6.5

CVSS3.1

CVE-2026-2720 - Hr Press Lite <= 1.0.2 - Missing Authorization to Authenticated (Subscriber+) Sensitive Employee In…

The Hr Press Lite plugin for WordPress is vulnerable to unauthorized access of sensitive employee data due to a missing capability check on the `hrp-fetch-employees` AJAX action in all versions up to, and including, 1.0.2. This makes it possible for authenticated attackers, with Subscriber-level ac…

📅 Published: March 21, 2026, 3:27 a.m. 🔄 Last Modified: April 24, 2026, 4:27 p.m.

6.4

CVSS3.1

CVE-2026-3554 - Sherk Custom Post Type Displays <= 1.2.1 - Authenticated (Contributor+) Stored Cross-Site Scripting…

The Sherk Custom Post Type Displays plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'title' shortcode attribute in all versions up to, and including, 1.2.1. This is due to insufficient input sanitization and output escaping on the 'title' attribute of the 'sherkcptdisplays…

📅 Published: March 21, 2026, 3:27 a.m. 🔄 Last Modified: April 24, 2026, 4:27 p.m.

6.5

CVSS3.1

CVE-2026-2503 - ElementCamp <= 2.3.6 - Authenticated (Author+) SQL Injection via 'meta_query[compare]' Parameter

The ElementCamp plugin for WordPress is vulnerable to time-based SQL Injection via the 'meta_query[compare]' parameter in the 'tcg_select2_search_post' AJAX action in all versions up to, and including, 2.3.6. This is due to the user-supplied compare value being placed as an SQL operator in the quer…

📅 Published: March 21, 2026, 3:27 a.m. 🔄 Last Modified: April 24, 2026, 4:27 p.m.

4.4

CVSS3.1

CVE-2026-3353 - Comment SPAM Wiper <= 1.2.1 - Authenticated (Administrator+) Stored Cross-Site Scripting via 'API K…

The Comment SPAM Wiper plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'API Key' setting in all versions up to, and including, 1.2.1. This is due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Administrator-…

📅 Published: March 21, 2026, 3:27 a.m. 🔄 Last Modified: April 24, 2026, 4:27 p.m.

6.5

CVSS3.1

CVE-2026-2351 - Task Manager <= 3.0.2 - Authenticated (Subscriber+) Arbitrary File Read

The Task Manager plugin for WordPress is vulnerable to Arbitrary File Read in all versions up to, and including, 3.0.2 via the callback_get_text_from_url() function. This makes it possible for authenticated attackers, with Subscriber-level access and above, to read the contents of arbitrary files o…

📅 Published: March 21, 2026, 3:27 a.m. 🔄 Last Modified: April 22, 2026, 9:32 p.m.

6.4

CVSS3.1

CVE-2026-1911 - Twitter Feeds <= 1.0.0 - Authenticated (Contributor+) Cross-Site Scripting via 'tweet_title' Shortc…

The Twitter Feeds plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'tweet_title' parameter in the 'TwitterFeeds' shortcode in all versions up to, and including, 1.0.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attack…

📅 Published: March 21, 2026, 3:27 a.m. 🔄 Last Modified: April 22, 2026, 9:32 p.m.

7.2

CVSS3.1

CVE-2026-1648 - Performance Monitor <= 1.0.6 - Unauthenticated Server-Side Request Forgery via 'url' Parameter

The Performance Monitor plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 1.0.6. This is due to insufficient validation of the 'url' parameter in the '/wp-json/performance-monitor/v1/curl_data' REST API endpoint. This makes it possible for unaut…

📅 Published: March 21, 2026, 3:27 a.m. 🔄 Last Modified: April 22, 2026, 9:32 p.m.

6.4

CVSS3.1

CVE-2026-0609 - Logo Slider <= 4.9.0 - Authenticated (Author+) Stored Cross-Site Scripting via 'logo-slider' Shortc…

The Logo Slider – Logo Carousel, Logo Showcase & Client Logo Slider Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the image alt text in all versions up to, and including, 4.9.0 due to insufficient input sanitization and output escaping in the 'logo-slider' shortcode. …

📅 Published: March 21, 2026, 3:27 a.m. 🔄 Last Modified: April 22, 2026, 9:32 p.m.

6.4

CVSS3.1

CVE-2026-1575 - Schema Shortcode <= 1.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode

The Schema Shortcode plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's `itemscope` shortcode in all versions up to, and including, 1.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated at…

📅 Published: March 21, 2026, 3:27 a.m. 🔄 Last Modified: April 22, 2026, 9:32 p.m.

5.3

CVSS3.1

CVE-2026-3645 - Punnel <= 1.3.1 - Missing Authorization to Authenticated (Subscriber+) Settings Update via 'punnel_…

The Punnel – Landing Page Builder plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 1.3.1. The save_config() function, which handles the 'punnel_save_config' AJAX action, lacks any capability check (current_user_can()) and nonce verification. This mak…

📅 Published: March 21, 2026, 3:27 a.m. 🔄 Last Modified: April 24, 2026, 4:27 p.m.
Total resulsts: 349182
Page 995 of 34,919
« previous page » next page
Filters