Skip to content
Threat Feed

Vendor

Wordpress

268 briefs RSS
high advisory

Sensitive Information Exposure in YS LeadGen WordPress Plugin

The YS LeadGen plugin for WordPress versions 2.1.4 and earlier contains an unauthenticated information exposure vulnerability allowing the retrieval of form submission data.

YS LeadGen web-application sensitive-information-exposure wordpress
1r 1t 1c
high advisory

Remote Code Execution in WP Photo Album Plus Plugin

The WP Photo Album Plus plugin for WordPress contains an RCE vulnerability (CVE-2026-87909) allowing authenticated attackers with subscriber-level access to execute arbitrary commands through improper sanitization of ImageMagick arguments.

WP Photo Album Plus
2t 1c
high advisory

Stored XSS in Asset CleanUp: Page Speed Booster WordPress Plugin

Asset CleanUp: Page Speed Booster versions 1.4.0.5 and earlier are vulnerable to stored cross-site scripting due to insufficient input sanitization of comment content.

Asset CleanUp: Page Speed Booster
1t 1c
high advisory

Arbitrary Shortcode Execution in WP Recipe Maker Plugin

The WP Recipe Maker plugin for WordPress (<= 10.8.1) is vulnerable to arbitrary shortcode execution due to recursive do_shortcode calls on user-supplied metadata fields.

PoC WP Recipe Maker web-vulnerability wordpress cve-2026-89274
1t 1c updated
high advisory

Stored XSS in Popup Maker WordPress Plugin (CVE-2026-87915)

The Popup Maker WordPress plugin is vulnerable to Stored Cross-Site Scripting via the 'values[Name]' parameter, allowing unauthenticated attackers to inject malicious scripts that execute in the wp-admin dashboard.

Popup Maker
2t 1c
high advisory

Booking Calendar Plugin Privilege Escalation via AJAX Parameter Injection

The Booking Calendar plugin for WordPress is vulnerable to privilege escalation (CVE-2026-92619) allowing authenticated Editors to modify arbitrary site settings and create administrative accounts.

Booking Calendar privilege-escalation wordpress web-application
1t 1c
high advisory

Authorization Bypass in WordPress Filter Gallery Plugin

The Filter Gallery WordPress plugin contains an authorization bypass vulnerability (CVE-2026-89413) allowing authenticated users with low-level privileges to delete arbitrary gallery records by omitting mandatory nonce checks.

Filter Gallery
1t 1c
high advisory

Arbitrary File Upload Vulnerability in Paid Downloads WordPress Plugin

An unauthenticated arbitrary file upload vulnerability in the Paid Downloads plugin (<= 3.15) allows remote attackers to execute code by bypassing file type validation via the admin_request_handler function.

Paid Downloads web-vulnerability wordpress remote-code-execution
1r 1t 1c
critical advisory

CVE-2026-87796 - Arbitrary File Upload in Multi Uploader for Gravity Forms

The Multi Uploader for Gravity Forms WordPress plugin is vulnerable to unauthenticated arbitrary file upload due to improper validation in the move_file function, enabling potential remote code execution.

PoC Multi Uploader for Gravity Forms
1t 1c updated
critical advisory

Authorization Bypass in TrueBooker WordPress Plugin

The TrueBooker Appointment Booking and Scheduler System plugin for WordPress contains an authorization bypass vulnerability allowing unauthenticated attackers to modify arbitrary user email addresses and facilitate account takeover.

TrueBooker – Appointment Booking and Scheduler System wordpress vulnerability authorization-bypass
2t 1c
high advisory

Generative Threat Groups Automating Cyber Operations with AI

Anthropic has documented multiple threat actors leveraging AI models to automate end-to-end cyberattack workflows including reconnaissance, vulnerability research, credential harvesting, and large-scale data exfiltration.

AWS EC2 +2 ai-threat cyber-espionage surveillance reconnaissance data-exfiltration
3t
high advisory

Stored XSS in Simple Ajax Chat WordPress Plugin via CVE-2026-81825

The Simple Ajax Chat plugin for WordPress contains a stored cross-site scripting vulnerability in versions <= 20260811, allowing unauthenticated attackers to inject malicious scripts due to exposed nonces and insufficient input sanitization.

Simple Ajax Chat – Add a Fast, Secure Chat Box xss web-security wordpress vulnerability
2t 1c
high advisory

Stored XSS in The Vigilant Security Plugin for WordPress

The Vigilant security plugin for WordPress version 2.10.2 and earlier is vulnerable to Stored Cross-Site Scripting via the User-Agent header, allowing unauthenticated attackers to execute arbitrary scripts in the dashboard.

The Vigilant – 100% Free Security Suite: Firewall, 2FA, Login, Headers, Scanner… xss wordpress cve-2026-81754
1t 1c
high advisory

Stored XSS Vulnerability in WP Photo Album Plus Plugin

An unauthenticated stored XSS vulnerability in WP Photo Album Plus versions 9.2.08.003 and earlier allows attackers to inject malicious scripts via the HTTP_X_FORWARDED_FOR header, which is logged without sanitization.

WP Photo Album Plus web-application xss wordpress
1r 2t 1c
high advisory

SQL Injection in Sticky Chat Widget WordPress Plugin

The Sticky Chat Widget plugin for WordPress (<= 1.4.2) is vulnerable to unauthenticated SQL injection via the 'scw_save_form_data' AJAX action, allowing potential exfiltration of sensitive database information.

Sticky Chat Widget web-application-vulnerability sqli wordpress
1r 1t 1c
high advisory

Stored Cross-Site Scripting in Sidebar Manager Light Plugin

The Sidebar Manager Light plugin for WordPress is vulnerable to Stored Cross-Site Scripting due to insufficient input sanitization of the sbm_description parameter, allowing unauthenticated attackers to execute arbitrary scripts in victim browsers.

Sidebar Manager Light wordpress xss web-vulnerability
1t 1c
high advisory

Directory Traversal in Direct Download for WooCommerce Plugin

An unauthenticated directory traversal vulnerability in the Direct Download for WooCommerce plugin (v1.19 and below) allows attackers to read arbitrary files from the underlying server.

Direct Download for WooCommerce wordpress web-application cve directory-traversal
1t 1c
high advisory

Privilege Escalation Vulnerability in Bulk Password Reset WordPress Plugin

The Bulk Password Reset WordPress plugin, versions 1.3.3 and earlier, contains a privilege escalation vulnerability allowing authenticated users to perform unauthorized account takeovers.

Bulk Password Reset wordpress vulnerability privilege-escalation
2t 1c
critical advisory

Unauthenticated Remote Code Execution in Drag and Drop File Upload for Elementor Forms

An arbitrary file upload vulnerability in the Drag and Drop File Upload for Elementor Forms WordPress plugin allows unauthenticated attackers to execute arbitrary code via MIME type validation bypass.

PoC Drag and Drop File Upload for Elementor Forms vulnerability rce wordpress web-application
1r 2t 1c updated
high advisory

Stored Cross-Site Scripting in WPBot WordPress Plugin

The WPBot - AI ChatBot for Live Support, Lead Generation, AI Services plugin for WordPress contains a Stored Cross-Site Scripting (XSS) vulnerability in versions up to 8.7.3, allowing unauthenticated attackers to execute arbitrary web scripts.

WPBot – AI ChatBot for Live Support, Lead Generation, AI Services xss web-application-vulnerability wordpress cve-2026-83593
1r 1t 1c
high advisory

Stored XSS in Repeater Fields for Gravity Forms Plugin

The Repeater Fields for Gravity Forms plugin for WordPress is vulnerable to Stored XSS due to improper sanitization of multi-input sub-fields, allowing unauthenticated attackers to execute arbitrary JavaScript.

Repeater Fields for Gravity Forms xss web-vulnerability wordpress
1c
medium advisory

Unauthenticated Stripe Credential Overwrite in WordPress Event Tickets Plugin

The Event Tickets and Registration plugin for WordPress (v5.27.4 and earlier) contains an authorization flaw in the Stripe OAuth return endpoint, allowing unauthenticated attackers to hijack site payment processing.

Event Tickets and Registration web-application wordpress financial-fraud cve-2026-3174
1t 1c
high advisory

Stored Cross-Site Scripting in User Profile Builder Plugin for WordPress

The User Profile Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting (XSS) due to insufficient input sanitization, allowing unauthenticated attackers to execute arbitrary scripts via the 'Biographical Info' field.

User Profile Builder – Beautiful User Registration Forms, User Profiles & User Role Editor wordpress xss web-security
2t 1c
critical advisory

Unauthenticated Arbitrary File Upload in Drag and Drop Multiple File Upload for WooCommerce

The Drag and Drop Multiple File Upload for WooCommerce plugin for WordPress versions 1.1.6 and below contains an unauthenticated arbitrary file upload vulnerability, allowing attackers to achieve remote code execution.

Drag and Drop Multiple File Upload for WooCommerce wordpress file-upload rce vulnerability
1r 1t 1c
high advisory

Unauthenticated Blind SQL Injection in WP Fastest Cache

WP Fastest Cache versions 1.2.2 and earlier contain a blind SQL injection vulnerability allowing unauthenticated attackers to exfiltrate sensitive user data via the wordpress_logged_in cookie.

WP Fastest Cache sqli vulnerability wordpress plugin
1r 2t 1c
high advisory

Privilege Escalation Vulnerability in Nokri Job Board WordPress Theme

The Nokri Job Board WordPress theme (<= 1.6.4) is vulnerable to privilege escalation via a missing capability check in the 'nokri_account_member_permissions' function, allowing authenticated subscribers to escalate access.

Nokri – Job Board WordPress Theme wordpress privilege-escalation web-application-vulnerability
1t 1c
critical advisory

Unauthenticated Hook Injection in The Post Grid and Gutenberg Blocks Plugin

The Post Grid and Gutenberg Blocks - ComboBlocks plugin for WordPress contains an unauthenticated hook injection vulnerability in versions 2.2.32 to 2.3.1 that allows remote attackers to execute arbitrary actions via hook functions.

The Post Grid and Gutenberg Blocks – ComboBlocks wordpress cve web-application injection
1t 1c
high advisory

Stored Cross-Site Scripting in WordPress QuickCal Plugin

The QuickCal WordPress plugin is vulnerable to unauthenticated Stored Cross-Site Scripting (XSS) via custom field parameters, allowing attackers to execute arbitrary scripts in the context of site users.

QuickCal wordpress xss cve-2026-15984
1t 1c
high advisory

CVE-2026-75528 Stored XSS in Broken Link Checker WordPress Plugin

The Broken Link Checker WordPress plugin up to version 2.4.13 is vulnerable to Stored Cross-Site Scripting, allowing unauthenticated attackers to execute malicious scripts in the administrative session context.

Broken Link Checker
1t 1c
critical advisory

Arbitrary File Deletion Vulnerability in SigmaForms Pro

The SigmaForms Pro WordPress plugin is vulnerable to arbitrary file deletion via path traversal in the delete_submission_files function, allowing unauthenticated attackers to delete critical server files and potentially achieve remote code execution.

