4.3

CVSS3.1

CVE-2026-2023 - WP Plugin Info Card <= 6.2.0 - Cross-Site Request Forgery to Arbitrary Custom Plugin Entry Creation

The WP Plugin Info Card plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 6.2.0. This is due to missing nonce validation in the ajax_save_custom_plugin() function, which is disabled by prefixing the check with 'false &&'. This makes it possible f…

📅 Published: Feb. 18, 2026, 5:29 a.m. 🔄 Last Modified: April 15, 2026, 8:30 p.m.

4.3

CVSS3.1

CVE-2026-1925 - EmailKit – Email Customizer for WooCommerce & WP <= 1.6.2 - Missing Authorization to Authenticated …

The EmailKit – Email Customizer for WooCommerce & WP plugin for WordPress is vulnerable to unauthorized data modification due to a missing capability check on the 'update_template_data' function in all versions up to, and including, 1.6.2. This makes it possible for authenticated attackers, with Su…

📅 Published: Feb. 18, 2026, 4:35 a.m. 🔄 Last Modified: April 15, 2026, 5:30 p.m.

7.5

CVSS3.1

CVE-2026-2576 - Business Directory Plugin <= 6.4.21 - Unauthenticated SQL Injection via payment Parameter

The Business Directory Plugin – Easy Listing Directories for WordPress plugin for WordPress is vulnerable to time-based SQL Injection via the 'payment' parameter in all versions up to, and including, 6.4.2 due to insufficient escaping on the user supplied parameter and lack of sufficient preparatio…

📅 Published: Feb. 18, 2026, 4:35 a.m. 🔄 Last Modified: April 15, 2026, 5:30 p.m.

8.6

CVSS3.1

CVE-2026-1714 - ShopLentor <= 3.3.2 - Unauthenticated Email Relay Abuse via 'woolentor_suggest_price_action' AJAX A…

The ShopLentor – WooCommerce Builder for Elementor & Gutenberg +21 Modules – All in One Solution plugin for WordPress is vulnerable to Email Relay Abuse in all versions up to, and including, 3.3.2. This is due to the lack of validation on the 'send_to', 'product_title', 'wlmessage', and 'wlemail' p…

📅 Published: Feb. 18, 2026, 4:35 a.m. 🔄 Last Modified: April 15, 2026, 5:30 p.m.

4.7

CVSS3.1

CVE-2026-1277 - URL Shortify <= 1.12.1 - Unauthenticated Open Redirect via 'redirect_to' Parameter

The URL Shortify plugin for WordPress is vulnerable to Open Redirect in all versions up to, and including, 1.12.1 due to insufficient validation on the 'redirect_to' parameter in the promotional dismissal handler. This makes it possible for unauthenticated attackers to redirect users to potentially…

📅 Published: Feb. 18, 2026, 4:35 a.m. 🔄 Last Modified: April 15, 2026, 6:30 p.m.

4.4

CVSS3.1

CVE-2025-12037 - WP 404 Auto Redirect <= 1.0.5 - Authenticated (Admin+) Stored Cross-Site Scripting

The WP 404 Auto Redirect to Similar Post plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 1.0.5 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrato…

📅 Published: Feb. 18, 2026, 4:35 a.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

6.4

CVSS3.1

CVE-2025-6460 - Display During Conditional Shortcode <= 1.2 - Authenticated (Contributor+) Stored Cross-Site Script…

The Display During Conditional Shortcode plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘message’ parameter in all versions up to, and including, 1.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contr…

📅 Published: Feb. 18, 2026, 4:35 a.m. 🔄 Last Modified: April 20, 2026, 9 p.m.

6.1

CVSS3.1

CVE-2026-1296 - Frontend Post Submission Manager Lite <= 1.2.7 - Unauthenticated Open Redirect via 'requested_page'…

The Frontend Post Submission Manager Lite plugin for WordPress is vulnerable to Open Redirection in all versions up to, and including, 1.2.7 due to insufficient validation on the 'requested_page' POST parameter in the verify_username_password function. This makes it possible for unauthenticated att…

📅 Published: Feb. 18, 2026, 4:35 a.m. 🔄 Last Modified: April 17, 2026, 7 p.m.

4.3

CVSS3.1

CVE-2025-12075 - Order Splitter for WooCommerce <= 5.3.5 - Missing Authorization to Authenticated (Subscriber+) Orde…

The Order Splitter for WooCommerce plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the 'wos_troubleshooting' AJAX endpoint in all versions up to, and including, 5.3.5. This makes it possible for authenticated attackers, with Subscriber-level ac…

📅 Published: Feb. 18, 2026, 4:35 a.m. 🔄 Last Modified: April 22, 2026, noon

7.2

CVSS3.1

CVE-2026-1931 - Rent Fetch <= 0.32.4 - Unauthenticated Stored Cross-Site Scripting via 'keyword' Parameter

The Rent Fetch plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'keyword' parameter in all versions up to, and including, 0.32.4 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for unauthenticated attackers to i…

📅 Published: Feb. 18, 2026, 4:35 a.m. 🔄 Last Modified: April 15, 2026, 6:30 p.m.
Total resulsts: 349182
Page 1598 of 34,919
« previous page » next page
Filters