6.4

CVSS3.1

CVE-2026-4278 - Simple Download Counter <= 2.3 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'text…

The Simple Download Counter plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'sdc_menu' shortcode in all versions up to, and including, 2.3. This is due to insufficient input sanitization and output escaping on user-supplied shortcode attributes, specifically the 'text' and…

📅 Published: March 26, 2026, 3:37 a.m. 🔄 Last Modified: April 24, 2026, 4:35 p.m.

7.2

CVSS3.1

CVE-2026-4329 - Blackhole for Bad Bots <= 3.8 - Unauthenticated Stored Cross-Site Scripting via User-Agent HTTP Hea…

The Blackhole for Bad Bots plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the User-Agent HTTP header in all versions up to and including 3.8. This is due to insufficient input sanitization and output escaping. The plugin uses sanitize_text_field() when capturing bot data (whi…

📅 Published: March 26, 2026, 3:37 a.m. 🔄 Last Modified: April 24, 2026, 4:35 p.m.

5.3

CVSS3.1

CVE-2026-4281 - FormLift for Infusionsoft Web Forms <= 7.5.21 - Missing Authorization to Unauthenticated Infusionso…

The FormLift for Infusionsoft Web Forms plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 7.5.21. This is due to missing capability checks on the connect() and listen_for_tokens() methods of the FormLift_Infusionsoft_Manager class, both of which are h…

📅 Published: March 26, 2026, 3:37 a.m. 🔄 Last Modified: April 24, 2026, 4:35 p.m.

8.8

CVSS3.1

CVE-2026-2931 - Amelia Booking <= 9.1.2 - Authenticated (Customer+) Insecure Direct Object Reference to Arbitrary U…

The Amelia Booking plugin for WordPress is vulnerable to Insecure Direct Object References in versions up to, and including, 9.1.2. This is due to the plugin providing user-controlled access to objects, letting a user bypass authorization and access system resources. This makes it possible for auth…

📅 Published: March 26, 2026, 3:37 a.m. 🔄 Last Modified: April 24, 2026, 4:35 p.m.

4.3

CVSS3.1

CVE-2026-4331 - Blog2Social: Social Media Auto Post & Scheduler <= 8.8.2 - Missing Authorization to Authenticated (…

The Blog2Social: Social Media Auto Post & Scheduler plugin for WordPress is vulnerable to unauthorized data loss in all versions up to, and including, 8.8.2. This is due to the resetSocialMetaTags() function only verifying that the user has the 'read' capability and a valid b2s_security_nonce, both…

📅 Published: March 26, 2026, 3:37 a.m. 🔄 Last Modified: April 24, 2026, 4:35 p.m.

6.9

CVSS4.0

CVE-2026-4839 - SourceCodester Food Ordering System Parameter purchase.php sql injection

A vulnerability has been found in SourceCodester Food Ordering System 1.0. This affects an unknown function of the file /purchase.php of the component Parameter Handler. The manipulation of the argument custom leads to sql injection. The attack can be initiated remotely. The exploit has been disclo…

📅 Published: March 26, 2026, 3:14 a.m. 🔄 Last Modified: April 24, 2026, 4:35 p.m.

6.9

CVSS4.0

CVE-2026-4838 - SourceCodester Malawi Online Market display.php sql injection

A flaw has been found in SourceCodester Malawi Online Market 1.0. The impacted element is an unknown function of the file /display.php. Executing a manipulation of the argument ID can lead to sql injection. It is possible to launch the attack remotely. The exploit has been published and may be used.

📅 Published: March 26, 2026, 2:31 a.m. 🔄 Last Modified: April 24, 2026, 4:35 p.m.

6.4

CVSS3.1

CVE-2026-4075 - BWL Advanced FAQ Manager Lite <= 1.1.1 - Authenticated (Contributor+) Stored Cross-Site Scripting v…

The BWL Advanced FAQ Manager Lite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'baf_sbox' shortcode in all versions up to and including 1.1.1. This is due to insufficient input sanitization and output escaping on user-supplied shortcode attributes such as 'sbox_id', 'sb…

📅 Published: March 26, 2026, 2:25 a.m. 🔄 Last Modified: April 24, 2026, 4:35 p.m.

6.1

CVSS3.1

CVE-2026-1986 - FloristPress for Woo <= 7.8.2 - Reflected Cross-Site Scripting via 'noresults' Parameter

The FloristPress for Woo – Customize your eCommerce store for your Florist plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'noresults' parameter in all versions up to, and including, 7.8.2 due to insufficient input sanitization and output escaping on the user supplied '…

📅 Published: March 26, 2026, 2:25 a.m. 🔄 Last Modified: April 24, 2026, 4:35 p.m.

5.4

CVSS3.1

CVE-2026-4335 - ShortPixel Image Optimizer <= 6.4.3 - Authenticated (Author+) Stored Cross-Site Scripting via Attac…

The ShortPixel Image Optimizer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the attachment post_title in all versions up to, and including, 6.4.3. This is due to insufficient output escaping in the getEditorPopup() function and its corresponding media-popup.php template. Sp…

📅 Published: March 26, 2026, 2:25 a.m. 🔄 Last Modified: April 24, 2026, 4:35 p.m.
Total resulsts: 349182
Page 867 of 34,919
« previous page » next page
Filters