6.4

CVSS3.1

CVE-2026-1822 - WP NG Weather <= 1.0.9 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode Att…

The WP NG Weather plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'ng-weather' shortcode in all versions up to, and including, 1.0.9 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated at…

📅 Published: March 21, 2026, 3:26 a.m. 🔄 Last Modified: April 22, 2026, 9:32 p.m.

8.8

CVSS3.1

CVE-2026-2941 - Linksy Search and Replace <= 1.0.4 - Missing Authorization to Authenticated (Subscriber+) Arbitrary…

The Linksy Search and Replace plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'linksy_search_and_replace_item_details' function in all versions up to, and including, 1.0.4. This makes it possible for authenticated attackers, with subs…

📅 Published: March 21, 2026, 3:26 a.m. 🔄 Last Modified: April 24, 2026, 4:27 p.m.

6.4

CVSS3.1

CVE-2026-4086 - WP Random Button <= 1.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'cat' Shortc…

The WP Random Button plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'cat', 'nocat', and 'text' shortcode attributes of the 'wp_random_button' shortcode in all versions up to, and including, 1.0. This is due to insufficient input sanitization and output escaping on user-su…

📅 Published: March 21, 2026, 3:26 a.m. 🔄 Last Modified: April 24, 2026, 4:27 p.m.

6.5

CVSS3.1

CVE-2026-2375 - App Builder – Create Native Android & iOS Apps On The Flight <= 5.5.10 - Unauthenticated Privilege …

The App Builder – Create Native Android & iOS Apps On The Flight plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 5.5.10. This is due to the `verify_role()` function in `AuthTrails.php` explicitly whitelisting the `wcfm_vendor` role alongside `subscri…

📅 Published: March 21, 2026, 3:26 a.m. 🔄 Last Modified: April 22, 2026, 9:32 p.m.

7.5

CVSS3.1

CVE-2026-1800 - Fonts Manager | Custom Fonts <= 1.2 - Unauthenticated SQL Injection via fmcfIdSelectedFnt parameter

The Fonts Manager | Custom Fonts plugin for WordPress is vulnerable to time-based SQL Injection via the ‘fmcfIdSelectedFnt’ parameter in all versions up to, and including, 1.2 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. …

📅 Published: March 21, 2026, 3:26 a.m. 🔄 Last Modified: April 22, 2026, 9:32 p.m.

7.2

CVSS3.1

CVE-2026-2440 - SurveyJS: Drag & Drop Form Builder <= 2.5.3 - Unauthenticated Stored Cross-Site Scripting

The SurveyJS plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 2.5.3 via survey result submissions. This is due to insufficient input sanitization and output escaping. The public survey page exposes the nonce required for submission, allowing un…

📅 Published: March 21, 2026, 3:26 a.m. 🔄 Last Modified: April 22, 2026, 9:32 p.m.

5.3

CVSS3.1

CVE-2026-3335 - Canto <= 3.1.1 - Missing Authorization to Unauthenticated File Upload

The Canto plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 3.1.1 via the `/wp-content/plugins/canto/includes/lib/copy-media.php` file. This is due to the file being directly accessible without any authentication, authorization, or nonce checks, and t…

📅 Published: March 21, 2026, 3:26 a.m. 🔄 Last Modified: April 24, 2026, 4:27 p.m.

5.3

CVSS3.1

CVE-2026-3570 - Smarter Analytics <= 2.0 - Missing Authorization to Unauthenticated Plugin Settings Reset via 'rese…

The Smarter Analytics plugin for WordPress is vulnerable to unauthorized access in all versions up to, and including, 2.0. This is due to missing authentication and capability checks on the configuration reset functionality in the global scope of smarter-analytics.php. This makes it possible for un…

📅 Published: March 21, 2026, 3:26 a.m. 🔄 Last Modified: April 24, 2026, 4:27 p.m.

8.8

CVSS3.1

CVE-2026-3334 - CMS Commander <= 2.288 - Authenticated (Custom+) SQL Injection via 'or_blogname' Parameter

The CMS Commander plugin for WordPress is vulnerable to SQL Injection via the 'or_blogname', 'or_blogdescription', and 'or_admin_email' parameters in all versions up to, and including, 2.288. This is due to insufficient escaping on the user supplied parameters and lack of sufficient preparation on …

📅 Published: March 21, 2026, 3:26 a.m. 🔄 Last Modified: April 24, 2026, 4:27 p.m.

7.2

CVSS3.1

CVE-2026-2279 - myLinksDump <= 1.6 - Authenticated (Administrator+) SQL Injection via 'sort_by' and 'sort_order' Pa…

The myLinksDump plugin for WordPress is vulnerable to SQL Injection via the 'sort_by' and 'sort_order' parameters in all versions up to, and including, 1.6 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possibl…

📅 Published: March 21, 2026, 3:26 a.m. 🔄 Last Modified: April 22, 2026, 9:32 p.m.
Total resulsts: 349182
Page 1001 of 34,919
« previous page » next page
Filters