4.9

CVSS3.1

CVE-2026-1370 - SIBS - WooCommerce <= 2.2.0 - Authenticated (Admin+) SQL Injection via 'referencedId' Parameter

The SIBS woocommerce payment gateway plugin for WordPress is vulnerable to time-based SQL Injection via the ‘referencedId’ parameter in all versions up to, and including, 2.2.0 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. …

📅 Published: Feb. 4, 2026, 8:25 a.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

4.4

CVSS3.1

CVE-2026-0743 - WP Content Permission <= 1.2 - Authenticated (Administrator+) Stored Cross-Site Scripting via 'ohme…

The WP Content Permission plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'ohmem-message' parameter in all versions up to, and including, 1.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Administrator-…

📅 Published: Feb. 4, 2026, 8:25 a.m. 🔄 Last Modified: April 15, 2026, 9:30 p.m.

6.4

CVSS3.1

CVE-2026-0742 - Smart Appointment & Booking <= 1.0.7 - Authenticated (Subscriber+) Stored Cross-Site Scripting via …

The Smart Appointment & Booking plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the saab_save_form_data AJAX action in all versions up to, and including, 1.0.7 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for au…

📅 Published: Feb. 4, 2026, 8:25 a.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

5.3

CVSS3.1

CVE-2026-0679 - Fortis for WooCommerce <= 1.2.0 - Missing Authorization to Unauthenticated Arbitrary Order Status U…

The Fortis for WooCommerce plugin for WordPress is vulnerable to authorization bypass due to an inverted nonce check in the 'check_fortis_notify_response' function in all versions up to, and including, 1.2.0. This makes it possible for unauthenticated attackers to update arbitrary WooCommerce order…

📅 Published: Feb. 4, 2026, 8:25 a.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

5.3

CVSS3.1

CVE-2025-15508 - Magic Import Document Extractor <= 1.0.6 - Unauthenticated Sensitive Information Exposure

The Magic Import Document Extractor plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.0.4 via the get_frontend_settings() function. This makes it possible for unauthenticated attackers to extract the site's magicimport.ai license key from t…

📅 Published: Feb. 4, 2026, 8:25 a.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

6.5

CVSS3.1

CVE-2026-0572 - WebPurify Profanity Filter <= 4.0.2 - Missing Authorization to Unauthenticated Plugin Settings Chan…

The WebPurify Profanity Filter plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'webpurify_save_options' function in all versions up to, and including, 4.0.2. This makes it possible for unauthenticated attackers to change plugin settin…

📅 Published: Feb. 4, 2026, 8:25 a.m. 🔄 Last Modified: April 15, 2026, 9:30 p.m.

5.3

CVSS3.1

CVE-2025-15507 - Magic Import Document Extractor <= 1.0.5 - Missing Authorization to Unauthenticated Plugin License …

The Magic Import Document Extractor plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the ajax_sync_usage() function in all versions up to, and including, 1.0.5. This makes it possible for unauthenticated attackers to modify the plugin's li…

📅 Published: Feb. 4, 2026, 8:25 a.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

7.5

CVSS3.1

CVE-2025-15268 - Infility Global <= 2.14.46 - Unauthenticated SQL Injection via Predictable API Key and IP Whitelist…

The Infility Global plugin for WordPress is vulnerable to unauthenticated SQL Injection via the 'infility_get_data' API action in all versions up to, and including, 2.14.46. This is due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL qu…

📅 Published: Feb. 4, 2026, 8:25 a.m. 🔄 Last Modified: April 22, 2026, midnight

4.4

CVSS3.1

CVE-2026-0681 - Extended Random Number Generator <= 1.1 - Authenticated (Administrator+) Stored Cross-Site Scriptin…

The Extended Random Number Generator plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin settings in all versions up to, and including, 1.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator…

📅 Published: Feb. 4, 2026, 8:25 a.m. 🔄 Last Modified: April 15, 2026, 9:30 p.m.

7.5

CVSS3.1

CVE-2025-15285 - SEO Flow by LupsOnline <= 2.2.1 - Unauthenticated Arbitrary Post/Category Modification

The SEO Flow by LupsOnline plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the checkBlogAuthentication() and checkCategoryAuthentication() functions in all versions up to, and including, 2.2.1. These authorization functions only implement…

📅 Published: Feb. 4, 2026, 8:25 a.m. 🔄 Last Modified: April 22, 2026, midnight
Total resulsts: 347939
Page 1682 of 34,794
« previous page » next page
Filters