4.3

CVSS3.1

CVE-2026-1215 - MMA Call Tracking <= 2.3.15 - Cross-Site Request Forgery to Plugin Settings Update

The MMA Call Tracking plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.3.15. This is due to missing nonce validation when saving plugin configuration on the `mma_call_tracking_menu` admin page. This makes it possible for unauthenticated attack…

📅 Published: Feb. 11, 2026, 8:26 a.m. 🔄 Last Modified: April 15, 2026, 6:45 p.m.

6.4

CVSS3.1

CVE-2026-1853 - BuddyHolis ListSearch <= 1.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'placeh…

The BuddyHolis ListSearch plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'listsearch' shortcode in all versions up to, and including, 1.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authentica…

📅 Published: Feb. 11, 2026, 8:26 a.m. 🔄 Last Modified: April 15, 2026, 9:15 p.m.

6.4

CVSS3.1

CVE-2026-1804 - WDES Responsive Popup <= 1.3.6 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'attr…

The WDES Responsive Popup plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'wdes-popup-title' shortcode in all versions up to, and including, 1.3.6 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for au…

📅 Published: Feb. 11, 2026, 8:26 a.m. 🔄 Last Modified: April 15, 2026, 9:15 p.m.

6.4

CVSS3.1

CVE-2026-1821 - Microtango <= 0.9.29 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode Attri…

The Microtango plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'restkey' parameter of the mt_reservation shortcode in all versions up to, and including, 0.9.29 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, w…

📅 Published: Feb. 11, 2026, 8:26 a.m. 🔄 Last Modified: April 15, 2026, 9:15 p.m.

6.4

CVSS3.1

CVE-2026-1885 - Slideshow Wp <= 1.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'sswp-slide' Sho…

The Slideshow Wp plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'sswpid' attribute of the 'sswp-slide' shortcode in all versions up to, and including, 1.1. This is due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possib…

📅 Published: Feb. 11, 2026, 8:26 a.m. 🔄 Last Modified: April 16, 2026, 1:15 a.m.

7.2

CVSS3.1

CVE-2025-15440 - iONE360 configurator <= 2.0.57 - Unauthenticated Stored Cross-Site Scripting via Contact Form Param…

The iONE360 configurator plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Contact Form Parameters in all versions up to, and including, 2.0.57 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitra…

📅 Published: Feb. 11, 2026, 8:26 a.m. 🔄 Last Modified: April 22, 2026, 3:30 p.m.

8.3

CVSS3.1

CVE-2025-10913 - XSS in saastech.io's TemizlikYolda

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Saastech Cleaning and Internet Services Inc. TemizlikYolda allows Cross-Site Scripting (XSS).This issue affects TemizlikYolda: through 11022026. NOTE: The vendor was contacted early about t…

📅 Published: Feb. 11, 2026, 8:01 a.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

5.4

CVSS3.1

CVE-2025-10912 - IDOR in saastech.io's TemizlikYolda

Authorization Bypass Through User-Controlled Key vulnerability in Saastech Cleaning and Internet Services Inc. TemizlikYolda allows Manipulating User-Controlled Variables.This issue affects TemizlikYolda: through 11022026. NOTE: The vendor was contacted early about this disclosure but did not resp…

📅 Published: Feb. 11, 2026, 7:54 a.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

6.5

CVSS3.1

CVE-2026-1235 - WP eCommerce <= 3.15.1 - Unauthenticated PHP Object Injection

The WP eCommerce WordPress plugin through 3.15.1 unserializes user input via ajax actions, which could allow unauthenticated users to perform PHP Object Injection when a suitable gadget is present on the blog.

📅 Published: Feb. 11, 2026, 6 a.m. 🔄 Last Modified: April 15, 2026, 9:15 p.m.

6.5

CVSS3.1

CVE-2025-15400 - OpenPix <= 2.13.3 - Subscriber+ Payment Gateway Settings Reset

The OpenPix for WooCommerce WordPress plugin through 2.13.3 allows any authenticated user to trigger AJAX actions that reset payment gateway configuration options without capability or nonce checks. This permits any authenticated users, such as subscribers to clear API credentials and webhook statu…

📅 Published: Feb. 11, 2026, 6 a.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.
Total resulsts: 349182
Page 1693 of 34,919
« previous page » next page
Filters