Skip to content
Threat Feed

Tag

Plugin-Vulnerability

25 briefs RSS
critical advisory

Meta Box AIO Plugin Vulnerable to Unauthenticated Post Deletion via CVE-2026-14488

Unauthenticated attackers can exploit a Missing Authorization vulnerability (CVE-2026-14488) in the MB Frontend Submission extension of the Meta Box AIO plugin for WordPress, affecting versions up to 3.8.0, to delete arbitrary posts and pages by injecting a crafted post ID via a GET parameter.

Meta Box AIO plugin +1 wordpress missing-authorization web-application plugin-vulnerability cve
1r 1t 1c
high advisory

WordPress Database for CF7 Plugin Stored Cross-Site Scripting (CVE-2026-13425)

The Database for CF7 plugin for WordPress is vulnerable to stored Cross-Site Scripting (XSS) via Array Form Field Values, allowing unauthenticated attackers to inject arbitrary web scripts by sending specially crafted array-structured input to the Contact Form 7 REST API endpoint /wp-json/contact-form-7/v1/contact-forms/{id}/feedback, which are insufficiently sanitized and executed when a user accesses an affected page.

Database for CF7 plugin < 1.2.7 web-application wordpress xss cve-2026-13425 stored-xss plugin-vulnerability
1r 2t 1c
medium advisory

The Demi WordPress Plugin Vulnerable to Arbitrary Directory Deletion (CVE-2026-14490)

Unauthenticated attackers can exploit CVE-2026-14490 in The Demi - One Click Demo Import, WP Backup & Site Migration WordPress plugin (versions up to and including 0.0.7) to achieve arbitrary directory deletion by retrieving a publicly exposed HMAC signing key and forging valid requests to a vulnerable AJAX handler.

The Demi – One Click Demo Import, WP Backup & Site Migration plugin <= 0.0.7 wordpress plugin-vulnerability arbitrary-deletion web-vulnerability
2t 1c
critical advisory

Critical Code Injection Vulnerability in WordPress Customer Support Ticket System & Helpdesk Plugin (CVE-2026-15011)

A critical code injection vulnerability, CVE-2026-15011, affects the Customer Support Ticket System & Helpdesk plugin for WordPress versions up to and including 6.0.5, allowing unauthenticated attackers to invoke arbitrary parameterless PHP functions via the 'path' parameter, potentially disrupting site functionality or exposing sensitive information without prior authentication.

Customer Support Ticket System & Helpdesk plugin for WordPress <= 6.0.5 code-injection wordpress web-application plugin-vulnerability php
1t 1c
high advisory

PraisonAI Plugin Manager Remote Code Execution Vulnerability (CVE-2026-61446)

PraisonAI (praisonaiagents) versions prior to 1.6.78 are susceptible to a remote code execution vulnerability residing in the plugin manager's handling of Python files, where it loads and executes arbitrary .py files from specific plugin directories without implementing crucial security measures, allowing an attacker who can place a malicious .py file to achieve arbitrary code execution upon plugin system initialization.

praisonaiagents < 1.6.78 remote-code-execution plugin-vulnerability python supply-chain path-traversal
1t 1c
high advisory

CVE-2026-13114: Stored Cross-Site Scripting in WordPress Motors - Car Dealership & Classified Listings Plugin

An unauthenticated attacker can exploit CVE-2026-13114, a Stored Cross-Site Scripting vulnerability in the WordPress Motors - Car Dealership & Classified Listings Plugin versions up to 1.4.112, by injecting arbitrary web scripts into comment content or user biographical information, leading to client-side code execution when a victim views the affected page.

Motors – Car Dealership & Classified Listings Plugin wordpress xss web-application cve plugin-vulnerability
2t 1c
high advisory

Arbitrary Post Creation and Stored XSS in Squirrly SEO Plugin for WordPress

An arbitrary post creation and stored cross-site scripting (XSS) vulnerability exists in The SEO Plugin by Squirrly SEO for WordPress, affecting versions up to and including 14.0.0. This flaw, caused by an API token leak and insufficient input sanitization/output escaping, allows unauthenticated attackers to create arbitrary posts. If the Advanced Custom Fields plugin is also installed, attackers can inject arbitrary web scripts into pages that execute when a user accesses an injected page, leading to potential client-side compromise.