SigmaForms Pro – AI Generated Forms wordpress vulnerability arbitrary-file-deletion
2t 1c
high advisory

Arbitrary File Deletion in WP File Download Plugin

The WP File Download plugin for WordPress contains a path traversal vulnerability in its file save and delete functions, allowing authenticated subscribers to delete arbitrary files on the server, potentially leading to remote code execution.

WP File Download
1r 2t 1c
high advisory

Stored XSS Vulnerability in Listdom WordPress Plugin

An unauthenticated stored XSS vulnerability in the Listdom WordPress plugin allows attackers to inject arbitrary scripts when specific premium add-ons are enabled.

Listdom: AI-powered Business Directory with Classifieds Ads Listings xss wordpress web-vulnerability
2t 1c
high advisory

Stored Cross-Site Scripting Vulnerability in Affiliate Super Assistent WordPress Plugin

The Affiliate Super Assistent plugin for WordPress contains a Stored Cross-Site Scripting (XSS) vulnerability via the doCommentShortcode function, allowing unauthenticated attackers to execute arbitrary scripts in the context of a victim's session.

Affiliate Super Assistent web-vulnerability xss wordpress
2t 1c
critical advisory

Unauthenticated Remote Code Execution in WPLP Cookie Consent Plugin

The WPLP Cookie Consent WordPress plugin is vulnerable to unauthenticated arbitrary file upload due to improper authorization and missing file type validation, enabling remote code execution.

WPLP Cookie Consent – Cookie Banner & Consent Management for GDPR, CCPA & Google Consent Mode wordpress remote-code-execution cve-2026-75865
2t 1c
high advisory

Information Exposure in Keep Backup Daily WordPress Plugin

The Keep Backup Daily plugin for WordPress before 2.1.4 contains a vulnerability allowing unauthenticated attackers to trigger database backups and retrieve them via predictable filenames.

Keep Backup Daily wordpress vulnerability web-application data-exfiltration
1r 2t 1c
critical advisory

Unauthenticated Privilege Escalation in Events Manager Plugin

An unauthenticated privilege escalation vulnerability (CVE-2026-18366) in the Events Manager WordPress plugin allows attackers to compromise user accounts and escalate privileges via REST API exploitation.

Events Manager
1r 2t 1c
critical advisory

Authentication Bypass in MyHome Core Plugin for WordPress

The MyHome Core plugin for WordPress is vulnerable to authentication bypass via insecure AJAX handlers, allowing unauthenticated attackers to hijack arbitrary user accounts.

MyHome Core plugin wordpress authentication-bypass vulnerability
1r 1t 1c
critical advisory

Privilege Escalation in Custom User Registration Fields for WooCommerce Plugin

An unauthenticated privilege escalation vulnerability (CVE-2026-15369) in Custom User Registration Fields for WooCommerce allows remote attackers to assign arbitrary user roles, including Administrator, by injecting malicious parameters during the checkout process.

Custom User Registration Fields for WooCommerce web wordpress privilege-escalation woocommerce
1r 1t 1c
high advisory

Authentication Bypass in SAML Single Sign On - SSO Login Plugin for WordPress

An unauthenticated authentication bypass vulnerability in the SAML Single Sign On - SSO Login plugin allows attackers to overwrite the IdP signing certificate and forge administrative sessions.

SAML Single Sign On – SSO Login cve-2026-75807 authentication-bypass wordpress
1t 1c
critical advisory

Remote Code Execution in Sigma Forms Pro Plugin for WordPress

The Sigma Forms Pro plugin for WordPress is vulnerable to unauthenticated remote code execution due to improper validation of file uploads and insecure capability management within the handle_form_submission function.

Sigma Forms Pro web-application-vulnerability wordpress rce file-upload
1r 1t 1c
high advisory

Stored XSS and RCE vulnerability in One User Avatar WordPress Plugin

The One User Avatar | User Profile Picture WordPress plugin versions 2.5.4 and earlier contain a stored XSS and RCE vulnerability via improper file type validation in the avatar upload process.

One User Avatar | User Profile Picture
2t 1c
high advisory

Unauthenticated SQL Injection in WooCommerce Lottery Plugin

The WooCommerce Lottery plugin for WordPress is vulnerable to unauthenticated time-based SQL injection via the 'orderby' and 'order' GET parameters, allowing attackers to extract sensitive database information.

WooCommerce Lottery web-vulnerability sqli wordpress
1r 1t 1c
high advisory

PHP Object Injection in Kalles Addons for WordPress

The Kalles Addons plugin for WordPress (<= 1.0.6) is vulnerable to unauthenticated PHP Object Injection, which may allow remote code execution or file operations if a compatible POP chain exists in the environment.

Kalles Addons
1t 1c
high advisory

Authorization Bypass in Security Hardener Plugin for WordPress

The Security Hardener plugin for WordPress contains an authorization bypass vulnerability in versions 2.4.4 and earlier that allows authenticated subscribers to escalate privileges to administrator.

Security Hardener
1r 2t 1c
high advisory

Unauthenticated Checkout Price Bypass in Advanced Product Fields for WooCommerce

The Advanced Product Fields for WooCommerce plugin for WordPress is vulnerable to improper input validation, allowing unauthenticated users to bypass mandatory paid add-ons during checkout.

Advanced Product Fields
1t 1c
critical advisory

Unauthenticated SSRF in Mailgun for WordPress Plugin

An unauthenticated SSRF vulnerability in the Mailgun for WordPress plugin (<= 2.2.0) allows attackers to perform unauthorized API requests and potentially intercept password reset emails, leading to account takeover.

Mailgun for WordPress
2t 1c
high advisory

Privilege Escalation in WPeMatico RSS Feed Fetcher Plugin for WordPress

An unauthenticated or low-privilege authenticated user can leverage a missing capability check in the wpematico_import_settings function to modify site options, enabling unauthorized privilege escalation.

WPeMatico RSS Feed Fetcher wordpress privilege-escalation vulnerability
1t 1c
high advisory

Unauthenticated Remote Code Execution in Elementor Pro

Elementor Pro versions 4.2.1 and below contain a critical file upload vulnerability (CVE-2026-32475) that allows unauthenticated attackers to achieve remote code execution by bypassing extension validation.

Elementor Pro +1 web-vulnerability wordpress remote-code-execution cve-2026-32475
1r 2t updated
critical advisory

Unauthenticated Account Takeover in TrueBooker WordPress Plugin

The TrueBooker plugin for WordPress up to version 1.2.6 is vulnerable to an unauthenticated account takeover via a flawed AJAX handler that allows attackers to modify user email addresses.

TrueBooker – Appointment Booking and Scheduler System
1r 2t 1c
high advisory

Authenticated Remote Code Execution in WCPOS WordPress Plugin

The WCPOS plugin for WooCommerce is vulnerable to authenticated remote code execution via a template engine misconfiguration that allows injection and execution of arbitrary PHP code.

WCPOS – Point of Sale wordpress rce web-application cve-2026-17581
2t 1c
high advisory

Remote Code Execution in Query Wrangler WordPress Plugin

An unauthenticated-accessible AJAX handler in Query Wrangler versions 1.5.57 and below allows authenticated attackers to perform remote code execution via object injection and callback manipulation.

Query Wrangler wordpress rce plugin-vulnerability
1r 2t 1c
high advisory

Arbitrary File Deletion in Link Library Plugin for WordPress

An unauthenticated arbitrary file deletion vulnerability in the Link Library WordPress plugin (CVE-2026-18855) allows attackers to trigger server-side file removal via manipulated input during standard administrative moderation.

Link Library
2t 1c
critical advisory

CVE-2026-19598: Authorization Bypass in Pods Plugin for WordPress

The Pods plugin for WordPress contains an authorization bypass in its AJAX router that allows unauthenticated attackers to escalate privileges or take over administrative accounts.

PoC Pods – Custom Content Types and Fields
2t 1c updated
critical advisory

Account Takeover in TrueBooker WordPress Plugin via Unauthenticated AJAX

The TrueBooker WordPress plugin contains an unauthenticated account takeover vulnerability (CVE-2026-16142) allowing attackers to modify arbitrary user email addresses and facilitate account hijacking.

TrueBooker
1r 2t 1c
high advisory

Privilege Escalation in Wholesale Market WordPress Plugin

The Wholesale Market plugin for WordPress up to version 2.2.2 contains a privilege escalation vulnerability via the ced_wholesale_request_send AJAX action that allows authenticated users to elevate to Administrator.

Wholesale Market wordpress privilege-escalation web-application
1r 1t 1c
critical advisory

Authentication Bypass in User Profile Builder Plugin for WordPress (CVE-2026-15826)

An authentication bypass vulnerability in the User Profile Builder plugin for WordPress versions 3.16.4 and below allows unauthenticated attackers to hijack the site administrator account via type confusion.

User Profile Builder
1t 1c
high advisory

Arbitrary File Upload in MaxUpload WordPress Plugin

The MaxUpload WordPress plugin is vulnerable to unauthenticated remote code execution via insufficient filename validation during chunk assembly.

MaxUpload – Big File Uploads – Increase Maximum File Upload Size
1r 2t 1c
critical advisory

Unauthenticated Arbitrary File Deletion in RapiSafe WordPress Plugin

The RapiSafe WordPress plugin contains a vulnerability in its AJAX upload handler allowing unauthenticated attackers to delete arbitrary server files, potentially leading to remote code execution.

RapiSafe – Secure Multi File Upload for Contact Form 7
1r 1c
high advisory

WordPress Authenticated Remote Code Execution Vulnerability

A remote authenticated attacker can exploit a vulnerability in WordPress to execute arbitrary code, requiring immediate focus on monitoring administrative actions and plugin modifications.

WordPress +1
2t 1c
critical advisory

Authorization Bypass in AI Copilot - Content Generator WordPress Plugin

An authorization bypass vulnerability in the AI Copilot - Content Generator WordPress plugin allows unauthenticated attackers to create administrator accounts and achieve full site takeover via malformed workflow execution.

AI Copilot – Content Generator web-application wordpress cve-2026-14526 auth-bypass
1r 2t 1c
high advisory

Multiple Vulnerabilities in WordPress

Multiple vulnerabilities, including CVE-2026-64638, affect WordPress versions prior to 7.0.3, enabling privilege escalation, data breaches, and Server-Side Request Forgery (SSRF).

PoC WordPress +1 cve web-application patch-management
1c 1i
high advisory

Arbitrary File Deletion Vulnerability in WordPress File Manager Plugin

The WordPress File Manager plugin (versions 6.0-6.9) contains an arbitrary file deletion vulnerability allowing authenticated attackers to delete critical server files and achieve remote code execution.

File Manager web-application-vulnerability wordpress remote-code-execution arbitrary-file-deletion
1r 2t 1c
high threat

Arbitrary File Deletion in Content Egg Plugin for WordPress

The Content Egg plugin for WordPress is vulnerable to a path traversal flaw in the 'img_file' parameter, allowing authenticated attackers with author-level permissions to delete arbitrary files on the web server.

exploited Content Egg – Affiliate Product Importer & Price Comparison
2t 1c
high advisory

CVE-2026-18881: SQL Injection in TableOn WordPress Plugin

An unauthenticated SQL injection vulnerability in the TableOn WordPress plugin allows attackers to extract sensitive database information via the filter_data[comment_count] parameter.

