Ultimate WordPress FSE Blocks Addons & Ecosystem <= 3.5.3 - Authenticated (Contributor…

The Gutenverse – Ultimate WordPress FSE Blocks Addons & Ecosystem plugin for WordPress is vulnerable to Server-Side Request Forgery in versions up to, and including, 3.5.3 via the import_images() function. This makes it possible for authenticated attackers, with contributor-level access and above, …

📅 Published: May 5, 2026, 3:37 a.m. 🔄 Last Modified: May 6, 2026, 2:04 p.m.

9.8

CVSS3.1

CVE-2026-5294 - GeekyBot <= 1.2.2 - Missing Authorization to Unauthenticated Arbitrary Plugin Installation via 'gee…

The Geeky Bot plugin for WordPress is vulnerable to Missing Authorization in versions up to, and including, 1.2.2. This is due to a nopriv AJAX route allowing attacker-controlled model/function dispatch and reaching a plugin installer helper that downloads and unzips attacker-supplied ZIP files int…

📅 Published: May 5, 2026, 3:37 a.m. 🔄 Last Modified: May 6, 2026, 9:21 a.m.

7.5

CVSS3.1

CVE-2026-3456 - GeekyBot — Generate AI Content Without Prompt, Chatbot and Lead Generation <= 1.2.0 - Unauthenticat…

The GeekyBot — Generate AI Content Without Prompt, Chatbot and Lead Generation plugin for WordPress is vulnerable to SQL Injection via the 'attributekey' parameter in versions up to, and including, 1.2.0 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation …

📅 Published: May 5, 2026, 3:37 a.m. 🔄 Last Modified: May 6, 2026, 9:22 a.m.

8.7

CVSS3.1

CVE-2026-35228 - Unauthenticated Remote SQL Injection in Oracle MCP Server Helper Tool

Vulnerability in the Oracle MCP Server Helper Tool product of Oracle Open Source Projects (component: helper tool). The supported versions that is affected is 1.0.1-1.0.156. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle MCP Server…

📅 Published: May 5, 2026, 3:24 a.m. 🔄 Last Modified: May 6, 2026, 9:22 a.m.

4.9

CVSS3.1

CVE-2026-1921 - Loco Translate <= 2.8.2 - Authenticated (Translator+) Path Traversal to Limited File Read via 'ref'…

The Loco Translate plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 2.8.2 via the `fsReference` AJAX route. This is due to the `findSourceFile()` method normalizing user-supplied `ref` paths containing `../` directory traversal sequences without validating …

📅 Published: May 5, 2026, 2:26 a.m. 🔄 Last Modified: May 5, 2026, 5 a.m.

6.4

CVSS3.1

CVE-2026-5505 - WP-Clippy <= 1.0.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode Attribu…

The WP-Clippy plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's `clippy` shortcode in all versions up to, and including, 1.0.0. This is due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated a…

📅 Published: May 5, 2026, 2:26 a.m. 🔄 Last Modified: May 6, 2026, 9:22 a.m.

6.4

CVSS3.1

CVE-2026-6255 - Simple Owl Shortcodes <= 2.1.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'num'…

The Simple Owl Shortcodes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'num' attribute of the 'owls_wrapper' shortcode in all versions up to, and including, 2.1.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possi…

📅 Published: May 5, 2026, 2:26 a.m. 🔄 Last Modified: May 6, 2026, 9:22 a.m.

6.1

CVSS3.1

CVE-2026-6704 - Blog Settings <= 1.0 - Reflected Cross-Site Scripting via 'page' Parameter

The Blog Settings plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'page' parameter in all versions up to, and including, 1.0. This is due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web…

📅 Published: May 5, 2026, 2:26 a.m. 🔄 Last Modified: May 6, 2026, 9:22 a.m.
Total resulsts: 349182
Page 119 of 34,919
« previous page » next page
Filters