5.5

CVSS3.1

CVE-2026-33237 - AVideo has SSRF in Scheduler Plugin via callbackURL Missing `isSSRFSafeURL()` Validation

WWBN AVideo is an open source video platform. Prior to version 26.0, the Scheduler plugin's `run()` function in `plugin/Scheduler/Scheduler.php` calls `url_get_contents()` with an admin-configurable `callbackURL` that is validated only by `isValidURL()` (URL format check). Unlike other AVideo endpo…

📅 Published: March 20, 2026, 11:30 p.m. 🔄 Last Modified: March 25, 2026, 2:33 p.m.

6.4

CVSS3.1

CVE-2026-2430 - Autoptimize <= 3.1.14 - Authenticated (Contributor+) Stored Cross-Site Scripting via Lazy-loaded Im…

The Autoptimize plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the lazy-loading image processing in all versions up to, and including, 3.1.14. This is due to the use of an overly permissive regular expression in the `add_lazyload` function that replaces all occurrences of `\s…

📅 Published: March 20, 2026, 11:25 p.m. 🔄 Last Modified: March 25, 2026, 2:33 p.m.

4.9

CVSS3.1

CVE-2026-3474 - EmailKit <= 1.6.3 - Authenticated (Administrator+) Path Traversal via 'emailkit-editor-template' RE…

The EmailKit – Email Customizer for WooCommerce & WP plugin for WordPress is vulnerable to arbitrary file read via path traversal in all versions up to, and including, 1.6.3. This is due to the action() function in the TemplateData class passing user-supplied input from the 'emailkit-editor-templat…

📅 Published: March 20, 2026, 11:25 p.m. 🔄 Last Modified: March 25, 2026, 2:33 p.m.

6.4

CVSS3.1

CVE-2026-3350 - Image Alt Text Manager <= 1.8.2 - Authenticated (Author+) Stored Cross-Site Scripting via Post Title

The Image Alt Text Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the post title in all versions up to, and including, 1.8.2. This is due to insufficient input sanitization and output escaping when dynamically generating image alt and title attributes using a DOM pars…

📅 Published: March 20, 2026, 11:25 p.m. 🔄 Last Modified: March 25, 2026, 2:33 p.m.

5.3

CVSS3.1

CVE-2026-3567 - RepairBuddy <= 4.1132 - Missing Authorization to Authenticated (Subscriber+) Plugin Settings Modifi…

The RepairBuddy – Repair Shop CRM & Booking Plugin for WordPress is vulnerable to unauthorized access in all versions up to, and including, 4.1132. The plugin exposes two AJAX handlers that, when combined, allow any authenticated user to modify admin-level plugin settings. First, the wc_rb_get_fres…

📅 Published: March 20, 2026, 11:25 p.m. 🔄 Last Modified: March 25, 2026, 2:33 p.m.

6.4

CVSS3.1

CVE-2026-3516 - Contact List <= 3.0.18 - Authenticated (Contributor+) Stored Cross-Site Scripting via '_cl_map_ifra…

The Contact List plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the '_cl_map_iframe' parameter in all versions up to, and including, 3.0.18. This is due to insufficient input sanitization and output escaping when handling the Google Maps iframe custom field. The saveCustomFie…

📅 Published: March 20, 2026, 11:25 p.m. 🔄 Last Modified: March 25, 2026, 2:33 p.m.

6.4

CVSS3.1

CVE-2026-2352 - Autoptimize <= 3.1.14 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'ao_post_prelo…

The Autoptimize plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'ao_post_preload' meta value in all versions up to, and including, 3.1.14. This is due to insufficient input sanitization in the `ao_metabox_save()` function and missing output escaping when the value is rende…

📅 Published: March 20, 2026, 11:25 p.m. 🔄 Last Modified: March 25, 2026, 1:42 p.m.

6.1

CVSS3.1

CVE-2026-3572 - iTracker360 <= 2.2.0 - Cross-Site Request Forgery to Stored Cross-Site Scripting via 'itracker_lice…

The iTracker360 plugin for WordPress is vulnerable to Cross-Site Request Forgery leading to Stored Cross-Site Scripting in all versions up to and including 2.2.0. This is due to missing nonce verification on the settings form submission and insufficient input sanitization combined with missing outp…

📅 Published: March 20, 2026, 11:25 p.m. 🔄 Last Modified: March 25, 2026, 2:33 p.m.

6.4

CVSS3.1

CVE-2026-4083 - Scoreboard for HTML5 Games Lite <= 1.2 - Authenticated (Contributor+) Stored Cross-Site Scripting v…

The Scoreboard for HTML5 Games Lite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'scoreboard' shortcode in all versions up to, and including, 1.2. The shortcode function sfhg_shortcode() allows arbitrary HTML attributes to be added to the rendered <iframe> element, with…

📅 Published: March 20, 2026, 11:25 p.m. 🔄 Last Modified: March 25, 2026, 2:33 p.m.

4.4

CVSS3.1

CVE-2026-3577 - Keep Backup Daily <= 2.1.2 - Authenticated (Admin+) Stored Cross-Site Scripting via Backup Title

The Keep Backup Daily plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the backup title alias (`val` parameter) in the `update_kbd_bkup_alias` AJAX action in all versions up to, and including, 2.1.2. This is due to insufficient input sanitization and output escaping. While `san…

📅 Published: March 20, 2026, 11:25 p.m. 🔄 Last Modified: March 25, 2026, 2:33 p.m.
Total resulsts: 340382
Page 128 of 34,039
« previous page » next page
Filters