5.3

CVSS3.1

CVE-2026-3506 - WP-Chatbot for Messenger <= 4.9 - Missing Authorization to Unauthenticated Chatbot Configuration Ta…

The WP-Chatbot for Messenger plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 4.9. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for unauthenticated attackers to overwrite the s…

📅 Published: March 21, 2026, 3:26 a.m. 🔄 Last Modified: April 24, 2026, 4:27 p.m.

6.4

CVSS3.1

CVE-2026-4067 - Ad Short <= 2.0.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'client' Shortcode…

The Ad Short plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'ad' shortcode's 'client' attribute in all versions up to and including 2.0.1. This is due to insufficient input sanitization and output escaping on the 'client' shortcode attribute. The ad_func() shortcode handl…

📅 Published: March 21, 2026, 3:26 a.m. 🔄 Last Modified: April 24, 2026, 4:27 p.m.

6.1

CVSS3.1

CVE-2026-2277 - rexCrawler <= 1.0.15 - Reflected Cross-Site Scripting via 'url' and 'regex' Parameters

The rexCrawler plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'url' and 'regex' parameters in the search-pattern tester page in all versions up to, and including, 1.0.15 due to insufficient input sanitization and output escaping. This makes it possible for unauthentica…

📅 Published: March 21, 2026, 3:26 a.m. 🔄 Last Modified: April 22, 2026, 9:32 p.m.

6.4

CVSS3.1

CVE-2026-1889 - Outgrow <= 2.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'outgrow' Shortcode '…

The Outgrow plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'id' attribute of the 'outgrow' shortcode in all versions up to, and including, 2.1. This is due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authe…

📅 Published: March 21, 2026, 3:26 a.m. 🔄 Last Modified: April 22, 2026, 9:32 p.m.

6.4

CVSS3.1

CVE-2026-1851 - iVysilani Shortcode <= 3.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'width' S…

The iVysilani Shortcode plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'width' shortcode attribute in all versions up to, and including, 3.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-le…

📅 Published: March 21, 2026, 3:26 a.m. 🔄 Last Modified: April 22, 2026, 9:32 p.m.

6.4

CVSS3.1

CVE-2026-4077 - Ecover Builder For Dummies <= 1.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'i…

The Ecover Builder For Dummies plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'id' parameter of the 'ecover' shortcode in all versions up to and including 1.0. This is due to insufficient input sanitization and output escaping on the user-supplied 'id' shortcode attribute…

📅 Published: March 21, 2026, 3:26 a.m. 🔄 Last Modified: April 24, 2026, 4:27 p.m.

4.3

CVSS3.1

CVE-2026-1390 - Redirect countdown <= 1.0 - Cross-Site Request Forgery to Settings Update

The Redirect countdown plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0. This is due to missing nonce validation on the `countdown_settings_content()` function. This makes it possible for unauthenticated attackers to update the plugin settin…

📅 Published: March 21, 2026, 3:26 a.m. 🔄 Last Modified: April 22, 2026, 9:32 p.m.

4.3

CVSS3.1

CVE-2026-1378 - WP Posts Re-order <= 1.0 - Cross-Site Request Forgery to Settings Update

The WP Posts Re-order plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0. This is due to missing nonce validation on the `cpt_plugin_options()` function. This makes it possible for unauthenticated attackers to update the plugin settings includ…

📅 Published: March 21, 2026, 3:26 a.m. 🔄 Last Modified: April 22, 2026, 9:32 p.m.

4.3

CVSS3.1

CVE-2026-1393 - Add Google Social Profiles to Knowledge Graph Box <= 1.0 - Cross-Site Request Forgery to Settings U…

The Add Google Social Profiles to Knowledge Graph Box plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0. This is due to missing nonce validation on the settings update functionality. This makes it possible for unauthenticated attackers to upd…

📅 Published: March 21, 2026, 3:26 a.m. 🔄 Last Modified: April 22, 2026, 9:32 p.m.

6.4

CVSS3.1

CVE-2026-1854 - Post Flagger <= 1.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'slug' Shortcode…

The Post Flagger plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'flag' shortcode in all versions up to, and including, 1.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, …

📅 Published: March 21, 2026, 3:26 a.m. 🔄 Last Modified: April 22, 2026, 9:32 p.m.
Total resulsts: 349182
Page 1000 of 34,919
« previous page » next page
Filters