The SEO Plugin by Squirrly SEO +1 wordpress plugin-vulnerability xss arbitrary-post-creation
1r 3t 1c
high advisory

CVE-2026-15293 - WP Business Intelligence Lite Plugin Authorization Bypass Leading to Privilege Escalation

The WP Business Intelligence Lite plugin for WordPress contains an authorization bypass vulnerability (CVE-2026-15293) affecting all versions up to and including 3.2.0, allowing authenticated attackers with Subscriber-level access or higher to modify stored SQL queries which can lead to arbitrary SQL execution and privilege escalation when an administrator views the modified query.

WP Business Intelligence Lite plugin wordpress plugin-vulnerability authorization-bypass privilege-escalation web-application cve
2t 1c
high advisory

CVE-2026-14489: WHMCS Bridge Plugin Arbitrary File Upload Leads to RCE

Authenticated attackers with Custom-level access or higher can exploit CVE-2026-14489, a missing file type validation vulnerability (CWE-434) in the `connect()` function of the WHMCS Bridge plugin for WordPress versions up to and including 6.9, to upload arbitrary files, potentially leading to remote code execution.

WHMCS Bridge <= 6.9 wordpress arbitrary-file-upload remote-code-execution web-vulnerability plugin-vulnerability
3t 1c
critical advisory

CVE-2026-14345: Unauthenticated Remote Code Execution in WPFunnels WordPress Plugin

An unauthenticated remote code execution vulnerability (CVE-2026-14345) exists in the WPFunnels – Funnel Builder for WooCommerce with Checkout & One Click Upsell plugin for WordPress, affecting versions up to and including 3.12.7, allowing attackers to inject malicious PHP code into a log file via the 'postData' parameter, which is then executed when an administrator views the log.

WPFunnels – Funnel Builder for WooCommerce with Checkout & One Click Upsell plugin <= 3.12.7 web-exploit rce wordpress plugin-vulnerability
2t 1c
critical threat

CVE-2026-8380: WordPress Frontend File Manager Arbitrary Post Deletion

CVE-2026-8380 is a critical authorization bypass vulnerability in the WordPress Frontend File Manager plugin <= 23.6 that allows authenticated low-privilege users, or unauthenticated users with guest uploads enabled, to permanently delete arbitrary WordPress posts, pages, attachments, and custom post types.

Frontend File Manager cve wordpress authorization privilege-escalation arbitrary-deletion plugin-vulnerability
2r 1t
high threat

CVE-2026-9200: WordPress Query Shortcode Plugin Vulnerable to Local File Inclusion

The Query Shortcode plugin for WordPress is vulnerable to Local File Inclusion (CVE-2026-9200) in versions up to 0.2.1, allowing authenticated attackers with contributor-level access and above to include and execute arbitrary PHP files on the server, potentially leading to privilege escalation and code execution.

Query Shortcode plugin <= 0.2.1 local-file-inclusion wordpress plugin-vulnerability CVE-2026-9200
2r 2t 1c
medium threat

CVE-2026-9011: Ditty WordPress Plugin Authorization Bypass Vulnerability

The Ditty – Responsive News Tickers, Sliders, and Lists plugin for WordPress versions up to 3.1.65 is vulnerable to an authorization bypass (CVE-2026-9011) that allows unauthenticated attackers to retrieve the full content of non-public Dittys by exploiting the ditty_init AJAX endpoint.

Ditty – Responsive News Tickers, Sliders, and Lists plugin <= 3.1.65 cve cve-2026-9011 wordpress authorization bypass plugin vulnerability cloud
2r 1t 1c
critical advisory

Easy Elements for Elementor Plugin Privilege Escalation (CVE-2026-9018)

CVE-2026-9018 allows unauthenticated attackers to escalate privileges to administrator by exploiting a vulnerability in the Easy Elements for Elementor plugin, which lacks proper input validation during user registration.

Easy Elements for Elementor – Addons & Website Templates plugin privilege-escalation wordpress plugin-vulnerability cve
2r 1t 1c
high advisory

Contest Gallery WordPress Plugin SQL Injection Vulnerability (CVE-2026-8912)

The Contest Gallery plugin for WordPress is vulnerable to SQL Injection via the 'form_input' parameter in versions up to 28.1.6, allowing unauthenticated attackers to extract sensitive information from the database.