TableOn – WordPress Posts Table Filterable
1r 1t 1c
high advisory

OS Command Injection in Backup Migration WordPress Plugin

The Backup Migration WordPress plugin is vulnerable to authenticated OS command injection in versions up to 2.1.5.1, allowing attackers with administrative capabilities to execute arbitrary shell commands via the restoreBackup AJAX handler.

Backup Migration plugin
1r 1t 2c
high advisory

Unauthenticated Stripe Credential Modification in WPFormify WordPress Plugin

An unauthenticated vulnerability in the WPFormify plugin allows attackers to overwrite or delete Stripe API credentials via missing capability checks on admin-post.php.

WPFormify – Stripe Payments with Form and Checkout
1r 1t 1c
high advisory

CVE-2026-6020 Arbitrary Function Execution in ShopLentor Plugin

The ShopLentor WordPress plugin is vulnerable to authenticated remote code execution via insecure deserialization of user input in the REST API handler, allowing administrators to execute arbitrary PHP functions.

ShopLentor web-application wordpress cve-2026-6020 rce
1r 1t 1c
high advisory

Sensitive Information Exposure in Page and Post Restriction WordPress Plugin

The Page and Post Restriction plugin for WordPress versions 1.4.0 and earlier fails to enforce global privacy settings on REST API endpoints, enabling unauthenticated access to restricted content.

Page and Post Restriction
1r 1t 1c
high advisory

Unauthenticated Arbitrary Media Deletion in Multi Uploader for Gravity Forms

The Multi Uploader for Gravity Forms WordPress plugin is vulnerable to unauthenticated arbitrary media deletion via missing capability checks and exposed CSRF nonces.

Multi Uploader for Gravity Forms wordpress cve-2026-5581 arbitrary-file-deletion web-application
1r 1t 1c
high advisory

Unauthenticated Data Modification in Easy Post Submission Plugin

The Easy Post Submission plugin for WordPress is vulnerable to unauthorized data modification via an unauthenticated AJAX action, allowing attackers to alter or unpublish existing posts.

Easy Post Submission
1r 1t 1c
high advisory

Stored XSS Vulnerability in VikRentItems WordPress Plugin

The VikRentItems WordPress plugin contains a stored XSS vulnerability in the checkout booking form allowing unauthenticated attackers to execute arbitrary scripts in the administrative backend.

VikRentItems – Flexible Rental Management System
1t 1c
high advisory

Directory Traversal Vulnerability in User Access Manager for WordPress

An unauthenticated directory traversal vulnerability in the User Access Manager WordPress plugin (CVE-2026-18352) allows attackers to read arbitrary files by bypassing access controls via the uamgetfile parameter.

User Access Manager
1r 2t 1c
critical advisory

Authentication Bypass Vulnerability in WooCommerce Social Login Plugin

The WooCommerce - Social Login plugin for WordPress contains an authentication bypass vulnerability (CVE-2026-8457) that allows unauthenticated attackers to log in as any user, including administrators, via forged Apple ID tokens.

WooCommerce - Social Login
2t 1c
high advisory

Arbitrary File Deletion in Nex Forms Plugin for WordPress

The Nex Forms - Ultimate Form Builder - Lite plugin for WordPress is vulnerable to arbitrary file deletion via path traversal, allowing authenticated attackers to delete critical system files.

Nex Forms – Ultimate Form Builder – Lite wordpress arbitrary-file-deletion path-traversal web-application
1t 1c
high advisory

CVE-2026-15988: CSRF Vulnerability in AI Engine WordPress Plugin

The AI Engine WordPress plugin contains a CSRF vulnerability in the reauth_for_authorize function allowing unauthenticated attackers to create administrator accounts.

The AI Engine – The Chatbot, AI Framework & MCP for WordPress
1r 2t 1c
critical advisory

Authentication Bypass in Single Sign On For TNG WordPress Plugin

An unauthenticated password reset vulnerability in the Single Sign On For TNG plugin (CVE-2026-15964) allows attackers to perform full site takeover by bypassing AJAX nonce protections.

PoC Single Sign On For TNG +1
1r 1c 1i updated
critical advisory

Unauthenticated Arbitrary File Deletion in FormGent WordPress Plugin

The FormGent WordPress plugin is vulnerable to unauthorized arbitrary file deletion via an unauthenticated REST API endpoint, potentially allowing attackers to delete critical files like wp-config.php and achieve site takeover.

FormGent
1r 1c
high advisory

Privilege Escalation in Subscriptions for WooCommerce Plugin

The Subscriptions for WooCommerce plugin for WordPress is susceptible to privilege escalation allowing authenticated users with Contributor access to promote themselves to Administrator via insecure meta box handling.

Subscriptions for WooCommerce wordpress privilege-escalation web-application cve-2026-15414
1t 1c
high advisory

BuddyPress Insecure Deserialization Vulnerability

An insecure deserialization vulnerability in the BuddyPress WordPress plugin allows authenticated attackers to inject arbitrary PHP objects, potentially leading to remote code execution.

BuddyPress wordpress deserialization rce web-vulnerability
1t
high advisory

Authorization Bypass in FleekDash V2 WordPress Plugin

The FleekDash V2 plugin for WordPress contains an authorization bypass vulnerability (CVE-2026-14356) that allows authenticated attackers to overwrite user credentials, including administrative accounts, leading to full site compromise.

FleekDash V2
1r
critical advisory

Unauthenticated Remote Code Execution in ASE Pro WordPress Plugin

The ASE Pro WordPress plugin up to version 8.9.0 is vulnerable to unauthenticated remote code execution via insecure input handling in the recursive_html function.

Admin and Site Enhancements
1r 1c
critical advisory

Critical Arbitrary File Upload in WordPress Extra Checkout Options Plugin Leads to RCE (CVE-2026-14270)

A critical arbitrary file upload vulnerability (CVE-2026-14270) in the Extra Checkout Options plugin for WordPress, affecting versions up to and including 2.3.2, allows low-privileged authenticated users to modify upload allowlists and upload malicious PHP files via an AJAX action, ultimately achieving remote code execution on the server.

Extra Checkout Options wordpress plugin arbitrary-file-upload rce web-application
2r 4t 1c
critical advisory

Meta Box AIO Plugin Vulnerable to Unauthenticated Post Deletion via CVE-2026-14488

Unauthenticated attackers can exploit a Missing Authorization vulnerability (CVE-2026-14488) in the MB Frontend Submission extension of the Meta Box AIO plugin for WordPress, affecting versions up to 3.8.0, to delete arbitrary posts and pages by injecting a crafted post ID via a GET parameter.

Meta Box AIO plugin +1 wordpress missing-authorization web-application plugin-vulnerability cve
1r 1t 1c
critical advisory

Authentication Bypass in Advanced Responsive Video Embedder WordPress Plugin

A critical authentication bypass vulnerability, CVE-2026-18072, affects version 10.8.7 of the Advanced Responsive Video Embedder for Rumble, Odysee, YouTube, Vimeo, Kick … plugin for WordPress, allowing unauthenticated attackers to gain full administrative control by supplying a hardcoded token via the `_wplogin` or `_wpm` URL parameter.

Advanced Responsive Video Embedder for Rumble, Odysee, YouTube, Vimeo, Kick … plugin +7 wordpress authentication-bypass web-vulnerability
1r 3t 1i updated
critical advisory

WP Password Policy Plugin Privilege Escalation via Crafted POST Request (CVE-2026-15992)

The WP Password Policy plugin for WordPress, in versions up to and including 3.7.1, is vulnerable to privilege escalation, allowing authenticated attackers with subscriber-level access to escalate their privileges to Administrator by sending a crafted POST request to the password-reset form endpoint, leveraging missing authorization checks and nonce verification.

WP Password Policy wordpress privilege-escalation web-vulnerability php
1r 1t 1c
high threat

WordPress Coding Standards Contains an Arbitrary Code Execution Vulnerability

WordPress Coding Standards (WordPressCS) versions before 3.4.1 are vulnerable to arbitrary code execution due to a flaw in the `WordPress.WP.EnqueuedResourceParameters` sniff, allowing an attacker to execute arbitrary commands on the scanning host by crafting a malicious `$ver` argument, posing a risk for users running PHPCS with specific rulesets in CI pipelines or developer environments.

exploited WordPress Coding Standards wordpress code-execution vulnerability php ci/cd
1t
high advisory

WordPress PickPlugins Question Answer Plugin SQL Injection Vulnerability (CVE-2026-10207)

An unauthenticated SQL injection vulnerability, tracked as CVE-2026-10207, exists in the PickPlugins Question Answer plugin for WordPress versions up to and including 1.2.73, allowing attackers to extract sensitive database information due to insufficient input sanitization of the 'id' GET parameter and improper SQL query construction.

Question Answer plugin <= 1.2.73 wordpress sql-injection vulnerability web-application
1r 2t 1c
critical advisory

Authentication Bypass in WordPress SMS Alert Plugin Leads to Account Takeover (CVE-2026-15014)

An authentication bypass vulnerability (CVE-2026-15014) in the 'SMS Alert - SMS & OTP for WooCommerce, Order Notifications & Abandoned Cart Recovery' WordPress plugin allows unauthenticated attackers to achieve account takeover by exploiting a flaw in the `processRegistration()` function's OTP verification, enabling authentication as any existing WordPress user with a known phone number.

SMS Alert – SMS & OTP for WooCommerce, Order Notifications & Abandoned Cart Recovery plugin +1 wordpress authentication-bypass account-takeover web-application cve
1r 2t 1c
high advisory

Fluent Forms Pro Add On Pack Vulnerable to PHP Object Injection (CVE-2026-15962)

An authenticated attacker with Subscriber-level access or higher can exploit a PHP Object Injection vulnerability in the Fluent Forms Pro Add On Pack plugin for WordPress, affecting versions up to and including 6.2.6. This deserialization of untrusted input, when combined with a POP chain, allows attackers to change user passwords and potentially achieve administrator account takeover. Exploitation is contingent on user update integration being enabled and a user meta field being mapped.

Fluent Forms Pro Add On Pack plugin <= 6.2.6 wordpress php-object-injection deserialization rce privilege-escalation
3t 1c
high advisory

WPForms Pro Plugin Arbitrary File Upload Vulnerability Leading to RCE

The WPForms Pro plugin for WordPress, in versions up to and including 1.10.1.1, is vulnerable to arbitrary file upload via the ajax_chunk_upload_finalize function, allowing unauthenticated attackers to upload executable files due to improper file type validation occurring after file contents are written to disk, which can lead to remote code execution on the affected server.

WPForms Pro plugin for WordPress <= 1.10.1.1 +1 wordpress rce arbitrary-file-upload web-vulnerability
1r 2t 1i updated
high advisory

CVE-2026-8789: Easy Appointments WordPress Plugin Data Modification Vulnerability

The Easy Appointments plugin for WordPress, in versions up to and including 3.12.27, is vulnerable to unauthorized data modification due to a missing capability check and nonce verification on the `ea_delete_multiple_connections` AJAX action, allowing authenticated attackers with Contributor-level access or higher to delete arbitrary connection records and disrupt core booking functionality.

