6.5

CVSS3.1

CVE-2026-4004 - Task Manager <= 3.0.2 - Authenticated (Subscriber+) Arbitrary Shortcode Execution via 'task_id' Par…

The Task Manager plugin for WordPress is vulnerable to arbitrary shortcode execution via the 'search' AJAX action in all versions up to, and including, 3.0.2. This is due to missing capability checks in the callback_search() function and insufficient input validation that allows shortcode syntax (s…

📅 Published: March 21, 2026, 3:27 a.m. 🔄 Last Modified: April 24, 2026, 4:27 p.m.

4.4

CVSS3.1

CVE-2026-1278 - Mandatory Field <= 1.6.8 - Authenticated (Administrator+) Stored Cross-Site Scripting via Settings …

The Mandatory Field plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 1.6.8 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions a…

📅 Published: March 21, 2026, 3:27 a.m. 🔄 Last Modified: April 22, 2026, 9:32 p.m.

4.4

CVSS3.1

CVE-2026-2121 - Weaver Show Posts <= 1.8.1 - Authenticated (Administrator+) Stored Cross-Site Scripting via 'Additi…

The Weaver Show Posts plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'add_class' parameter in all versions up to, and including, 1.8.1. This is due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated…

📅 Published: March 21, 2026, 3:27 a.m. 🔄 Last Modified: April 22, 2026, 9:32 p.m.

4.4

CVSS3.1

CVE-2026-2837 - Ricerca – advanced search <= 1.1.12 - Authenticated (Administrator+) Stored Cross-Site Scripting vi…

The Ricerca – advanced search plugin for WordPress is vulnerable to Stored Cross-Site Scripting via plugin's settings in all versions up to, and including, 1.1.12 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level…

📅 Published: March 21, 2026, 3:27 a.m. 🔄 Last Modified: April 24, 2026, 4:27 p.m.

6.4

CVSS3.1

CVE-2026-1397 - PQ Addons – Creative Elementor Widgets <= 1.0.0 - Authenticated (Contributor+) Stored Cross-Site Sc…

The PQ Addons – Creative Elementor Widgets plugin for WordPress is vulnerable to Stored Cross-Site Scripting via widget attributes in all versions up to, and including, 1.0.0 due to insufficient input sanitization and output escaping on the html_tag parameter in the PQ Section Title widget. This ma…

📅 Published: March 21, 2026, 3:27 a.m. 🔄 Last Modified: April 22, 2026, 9:32 p.m.

6.1

CVSS3.1

CVE-2026-2723 - Post Snippits <= 1.0 - Cross-Site Request Forgery to Stored Cross-Site Scripting via Settings Update

The Post Snippits plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0. This is due to missing nonce validation on the settings page handlers for saving, adding, and deleting snippets. This makes it possible for unauthenticated attackers to modi…

📅 Published: March 21, 2026, 3:27 a.m. 🔄 Last Modified: April 24, 2026, 4:27 p.m.

6.4

CVSS3.1

CVE-2026-3997 - Text Toggle <= 1.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'title' Shortcode…

The Text Toggle plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'title' shortcode attribute of the [tt_part] and [tt] shortcodes in all versions up to and including 1.1. This is due to insufficient input sanitization and output escaping on user-supplied shortcode attribute…

📅 Published: March 21, 2026, 3:27 a.m. 🔄 Last Modified: April 24, 2026, 4:27 p.m.

4.4

CVSS3.1

CVE-2026-3354 - Wikilookup <= 1.1.5 - Authenticated (Administrator+) Stored Cross-Site Scripting via 'Popup Width' …

The Wikilookup plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'Popup Width' setting in all versions up to, and including, 1.1.5. This is due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Administrator-leve…

📅 Published: March 21, 2026, 3:27 a.m. 🔄 Last Modified: April 24, 2026, 4:27 p.m.

4.3

CVSS3.1

CVE-2026-4143 - Neos Connector for Fakturama <= 0.0.14 - Cross-Site Request Forgery to Settings Update

The Neos Connector for Fakturama plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to and including 0.0.14. This is due to missing nonce validation in the ncff_add_plugin_page() function which handles settings updates. This makes it possible for unauthenticated att…

📅 Published: March 21, 2026, 3:27 a.m. 🔄 Last Modified: April 24, 2026, 4:27 p.m.

8.8

CVSS3.1

CVE-2026-4261 - Expire Users <= 1.2.2 - Authenticated (Subscriber+) Privilege Escalation to Administrator via save_…

The Expire Users plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.2.2. This is due to the plugin allowing a user to update the 'on_expire_default_to_role' meta through the 'save_extra_user_profile_fields' function. This makes it possible for authent…

📅 Published: March 21, 2026, 3:27 a.m. 🔄 Last Modified: April 24, 2026, 4:27 p.m.
Total resulsts: 348752
Page 951 of 34,876
« previous page » next page
Filters