5

CVSS3.1

CVE-2026-1249 - MP3 Audio Player – Music Player, Podcast Player & Radio by Sonaar 5.3 - 5.10 - Authenticated (Autho…

The MP3 Audio Player – Music Player, Podcast Player & Radio by Sonaar plugin for WordPress is vulnerable to Server-Side Request Forgery in versions 5.3 to 5.10 via the 'load_lyrics_ajax_callback' function. This makes it possible for authenticated attackers, with author level access and above, to ma…

📅 Published: Feb. 14, 2026, 8:26 a.m. 🔄 Last Modified: April 18, 2026, 12:30 p.m.

7.5

CVSS3.1

CVE-2026-1988 - Flexi Product Slider and Grid for WooCommerce <= 1.0.5 - Authenticated (Contributor+) Local File In…

The Flexi Product Slider and Grid for WooCommerce plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1.0.5 via the `flexipsg_carousel` shortcode. This is due to the `theme` parameter being directly concatenated into a file path without proper sanitizati…

📅 Published: Feb. 14, 2026, 6:42 a.m. 🔄 Last Modified: April 15, 2026, 6:30 p.m.

5.4

CVSS3.1

CVE-2026-1987 - Scheduler Widget <= 0.1.6 - Insecure Direct Object Reference to Authenticated (Subscriber+) Arbitra…

The Scheduler Widget plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 0.1.6. This is due to the `scheduler_widget_ajax_save_event()` function lacking proper authorization checks and ownership verification when updating events. This makes i…

📅 Published: Feb. 14, 2026, 6:42 a.m. 🔄 Last Modified: April 15, 2026, 6:30 p.m.

6.4

CVSS3.1

CVE-2026-0736 - Chatbot for WordPress by Collect.chat ⚡️ <= 2.4.8 - Authenticated (Contributor+) Stored Cross-Site …

The Chatbot for WordPress by Collect.chat plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the '_inpost_head_script[synth_header_script]' post meta field in all versions up to, and including, 2.4.8 due to insufficient input sanitization and output escaping. This makes it possib…

📅 Published: Feb. 14, 2026, 6:42 a.m. 🔄 Last Modified: April 15, 2026, 6:30 p.m.

6.4

CVSS3.1

CVE-2026-1187 - ZoomifyWP Free <= 1.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'filename' Sho…

The ZoomifyWP Free plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'filename' parameter of the 'zoomify' shortcode in all versions up to, and including, 1.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for a…

📅 Published: Feb. 14, 2026, 6:42 a.m. 🔄 Last Modified: April 16, 2026, 1 a.m.

6.4

CVSS3.1

CVE-2026-1915 - Simple Plyr <= 0.0.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'poster' Shortc…

The Simple Plyr plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'poster' parameter in the 'plyr' shortcode in all versions up to, and including, 0.0.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authent…

📅 Published: Feb. 14, 2026, 6:42 a.m. 🔄 Last Modified: April 15, 2026, 5:30 p.m.

6.4

CVSS3.1

CVE-2026-1985 - Press3D <= 1.0.2 - Authenticated (Author+) Stored Cross-Site Scripting via Link URL Parameter in 3D…

The Press3D plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 3D Model Gutenberg block in all versions up to, and including, 1.0.2. This is due to the plugin failing to sanitize and validate the URL scheme when storing link URLs for 3D model blocks, allowing `javascript:` UR…

📅 Published: Feb. 14, 2026, 6:42 a.m. 🔄 Last Modified: April 15, 2026, 6:30 p.m.

7.2

CVSS3.1

CVE-2026-0753 - Super Simple Contact Form <= 1.6.2 - Reflected Cross-Site Scripting via 'sscf_name' Parameter

The Super Simple Contact Form plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'sscf_name' parameter in all versions up to, and including, 1.6.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arb…

📅 Published: Feb. 14, 2026, 6:42 a.m. 🔄 Last Modified: April 15, 2026, 8:45 p.m.

9.8

CVSS3.1

CVE-2026-1306 - midi-Synth <= 1.1.0 - Unauthenticated Arbitrary File Upload via 'export' AJAX Action

The midi-Synth plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type and file extension validation in the 'export' AJAX action in all versions up to, and including, 1.1.0. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected …

📅 Published: Feb. 14, 2026, 6:42 a.m. 🔄 Last Modified: April 22, 2026, midnight

4.4

CVSS3.1

CVE-2026-0735 - User Language Switch <= 1.6.10 - Authenticated (Administrator+) Stored Cross-Site Scripting via 'ta…

The User Language Switch plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'tab_color_picker_language_switch' parameter in all versions up to, and including, 1.6.10 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers…

📅 Published: Feb. 14, 2026, 6:42 a.m. 🔄 Last Modified: April 15, 2026, 6:30 p.m.
Total resulsts: 346547
Page 1366 of 34,655
« previous page » next page
Filters