Easy Appointments plugin wordpress plugin vulnerability data-modification
1r 1t 1c
high advisory

EventON Action User Plugin Authorization Bypass in WordPress

An authorization bypass vulnerability (CVE-2026-10033) in the EventON Action User plugin for WordPress, affecting all versions up to and including 2.5.14, allows unauthenticated attackers to grant EventON management and file upload capabilities to non-administrator users, enumerate WordPress users, and tamper with event-to-user assignments, leading to privilege escalation.

EventON Action User plugin <= 2.5.14 +1 authorization-bypass privilege-escalation wordpress-plugin web-application cve
2t 1c
high advisory

Wpify Woo Plugin Privilege Escalation Vulnerability (CVE-2026-12736)

A privilege escalation vulnerability (CVE-2026-12736) in the Wpify Woo plugin for WordPress, affecting versions up to and including 5.4.16, allows authenticated attackers with 'Shop Manager' capabilities or higher to gain Administrator privileges by exploiting a REST route that overwrites arbitrary WordPress options.

Wpify Woo plugin +1 privilege-escalation wordpress web-vulnerability
1r 2t 1c
critical advisory

WordPress SAML Single Sign On Plugin Authentication Bypass (CVE-2026-15981)

A critical authentication bypass vulnerability, CVE-2026-15981, affects the SAML Single Sign On - SSO Login plugin for WordPress (versions up to and including 5.4.4), allowing unauthenticated attackers to log in as any existing user, including administrators, by crafting a malformed SAMLResponse that misleads the plugin's signature validation logic.

PoC SAML Single Sign On – SSO Login plugin +2 authentication-bypass wordpress web-vulnerability cve-2026-15981
2t 2c 2i updated
high advisory

WordPress MDJM Event Management Plugin Privilege Escalation (CVE-2026-15017)

An unauthenticated privilege escalation vulnerability (CVE-2026-15017) in the MDJM Event Management plugin for WordPress, affecting all versions up to 1.7.8.4, allows attackers to grant arbitrary MDJM capabilities to any registered WordPress role due to missing capability checks and nonce verification, ultimately enabling a low-privilege user to escalate to Administrator.

MDJM Event Management plugin <= 1.7.8.4 +1 wordpress plugin privilege-escalation cve web-application
2t 1c
critical advisory

Critical Code Injection Vulnerability in WordPress Customer Support Ticket System & Helpdesk Plugin (CVE-2026-15011)

A critical code injection vulnerability, CVE-2026-15011, affects the Customer Support Ticket System & Helpdesk plugin for WordPress versions up to and including 6.0.5, allowing unauthenticated attackers to invoke arbitrary parameterless PHP functions via the 'path' parameter, potentially disrupting site functionality or exposing sensitive information without prior authentication.

Customer Support Ticket System & Helpdesk plugin for WordPress <= 6.0.5 code-injection wordpress web-application plugin-vulnerability php
1t 1c
critical advisory

GoDAM WordPress Plugin Arbitrary File Upload Vulnerability (CVE-2026-14282)

An arbitrary file upload vulnerability exists in the GoDAM WordPress plugin versions up to and including 1.12.2 due to insufficient file type validation in the `save_video_file()` function, allowing unauthenticated attackers to upload arbitrary files to the server and potentially achieve remote code execution.

PoC GoDAM - Organize WordPress Media Library & File Manager with Unlimited Folders for Images, Vid... <= 1.12.2 wordpress arbitrary-file-upload remote-code-execution web-exploitation
1r 2t 1c updated
high advisory

CVE-2026-9713: Lumise Product Designer for WooCommerce Plugin SQL Injection

The Lumise Product Designer for WooCommerce plugin for WordPress, in versions up to and including 2.1.1, is vulnerable to SQL Injection via the 'id' and 'table' parameters within an uploaded cart JSON file processed by the checkout AJAX action, allowing unauthenticated attackers to extract sensitive database information.

Lumise Product Designer for WooCommerce wordpress woocommerce sql-injection web-vulnerability cve
1r 2t 1c
high advisory

SUMO Reward Points WordPress Plugin Vulnerable to Unauthenticated Stored XSS via REST API (CVE-2026-7534)

The SUMO Reward Points plugin for WordPress, versions up to and including 32.7.0, is vulnerable to CVE-2026-7534, an Unauthenticated Stored Cross-Site Scripting flaw that allows attackers to inject arbitrary web scripts into the reward points log via the `/wp-json/wc-srp/v1/earning` REST API endpoint, executing when an administrator accesses specific admin pages.

SUMO Reward Points plugin < 32.7.0 +1 wordpress xss web-vulnerability plugin stored-xss
1r 2t 1c
critical advisory

Ninja Forms Plugin Vulnerability Allows Network-Wide Data Deletion in WordPress Multisite

A critical privilege escalation vulnerability, CVE-2026-65049, in the Ninja Forms plugin (version 3.14.8 and prior) for WordPress Multisite allows a subsite Administrator to trigger network-wide deletion of all Ninja Forms data by exploiting an incorrect authorization check combined with unsafe multisite migration defaults, leading to severe data loss.

Ninja Forms plugin +1 wordpress plugin privilege-escalation data-deletion webserver cve
1r 2t 1c
critical advisory

Critical Unauthenticated Stored XSS in Ninja Forms WordPress Plugin (CVE-2026-65048)

A critical unauthenticated stored cross-site scripting (XSS) vulnerability (CVE-2026-65048) in the Ninja Forms plugin for WordPress allows attackers to inject malicious script payloads via crafted form submissions, leading to session-cookie theft, administrator account creation, and arbitrary content modification when an administrator views the submission.

Ninja Forms plugin 3.10.4-3.14.9 wordpress xss plugin web-application cve
1r 6t 1c
critical threat

DD-WRT Stack-Based Buffer Overflow Vulnerability (CVE-2021-27137)

CVE-2021-27137 is a stack-based buffer overflow vulnerability in DD-WRT's UPnP component that allows an unauthenticated attacker to trigger remote code execution on affected router devices.

exploited DD-WRT +2 vulnerability-exploitation firmware router rce buffer-overflow
1t 4c
critical advisory

WordPress Easy Form Builder Plugin Vulnerable to Unauthenticated Administrator Privilege Escalation (CVE-2026-13439)

An unauthenticated privilege escalation vulnerability exists in the Easy Form Builder by WhiteStudio plugin for WordPress, affecting versions up to and including 4.0.11, allowing attackers to exploit a flaw in the password recovery process by using a publicly visible session identifier ('sid') as a reset token, combined with a publicly accessible nonce refresh endpoint, to set an arbitrary new password for any WordPress user, including administrators, to gain full control.

Easy Form Builder by WhiteStudio plugin for WordPress <= 4.0.11 wordpress plugin privilege-escalation web-vulnerability
1r 2t 1c
low advisory

PHP File Creation in WordPress Plugin Directory

Attackers commonly establish persistence on compromised Linux WordPress web servers by creating malicious PHP files, often web shells, within the WordPress plugin directory, enabling remote access and command execution following initial compromise of a public-facing application.

WordPress persistence initial-access execution web-shell linux endpoint threat-detection vulnerability
1r 3t 1c 1i updated
critical threat

CVE-2026-63030: Critical Remote Code Execution Vulnerability in WordPress Core

CVE-2026-63030 is a critical unauthenticated remote code execution vulnerability affecting WordPress Core versions 6.9.0 through 6.9.4 and 7.0.0 through 7.0.1, allowing an unauthenticated attacker to execute arbitrary code via the WordPress REST API batch endpoint, potentially leading to complete website compromise.

exploited PoC WordPress Core 6.9.0 +51 wordpress rce web-vulnerability cve
2t 15c 8i updated
critical advisory

Privilege Escalation Vulnerability in Aimogen Pro WordPress Plugin

A critical privilege escalation vulnerability, CVE-2026-15982, exists in the Aimogen Pro - All-in-One AI Content Writer, Editor, ChatBot & Automation Toolkit WordPress plugin, affecting versions up to and including 2.8.4, allowing unauthenticated attackers to leverage the 'aimogen_wp_god_mode' tool to clear function blacklists, execute arbitrary PHP functions, and create administrator accounts, leading to full compromise of the WordPress site.

Aimogen Pro - All-in-One AI Content Writer, Editor, ChatBot & Automation Toolkit plugin web wordpress plugin privilege-escalation cve
2t 1c
high advisory

Kali Forms WordPress Plugin Vulnerable to Stored Cross-Site Scripting via digitalSignature Field

The Kali Forms - Contact Form & Drag-and-Drop Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting (XSS) via the 'digitalSignature' field in versions up to and including 2.4.18, allowing unauthenticated attackers to inject arbitrary web scripts that execute when a user accesses an affected page.

Kali Forms - Contact Form & Drag-and-Drop Builder wordpress plugin xss web-vulnerability stored-xss
1r 6t 1c
critical advisory

WPFunnels Plugin Privilege Escalation via Arbitrary Option Update

Authenticated attackers with the `wpf_manage_funnels` capability can exploit CVE-2026-15103, a privilege escalation vulnerability in the `update_settings()` REST callback of the WPFunnels - Funnel Builder for WooCommerce with Checkout & One Click Upsell plugin for WordPress (versions up to and including 3.12.8), allowing them to gain full site administrator access by injecting a crafted role definition into the `wp_user_roles` option.

WPFunnels – Funnel Builder for WooCommerce with Checkout & One Click Upsell plugin privilege-escalation wordpress plugin
1r 1t 1c
high advisory

Gravity Forms Directory Traversal Vulnerability (CVE-2026-12997)

Unauthenticated attackers can exploit a Directory Traversal vulnerability (CVE-2026-12997) in the Gravity Forms plugin for WordPress, affecting all versions up to and including 2.10.4, to read arbitrary files on the server and receive their contents as an email attachment, potentially exfiltrating sensitive information.

Gravity Forms plugin wordpress plugin web-vulnerability collection network
1r 2t 1c
high advisory

Vulnerability in Genolve WordPress Plugin Allows Privilege Escalation

A vulnerability in the Genolve AI image AI video generation plugin for WordPress, affecting versions up to and including 5.0.5, allows authenticated attackers with Contributor-level access to achieve privilege escalation due to a missing capability check in the `genolve_setOpt()` function, enabling them to modify arbitrary WordPress options such as enabling user registration and setting the default role to administrator.

Genolve - AI image AI video generation plugin for WordPress wordpress plugin privilege-escalation vulnerability
1r 1t 1c
high advisory

Directory Traversal in W3 Total Cache WordPress Plugin (CVE-2026-9282)

An unauthenticated directory traversal vulnerability (CVE-2026-9282) in all versions up to 2.9.4 of the W3 Total Cache plugin for WordPress allows attackers to read arbitrary files by manipulating the minify filename when manual minify mode is enabled.

