5.3

CVSS3.1

CVE-2026-1782 - MetForm Pro <= 3.9.7 - Unauthenticated Payment Amount Manipulation via 'mf-calculation'

The MetForm Pro plugin for WordPress is vulnerable to Improper Input Validation in all versions up to, and including, 3.9.7 This is due to the payment integrations (Stripe/PayPal) trusting a user-submitted calculation field value without recomputing or validating it against the configured form pri…

📅 Published: April 15, 2026, 8:28 a.m. 🔄 Last Modified: April 22, 2026, 8:23 p.m.

5.3

CVSS3.1

CVE-2026-3649 - Katalogportal-pdf-sync Widget <= 1.0.0 - Missing Authorization to Authenticated (Subscriber+) Infor…

The Katalogportal PDF Sync plugin for WordPress is vulnerable to Missing Authorization in all versions up to and including 1.0.0. The katalogportal_popup_shortcode() function is registered as an AJAX handler via wp_ajax_katalogportal_shortcodePrinter but lacks any capability check (current_user_can…

📅 Published: April 15, 2026, 8:28 a.m. 🔄 Last Modified: April 22, 2026, 8:23 p.m.

6.1

CVSS3.1

CVE-2026-4091 - OPEN-BRAIN <= 0.5.0 - Cross-Site Request Forgery

The OPEN-BRAIN plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 0.5.0. This is due to missing nonce verification on the settings form in the func_page_main() function. This makes it possible for unauthenticated attackers to inject malicious web …

📅 Published: April 15, 2026, 8:28 a.m. 🔄 Last Modified: April 22, 2026, 8:23 p.m.

9.8

CVSS3.1

CVE-2026-3461 - Visa Acceptance Solutions <= 2.1.0 - Unauthenticated Authentication Bypass via Billing Email

The Visa Acceptance Solutions plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 2.1.0. This is due to the `express_pay_product_page_pay_for_order()` function logging users in based solely on a user-supplied billing email address during guest checkout …

📅 Published: April 15, 2026, 8:28 a.m. 🔄 Last Modified: April 22, 2026, 8:23 p.m.

5.3

CVSS3.1

CVE-2026-3642 - e-shot <= 1.0.2 - Missing Authorization to Authenticated (Subscriber+) Form Settings Modification v…

The e-shot™ form builder plugin for WordPress is vulnerable to Missing Authorization in all versions up to and including 1.0.2. The eshot_form_builder_update_field_data() AJAX handler lacks any capability checks (current_user_can()) or nonce verification (check_ajax_referer()/wp_verify_nonce()). Th…

📅 Published: April 15, 2026, 8:28 a.m. 🔄 Last Modified: April 22, 2026, 8:23 p.m.

6.4

CVSS3.1

CVE-2026-4005 - Coachific Shortcode <= 1.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'userhash…

The Coachific Shortcode plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'userhash' shortcode attribute in all versions up to and including 1.0. This is due to insufficient input sanitization and output escaping. The plugin uses sanitize_text_field() on the 'userhash' param…

📅 Published: April 15, 2026, 8:28 a.m. 🔄 Last Modified: April 22, 2026, 8:23 p.m.

4.3

CVSS3.1

CVE-2026-4002 - Petje.af <= 2.1.8 - Cross-Site Request Forgery to Account Deletion via 'petjeaf_disconnect' AJAX Ac…

The Petje.af plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to and including 2.1.8. This is due to missing nonce validation in the ajax_revoke_token() function which handles the 'petjeaf_disconnect' AJAX action. The function performs destructive operations inclu…

📅 Published: April 15, 2026, 8:28 a.m. 🔄 Last Modified: April 22, 2026, 8:23 p.m.

6.4

CVSS3.1

CVE-2026-3659 - WP Circliful <= 1.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'id' Shortcode A…

The WP Circliful plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'id' shortcode attribute of the [circliful] shortcode and via multiple shortcode attributes of the [circliful_direct] shortcode in all versions up to and including 1.2. This is due to insufficient input sanit…

📅 Published: April 15, 2026, 8:28 a.m. 🔄 Last Modified: April 22, 2026, 8:23 p.m.

7.1

CVSS4.0

CVE-2025-40899 - Stored Cross-Site Scripting (XSS) in Assets and Nodes in Guardian/CMC before 26.0.0

A Stored Cross-Site Scripting vulnerability was discovered in the Assets and Nodes functionality due to improper validation of an input parameter. An authenticated user with custom fields privileges can define a malicious custom field containing a JavaScript payload. When the victim views the Asset…

📅 Published: April 15, 2026, 8:18 a.m. 🔄 Last Modified: April 17, 2026, 3:38 p.m.

7.2

CVSS4.0

CVE-2025-40897 - Incorrect authorization for Threat Intelligence in Guardian/CMC before 26.0.0

An access control vulnerability was discovered in the Threat Intelligence functionality due to a specific access restriction not being properly enforced for users with view-only privileges. An authenticated user with view-only privileges for the Threat Intelligence functionality can perform adminis…

📅 Published: April 15, 2026, 8:18 a.m. 🔄 Last Modified: April 17, 2026, 3:38 p.m.
Total resulsts: 349182
Page 447 of 34,919
« previous page » next page
Filters