4.4

CVSS3.1

CVE-2026-2282 - Slidorion <= 1.0.2 - Authenticated (Administrator+) Stored Cross-Site Scripting via Slidorion Setti…

The Slidorion plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 1.0.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and abo…

📅 Published: Feb. 19, 2026, 4:36 a.m. 🔄 Last Modified: April 15, 2026, 6:15 p.m.

7.2

CVSS3.1

CVE-2025-12975 - CTX Feed – WooCommerce Product Feed Manager <= 6.6.11 - Missing Authorization to Authenticated (Sho…

The CTX Feed – WooCommerce Product Feed Manager plugin for WordPress is vulnerable to unauthorized arbitrary plugin installation due to a missing capability check on the woo_feed_plugin_installing() function in all versions up to, and including, 6.6.11. This makes it possible for authenticated atta…

📅 Published: Feb. 19, 2026, 4:36 a.m. 🔄 Last Modified: April 21, 2026, 4 p.m.

8.8

CVSS3.1

CVE-2026-0912 - Toret Manager <= 1.2.7 - Authenticated (Subscriber+) Arbitrary Options Update via AJAX actions

The Toret Manager plugin for WordPress is vulnerable to unauthorized modification of data that can lead to privilege escalation due to a missing capability check on the 'trman_save_option' function and on the 'trman_save_option_items' in all versions up to, and including, 1.2.7. This makes it possi…

📅 Published: Feb. 19, 2026, 4:36 a.m. 🔄 Last Modified: April 15, 2026, 8:30 p.m.

6.4

CVSS3.1

CVE-2025-13612 - Album and Image Gallery Plus Lightbox <= 2.1.7 - Authenticated (Contributor+) Stored Cross-Site Scr…

The Album and Image Gallery plus Lightbox plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's `aigpl-gallery-album` shortcode in all versions up to, and including, 2.1.7 due to insufficient input sanitization and output escaping on user supplied attributes. This makes…

📅 Published: Feb. 19, 2026, 4:36 a.m. 🔄 Last Modified: April 21, 2026, 11:45 p.m.

9.8

CVSS3.1

CVE-2026-1405 - Slider Future <= 1.0.5 - Unauthenticated Arbitrary File Upload

The Slider Future plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'slider_future_handle_image_upload' function in all versions up to, and including, 1.0.5. This makes it possible for unauthenticated attackers to upload arbitrary files on the a…

📅 Published: Feb. 19, 2026, 4:36 a.m. 🔄 Last Modified: April 21, 2026, 11:45 p.m.

5.3

CVSS3.1

CVE-2025-13930 - Checkout Field Manager (Checkout Manager) for WooCommerce <= 7.8.5 - Missing Authorization to Unaut…

The Checkout Field Manager (Checkout Manager) for WooCommerce plugin for WordPress is vulnerable to authorization bypass in versions up to, and including, 7.8.5. This is due to the plugin not properly verifying that a user is authorized to delete an attachment combined with flawed guest order owner…

📅 Published: Feb. 19, 2026, 4:36 a.m. 🔄 Last Modified: April 21, 2026, 11:45 p.m.

6.4

CVSS3.1

CVE-2026-1646 - Advance Block Extend <= 1.0.4 - Authenticated (Contributor+) Stored Cross-Site Scripting via TitleC…

The Advance Block Extend plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the TitleColor block attribute in the Latest Posts Gutenberg block in all versions up to, and including, 1.0.4 due to insufficient input sanitization and output escaping. This makes it possible for authen…

📅 Published: Feb. 19, 2026, 4:36 a.m. 🔄 Last Modified: April 15, 2026, 6:15 p.m.

7.2

CVSS3.1

CVE-2025-15041 - BackWPup <= 5.6.2 - Authenticated (BackWPup Helper+) Privilege Escalation via Arbitrary Options Upd…

The BackWPup – WordPress Backup & Restore Plugin plugin for WordPress is vulnerable to unauthorized modification of data that can lead to privilege escalation due to a missing capability check on the save_site_option() function in all versions up to, and including, 5.6.2. This makes it possible for…

📅 Published: Feb. 19, 2026, 4:36 a.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

5.3

CVSS3.1

CVE-2025-14294 - Razorpay for WooCommerce <= 4.7.8 - Missing Authentication to Unauthenticated Order Modification

The Razorpay for WooCommerce plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the getCouponList() function in all versions up to, and including, 4.7.8. This is due to the checkAuthCredentials() permission callback always returning true, pr…

📅 Published: Feb. 19, 2026, 4:36 a.m. 🔄 Last Modified: April 22, 2026, 8 p.m.

4.3

CVSS3.1

CVE-2025-13413 - Country Blocker for AdSense <= 1.0 - Cross-Site Request Forgery to Settings Update

The Country Blocker for AdSense plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0. This is due to missing nonce validation on the CBFA_guardar_cbfa() function. This makes it possible for unauthenticated attackers to update the plugin's settin…

📅 Published: Feb. 19, 2026, 4:36 a.m. 🔄 Last Modified: April 22, 2026, 3:30 p.m.
Total resulsts: 349182
Page 1575 of 34,919
« previous page » next page
Filters