WordPress +1 plugin directory-traversal cve web-exploit
1r 3t 1c
high advisory

CVE-2026-6939: Unauthenticated Stored XSS in CorvusPay WooCommerce Payment Gateway for WordPress

The CorvusPay WooCommerce Payment Gateway plugin for WordPress versions up to and including 2.7.4 is vulnerable to Stored Cross-Site Scripting (XSS), tracked as CVE-2026-6939, allowing unauthenticated attackers to inject malicious web scripts via the 'approval_code' parameter to the `/wp-json/corvuspay/success/` REST endpoint, which processes requests without proper signature validation, leading to script execution when a user accesses an affected page.

CorvusPay WooCommerce Payment Gateway plugin <= 2.7.4 +1 wordpress xss web-application plugin
1r 2t 1c
high advisory

WP CTA Plugin Vulnerable to Unauthenticated Time-Based Blind SQL Injection (CVE-2026-4661)

The WP CTA - Sticky CTA Builder, Generate Leads, Promote Sales plugin for WordPress is vulnerable to time-based blind SQL Injection via the 'fildname' parameter in versions up to and including 2.2.2. This vulnerability is due to insufficient escaping of user-supplied column names and lack of preparation in database queries. Unauthenticated attackers can exploit this by injecting arbitrary SQL queries to extract sensitive information, including administrator password hashes, from the database.

WP CTA – Sticky CTA Builder, Generate Leads, Promote Sales plugin <= 2.2.2 wordpress plugin sql-injection time-based-blind unauthenticated web-vulnerability
1r 2t 1c
high advisory

Authenticated Account Takeover in Essential Addons for Elementor WordPress Plugin

A vulnerability (CVE-2026-15155) in the Essential Addons for Elementor WordPress plugin, specifically within its Login/Register widget, allows authenticated attackers with Contributor-level access or higher to achieve administrator account takeover by injecting an additional Bcc header into administrator password-reset notification emails.

Essential Addons for Elementor – Popular Elementor Templates & Widgets plugin wordpress plugin web-application cve account-takeover email-injection
3t 1c
high advisory

Remote Code Execution in WordPress Code Engine Plugin via Shortcode (CVE-2025-6784)

The Code Engine plugin for WordPress, in versions up to and including 0.3.5, is vulnerable to Remote Code Execution (RCE) via its 'code-engine' shortcode, allowing authenticated attackers with Contributor-level access or above to execute arbitrary code on the server.

Code Engine plugin wordpress plugin rce cve web-application
1r 2t 1c
high advisory

SureCart WordPress Plugin Vulnerable to Account Takeover and Privilege Escalation

The SureCart plugin for WordPress, in versions up to and including 4.2.3, is vulnerable to privilege escalation through an account takeover, where unauthenticated attackers can exploit a lack of proper identity validation during customer profile synchronization via webhook events to change linked user email addresses, potentially leading to administrator account compromise.

SureCart plugin +1 privilege-escalation account-takeover wordpress plugin web-application
2t 1c
high advisory

CVE-2026-3576: Planyo WordPress Plugin Vulnerable to SSRF and LFI

The Planyo Online Reservation System plugin for WordPress, in all versions up to and including 3.0, is vulnerable to Server-Side Request Forgery (SSRF) leading to Local File Inclusion (LFI), allowing an unauthenticated attacker to exploit the `ulap.php` file by supplying a `file://` URL that bypasses the host allowlist, reading arbitrary local files on the server and retrieving their contents in the HTTP response, potentially disclosing sensitive data.

PoC Planyo Online Reservation System plugin <= 3.0 wordpress plugin ssrf lfi web-application cve
1r 2t 1c updated
high advisory

WordPress Booking Package Plugin Vulnerable to Unauthenticated SQL Injection

The Booking Package plugin for WordPress is vulnerable to unauthenticated generic SQL Injection via the 'email' form parameter in versions up to and including 1.7.20, allowing attackers to extract sensitive information from the database.

Booking Package plugin <= 1.7.20 wordpress sqli web-vulnerability cms
1t 1c
high advisory

Local File Inclusion Vulnerability in LA-Studio Element Kit for Elementor Plugin for WordPress

A Local File Inclusion vulnerability exists in the LA-Studio Element Kit for Elementor plugin for WordPress, affecting all versions up to and including 1.6.1, which allows authenticated attackers with contributor-level access or higher to include and execute arbitrary .php files on the server due to improper path traversal handling and an easily bypassed extension check, leading to PHP code execution, access control bypass, and sensitive data exposure.

LA-Studio Element Kit for Elementor plugin for WordPress wordpress plugin vulnerability lfi web
4t 1c
high advisory

CVE-2026-13756 - Privilege Escalation in WP Grid Builder WordPress Plugin

An authenticated attacker with Subscriber-level access or higher can exploit a missing authorization and meta key validation vulnerability in the WP Grid Builder plugin for WordPress (versions up to and including 2.3.3) by sending a crafted nested array payload to the `/wp-json/wpgb/v2/metadata` REST endpoint, which allows them to update their own `wp_capabilities` user meta and effectively escalate their privileges to Administrator level.

WP Grid Builder plugin <= 2.3.3 privilege-escalation wordpress plugin cve
1r 1t 1c
critical threat

iCagenda Unrestricted File Upload Vulnerability Leading to RCE (CVE-2026-48939)

Attackers are actively exploiting CVE-2026-48939, an unrestricted file upload vulnerability in iCagenda, to upload malicious PHP code and achieve remote code execution on affected web servers.

exploited PoC iCagenda +19 web-application rce file-upload cve
1r 2t 5c 7i updated
high advisory

WordPress Hide My WP Lite Plugin Vulnerable to Arbitrary File Read (CVE-2026-13347)

The Hide My WP Lite plugin for WordPress, versions up to and including 1.3, is vulnerable to Arbitrary File Read (CVE-2026-13347) due to inadequate validation of user-supplied input in query parameters `he_wrapper_js` and `he_wrapper_css` within the `elementor_assets_filter()` function, allowing unauthenticated attackers to read arbitrary files on the server like `wp-config.php` when the Elementor plugin and 'Hide Elementor' feature are enabled.

Hide My WP Lite <= 1.3 +1 wordpress plugin arbitrary-file-read path-traversal web-application cve
1r 2t 1c
high advisory

CVE-2026-15298: WordPress TelSender Plugin DOM-Based Cross-Site Scripting

The TelSender plugin for WordPress, versions up to and including 1.14.14, is vulnerable to DOM-Based Cross-Site Scripting (CWE-79), allowing unauthenticated attackers to inject malicious scripts via Telegram chat titles which execute within an administrator's browser upon interacting with the plugin's settings.

TelSender plugin +1 wordpress plugin xss web-application cve
1t 1c 8i
high advisory

CVE-2026-15293 - WP Business Intelligence Lite Plugin Authorization Bypass Leading to Privilege Escalation

The WP Business Intelligence Lite plugin for WordPress contains an authorization bypass vulnerability (CVE-2026-15293) affecting all versions up to and including 3.2.0, allowing authenticated attackers with Subscriber-level access or higher to modify stored SQL queries which can lead to arbitrary SQL execution and privilege escalation when an administrator views the modified query.

WP Business Intelligence Lite plugin wordpress plugin-vulnerability authorization-bypass privilege-escalation web-application cve
2t 1c
high advisory

CVE-2026-15290: Ultimate Member Plugin Blind SQL Injection

The Ultimate Member plugin for WordPress is vulnerable to blind SQL Injection via the 'search' parameter in all versions up to and including 2.10.1, due to insufficient escaping of user-supplied input and inadequate preparation of existing SQL queries, allowing unauthenticated attackers to append additional SQL queries and extract sensitive information from the database.

Ultimate Member - User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin <= 2.10.1 wordpress plugin sql-injection web-vulnerability
1r 2t 2c
critical advisory

CVE-2026-15300: Critical SQL Injection in GEO my WP WordPress Plugin

A critical SQL Injection vulnerability, identified as CVE-2026-15300, was found in the GEO my WP plugin for WordPress, affecting versions up to and including 4.5.4, allowing attackers to inject SQL payloads through the 'distance', 'lat', and 'lng' parameters, leading to potential data compromise or denial of service.

GEO my WP plugin <= 4.5.4 wordpress plugin sql-injection vulnerability webserver
1r 2t 1c
critical advisory

CVE-2026-15282: WordPress Instant Appointment Plugin Arbitrary File Upload to RCE

An unauthenticated attacker can exploit CVE-2026-15282, an arbitrary file upload vulnerability due to missing file type validation in the `insapp_upload_image_as_attachment` function of the WordPress Instant Appointment plugin up to version 1.2, to upload malicious files and achieve remote code execution on the affected server.

PoC Instant Appointment Plugin <= 1.2 wordpress plugin vulnerability rce file-upload webserver
1r 2t 1c updated
high advisory

CVE-2026-15070: WordPress Salon Booking Plugin CSRF to RCE

The Salon Booking System - Free Version plugin for WordPress (versions up to and including 10.30.32) is susceptible to a Cross-Site Request Forgery (CSRF) vulnerability stemming from a lack of nonce validation in the setCustomText function, allowing unauthenticated attackers to inject arbitrary PHP code into the web-accessible translate-constants.php file, which can lead to remote code execution (RCE) on the server if an administrator is tricked into clicking a crafted link.

Salon Booking System - Free Version plugin for WordPress <= 10.30.32 web-exploitation vulnerability wordpress rce csrf
1r 3t
critical advisory

WordPress Super Forms Plugin Arbitrary File Upload (CVE-2026-14894)

An unauthenticated arbitrary file upload vulnerability (CVE-2026-14894) exists in the Super Forms - Drag & Drop Form Builder plugin for WordPress, affecting all versions up to and including 6.3.313, allowing unauthenticated attackers to upload executable files via the `submit_form` AJAX handler, leading to remote code execution after trivial nonce bypass.

PoC Super Forms – Drag & Drop Form Builder <= 6.3.313 +1 wordpress plugin arbitrary-file-upload rce web-exploit
1r 2t 1c 11i updated
high advisory

CVE-2026-12598: LoginPress Pro WordPress Plugin Authentication Bypass

An authentication bypass vulnerability (CVE-2026-12598) exists in the LoginPress Pro plugin for WordPress, affecting versions up to and including 6.2.3 within the Spotify Social Login addon, enabling unauthenticated attackers to log in as any existing WordPress user, including administrators, by registering a Spotify account with the target's email.

LoginPress Pro plugin <= 6.2.3 +1 wordpress plugin authentication-bypass web
2t 1c
high advisory

UsersWP Plugin Arbitrary File Deletion (CVE-2026-13492)

The UsersWP plugin for WordPress contains an Arbitrary File Deletion vulnerability, CVE-2026-13492, in versions up to and including 1.2.65, allowing an authenticated attacker with Subscriber-level access or higher to exploit insufficient validation in file-field values combined with an AJAX handler that lacks proper path canonicalization to delete arbitrary files on the server, including critical files like `wp-config.php`, leading to system impact.

UsersWP plugin <= 1.2.65 +1 wordpress plugin vulnerability web file-deletion remote-code-execution
1r 3t 1c
high advisory

EventPrime WordPress Plugin Stored XSS (CVE-2026-13441)

A critical stored Cross-Site Scripting (XSS) vulnerability, CVE-2026-13441, exists in all versions up to 4.3.4.2 of the EventPrime - Events Calendar, Bookings and Tickets plugin for WordPress, allowing authenticated attackers with custom-level access (or unauthenticated attackers if 'Guest Submissions' is enabled) to inject malicious web scripts via the new_event_type_background_color parameter that execute whenever a user accesses an affected page, potentially leading to session hijacking, defacement, or further compromise.

