6.5

CVSS3.1

CVE-2026-24528 - WordPress Nova Blocks plugin <= 2.1.9 - Cross Site Scripting (XSS) vulnerability

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in pixelgrade Nova Blocks nova-blocks allows DOM-Based XSS.This issue affects Nova Blocks: from n/a through <= 2.1.9.

πŸ“… Published: Jan. 23, 2026, 2:28 p.m. πŸ”„ Last Modified: April 16, 2026, 7:45 a.m.

6.5

CVSS3.1

CVE-2026-24526 - WordPress Email Inquiry & Cart Options for WooCommerce plugin <= 3.4.3 - Cross Site Scripting (XSS)…

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Steve Truman Email Inquiry &amp; Cart Options for WooCommerce woocommerce-email-inquiry-cart-options allows DOM-Based XSS.This issue affects Email Inquiry &amp; Cart Options for WooCommerce: from n…

πŸ“… Published: Jan. 23, 2026, 2:28 p.m. πŸ”„ Last Modified: April 24, 2026, 6:17 p.m.

5.3

CVSS3.1

CVE-2026-24525 - WordPress CLP Varnish Cache plugin <= 1.0.2 - Broken Access Control vulnerability

Missing Authorization vulnerability in CloudPanel CLP Varnish Cache clp-varnish-cache allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects CLP Varnish Cache: from n/a through <= 1.0.2.

πŸ“… Published: Jan. 23, 2026, 2:28 p.m. πŸ”„ Last Modified: April 24, 2026, 6:17 p.m.

4.3

CVSS3.1

CVE-2026-24524 - WordPress Tablesome plugin <= 1.2.8 - Broken Access Control vulnerability

Missing Authorization vulnerability in Essekia Tablesome tablesome allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Tablesome: from n/a through <= 1.2.8.

πŸ“… Published: Jan. 23, 2026, 2:28 p.m. πŸ”„ Last Modified: April 24, 2026, 6:17 p.m.

5.3

CVSS3.1

CVE-2026-24523 - WordPress WP FullCalendar plugin <= 1.6 - Sensitive Data Exposure vulnerability

Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Marcus (aka @msykes) WP FullCalendar wp-fullcalendar allows Retrieve Embedded Sensitive Data.This issue affects WP FullCalendar: from n/a through <= 1.6.

πŸ“… Published: Jan. 23, 2026, 2:28 p.m. πŸ”„ Last Modified: April 24, 2026, 6:17 p.m.

4.3

CVSS3.1

CVE-2026-24522 - WordPress WP Subscribe plugin <= 1.2.16 - Broken Access Control vulnerability

Missing Authorization vulnerability in MyThemeShop WP Subscribe wp-subscribe allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP Subscribe: from n/a through <= 1.2.16.

πŸ“… Published: Jan. 23, 2026, 2:28 p.m. πŸ”„ Last Modified: April 24, 2026, 6:17 p.m.

4.3

CVSS3.1

CVE-2026-24521 - WordPress Kama Thumbnail plugin <= 3.5.1 - Cross Site Request Forgery (CSRF) vulnerability

Cross-Site Request Forgery (CSRF) vulnerability in Timur Kamaev Kama Thumbnail kama-thumbnail allows Cross Site Request Forgery.This issue affects Kama Thumbnail: from n/a through <= 3.5.1.

πŸ“… Published: Jan. 23, 2026, 2:28 p.m. πŸ”„ Last Modified: April 16, 2026, 7:45 a.m.

4.3

CVSS3.1

CVE-2025-13921 - weDocs <= 2.1.16 - Missing Authorization to Authenticated (Subscriber+) Documentation Post Update

The weDocs: AI Powered Knowledge Base, Docs, Documentation, Wiki & AI Chatbot plugin for WordPress is vulnerable to unauthorized modification or loss of data due to a missing capability check on the 'wedocs_user_documentation_handling_capabilities' function in all versions up to, and including, 2.1…

πŸ“… Published: Jan. 23, 2026, 1:24 p.m. πŸ”„ Last Modified: April 21, 2026, 12:30 a.m.

6.4

CVSS3.1

CVE-2026-0914 - WP DSGVO Tools (GDPR) <= 3.1.36 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'lw_…

The WP DSGVO Tools (GDPR) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'lw_content_block' shortcode in all versions up to, and including, 3.1.36 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for a…

πŸ“… Published: Jan. 23, 2026, 12:26 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

8.8

CVSS3.1

CVE-2025-14866 - Melapress Role Editor <= 1.1.1 - Improper Authorization to Authenticated (Subscriber+) Privilege Es…

The Melapress Role Editor plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.1.1. This is due to a misconfigured capability check on the 'save_secondary_roles_field' function. This makes it possible for authenticated attackers, with Subscriber-level a…

πŸ“… Published: Jan. 23, 2026, 12:26 p.m. πŸ”„ Last Modified: April 22, 2026, 8:15 p.m.
Total resulsts: 346618
Page 1720 of 34,662
Β« previous page Β» next page
Filters