4.3

CVSS3.1

CVE-2026-4118 - Call To Action Plugin <= 3.1.3 - Cross-Site Request Forgery via Settings Update

The Call To Action Plugin plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.1.3. This is due to missing nonce validation in the cbox_options_page() function which handles saving, creating, and deleting plugin settings. The form rendered on the …

📅 Published: April 22, 2026, 7:45 a.m. 🔄 Last Modified: April 22, 2026, 8:22 p.m.

4.3

CVSS3.1

CVE-2026-4139 - mCatFilter <= 0.5.2 - Cross-Site Request Forgery via compute_post() Function

The mCatFilter plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to and including 0.5.2. This is due to the complete absence of nonce verification and capability checks in the compute_post() function, which processes settings updates. The compute_post() function is…

📅 Published: April 22, 2026, 7:45 a.m. 🔄 Last Modified: April 22, 2026, 8:22 p.m.

6.4

CVSS3.1

CVE-2026-4125 - WPMK Block <= 1.0.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode Attrib…

The WPMK Block plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'class' shortcode attribute in all versions up to and including 1.0.1. This is due to insufficient input sanitization and output escaping on user-supplied shortcode attributes. Specifically, in the wpmk_block_s…

📅 Published: April 22, 2026, 7:45 a.m. 🔄 Last Modified: April 22, 2026, 8:22 p.m.

4.3

CVSS3.1

CVE-2026-4128 - TP Restore Categories And Taxonomies <= 1.0.1 - Missing Authorization to Authenticated (Subscriber+…

The TP Restore Categories And Taxonomies plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 1.0.1. The delete_term() function, which handles the 'tpmcattt_delete_term' AJAX action, does not perform any capability check (e.g., current_user_can()) to ver…

📅 Published: April 22, 2026, 7:45 a.m. 🔄 Last Modified: April 22, 2026, 8:22 p.m.

6.4

CVSS3.1

CVE-2026-5767 - SlideShowPro SC <= 1.0.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'album' Sho…

The SlideShowPro SC plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's `slideShowProSC` shortcode in all versions up to, and including, 1.0.2 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authentica…

📅 Published: April 22, 2026, 7:45 a.m. 🔄 Last Modified: April 22, 2026, 12:13 p.m.

6.4

CVSS3.1

CVE-2026-4089 - Twittee Text Tweet <= 1.0.8 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'id' Sho…

The Twittee Text Tweet plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'id' shortcode attribute in all versions up to and including 1.0.8. This is due to insufficient input sanitization and output escaping on user-supplied shortcode attributes. The ttt_twittee_tweeter() fu…

📅 Published: April 22, 2026, 7:45 a.m. 🔄 Last Modified: April 22, 2026, 8:22 p.m.

4.4

CVSS3.1

CVE-2026-3362 - Short Comment Filter <= 2.2 - Authenticated (Administrator+) Stored Cross-Site Scripting via 'Minim…

The Short Comment Filter plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'Minimum Count' settings field in all versions up to and including 2.2. This is due to insufficient input sanitization (no sanitize callback on register_setting) and missing output escaping (no esc_at…

📅 Published: April 22, 2026, 7:45 a.m. 🔄 Last Modified: April 22, 2026, 8:22 p.m.

4.3

CVSS3.1

CVE-2026-6396 - Fast & Fancy Filter – 3F <= 1.2.2 - Cross-Site Request Forgery to Settings Modification via fff_sav…

The Fast & Fancy Filter – 3F plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to and including 1.2.2. This is due to missing nonce verification in the saveFields() function, which handles the fff_save_settins AJAX action. This makes it possible for unauthenticated att…

📅 Published: April 22, 2026, 7:45 a.m. 🔄 Last Modified: April 22, 2026, 1:02 p.m.

6.5

CVSS3.1

CVE-2026-4280 - Breaking News WP <= 1.3 - Missing Authorization to Authenticated (Subscriber+) Local File Inclusion…

The Breaking News WP plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1.3. This is due to the brnwp_ajax_form AJAX endpoint lacking both authorization checks and CSRF verification, combined with insufficient path validation when the brnwp_theme option…

📅 Published: April 22, 2026, 7:45 a.m. 🔄 Last Modified: April 23, 2026, 1:44 p.m.

4.3

CVSS3.1

CVE-2026-4140 - Ni WooCommerce Order Export <= 3.1.6 - Cross-Site Request Forgery to Settings Update via ni_order_e…

The Ni WooCommerce Order Export plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to and including 3.1.6. This is due to missing nonce validation in the ni_order_export_action() AJAX handler function. The handler processes settings updates when the 'page' parameter…

📅 Published: April 22, 2026, 7:45 a.m. 🔄 Last Modified: April 22, 2026, 8:22 p.m.
Total resulsts: 346515
Page 64 of 34,652
« previous page » next page
Filters