EventPrime – Events Calendar, Bookings and Tickets plugin web-vulnerability wordpress xss plugin
1r 2t 1c
critical advisory

CVE-2026-15158: Blocksy Companion Plugin Arbitrary File Upload Leading to RCE

The Blocksy Companion plugin for WordPress, specifically the premium version (blocksy-companion-pro) with the WooCommerce Extra (Advanced Reviews) and Custom Fonts extensions active, is vulnerable to Arbitrary File Upload (CVE-2026-15158). This flaw, present in versions up to and including 2.1.46, arises from improper file type validation within the `save_attachments` function, allowing double-extension files like `shell.woff2.php` to bypass MIME checks, which unauthenticated attackers can exploit to upload executable files, leading to remote code execution.

Blocksy Companion plugin +3 web vulnerability arbitrary-file-upload wordpress
2t 1c
critical advisory

Critical RCE Vulnerability in Blocksy Companion Pro WordPress Plugin (CVE-2026-58480)

An unauthenticated arbitrary file upload vulnerability (CVE-2026-58480) in Blocksy Companion Pro plugin for WordPress versions prior to 2.1.47 allows attackers to bypass extension validation via double-extension files, leading to remote code execution by forcing the web server to execute uploaded PHP files.

PoC Blocksy Companion Pro plugin < 2.1.47 +2 wordpress plugin rce file-upload web
1r 3t 2c 1i updated
high advisory

CVE-2026-5356: LatePoint WordPress Plugin Improper Input Validation Leading to Arbitrary Payments

An improper input validation vulnerability (CVE-2026-5356) in the LatePoint - Calendar Booking Plugin for Appointments and Events for WordPress, versions up to and including 5.4.0, allows unauthenticated attackers to exploit its Stripe Connect payment processor by supplying a previously succeeded PaymentIntent ID, resulting in the processing of arbitrary payments.

LatePoint – Calendar Booking Plugin for Appointments and Events wordpress plugin vulnerability webserver cve
2t 1c
high advisory

CVE-2026-6230: Tainacan WordPress Plugin SQL Injection Vulnerability

An unauthenticated attacker can exploit CVE-2026-6230, a time-based blind SQL Injection vulnerability in the Tainacan plugin for WordPress (versions up to and including 1.0.3) via the 'geoquery' parameter, to append arbitrary SQL queries and exfiltrate sensitive information from the database due to insufficient input validation.

Tainacan plugin wordpress sql-injection webserver vulnerability cve
1r 1t 1c
high advisory

CVE-2026-6854 - WordPress My Calendar Plugin Time-Based Blind SQL Injection

A time-based blind SQL Injection vulnerability exists in the My Calendar - Accessible Event Manager plugin for WordPress, affecting all versions up to and including 3.7.8. This flaw, located in the 'mc_auth' parameter, stems from insufficient input sanitization and improper SQL query preparation, allowing unauthenticated attackers to inject additional SQL queries to extract sensitive information from the underlying database.

My Calendar - Accessible Event Manager plugin <= 3.7.8 wordpress sql-injection vulnerability web-application collection initial-access
1r 2t 1c
high advisory

CVE-2026-6818: VikBooking WordPress Plugin Stored XSS Vulnerability

A stored cross-site scripting vulnerability (CVE-2026-6818) exists in the VikBooking Hotel Booking Engine & PMS plugin for WordPress, affecting versions up to and including 1.8.8, caused by insufficient input sanitization of the 'special_requests' parameter, enabling unauthenticated attackers to inject arbitrary web scripts that execute whenever a user accesses an affected page, potentially leading to unauthorized data access, session hijacking, or defacement.

VikBooking Hotel Booking Engine & PMS plugin < 1.8.9 wordpress plugin xss web-vulnerability cms
1r 5t 1c
high advisory

CVE-2026-3688: WordPress WCFM Membership Plugin Insecure Direct Object Reference

Authenticated attackers with vendor-level access can exploit an Insecure Direct Object Reference (IDOR) vulnerability (CVE-2026-3688) in the WCFM Membership - WooCommerce Memberships for Multivendor Marketplace plugin for WordPress to change any user's role to 'wcfm_vendor' by manipulating membership plans, leading to unauthorized privilege escalation.

WCFM Membership – WooCommerce Memberships for Multivendor Marketplace < 2.11.10 wordpress web vulnerability idor privilege-escalation
2t 1c
critical advisory

CVE-2026-14345: Unauthenticated Remote Code Execution in WPFunnels WordPress Plugin

An unauthenticated remote code execution vulnerability (CVE-2026-14345) exists in the WPFunnels – Funnel Builder for WooCommerce with Checkout & One Click Upsell plugin for WordPress, affecting versions up to and including 3.12.7, allowing attackers to inject malicious PHP code into a log file via the 'postData' parameter, which is then executed when an administrator views the log.

WPFunnels – Funnel Builder for WooCommerce with Checkout & One Click Upsell plugin <= 3.12.7 web-exploit rce wordpress plugin-vulnerability
2t 1c
high advisory

WordPress WPZOOM Portfolio Plugin XSS Vulnerability (CVE-2026-49069)

A critical reflected cross-site scripting (XSS) vulnerability, CVE-2026-49069, affects the WPZOOM Portfolio plugin (version 1.4.21 and earlier) for WordPress, enabling unauthenticated attackers to inject malicious JavaScript into web pages via the `wpzoom_load_more_items` AJAX action, leading to client-side script execution in victims' browsers.

WordPress Plugin WPZOOM Portfolio <= 1.4.21 +1 xss wordpress webapps cve
1r 2t 1c 2i
critical advisory

ARMember Premium Plugin Insecure Password Reset (CVE-2026-5076) Leads to Account Takeover

The ARMember Premium plugin for WordPress, in versions up to and including 7.3.1, contains an insecure password reset mechanism (CVE-2026-5076) that stores plaintext password reset keys in the `wp_usermeta` table, which, when chained with other vulnerabilities like SQL Injection (CVE-2026-5073, CVE-2026-5074), allows unauthenticated attackers to extract these plaintext keys to reset passwords and compromise any user account, including administrators, leading to account takeover.

PoC ARMember Premium plugin <= 7.3.1 wordpress plugin-vulnerability account-takeover sql-injection password-reset cve web
2r 3t 3c updated
high threat

WP AutoSuggest 0.24 SQL Injection Vulnerability (CVE-2018-25434)

WP AutoSuggest version 0.24 contains an SQL injection vulnerability that allows an unauthenticated attacker to execute arbitrary SQL queries by injecting malicious code through the wpas_keys parameter via GET requests to autosuggest.php, potentially extracting sensitive database information.

WP AutoSuggest sql-injection wordpress cve-2018-25434
2r 1t 1c
high advisory

GEO my WP WordPress Plugin SQL Injection Vulnerability (CVE-2026-9757)

The GEO my WP plugin for WordPress is vulnerable to SQL Injection (CVE-2026-9757) via the 'swlatlng' and 'nelatlng' parameters, allowing unauthenticated attackers to extract sensitive information from the database by injecting SQL queries into a BETWEEN clause.

GEO my WP plugin <= 4.5.5 cve sqli wordpress plugin geomywp
2r 1t 1c
high advisory

CVE-2026-7465: Spectra Gutenberg Blocks WordPress Plugin Remote Code Execution

The Spectra Gutenberg Blocks WordPress plugin is vulnerable to remote code execution, allowing authenticated attackers with Contributor access or higher to execute arbitrary code by crafting a malicious two-block payload within post content.

Spectra Gutenberg Blocks – Website Builder for the Block Editor plugin wordpress rce plugin authenticated
2r 1t 1c
high advisory

CVE-2026-7459: Simple History WordPress Plugin Account Takeover Vulnerability

CVE-2026-7459 is an authenticated account takeover vulnerability in the Simple History WordPress plugin where a subscriber-level user can read password reset emails and escalate privileges to an administrator account.

Simple History – Track, Log, and Audit WordPress Changes plugin wordpress account-takeover privilege-escalation cve
2r 1t 1c
critical advisory

WP Travel Pro Plugin Vulnerable to Arbitrary User Deletion (CVE-2026-4290)

The WP Travel Pro plugin for WordPress is vulnerable to arbitrary user deletion via the REST API endpoint, allowing unauthenticated attackers to delete arbitrary user accounts due to a flawed permission check and lack of role validation.

WP Travel Pro plugin <= 10.6.0 wordpress plugin user-deletion rce CVE-2026-4290
2r 1t 1c
medium advisory

CVE-2025-11262: WordPress Link Whisper Free Plugin Stored XSS Vulnerability

The Link Whisper Free plugin for WordPress is vulnerable to Stored Cross-Site Scripting (XSS), allowing unauthenticated attackers to inject arbitrary web scripts into pages, which execute when a user accesses the injected page, affecting versions up to and including 0.9.0.

PoC Link Whisper Free plugin wordpress xss plugin
2r 1t 1c updated
critical advisory

CVE-2026-3655: WordPress OTP Login Plugin Authentication Bypass Vulnerability

The OTP Login With Phone Number, OTP Verification plugin for WordPress versions 1.8.50 through 1.8.60 is vulnerable to authentication bypass due to improper validation of the Firebase session, allowing unauthenticated attackers to authenticate as arbitrary users, including administrators, by supplying a victim's phone number.

OTP Login With Phone Number, OTP Verification plugin authentication-bypass wordpress plugin cve-2026-3655 privilege-escalation
2r 1t 1c
critical advisory

CVE-2026-8732 WP Maps Pro Plugin Privilege Escalation via Administrator Account Creation

The WP Maps Pro plugin for WordPress is vulnerable to privilege escalation (CVE-2026-8732), allowing unauthenticated attackers to create administrator accounts and take over vulnerable sites.

WP Maps Pro plugin <= 6.1.0 privilege-escalation wordpress plugin CVE-2026-8732
2r 1t 1c
critical advisory

CVE-2026-8809: Advanced Custom Fields: Extended WordPress Plugin Privilege Escalation

The Advanced Custom Fields: Extended plugin for WordPress is vulnerable to Privilege Escalation (CVE-2026-8809), allowing an unauthenticated attacker to create an administrator-level user by bypassing validation in versions up to 0.9.2.5 if a specific form is exposed.

Advanced Custom Fields: Extended plugin <= 0.9.2.5 privilege-escalation wordpress acf acfe cloud
2r 1t 1c
critical threat

CVE-2026-8380: WordPress Frontend File Manager Arbitrary Post Deletion

CVE-2026-8380 is a critical authorization bypass vulnerability in the WordPress Frontend File Manager plugin <= 23.6 that allows authenticated low-privilege users, or unauthenticated users with guest uploads enabled, to permanently delete arbitrary WordPress posts, pages, attachments, and custom post types.

