6.4

CVSS3.1

CVE-2026-1886 - Go Night Pro | WordPress Dark Mode Plugin <= 1.1.0 - Authenticated (Contributor+) Stored Cross-Site…

The Go Night Pro | WordPress Dark Mode Plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'go-night-pro-shortcode' shortcode in all versions up to, and including, 1.1.0 due to insufficient input sanitization and output escaping on the user-supplied 'margin' attribute…

📅 Published: March 21, 2026, 3:26 a.m. 🔄 Last Modified: April 22, 2026, 9:32 p.m.

6.4

CVSS3.1

CVE-2026-1891 - Simple Football Scoreboard <= 1.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via Sh…

The Simple Football Scoreboard plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'ytmr_fb_scoreboard' shortcode in all versions up to, and including, 1.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authen…

📅 Published: March 21, 2026, 3:26 a.m. 🔄 Last Modified: April 22, 2026, 9:32 p.m.

6.1

CVSS3.1

CVE-2025-13910 - WP-WebAuthn <= 1.3.4 - Unauthenticated Stored Cross-Site Scripting

The WP-WebAuthn plugin for WordPress is vulnerable to Unauthenticated Stored Cross-Site Scripting via the `wwa_auth` AJAX endpoint in all versions up to, and including, 1.3.4 due to insufficient input sanitization and output escaping on user supplied attributes logged by the plugin. This makes it p…

📅 Published: March 21, 2026, 3:26 a.m. 🔄 Last Modified: April 22, 2026, 9:32 p.m.

6.1

CVSS3.1

CVE-2026-4069 - Alfie – Feed Plugin <= 1.2.1 - Cross-Site Request Forgery to Stored Cross-Site Scripting via 'naam'…

The Alfie – Feed Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'naam' parameter in all versions up to, and including, 1.2.1. This is due to missing nonce validation on the alfie_option_page() function combined with insufficient input sanitization and output escapi…

📅 Published: March 21, 2026, 3:26 a.m. 🔄 Last Modified: April 24, 2026, 4:27 p.m.

6.4

CVSS3.1

CVE-2026-2496 - Ed's Font Awesome <= 2.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode A…

The Ed's Font Awesome plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's `eds_font_awesome` shortcode in all versions up to, and including, 2.0. This is due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for…

📅 Published: March 21, 2026, 3:26 a.m. 🔄 Last Modified: April 22, 2026, 9:32 p.m.

4.4

CVSS3.1

CVE-2026-2424 - Reward Video Ad for WordPress <= 1.6 - Authenticated (Administrator+) Stored Cross-Site Scripting v…

The Reward Video Ad for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 1.6. This is due to insufficient input sanitization and output escaping on plugin settings such as the 'Account ID', 'Message before the video…

📅 Published: March 21, 2026, 3:26 a.m. 🔄 Last Modified: April 22, 2026, 9:32 p.m.

6.4

CVSS3.1

CVE-2026-4084 - fyyd podcast shortcodes <= 0.3.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'co…

The fyyd podcast shortcodes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'fyyd-podcast', 'fyyd-episode', and 'fyyd' shortcodes in all versions up to, and including, 0.3.1. This is due to insufficient input sanitization and output escaping on user-supplied shortcode attr…

📅 Published: March 21, 2026, 3:26 a.m. 🔄 Last Modified: April 24, 2026, 4:27 p.m.

4.3

CVSS3.1

CVE-2026-4127 - Speedup Optimization <= 1.5.9 - Missing Authorization to Authenticated (Subscriber+) Plugin Setting…

The Speedup Optimization plugin for WordPress is vulnerable to Missing Authorization in all versions up to and including 1.5.9. The `speedup01_ajax_enabled()` function, which handles the `wp_ajax_speedup01_enabled` AJAX action, does not perform any capability check via `current_user_can()` and also…

📅 Published: March 21, 2026, 3:26 a.m. 🔄 Last Modified: April 24, 2026, 4:27 p.m.

6.4

CVSS3.1

CVE-2026-1093 - WPFAQBlock– FAQ & Accordion Plugin For Gutenberg <= 1.1 - Authenticated (Contributor+) Stored Cross…

The WPFAQBlock– FAQ & Accordion Plugin For Gutenberg plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'class' parameter of the 'wpfaqblock' shortcode in all versions up to, and including, 1.1 due to insufficient input sanitization and output escaping on user supplied attrib…

📅 Published: March 21, 2026, 3:26 a.m. 🔄 Last Modified: April 22, 2026, 9:32 p.m.

3.8

CVSS3.1

CVE-2026-2290 - Post Affiliate Pro <= 1.28.0 - Authenticated (Administrator+) Server-Side Request Forgery via 'Post…

The Post Affiliate Pro plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 1.28.0. This makes it possible for authenticated attackers, with Administrator-level access, to make web requests to initiate arbitrary outbound requests from the applicati…

📅 Published: March 21, 2026, 3:26 a.m. 🔄 Last Modified: April 22, 2026, 9:32 p.m.
Total resulsts: 349182
Page 999 of 34,919
« previous page » next page
Filters