5.3

CVSS3.1

CVE-2026-1303 - MailChimp Campaigns <= 3.2.4 - Missing Authorization to Authenticated (Subscriber+) MailChimp App D…

The MailChimp Campaigns plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 3.2.4. This is due to missing capability checks on the `mailchimp_campaigns_manager_disconnect_app` function that is hooked to the AJAX action of the same name. This makes it po…

📅 Published: Feb. 14, 2026, 6:42 a.m. 🔄 Last Modified: April 15, 2026, 6:30 p.m.

6.4

CVSS3.1

CVE-2026-1910 - UpMenu <= 3.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'upmenu-menu' Shortcod…

The UpMenu – Online ordering for restaurants plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'lang' attribute of the 'upmenu-menu' shortcode in all versions up to, and including, 3.1. This is due to insufficient input sanitization and output escaping on user supplied attri…

📅 Published: Feb. 14, 2026, 6:42 a.m. 🔄 Last Modified: April 15, 2026, 5:30 p.m.

4.4

CVSS3.1

CVE-2026-0693 - Allow HTML in Category Descriptions <= 1.2.4 - Authenticated (Administrator+) Stored Cross-Site Scr…

The Allow HTML in Category Descriptions plugin for WordPress is vulnerable to Stored Cross-Site Scripting via category descriptions in all versions up to, and including, 1.2.4. This is due to the plugin unconditionally removing the `wp_kses_data` output filter for term_description, link_description…

📅 Published: Feb. 14, 2026, 6:42 a.m. 🔄 Last Modified: April 15, 2026, 6:30 p.m.

6.4

CVSS3.1

CVE-2026-1096 - Best-wp-google-map <= 2.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'latitude'…

The Best-wp-google-map plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'latitude' and 'longitudinal' parameters of the 'google_map_view' shortcode in all versions up to, and including, 2.1 due to insufficient input sanitization and output escaping. This makes it possible f…

📅 Published: Feb. 14, 2026, 6:42 a.m. 🔄 Last Modified: April 15, 2026, 6:30 p.m.

6.4

CVSS3.1

CVE-2026-0559 - MasterStudy LMS WordPress Plugin – for Online Courses and Education <= 3.7.11 - Authenticated (Cont…

The MasterStudy LMS WordPress Plugin – for Online Courses and Education plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'stm_lms_courses_grid_display' shortcode in all versions up to, and including, 3.7.11 due to insufficient input sanitization and output escaping…

📅 Published: Feb. 14, 2026, 6:42 a.m. 🔄 Last Modified: April 16, 2026, 7 a.m.

4.3

CVSS3.1

CVE-2026-1394 - WP Quick Contact Us <= 1.0 - Cross-Site Request Forgery to Settings Update

The WP Quick Contact Us plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0. This is due to missing nonce validation on the settings update functionality. This makes it possible for unauthenticated attackers to update the plugin's settings via …

📅 Published: Feb. 14, 2026, 6:42 a.m. 🔄 Last Modified: April 15, 2026, 5:30 p.m.

6.4

CVSS3.1

CVE-2026-1905 - Sphere Manager <= 1.0.2 - Authenticated (Contributor+) Cross-Site Scripting via 'width' Shortcode A…

The Sphere Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'width' parameter in the 'show_sphere_image' shortcode in all versions up to, and including, 1.0.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attack…

📅 Published: Feb. 14, 2026, 6:42 a.m. 🔄 Last Modified: April 15, 2026, 6:30 p.m.

4.3

CVSS3.1

CVE-2025-14852 - MDirector Newsletter <= 4.5.8 - Cross-Site Request Forgery to Plugin Settings Update

The MDirector Newsletter plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 4.5.8. This is due to missing nonce verification on the mdirectorNewsletterSave function. This makes it possible for unauthenticated attackers to update the plugin's setti…

📅 Published: Feb. 14, 2026, 6:42 a.m. 🔄 Last Modified: April 21, 2026, 4:15 p.m.

5.3

CVSS3.1

CVE-2026-1944 - CallbackKiller service widget <= 1.2 - Missing Authorization to Unauthenticated Arbitrary Plugin Se…

The CallbackKiller service widget plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the cbk_save() function in all versions up to, and including, 1.2. This makes it possible for unauthenticated attackers to modify the plugin's site ID setti…

📅 Published: Feb. 14, 2026, 6:42 a.m. 🔄 Last Modified: April 15, 2026, 6:30 p.m.

6.4

CVSS3.1

CVE-2026-0557 - WP Data Access <= 5.5.63 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'wpda_app' …

The WP Data Access plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'wpda_app' shortcode in all versions up to, and including, 5.5.63 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated at…

📅 Published: Feb. 14, 2026, 6:42 a.m. 🔄 Last Modified: April 15, 2026, 6:30 p.m.
Total resulsts: 349182
Page 1630 of 34,919
« previous page » next page
Filters