Frontend File Manager cve wordpress authorization privilege-escalation arbitrary-deletion plugin-vulnerability
2r 1t
high advisory

CVE-2026-9227: GutenBee WordPress Plugin Arbitrary File Upload

The GutenBee – Gutenberg Blocks plugin for WordPress is vulnerable to arbitrary file upload, allowing authenticated attackers with author-level access to achieve remote code execution by uploading executable files with double extensions.

GutenBee – Gutenberg Blocks plugin <= 2.20.1 arbitrary-file-upload remote-code-execution wordpress
2r 1c
high advisory

CVE-2026-7797: WordPress Simply Schedule Appointments Plugin Time-Based Blind SQL Injection

The Appointment Booking Calendar WordPress plugin is vulnerable to time-based blind SQL Injection (CVE-2026-7797) via the 'append_where_sql' parameter, allowing unauthenticated attackers to extract sensitive information from the database by injecting SQL queries through the /appointments/bulk REST endpoint with a specific request format.

Appointment Booking Calendar - Simply Schedule Appointments Booking Plugin wordpress sqli cve-2026-7797 attack.initial_access
2r 1t 1c
medium advisory

WordPress SlimStat Analytics Plugin Stored XSS Vulnerability (CVE-2026-7634)

The SlimStat Analytics plugin for WordPress is vulnerable to stored cross-site scripting (XSS) via the User-Agent header, allowing unauthenticated attackers to inject arbitrary web scripts if the 'show_complete_user_agent_tooltip' setting is enabled.

SlimStat Analytics plugin <= 5.4.11 cve xss wordpress
2r 1t 1c
medium advisory

HT Contact Form WordPress Plugin Vulnerable to Stored XSS (CVE-2026-7052)

The HT Contact Form – Drag & Drop Form Builder for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting (CVE-2026-7052) via the 'file_upload' parameter in versions up to 2.8.2, allowing unauthenticated attackers to inject arbitrary web scripts.

HT Contact Form – Drag & Drop Form Builder for WordPress plugin <= 2.8.2 stored-xss wordpress plugin CVE-2026-7052
2r 1t 1c
high threat

WP Contact Form 7 DB Handler Plugin CSRF leading to Arbitrary File Deletion (CVE-2026-6455)

The WP Contact Form 7 DB Handler plugin for WordPress is vulnerable to Cross-Site Request Forgery (CSRF), leading to arbitrary file deletion via SQL injection and PHP object injection due to missing nonce verification and unsafe deserialization, allowing attackers to delete arbitrary files on the server.

WP Contact Form 7 DB Handler plugin cve csrf sqli php object injection wordpress
2r 3t 1c
critical advisory

Crawlomatic Multipage Scraper Post Generator Plugin RCE (CVE-2026-9009)

The Crawlomatic Multipage Scraper Post Generator plugin for WordPress is vulnerable to remote code execution (RCE) via the 'callback_raw' shortcode attribute, allowing authenticated attackers with author-level access or higher to execute arbitrary code on the server.

Crawlomatic Multipage Scraper Post Generator plugin <= 2.7.2 CVE-2026-9009 rce wordpress plugin crawlomatic
2r 1t 1c
high advisory

CVE-2026-8832 - WPCode WordPress Plugin Remote Code Execution Vulnerability

The WPCode WordPress plugin before or equal to 2.3.5 is vulnerable to remote code execution due to missing capability restrictions on the 'wpcode' custom post type, allowing authenticated attackers with author-level access to execute arbitrary PHP code via XML-RPC.

WPCode - Insert Headers and Footers + Custom Code Snippets - WordPress Code Manager plugin <= 2.3.5 wordpress rce cve-2026-8832 xml-rpc
2r 1t 1c
high advisory

affiliate-toolkit WordPress Plugin RCE via BladeOne Template Injection (CVE-2026-6169)

The affiliate-toolkit plugin for WordPress is vulnerable to remote code execution (CVE-2026-6169) due to the use of the BladeOne templating engine's runString() method, which allows authenticated attackers with Editor-level access or higher to execute arbitrary PHP code by injecting it into a plugin template.

affiliate-toolkit plugin <= 3.8.5 cve rce wordpress affiliate-toolkit template injection
2r 1t 1c
high threat

CVE-2026-9200: WordPress Query Shortcode Plugin Vulnerable to Local File Inclusion

The Query Shortcode plugin for WordPress is vulnerable to Local File Inclusion (CVE-2026-9200) in versions up to 0.2.1, allowing authenticated attackers with contributor-level access and above to include and execute arbitrary PHP files on the server, potentially leading to privilege escalation and code execution.

Query Shortcode plugin <= 0.2.1 local-file-inclusion wordpress plugin-vulnerability CVE-2026-9200
2r 2t 1c
high advisory

CVE-2026-8994 - WordPress Login with NEAR Plugin Authentication Bypass

The Login with NEAR plugin for WordPress is vulnerable to authentication bypass due to the `ajaxLoginWithNear()` function issuing valid authentication cookies based on a substring check of the `account` POST parameter, allowing unauthenticated attackers to log in as existing users or create new accounts.

Login with NEAR plugin <= 0.3.3 wordpress authentication-bypass cve-2026-8994 cloud
2r 1t 1c
critical advisory

CVE-2026-8787: WordPress Firebase Support & Chat Management Plugin Privilege Escalation

The Firebase Support & Chat Management plugin for WordPress is vulnerable to privilege escalation (CVE-2026-8787) where an authenticated attacker with Subscriber-level access can log in as any existing user, including an Administrator, by submitting that user's email address to the `acb_firebase_auth` AJAX action without proper ownership verification, leading to full account takeover.

Firebase Support & Chat Management plugin <= 3.1.1 privilege-escalation wordpress cloud cve
2r 1t 1c
critical threat

CVE-2026-8760: WordPress Login with OTP Plugin Authentication Bypass

The Login with OTP plugin for WordPress is vulnerable to authentication bypass due to an incomplete fix for CVE-2024-11178, allowing unauthenticated attackers to brute-force OTP codes and gain administrative access.

Login with OTP plugin wordpress authentication-bypass cve-2026-8760 brute-force
2r 1t 2c
critical advisory

WordPress Temporary Login Plugin Authentication Bypass Vulnerability

A public exploit is available for WordPress Temporary Login Plugin version 1.0.0, which demonstrates an authentication bypass vulnerability that can lead to account takeover, increasing the risk for unpatched systems.

Temporary Login Plugin 1.0.0 wordpress authentication-bypass account-takeover webapps
2r 1t
high advisory

WordPress Ultimate Form Builder Lite Plugin SQL Injection Vulnerability

WordPress Ultimate Form Builder Lite plugin version 1.3.7 and below contains an SQL injection vulnerability (CVE-2018-25352) that allows authenticated attackers to manipulate database queries by injecting SQL code through the entry_id POST parameter, potentially leading to privilege escalation.

Ultimate Form Builder Lite plugin <= 1.3.7 sqli wordpress plugin CVE-2018-25352
2r 1t 1c
high advisory

WordPress Contact Form Maker Plugin SQL Injection Vulnerability (CVE-2018-25347)

WordPress Contact Form Maker Plugin version 1.12.20 is vulnerable to SQL injection, enabling authenticated attackers to manipulate database queries via AJAX actions (FormMakerSQLMapping and generete_csv_fmc) by injecting malicious SQL code through the 'name' and 'search_labels' parameters, potentially extracting sensitive database information or escalating privileges.

Contact Form Maker Plugin 1.12.20 sqli wordpress plugin
2r 1t 1c
high threat

WordPress Form Maker Plugin SQL Injection Vulnerability (CVE-2018-25346)

WordPress Form Maker Plugin version 1.12.24 and below is vulnerable to SQL injection, allowing authenticated attackers to manipulate database queries through the FormMakerSQLMapping and generete_csv actions via crafted POST requests, potentially leading to data extraction, modification, or privilege escalation.

Form Maker Plugin <= 1.12.24 sqli wordpress plugin
2r 1t 1c
critical advisory

CVE-2026-6898: Wishlist Member WordPress Plugin Vulnerability Leads to Site Takeover

The Wishlist Member plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check (CVE-2026-6898), allowing authenticated attackers with subscriber-level access or higher to update the REST API Secret Key, create administrator accounts, and achieve complete site takeover.

Wishlist Member plugin wordpress plugin privilege-escalation credential-access persistence initial-access
2r 4t 1c
critical advisory

CVE-2026-6897: Wishlist Member Plugin Vulnerability Leads to WordPress Site Takeover

CVE-2026-6897 is a critical vulnerability in the Wishlist Member plugin for WordPress, allowing authenticated attackers with subscriber-level access to modify plugin settings, including the REST API secret key, ultimately enabling them to create administrator accounts and take over the entire site.

Wishlist Member plugin wordpress plugin privilege-escalation credential-access persistence
2r 3t 1c
critical advisory

WishList Member WordPress Plugin Missing Authorization Leads to Privilege Escalation (CVE-2026-6895)

The WishList Member plugin for WordPress is vulnerable to Missing Authorization, allowing attackers to obtain the REST API Secret Key and escalate privileges to administrator.

WishList Member plugin <= 3.30.1 wordpress plugin privilege-escalation cve
2r 3t 1c
critical threat

WishList Member Plugin Privilege Escalation via Missing Authorization (CVE-2026-6419)

The WishList Member plugin for WordPress is vulnerable to privilege escalation (CVE-2026-6419) due to a missing capability and nonce check in the ajax_get_screen() function, allowing authenticated attackers with subscriber-level access to retrieve the plugin's REST API Secret Key and create administrator accounts, leading to complete site takeover.

WishList Member plugin privilege-escalation wordpress plugin CVE-2026-6419
2r 1t 1c
critical advisory

CVE-2026-27384: W3 Total Cache Unauthenticated RCE via eval() Code Injection

A public exploit has been published for CVE-2026-27384, a critical unauthenticated remote code execution vulnerability in the W3 Total Cache WordPress plugin.

W3 Total Cache < 2.9.2 rce wordpress code-injection eval w3-total-cache
2r 1t
medium threat

CVE-2026-9011: Ditty WordPress Plugin Authorization Bypass Vulnerability

The Ditty – Responsive News Tickers, Sliders, and Lists plugin for WordPress versions up to 3.1.65 is vulnerable to an authorization bypass (CVE-2026-9011) that allows unauthenticated attackers to retrieve the full content of non-public Dittys by exploiting the ditty_init AJAX endpoint.

Ditty – Responsive News Tickers, Sliders, and Lists plugin <= 3.1.65 cve cve-2026-9011 wordpress authorization bypass plugin vulnerability cloud
2r 1t 1c
medium advisory

AudioIgniter WordPress Plugin Vulnerable to Insecure Direct Object Reference (CVE-2026-8679)

The AudioIgniter plugin for WordPress is vulnerable to Insecure Direct Object Reference (CVE-2026-8679) in versions up to 2.0.2, allowing unauthenticated attackers to view track metadata of any playlist, regardless of its status.

