6.4

CVSS3.1

CVE-2026-2437 - WP Travel Engine - Travel and Tour Booking Plugin <= 6.7.5 - Authenticated (Contributor+) Stored Cr…

The WP Travel Engine – Tour Booking Plugin – Tour Operator Software plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'wte_trip_tax' shortcode in all versions up to, and including, 6.7.5 due to insufficient input sanitization and output escaping on user supplied att…

📅 Published: April 4, 2026, 8:25 a.m. 🔄 Last Modified: April 24, 2026, 6:13 p.m.

7.2

CVSS3.1

CVE-2026-5425 - Widgets for Social Photo Feed <= 1.7.9 - Unauthenticated Stored Cross-Site Scripting via feed_data

The Widgets for Social Photo Feed plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'feed_data' parameter keys in all versions up to, and including, 1.7.9 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inje…

📅 Published: April 4, 2026, 8:25 a.m. 🔄 Last Modified: April 24, 2026, 6:13 p.m.

8.1

CVSS3.1

CVE-2026-4896 - WCFM - WooCommerce Frontend Manager <= 6.7.25 - Insecure Direct Object References to Autenticated (…

The WCFM – Frontend Manager for WooCommerce along with Bookings Subscription Listings Compatible plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 6.7.25 via multiple AJAX actions including `wcfm_modify_order_status`, `delete_wcfm_article`,…

📅 Published: April 4, 2026, 7:42 a.m. 🔄 Last Modified: April 24, 2026, 6:13 p.m.

6.4

CVSS3.1

CVE-2025-13368 - Xpro Addons — 140+ Widgets for Elementor <= 1.4.20 - Authenticated (Contributor+) Stored Cross-Site…

The Xpro Addons — 140+ Widgets for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Pricing Widget's 'onClick Event' setting in all versions up to, and including, 1.4.20 due to insufficient input sanitization and output escaping. This makes it possible for authent…

📅 Published: April 4, 2026, 7:41 a.m. 🔄 Last Modified: April 24, 2026, 6:13 p.m.

6.4

CVSS3.1

CVE-2026-0552 - Simple Shopping Cart <= 5.2.4 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'wpsc_…

The Simple Shopping Cart plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'wpsc_display_product' shortcode in all versions up to, and including, 5.2.4 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for…

📅 Published: April 4, 2026, 7:41 a.m. 🔄 Last Modified: April 24, 2026, 6:13 p.m.

6.4

CVSS3.1

CVE-2026-0737 - Shortcodes Ultimate <= 7.4.7 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'su_lig…

The WP Shortcodes Plugin - Shortcodes Ultimate plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 7.4.7. This is due to insufficient input sanitization and output escaping in the 'src' attribute of the su_lightbox shortcode. This makes it possibl…

📅 Published: April 4, 2026, 7:41 a.m. 🔄 Last Modified: April 24, 2026, 6:13 p.m.

6.4

CVSS3.1

CVE-2026-0738 - Shortcodes Ultimate <= 7.4.8 - authenticated (Contributor+) Stored Cross-Site Scripting via 'su_car…

The WP Shortcodes Plugin - Shortcodes Ultimate plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the su_carousel shortcode in all versions up to, and including, 7.4.8. This is due to insufficient input sanitization and output escaping in the 'su_slide_link' attachment meta field…

📅 Published: April 4, 2026, 7:41 a.m. 🔄 Last Modified: April 24, 2026, 6:13 p.m.

6.4

CVSS3.1

CVE-2026-2600 - ElementsKit Elementor Addons and Templates <= 3.7.9 - Authenticated (Contributor+) Stored Cross-Sit…

The ElementsKit Elementor Addons and Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'ekit_tab_title' parameter in the Simple Tab widget in all versions up to, and including, 3.7.9 due to insufficient input sanitization and output escaping on user supplied attrib…

📅 Published: April 4, 2026, 7:41 a.m. 🔄 Last Modified: April 24, 2026, 6:13 p.m.

6.4

CVSS3.1

CVE-2026-0664 - Royal Elementor Addons <= 1.7.1049 - Authenticated (Contributor+) Stored Cross-Site Scripting via R…

The Royal Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'button_text' parameter in all versions up to, and including, 1.7.1049 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contri…

📅 Published: April 4, 2026, 7:41 a.m. 🔄 Last Modified: April 24, 2026, 6:13 p.m.

6.4

CVSS3.1

CVE-2025-15064 - Ultimate Member <= 2.11.1 - Authenticated (Subscriber+) Stored Cross-Site Scripting via DOM Gadgets

The Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the user description field in all versions up to, and including, 2.11.1 due to insufficient input sanitization and…

📅 Published: April 4, 2026, 7:41 a.m. 🔄 Last Modified: April 24, 2026, 6:13 p.m.
Total resulsts: 349182
Page 693 of 34,919
« previous page » next page
Filters