5.3

CVSS3.1

CVE-2025-13920 - WP Directory Kit <= 1.4.9 - Unauthenticated Email Exposure via wdk_public_action

The WP Directory Kit plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.4.9 via the wdk_public_action AJAX handler. This makes it possible for unauthenticated attackers to extract email addresses for users with Directory Kit-specific user ro…

📅 Published: Jan. 24, 2026, 12:27 p.m. 🔄 Last Modified: April 22, 2026, 6:15 a.m.

7.5

CVSS3.1

CVE-2026-0911 - Hustle <= 7.8.9.2 - Authenticated (Subscriber+) Arbitrary File Upoload via Module Import

The Hustle – Email Marketing, Lead Generation, Optins, Popups plugin for WordPress is vulnerable to arbitrary file uploads due to incorrect file type validation in the action_import_module() function in all versions up to, and including, 7.8.9.2. This makes it possible for authenticated attackers, …

📅 Published: Jan. 24, 2026, 12:27 p.m. 🔄 Last Modified: April 15, 2026, 9:45 p.m.

4.3

CVSS3.1

CVE-2025-13205 - SurveyJS: Drag & Drop WordPress Form Builder to create, style and embed multiple forms of any compl…

The SurveyJS: Drag & Drop WordPress Form Builder to create, style and embed multiple forms of any complexity plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.5.2. This is due to missing or incorrect nonce validation on the `SurveyJS_CloneSurve…

📅 Published: Jan. 24, 2026, 9:08 a.m. 🔄 Last Modified: April 21, 2026, 12:30 a.m.

6.1

CVSS3.1

CVE-2026-1127 - Timeline Event History <= 3.2 - Reflected Cross-Site Scripting

The Timeline Event History plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the `id` parameter in all versions up to, and including, 3.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web s…

📅 Published: Jan. 24, 2026, 9:08 a.m. 🔄 Last Modified: April 15, 2026, 9:45 p.m.

4.3

CVSS3.1

CVE-2025-13194 - SurveyJS: Drag & Drop WordPress Form Builder to create, style and embed multiple forms of any compl…

The SurveyJS: Drag & Drop WordPress Form Builder to create, style and embed multiple forms of any complexity plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.5.2. This is due to missing nonce verification on the 'SurveyJS_RenameSurvey' AJAX ac…

📅 Published: Jan. 24, 2026, 9:08 a.m. 🔄 Last Modified: April 22, 2026, midnight

4.4

CVSS3.1

CVE-2026-1191 - JavaScript Notifier <= 1.2.8 - Authenticated (Administrator+) Stored Cross-Site Scripting via Plugi…

The JavaScript Notifier plugin for WordPress is vulnerable to Stored Cross-Site Scripting via plugin settings in all versions up to, and including, 1.2.8. This is due to insufficient input sanitization and output escaping on user-supplied attributes in the `wp_footer` action. This makes it possible…

📅 Published: Jan. 24, 2026, 9:08 a.m. 🔄 Last Modified: April 16, 2026, 1:30 a.m.

4.3

CVSS3.1

CVE-2026-1208 - Friendly Functions for Welcart <= 1.2.5 - Cross-Site Request Forgery to Settings Update

The Friendly Functions for Welcart plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.2.5. This is due to missing or incorrect nonce validation on the settings page. This makes it possible for unauthenticated attackers to update plugin settings …

📅 Published: Jan. 24, 2026, 9:08 a.m. 🔄 Last Modified: April 15, 2026, 9:45 p.m.

6.4

CVSS3.1

CVE-2026-1189 - LeadBI Plugin for WordPress <= 1.7 - Authenticated (Contributor+) Stored Cross-Site Scripting via '…

The LeadBI Plugin for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'form_id' parameter of the 'leadbi_form' shortcode in all versions up to, and including, 1.7 due to insufficient input sanitization and output escaping on user supplied attributes. This makes i…

📅 Published: Jan. 24, 2026, 9:08 a.m. 🔄 Last Modified: April 16, 2026, 1:30 a.m.

4.4

CVSS3.1

CVE-2026-1300 - Responsive Header Plugin <= 1.0 - Authenticated (Administrator+) Stored Cross-Site Scripting via Se…

The Responsive Header plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multiple plugin settings parameters in all versions up to, and including, 1.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrato…

📅 Published: Jan. 24, 2026, 9:08 a.m. 🔄 Last Modified: April 15, 2026, 9:45 p.m.

4.3

CVSS3.1

CVE-2025-13139 - SurveyJS: Drag & Drop WordPress Form Builder <= 2.5.2 - Cross-Site Request Forgery to Survey Creati…

The SurveyJS: Drag & Drop WordPress Form Builder plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.5.2. This is due to missing nonce validation on the SurveyJS_AddSurvey AJAX action. This makes it possible for unauthenticated attackers to creat…

📅 Published: Jan. 24, 2026, 9:08 a.m. 🔄 Last Modified: April 22, 2026, 3:45 p.m.
Total resulsts: 348435
Page 1882 of 34,844
« previous page » next page
Filters