8.8

CVSS3.1

CVE-2026-3666 - wpForo Forum <= 2.4.16 - Authenticated (Subscriber+) Arbitrary File Deletion via Post Body

The wpForo Forum plugin for WordPress is vulnerable to arbitrary file deletion in all versions up to, and including, 2.4.16. This is due to a missing file name/path validation against path traversal sequences. This makes it possible for authenticated attackers, with subscriber level access and abov…

πŸ“… Published: April 4, 2026, 11:16 a.m. πŸ”„ Last Modified: April 4, 2026, 11:16 a.m.

7.2

CVSS3.1

CVE-2026-2936 - Visitor Traffic Real Time Statistics <= 8.4 - Unauthenticated Stored Cross-Site Scripting

The Visitor Traffic Real Time Statistics plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'page_title' parameter in all versions up to, and including, 8.4 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inj…

πŸ“… Published: April 4, 2026, 11:16 a.m. πŸ”„ Last Modified: April 4, 2026, 11:16 a.m.

7.5

CVSS3.1

CVE-2026-1233 - Text to Speech (TTS) by Mementor <= 1.9.8 - Use of Hardcoded Password to Unauthenticated Remote Dat…

The Text to Speech for WP (AI Voices by Mementor) plugin for WordPress is vulnerable to sensitive information exposure in all versions up to, and including, 1.9.8. This is due to the plugin containing hardcoded MySQL database credentials for the vendor's external telemetry server in the `Mementor_T…

πŸ“… Published: April 4, 2026, 11:16 a.m. πŸ”„ Last Modified: April 4, 2026, 11:16 a.m.

5.3

CVSS3.1

CVE-2025-14938 - Listeo-Core - Directory Plugin by Purethemes <= 2.0.27 - Unauthenticated Arbitrary Media Upload

The Listeo Core plugin for WordPress is vulnerable to unauthenticated arbitrary media upload in all versions up to, and including, 2.0.27 via the "listeo_core_handle_dropped_media" function. This is due to missing authorization and capability checks on the AJAX endpoint handling file uploads. This …

πŸ“… Published: April 4, 2026, 11:16 a.m. πŸ”„ Last Modified: April 4, 2026, 11:16 a.m.

6.5

CVSS3.1

CVE-2026-3309 - Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Cont…

The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 4.16.11. This is due to the plugin allowing user-supplied billing field…

πŸ“… Published: April 4, 2026, 11:16 a.m. πŸ”„ Last Modified: April 4, 2026, 11:16 a.m.

6.4

CVSS3.1

CVE-2026-0626 - WPFunnels <= 3.7.9 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'wpf_optin_form' …

The WPFunnels – Easy Funnel Builder To Optimize Buyer Journeys And Get More Leads & Sales plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'wpf_optin_form' shortcode in all versions up to, and including, 3.7.9 due to insufficient input sanitization and output escaping of th…

πŸ“… Published: April 4, 2026, 11:16 a.m. πŸ”„ Last Modified: April 4, 2026, 11:16 a.m.

7.1

CVSS3.1

CVE-2026-3445 - Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Cont…

The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress plugin for WordPress is vulnerable to unauthorized membership payment bypass in all versions up to, and including, 4.16.11. This is due to a missing ownership verification on th…

πŸ“… Published: April 4, 2026, 8:25 a.m. πŸ”„ Last Modified: April 4, 2026, 8:25 a.m.

4.3

CVSS3.1

CVE-2026-2826 - Kadence Blocks β€” Page Builder Toolkit for Gutenberg Editor <= 3.6.3 - Missing Authorization to Auth…

The Kadence Blocks β€” Page Builder Toolkit for Gutenberg Editor plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 3.6.3. This is due to the plugin not properly verifying that a user has the `upload_files` capability in the `process_pattern` REST API end…

πŸ“… Published: April 4, 2026, 8:25 a.m. πŸ”„ Last Modified: April 4, 2026, 8:25 a.m.

6.4

CVSS3.1

CVE-2026-2437 - WP Travel Engine - Travel and Tour Booking Plugin <= 6.7.5 - Authenticated (Contributor+) Stored Cr…

The WP Travel Engine – Tour Booking Plugin – Tour Operator Software plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'wte_trip_tax' shortcode in all versions up to, and including, 6.7.5 due to insufficient input sanitization and output escaping on user supplied att…

πŸ“… Published: April 4, 2026, 8:25 a.m. πŸ”„ Last Modified: April 4, 2026, 8:25 a.m.

7.2

CVSS3.1

CVE-2026-5425 - Widgets for Social Photo Feed <= 1.7.9 - Unauthenticated Stored Cross-Site Scripting via feed_data

The Widgets for Social Photo Feed plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'feed_data' parameter keys in all versions up to, and including, 1.7.9 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inje…

πŸ“… Published: April 4, 2026, 8:25 a.m. πŸ”„ Last Modified: April 4, 2026, 8:25 a.m.
Total resulsts: 342218
Page 1 of 34,222
Β» next page
Filters