6.3

CVSS3.1

CVE-2026-27091 - WordPress UiPress lite plugin <= 3.5.09 - Broken Access Control vulnerability

Missing Authorization vulnerability in UiPress UiPress lite uipress-lite allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects UiPress lite: from n/a through <= 3.5.09.

πŸ“… Published: March 19, 2026, 6:48 a.m. πŸ”„ Last Modified: April 23, 2026, 3:37 p.m.

4.3

CVSS3.1

CVE-2026-2571 - Download Manager <= 3.3.49 - Missing Authorization to Authenticated (Subscriber+) User Email Enumer…

The Download Manager plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the 'reviewUserStatus' function in all versions up to, and including, 3.3.49. This makes it possible for authenticated attackers, with Subscriber-level access and above, to re…

πŸ“… Published: March 19, 2026, 6:46 a.m. πŸ”„ Last Modified: April 22, 2026, 9:32 p.m.

6.4

CVSS3.1

CVE-2026-4006 - Draft List <= 2.6.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'display_name' P…

The Simple Draft List plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'display_name' post meta (Custom Field) in all versions up to and including 2.6.2. This is due to insufficient input sanitization and output escaping on the author display name when no author URL is pres…

πŸ“… Published: March 19, 2026, 6:46 a.m. πŸ”„ Last Modified: April 22, 2026, 9:32 p.m.

6.4

CVSS3.1

CVE-2026-4120 - Info Cards <= 2.0.7 - Authenticated (Contributor+) Stored Cross-Site Scripting via Block Attributes

The Info Cards – Add Text and Media in Card Layouts plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'btnUrl' parameter within the Info Cards block in all versions up to, and including, 2.0.7. This is due to insufficient input validation on URL schemes, specifically the lac…

πŸ“… Published: March 19, 2026, 6:46 a.m. πŸ”„ Last Modified: April 22, 2026, 9:32 p.m.

4.3

CVSS3.1

CVE-2026-4068 - Add Custom Fields to Media <= 2.0.3 - Cross-Site Request Forgery to Custom Field Deletion via 'dele…

The Add Custom Fields to Media plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.0.3. This is due to missing nonce validation on the field deletion functionality in the admin display template. The plugin properly validates a nonce for the 'add …

πŸ“… Published: March 19, 2026, 6:46 a.m. πŸ”„ Last Modified: April 22, 2026, 9:32 p.m.

8.1

CVSS3.1

CVE-2026-27093 - WordPress Tripgo theme < 1.5.6 - Local File Inclusion vulnerability

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ovatheme Tripgo tripgo allows PHP Local File Inclusion.This issue affects Tripgo: from n/a through < 1.5.6.

πŸ“… Published: March 19, 2026, 6:41 a.m. πŸ”„ Last Modified: April 23, 2026, 3:37 p.m.

8.1

CVSS3.1

CVE-2026-27096 - WordPress ColorFolio - Freelance Designer WordPress Theme theme <= 1.3 - Deserialization of untrust…

Deserialization of Untrusted Data vulnerability in BuddhaThemes ColorFolio - Freelance Designer WordPress Theme allows Object Injection.This issue affects ColorFolio - Freelance Designer WordPress Theme: from n/a through 1.3.

πŸ“… Published: March 19, 2026, 5:31 a.m. πŸ”„ Last Modified: April 28, 2026, 4:15 p.m.

6.5

CVSS3.1

CVE-2026-27397 - WordPress Really Simple Security Pro plugin <= 9.5.4.0 - Insecure Direct Object References (IDOR) v…

Authorization Bypass Through User-Controlled Key vulnerability in Really Simple Plugins B.V. Really Simple Security Pro allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Really Simple Security Pro: from n/a through 9.5.4.0.

πŸ“… Published: March 19, 2026, 5:30 a.m. πŸ”„ Last Modified: April 28, 2026, 4:15 p.m.

9.3

CVSS3.1

CVE-2026-27413 - WordPress Profile Builder Pro plugin < 3.14.0 - SQL Injection vulnerability

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Cozmoslabs Profile Builder Pro profile-builder-pro allows Blind SQL Injection.This issue affects Profile Builder Pro: from n/a through < 3.14.0.

πŸ“… Published: March 19, 2026, 5:28 a.m. πŸ”„ Last Modified: April 23, 2026, 3:37 p.m.

0.0

CVE-2026-27540 - WordPress Woocommerce Wholesale Lead Capture plugin <= 2.0.3.1 - Arbitrary File Upload vulnerability

Unrestricted Upload of File with Dangerous Type vulnerability in Rymera Web Co Pty Ltd. Woocommerce Wholesale Lead Capture woocommerce-wholesale-lead-capture allows Using Malicious Files.This issue affects Woocommerce Wholesale Lead Capture: from n/a through <= 2.0.3.1.

πŸ“… Published: March 19, 2026, 5:24 a.m. πŸ”„ Last Modified: April 23, 2026, 3:37 p.m.
Total resulsts: 348413
Page 975 of 34,842
Β« previous page Β» next page
Filters