5.3

CVSS3.1

CVE-2026-3594 - Riaxe Product Customizer <= 2.4 - Unauthenticated Sensitive Information Disclosure via '/orders' REโ€ฆ

The Riaxe Product Customizer plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.4 via the '/wp-json/InkXEProductDesignerLite/orders' REST API endpoint. The endpoint is registered with 'permission_callback' set to '__return_true', meaning no โ€ฆ

๐Ÿ“… Published: April 8, 2026, 6:43 a.m. ๐Ÿ”„ Last Modified: April 8, 2026, 6:43 a.m.

0.0

CVE-2026-4338 - ActivityPub Routing < 8.0.2 - Unauthenticated Drafts/Scheduled/Pending Posts Disclosure

The ActivityPub WordPress plugin before 8.0.2 does not properly filter posts to be displayed, allowed unauthenticated users to access drafts/scheduled/pending posts

๐Ÿ“… Published: April 8, 2026, 6 a.m. ๐Ÿ”„ Last Modified: April 8, 2026, 6 a.m.

0.0

CVE-2026-5083 - Ado::Sessions versions through 0.935 for Perl generates insecure session ids

Ado::Sessions versions through 0.935 for Perl generates insecure session ids. The session id is generated from a SHA-1 hash seeded with the built-in rand function, the epoch time, and the PID. The PID will come from a small set of numbers, and the epoch time may be guessed, if it is not leaked froโ€ฆ

๐Ÿ“… Published: April 8, 2026, 5:53 a.m. ๐Ÿ”„ Last Modified: April 8, 2026, 5:53 a.m.

0.0

CVE-2026-5082 - Amon2::Plugin::Web::CSRFDefender versions from 7.00 through 7.03 for Perl generate an insecure sessโ€ฆ

Amon2::Plugin::Web::CSRFDefender versions from 7.00 through 7.03 for Perl generate an insecure session id. The generate_session_id function will attempt to read bytes from the /dev/urandom device, but if that is unavailable then it generates bytes using SHA-1 hash seeded with the built-in rand() fโ€ฆ

๐Ÿ“… Published: April 8, 2026, 5:48 a.m. ๐Ÿ”„ Last Modified: April 8, 2026, 5:48 a.m.

6.4

CVSS3.1

CVE-2026-3311 - The Plus Addons for Elementor โ€“ Addons for Elementor, Page Templates, Widgets, Mega Menu, WooCommerโ€ฆ

The The Plus Addons for Elementor โ€“ Addons for Elementor, Page Templates, Widgets, Mega Menu, WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Progress Bar shortcode in all versions up to, and including, 6.4.9 due to insufficient input sanitization and โ€ฆ

๐Ÿ“… Published: April 8, 2026, 5:28 a.m. ๐Ÿ”„ Last Modified: April 8, 2026, 5:28 a.m.

5.1

CVSS4.0

CVE-2026-27787 -

Cross-site scripting vulnerability exists in MATCHA SNS 1.3.9 and earlier. If this vulnerability is exploited, an arbitrary script may be executed on the web browser of the user who accessed the website using the product.

๐Ÿ“… Published: April 8, 2026, 5:11 a.m. ๐Ÿ”„ Last Modified: April 8, 2026, 5:11 a.m.

5.1

CVSS4.0

CVE-2026-33273 -

Unrestricted upload of file with dangerous type issue exists in MATCHA INVOICE 2.6.6 and earlier. If this vulnerability is exploited, an arbitrary file may be created by an administrator of the product. As a result, arbitrary code may be executed on the server.

๐Ÿ“… Published: April 8, 2026, 5:11 a.m. ๐Ÿ”„ Last Modified: April 8, 2026, 5:11 a.m.

8.7

CVSS4.0

CVE-2026-24913 -

SQL Injection vulnerability exists in MATCHA INVOICE 2.6.6 and earlier. If this vulnerability is exploited, information stored in the database may be obtained or altered by a user who can log in to the product.

๐Ÿ“… Published: April 8, 2026, 5:10 a.m. ๐Ÿ”„ Last Modified: April 8, 2026, 5:10 a.m.

6.4

CVSS3.1

CVE-2026-3239 - Strong Testimonials <= 3.2.21 - Authenticated (Contributor+) Stored Cross-Site Scripting via testimโ€ฆ

The Strong Testimonials plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's testimonial_view shortcode in all versions up to, and including, 3.2.21 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for autheโ€ฆ

๐Ÿ“… Published: April 8, 2026, 4:27 a.m. ๐Ÿ”„ Last Modified: April 8, 2026, 4:27 a.m.

6.4

CVSS3.1

CVE-2026-3600 - Investi <= 1.0.26 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'maximum-num-yearsโ€ฆ

The Investi plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'investi-announcements-accordion' shortcode's 'maximum-num-years' attribute in all versions up to, and including, 1.0.26. This is due to insufficient input sanitization and output escaping on user-supplied shortcoโ€ฆ

๐Ÿ“… Published: April 8, 2026, 4:27 a.m. ๐Ÿ”„ Last Modified: April 8, 2026, 4:27 a.m.
Total resulsts: 343048
Page 21 of 34,305
ยซ previous page ยป next page
Filters