Contest Gallery plugin for WordPress sql injection cve-2026-8912 wordpress plugin vulnerability
2r 1t 1c
critical advisory

InfusedWoo Pro Plugin for WordPress Authorization Bypass (CVE-2026-6512)

The InfusedWoo Pro plugin for WordPress is vulnerable to an authorization bypass (CVE-2026-6512) in versions up to 5.1.2, allowing unauthenticated attackers to delete posts, pages, products, orders, comments, and change post statuses.

InfusedWoo Pro plugin for WordPress <= 5.1.2 cve wordpress authorization bypass web application plugin vulnerability
2r 1t 1c
critical threat

CVE-2021-47940: WordPress Download From Files Plugin Arbitrary File Upload

WordPress Plugin Download From Files version 1.48 and earlier contains an arbitrary file upload vulnerability (CVE-2021-47940) that allows unauthenticated attackers to upload malicious files by exploiting the AJAX fileupload action.

Download From Files Plugin <= 1.48 cve-2021-47940 wordpress file upload rce plugin vulnerability
1r 1t 1c
high advisory

Salon Booking System WordPress Plugin Arbitrary File Read Vulnerability

The Salon Booking System WordPress plugin is vulnerable to arbitrary file read, allowing unauthenticated attackers to exfiltrate local files by manipulating file-field values in booking confirmation emails.

Salon Booking System – Free Version plugin for WordPress <= 10.30.25 arbitrary-file-read wordpress plugin-vulnerability cve
2r 1t 1c
high advisory

WP Mail Gateway Plugin Vulnerability Leads to Privilege Escalation

The WP Mail Gateway plugin for WordPress is vulnerable to unauthorized access due to a missing capability check, allowing authenticated attackers to modify SMTP settings and escalate privileges.

WP Mail Gateway plugin wordpress privilege-escalation plugin-vulnerability
2r 1t 1c
critical advisory

WordPress Temporary Login Plugin Authentication Bypass (CVE-2026-7567)

The Temporary Login plugin for WordPress versions up to 1.0.0 is vulnerable to authentication bypass due to improper input validation, allowing unauthenticated attackers to log in as arbitrary temporary users by sending a specially crafted GET request.

Temporary Login plugin authentication bypass wordpress plugin vulnerability cve-2026-7567 cloud
2r 1t 1c
critical advisory

WordPress Create DB Tables Plugin Authorization Bypass Vulnerability (CVE-2026-4119)

The Create DB Tables plugin for WordPress versions 1.2.1 and earlier is vulnerable to an authorization bypass, allowing authenticated users to create and delete database tables without proper checks, potentially leading to complete site destruction.

wordpress authorization-bypass plugin-vulnerability cve-2026-4119
2r 3t 1c
high advisory

Media Library Assistant WordPress Plugin SQL Injection Vulnerability

The Media Library Assistant WordPress plugin through version 3.34 is vulnerable to SQL injection, allowing attackers to manipulate database queries.

sql-injection wordpress plugin-vulnerability
2r 1t 1c
critical advisory

Contest Gallery WordPress Plugin Authentication Bypass Vulnerability (CVE-2026-4021)

CVE-2026-4021 describes an authentication bypass vulnerability in the Contest Gallery plugin for WordPress, allowing unauthenticated attackers to gain admin access by manipulating the user activation key and using an AJAX login endpoint.

wordpress authentication-bypass plugin-vulnerability cve-2026-4021
2r 3t
high advisory

WordPress Drag and Drop Multiple File Upload Plugin Path Traversal Vulnerability

The Drag and Drop Multiple File Upload for Contact Form 7 WordPress plugin is vulnerable to path traversal, allowing unauthenticated attackers to read arbitrary files within the 'wp-content' directory readable by the web server process.

Drag and Drop Multiple File Upload for Contact Form 7 wordpress path-traversal arbitrary-file-read plugin-vulnerability
2r 1t 1c
critical advisory

HKUDS OpenHarness Plugin Management Vulnerability (CVE-2026-6819)

HKUDS OpenHarness before PR #156 allows remote attackers with channel layer access to manage plugin lifecycle commands, enabling unauthorized plugin installation and activation.

OpenHarness cve-2026-6819 plugin-vulnerability remote-code-execution
2r 3t 1c