6.4

CVSS3.1

CVE-2026-1613 - Wonka Slide <= 1.3.3 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode

The Wonka Slide plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's `list_class` shortcode in all versions up to, and including, 1.3.3 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated atta…

📅 Published: Feb. 7, 2026, 8:26 a.m. 🔄 Last Modified: April 15, 2026, 6:45 p.m.

6.4

CVSS3.1

CVE-2026-1611 - Wikiloops Track Player <= 1.0.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shor…

The Wikiloops Track Player plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's `wikiloops` shortcode in all versions up to, and including, 1.0.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenti…

📅 Published: Feb. 7, 2026, 8:26 a.m. 🔄 Last Modified: April 15, 2026, 6:45 p.m.

4.3

CVSS3.1

CVE-2026-1082 - TITLE ANIMATOR <= 1.0 - Cross-Site Request Forgery to Settings Update

The TITLE ANIMATOR plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0. This is due to missing nonce validation on the settings page form handler in `inc/settings-page.php`. This makes it possible for unauthenticated attackers to modify plugin …

📅 Published: Feb. 7, 2026, 8:26 a.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

6.4

CVSS3.1

CVE-2026-0555 - Premmerce <= 1.3.20 - Authenticated (Subscriber+) Stored Cross-Site Scripting via 'premmerce_wizard…

The Premmerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'premmerce_wizard_actions' AJAX endpoint in all versions up to, and including, 1.3.20. This is due to missing capability checks and insufficient input sanitization and output escaping on the `state` parameter. T…

📅 Published: Feb. 7, 2026, 8:26 a.m. 🔄 Last Modified: April 15, 2026, 9:30 p.m.

6.4

CVSS3.1

CVE-2026-1608 - Video Onclick <= 0.4.7 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode

The Video Onclick plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's `youtube` shortcode in all versions up to, and including, 0.4.7 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attac…

📅 Published: Feb. 7, 2026, 8:26 a.m. 🔄 Last Modified: April 15, 2026, 6:45 p.m.

6.1

CVSS3.1

CVE-2026-1634 - Subitem AL Slider <= 1.0.0 - Reflected Cross-Site Scripting via $_SERVER['PHP_SELF']

The Subitem AL Slider plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the `$_SERVER['PHP_SELF']` parameter in all versions up to, and including, 1.0.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject …

📅 Published: Feb. 7, 2026, 8:26 a.m. 🔄 Last Modified: April 17, 2026, 10:15 p.m.

5.3

CVSS3.1

CVE-2026-1675 - Advanced Country Blocker <= 2.3.1 - Unauthenticated Authorization Bypass via Insecure Default Secre…

The Advanced Country Blocker plugin for WordPress is vulnerable to Authorization Bypass in all versions up to, and including, 2.3.1 due to the use of a predictable default value for the secret bypass key created during installation without requiring users to change it. This makes it possible for un…

📅 Published: Feb. 7, 2026, 8:26 a.m. 🔄 Last Modified: April 15, 2026, 9:30 p.m.

6.1

CVSS3.1

CVE-2026-1643 - MP-Ukagaka <= 1.5.2 - Reflected Cross-Site Scripting

The MP-Ukagaka plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and including, 1.5.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if t…

📅 Published: Feb. 7, 2026, 8:26 a.m. 🔄 Last Modified: April 16, 2026, 1:15 a.m.

6.4

CVSS3.1

CVE-2026-1570 - Simple Bible Verse via Shortcode <= 1.1 - Authenticated (Contributor+) Stored Cross-Site Scripting …

The Simple Bible Verse via Shortcode plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's `verse` shortcode in all versions up to, and including, 1.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for auth…

📅 Published: Feb. 7, 2026, 8:26 a.m. 🔄 Last Modified: April 15, 2026, 9:30 p.m.

5.3

CVSS4.0

CVE-2026-2078 - yeqifu warehouse Permission Management PermissionController.java deletePermission improper authoriz…

A vulnerability was detected in yeqifu warehouse up to aaf29962ba407d22d991781de28796ee7b4670e4. This affects the function addPermission/updatePermission/deletePermission of the file dataset\repos\warehouse\src\main\java\com\yeqifu\sys\controller\PermissionController.java of the component Permissio…

📅 Published: Feb. 7, 2026, 8:02 a.m. 🔄 Last Modified: April 18, 2026, 1:30 p.m.
Total resulsts: 349182
Page 1758 of 34,919
« previous page » next page
Filters