6.1

CVSS3.1

CVE-2026-1654 - Peter's Date Countdown <= 2.0.0 - Reflected Cross-Site Scripting via $_SERVER['PHP_SELF']

The Peter's Date Countdown plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the `$_SERVER['PHP_SELF']` parameter in all versions up to, and including, 2.0.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to in…

πŸ“… Published: Feb. 5, 2026, 9:13 a.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

7.2

CVSS3.1

CVE-2026-1294 - All In One Image Viewer Block <= 1.0.2 - Unauthenticated Server-Side Request Forgery via image-prox…

The All In One Image Viewer Block plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 1.0.2 due to missing authorization and URL validation on the image-proxy REST API endpoint. This makes it possible for unauthenticated attackers to make web requ…

πŸ“… Published: Feb. 5, 2026, 9:13 a.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

5.3

CVSS3.1

CVE-2026-1271 - ProfileGrid <= 5.9.7.2 - Insecure Direct Object Reference to Authenticated (Subscriber+) Arbitrary …

The ProfileGrid – User Profiles, Groups and Communities plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 5.9.7.2 via the 'pm_upload_image' and 'pm_upload_cover_image' AJAX actions. This is due to the update_user_meta() function being calle…

πŸ“… Published: Feb. 5, 2026, 9:13 a.m. πŸ”„ Last Modified: April 16, 2026, 1:15 a.m.

5.3

CVSS3.1

CVE-2025-14079 - ELEX WordPress HelpDesk & Customer Ticketing System <= 3.3.5 - Missing Authorization to Authenticat…

The ELEX WordPress HelpDesk & Customer Ticketing System plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 3.3.5. This is due to missing capability checks on the eh_crm_ticket_general function combined with a shared nonce that is exposed to low-privile…

πŸ“… Published: Feb. 5, 2026, 9:13 a.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

0.0

CVE-2026-25698 -

Not used

πŸ“… Published: Feb. 5, 2026, 8:56 a.m. πŸ”„ Last Modified: Feb. 6, 2026, 3:55 a.m.

0.0

CVE-2026-25696 -

Not used

πŸ“… Published: Feb. 5, 2026, 8:56 a.m. πŸ”„ Last Modified: Feb. 6, 2026, 3:55 a.m.

0.0

CVE-2026-25695 -

Not used

πŸ“… Published: Feb. 5, 2026, 8:56 a.m. πŸ”„ Last Modified: Feb. 6, 2026, 3:55 a.m.

0.0

CVE-2026-25697 -

Not used

πŸ“… Published: Feb. 5, 2026, 8:56 a.m. πŸ”„ Last Modified: Feb. 6, 2026, 3:55 a.m.

0.0

CVE-2026-25694 -

Not used

πŸ“… Published: Feb. 5, 2026, 8:56 a.m. πŸ”„ Last Modified: Feb. 6, 2026, 3:55 a.m.

0.0

CVE-2026-25692 -

Not used

πŸ“… Published: Feb. 5, 2026, 8:56 a.m. πŸ”„ Last Modified: Feb. 6, 2026, 3:55 a.m.
Total resulsts: 346560
Page 1528 of 34,656
Β« previous page Β» next page
Filters