7.2

CVSS3.1

CVE-2026-3643 - Accessibly <= 3.0.3 - Missing Authorization to Unauthenticated Stored Cross-Site Scripting via Widg…

The Accessibly plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the REST API in all versions up to, and including, 3.0.3. The plugin registers REST API endpoints at `/otm-ac/v1/update-widget-options` and `/otm-ac/v1/update-app-config` with the `permission_callback` set to `__re…

📅 Published: April 15, 2026, 8:28 a.m. 🔄 Last Modified: April 15, 2026, 8:28 a.m.

6.4

CVSS3.1

CVE-2026-4011 - Power Charts <= 0.1.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'id' Shortcode…

The Power Charts Lite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'id' parameter of the [pc] shortcode in all versions up to, and including, 0.1.0. This is due to insufficient input sanitization and output escaping on the 'id' shortcode attribute. Specifically, in the …

📅 Published: April 15, 2026, 8:28 a.m. 🔄 Last Modified: April 15, 2026, 8:28 a.m.

6.4

CVSS3.1

CVE-2026-3998 - WM JqMath <= 1.3 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'style' Shortcode A…

The WM JqMath plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'style' shortcode attribute of the [jqmath] shortcode in all versions up to and including 1.3. This is due to insufficient input sanitization and output escaping on user-supplied shortcode attributes. The genera…

📅 Published: April 15, 2026, 8:28 a.m. 🔄 Last Modified: April 15, 2026, 8:28 a.m.

5.3

CVSS3.1

CVE-2026-1782 - MetForm Pro <= 3.9.7 - Unauthenticated Payment Amount Manipulation via 'mf-calculation'

The MetForm Pro plugin for WordPress is vulnerable to Improper Input Validation in all versions up to, and including, 3.9.7 This is due to the payment integrations (Stripe/PayPal) trusting a user-submitted calculation field value without recomputing or validating it against the configured form pri…

📅 Published: April 15, 2026, 8:28 a.m. 🔄 Last Modified: April 15, 2026, 8:28 a.m.

5.3

CVSS3.1

CVE-2026-3649 - Katalogportal-pdf-sync Widget <= 1.0.0 - Missing Authorization to Authenticated (Subscriber+) Infor…

The Katalogportal PDF Sync plugin for WordPress is vulnerable to Missing Authorization in all versions up to and including 1.0.0. The katalogportal_popup_shortcode() function is registered as an AJAX handler via wp_ajax_katalogportal_shortcodePrinter but lacks any capability check (current_user_can…

📅 Published: April 15, 2026, 8:28 a.m. 🔄 Last Modified: April 15, 2026, 8:28 a.m.

6.1

CVSS3.1

CVE-2026-4091 - OPEN-BRAIN <= 0.5.0 - Cross-Site Request Forgery

The OPEN-BRAIN plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 0.5.0. This is due to missing nonce verification on the settings form in the func_page_main() function. This makes it possible for unauthenticated attackers to inject malicious web …

📅 Published: April 15, 2026, 8:28 a.m. 🔄 Last Modified: April 15, 2026, 8:28 a.m.

9.8

CVSS3.1

CVE-2026-3461 - Visa Acceptance Solutions <= 2.1.0 - Unauthenticated Authentication Bypass via Billing Email

The Visa Acceptance Solutions plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 2.1.0. This is due to the `express_pay_product_page_pay_for_order()` function logging users in based solely on a user-supplied billing email address during guest checkout …

📅 Published: April 15, 2026, 8:28 a.m. 🔄 Last Modified: April 15, 2026, 8:28 a.m.

5.3

CVSS3.1

CVE-2026-3642 - e-shot <= 1.0.2 - Missing Authorization to Authenticated (Subscriber+) Form Settings Modification v…

The e-shot™ form builder plugin for WordPress is vulnerable to Missing Authorization in all versions up to and including 1.0.2. The eshot_form_builder_update_field_data() AJAX handler lacks any capability checks (current_user_can()) or nonce verification (check_ajax_referer()/wp_verify_nonce()). Th…

📅 Published: April 15, 2026, 8:28 a.m. 🔄 Last Modified: April 16, 2026, 1:39 p.m.

6.4

CVSS3.1

CVE-2026-4005 - Coachific Shortcode <= 1.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'userhash…

The Coachific Shortcode plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'userhash' shortcode attribute in all versions up to and including 1.0. This is due to insufficient input sanitization and output escaping. The plugin uses sanitize_text_field() on the 'userhash' param…

📅 Published: April 15, 2026, 8:28 a.m. 🔄 Last Modified: April 16, 2026, 1:39 p.m.

4.3

CVSS3.1

CVE-2026-4002 - Petje.af <= 2.1.8 - Cross-Site Request Forgery to Account Deletion via 'petjeaf_disconnect' AJAX Ac…

The Petje.af plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to and including 2.1.8. This is due to missing nonce validation in the ajax_revoke_token() function which handles the 'petjeaf_disconnect' AJAX action. The function performs destructive operations inclu…

📅 Published: April 15, 2026, 8:28 a.m. 🔄 Last Modified: April 15, 2026, 8:28 a.m.
Total resulsts: 345132
Page 47 of 34,514
« previous page » next page
Filters