8.8

CVSS3.1

CVE-2026-1750 - Ecwid by Lightspeed Ecommerce Shopping Cart <= 7.0.7 - Authenticated (Subscriber+) Privilege Escala…

The Ecwid by Lightspeed Ecommerce Shopping Cart plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 7.0.7. This is due to a missing capability check in the 'save_custom_user_profile_fields' function. This makes it possible for authenticated attackers, wi…

📅 Published: Feb. 15, 2026, 3:24 a.m. 🔄 Last Modified: April 15, 2026, 8:30 p.m.

9.8

CVSS3.1

CVE-2026-1490 - Spam protection, Honeypot, Anti-Spam by CleanTalk <= 6.71 - Authorization Bypass via Reverse DNS (P…

The Spam protection, Anti-Spam, FireWall by CleanTalk plugin for WordPress is vulnerable to unauthorized Arbitrary Plugin Installation due to an authorization bypass via reverse DNS (PTR record) spoofing on the 'checkWithoutToken' function in all versions up to, and including, 6.71. This makes it p…

📅 Published: Feb. 15, 2026, 2:22 a.m. 🔄 Last Modified: April 15, 2026, 5:30 p.m.

4.3

CVSS3.1

CVE-2026-2312 - Media Library Folders <= 8.3.6 - Insecure Direct Object Reference to Authenticated (Author+) Arbitr…

The Media Library Folders plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 8.3.6 via the delete_maxgalleria_media() and maxgalleria_rename_image() functions due to missing validation on a user controlled key. This makes it possible for aut…

📅 Published: Feb. 14, 2026, 11:24 a.m. 🔄 Last Modified: April 15, 2026, 8:45 p.m.

6.4

CVSS3.1

CVE-2026-1512 - Essential Addons for Elementor <= 6.5.9 - Authenticated (Contributor+) Stored Cross-Site Scripting …

The Essential Addons for Elementor – Popular Elementor Templates & Widgets plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Info Box widget in all versions up to, and including, 6.5.9 due to insufficient input sanitization and output escaping on user supplied attri…

📅 Published: Feb. 14, 2026, 9:49 a.m. 🔄 Last Modified: April 15, 2026, 5:30 p.m.

4.9

CVSS3.1

CVE-2026-1258 - Mail Mint <= 1.19.2 - Authenticated (Administrator+) SQL Injection via Multiple API Endpoints

The Mail Mint plugin for WordPress is vulnerable to blind SQL Injection via the 'forms', 'automation', 'email/templates', and 'contacts/import/tutorlms/map' API endpoints in all versions up to, and including, 1.19.2 . This is due to insufficient escaping on the user supplied 'order-by', 'order-type…

📅 Published: Feb. 14, 2026, 8:26 a.m. 🔄 Last Modified: April 15, 2026, 8:45 p.m.

6.4

CVSS3.1

CVE-2026-0550 - myCred <= 2.9.7.3 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'mycred_load_coupo…

The myCred plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'mycred_load_coupon' shortcode in all versions up to, and including, 2.9.7.3 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated…

📅 Published: Feb. 14, 2026, 8:26 a.m. 🔄 Last Modified: April 15, 2026, 6:30 p.m.

9.8

CVSS3.1

CVE-2025-8572 - Truelysell Core <= 1.8.7 - Unauthenticated Privilege Escalation via Registration

The Truelysell Core plugin for WordPress is vulnerable to privilege escalation in versions less than, or equal to, 1.8.7. This is due to insufficient validation of the user_role parameter during user registration. This makes it possible for unauthenticated attackers to create accounts with elevated…

📅 Published: Feb. 14, 2026, 8:26 a.m. 🔄 Last Modified: April 20, 2026, 7 p.m.

7.2

CVSS3.1

CVE-2026-1843 - Super Page Cache <= 5.2.2 - Unauthenticated Stored Cross-Site Scripting via Activity Log

The Super Page Cache plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Activity Log in all versions up to, and including, 5.2.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in…

📅 Published: Feb. 14, 2026, 8:26 a.m. 🔄 Last Modified: April 15, 2026, 6:30 p.m.

4.3

CVSS3.1

CVE-2026-1254 - Modula Image Gallery – Photo Grid & Video Gallery <= 2.13.6 - Missing Authorization to Authenticate…

The Modula Image Gallery – Photo Grid & Video Gallery plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 2.13.6. This is due to the plugin not properly verifying that a user is authorized to modify specific posts before updating them via the REST API. T…

📅 Published: Feb. 14, 2026, 8:26 a.m. 🔄 Last Modified: April 15, 2026, 8:45 p.m.

5

CVSS3.1

CVE-2026-1249 - MP3 Audio Player – Music Player, Podcast Player & Radio by Sonaar 5.3 - 5.10 - Authenticated (Autho…

The MP3 Audio Player – Music Player, Podcast Player & Radio by Sonaar plugin for WordPress is vulnerable to Server-Side Request Forgery in versions 5.3 to 5.10 via the 'load_lyrics_ajax_callback' function. This makes it possible for authenticated attackers, with author level access and above, to ma…

📅 Published: Feb. 14, 2026, 8:26 a.m. 🔄 Last Modified: April 18, 2026, 12:30 p.m.
Total resulsts: 349182
Page 1628 of 34,919
« previous page » next page
Filters