AudioIgniter plugin for WordPress <= 2.0.2 idor wordpress plugin cve-2026-8679 vulnerability
2r 1t
critical advisory

Easy Elements for Elementor Plugin Privilege Escalation (CVE-2026-9018)

CVE-2026-9018 allows unauthenticated attackers to escalate privileges to administrator by exploiting a vulnerability in the Easy Elements for Elementor plugin, which lacks proper input validation during user registration.

Easy Elements for Elementor – Addons & Website Templates plugin privilege-escalation wordpress plugin-vulnerability cve
2r 1t 1c
critical advisory

CVE-2026-6960: BookingPress Pro Plugin Arbitrary File Upload Leading to Potential RCE

The BookingPress Pro plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'bookingpress_validate_submitted_booking_form_func' function in versions up to 5.6, allowing unauthenticated attackers to upload arbitrary files and potentially achieve remote code execution if a signature custom field is added to the booking form.

BookingPress Pro plugin <= 5.6 wordpress arbitrary-file-upload rce plugin CVE-2026-6960 webserver
2r 3t 1c
critical advisory

Divi Form Builder Unauthenticated Privilege Escalation via CVE-2026-5118

CVE-2026-5118 is a critical vulnerability in the Divi Form Builder WordPress plugin (versions 5.1.2 and earlier) that allows unauthenticated attackers to create administrator accounts directly through the registration form, leading to full site takeover.

Divi Form Builder <= 5.1.2 cve wordpress privilege escalation cloud
2r 1t 2i
critical advisory

CVE-2026-6279 - Avada Builder Plugin Unauthenticated RCE via PHP Function Injection

The Avada Builder (fusion-builder) plugin for WordPress is vulnerable to unauthenticated remote code execution (RCE) due to PHP function injection, allowing attackers to execute arbitrary code on affected sites.

Avada Builder wordpress rce php function-injection cve-2026-6279
2r 1t 1c
high advisory

AcyMailing WordPress Plugin Missing Authorization Vulnerability (CVE-2026-5200)

The AcyMailing plugin for WordPress is vulnerable to a missing authorization issue (CVE-2026-5200), allowing authenticated attackers with subscriber-level access to modify privileged AcyMailing configuration, export subscriber secret keys, and potentially achieve administrator account takeover if the administrator's email address is known.

AcyMailing – An Ultimate Newsletter Plugin and Marketing Automation Solution for WordPress plugin <= 10.8.2 acymailing wordpress authorization-bypass privilege-escalation
2r 2t 1c
high advisory

Advanced Database Cleaner Premium WordPress Plugin Vulnerable to Local File Inclusion (CVE-2026-7522)

The Advanced Database Cleaner – Premium plugin for WordPress is vulnerable to Local File Inclusion (LFI) in versions up to 4.1.0, allowing authenticated attackers with subscriber-level access to include and execute arbitrary PHP files on the server via the 'template' parameter, potentially leading to access control bypass, sensitive data access, or code execution.

Advanced Database Cleaner – Premium plugin <= 4.1.0 wordpress lfi cve-2026-7522 local-file-inclusion
2r 2t 1c
critical advisory

CVE-2026-7637 - Boost Plugin for WordPress PHP Object Injection

The Boost plugin for WordPress is vulnerable to PHP Object Injection (CVE-2026-7637) due to deserialization of untrusted input in the STYXKEY-BOOST_USER_LOCATION cookie, potentially leading to arbitrary code execution if a suitable property-oriented programming (POP) chain is present.

Boost plugin for WordPress php-object-injection wordpress vulnerability
2r 1t 1c
high advisory

CVE-2026-7467: WordPress Read More & Accordion Plugin Privilege Escalation

The Read More & Accordion plugin for WordPress is vulnerable to privilege escalation due to insufficient restrictions on database table writes and data validation during import, allowing authenticated attackers to create administrator accounts.

Read More & Accordion plugin <= 3.5.7 privilege-escalation wordpress CVE-2026-7467
2r 1t 1c
high advisory

CVE-2026-6456 - WordPress Account Switcher Plugin Privilege Escalation

The Account Switcher plugin for WordPress is vulnerable to privilege escalation (CVE-2026-6456) due to a loose comparison and lack of validation on the `rememberLogin` REST API endpoint, allowing authenticated attackers to gain administrator privileges.

Account Switcher plugin for WordPress <= 1.0.2 privilege-escalation wordpress cve web-application
2r 1t 1c
high advisory

Creative Mail WordPress Plugin Vulnerable to SQL Injection (CVE-2026-3985)

The Creative Mail plugin for WordPress is vulnerable to SQL Injection due to insufficient escaping of the 'checkout_uuid' parameter and lack of sufficient preparation on the SQL query in the `has_checkout_consent()` method, allowing unauthenticated attackers to extract sensitive information from the database.

Creative Mail – Easier WordPress & WooCommerce Email Marketing plugin <= 1.6.9 sqli wordpress plugin cve-2026-3985 cloud
2r 1t 1c
critical advisory

CVE-2026-7284 - Easy Elements for Elementor WordPress Plugin Privilege Escalation

The Easy Elements for Elementor plugin for WordPress is vulnerable to privilege escalation (CVE-2026-7284) due to unrestricted user role assignment during registration, allowing unauthenticated attackers to gain administrator access.

Easy Elements for Elementor – Addons & Website Templates plugin privilege-escalation wordpress cve-2026-7284
2r 1t 1c
critical advisory

ProSolution WP Client Plugin Arbitrary File Upload Vulnerability (CVE-2026-6555)

The ProSolution WP Client plugin for WordPress is vulnerable to arbitrary file upload (CVE-2026-6555) due to a validation mismatch, allowing unauthenticated attackers to upload malicious PHP files leading to remote code execution.

WP Client plugin <= 2.0.0 cve wordpress file-upload rce CVE-2026-6555
2r 1t 1c
high advisory

WordPress Kirki Plugin Arbitrary File Deletion (CVE-2026-8073)

The Kirki plugin for WordPress is vulnerable to arbitrary file deletion via CVE-2026-8073 due to insufficient file path validation and a missing capability check in the 'downloadZIP' function, allowing unauthenticated attackers to delete files within the WordPress uploads directory.

Kirki – Freeform Page Builder, Website Builder & Customizer plugin cve wordpress file-deletion
2r 1t 1c
high advisory

Contest Gallery WordPress Plugin SQL Injection Vulnerability (CVE-2026-8912)

The Contest Gallery plugin for WordPress is vulnerable to SQL Injection via the 'form_input' parameter in versions up to 28.1.6, allowing unauthenticated attackers to extract sensitive information from the database.

Contest Gallery plugin for WordPress sql injection cve-2026-8912 wordpress plugin vulnerability
2r 1t 1c
critical advisory

Piotnet Forms WordPress Plugin Arbitrary File Upload Vulnerability (CVE-2026-4883)

The Piotnet Forms plugin for WordPress is vulnerable to arbitrary file upload due to missing file type validation in the 'piotnetforms_ajax_form_builder' function, allowing unauthenticated attackers to upload arbitrary files and potentially achieve remote code execution.

Piotnet Forms plugin <= 2.1.40 arbitrary-file-upload wordpress plugin CVE-2026-4883
2r 1t 1c
critical threat

CVE-2026-4885: Piotnet Addons for Elementor Pro WordPress Plugin Arbitrary File Upload Vulnerability

The Piotnet Addons for Elementor Pro plugin for WordPress, versions up to 7.1.70, is vulnerable to unauthenticated arbitrary file upload due to insufficient file type validation in the 'pafe_ajax_form_builder' function, potentially leading to remote code execution.

Piotnet Addons for Elementor Pro <= 7.1.70 arbitrary-file-upload rce wordpress plugin
2r 1t 1c
high advisory

WordPress WP with Spritz Plugin 1.0 Remote File Inclusion

The WordPress WP with Spritz plugin version 1.0 is vulnerable to remote file inclusion (RFI), allowing unauthenticated attackers to read arbitrary files by injecting file paths into the `url` parameter of the `wp.spritz.content.filter.php` endpoint, potentially exposing sensitive system configuration and credentials.

WP with Spritz plugin 1.0 rfi wordpress cve-2018-25329 remote-file-inclusion
2r 1t 1c
critical threat

CVE-2018-25335 - WordPress Peugeot Music Plugin Arbitrary File Upload Vulnerability

WordPress Plugin Peugeot Music 1.0 contains an arbitrary file upload vulnerability (CVE-2018-25335) that allows unauthenticated attackers to upload malicious files by sending POST requests to the upload.php endpoint, leading to potential code execution.

Peugeot Music Plugin wordpress file-upload rce cve cve-2018-25335
2r 1t 1c
high advisory

CVE-2026-8719: Privilege Escalation Vulnerability in The AI Engine WordPress Plugin

The AI Engine – The Chatbot, AI Framework & MCP for WordPress plugin is vulnerable to privilege escalation (CVE-2026-8719) due to missing capability enforcement, allowing authenticated users (Subscriber+) to invoke admin-level MCP tools and gain administrator privileges.

The AI Engine – The Chatbot, AI Framework & MCP for WordPress plugin <= 3.4.9 privilege-escalation wordpress cve
2r 1t 1c
high advisory

WordPress Backup and Restore Plugin Arbitrary File Deletion (CVE-2021-47979)

WordPress Backup and Restore plugin 1.0.3 contains an arbitrary file deletion vulnerability (CVE-2021-47979) allowing authenticated attackers to delete files by manipulating parameters in AJAX requests to admin-ajax.php.

Backup and Restore wordpress file-deletion cve-2021-47979
2r 1t 1c
high advisory

WordPress Anti-Malware Security and Bruteforce Firewall Directory Traversal Vulnerability

WordPress Anti-Malware Security and Bruteforce Firewall 4.20.59 contains a directory traversal vulnerability (CVE-2021-47977) that allows unauthenticated attackers to read arbitrary files by manipulating the file parameter in requests to admin-ajax.php.

Anti-Malware Security and Bruteforce Firewall 4.20.59 directory-traversal wordpress plugin cve-2021-47977
2r 1t 1c
high threat

HS Brand Logo Slider 2.1 Unrestricted File Upload Vulnerability (CVE-2020-37227)

HS Brand Logo Slider version 2.1 contains an unrestricted file upload vulnerability (CVE-2020-37227) allowing authenticated users to bypass client-side validation and upload arbitrary files, leading to remote code execution by intercepting upload requests and renaming files to executable extensions.

HS Brand Logo Slider 2.1 file upload remote code execution wordpress CVE-2020-37227
2r 1t 1c
medium threat

CVE-2021-47959: WPGraphQL Plugin Denial of Service via Batched Queries

The WordPress Plugin WPGraphQL version 1.3.5 is vulnerable to a denial-of-service attack where unauthenticated attackers can exhaust server resources by sending batched GraphQL queries with duplicated fields, potentially causing server out-of-memory conditions and MySQL connection errors.

WPGraphQL 1.3.5 denial-of-service wordpress graphql
2r 1t 1c
critical threat

CVE-2021-47965: WordPress WP Super Edit Plugin Unrestricted File Upload

WordPress WP Super Edit plugin version 2.5.4 and earlier contains an unrestricted file upload vulnerability in the FCKeditor component, allowing unauthenticated attackers to upload arbitrary files leading to remote code execution and complete system compromise.

WP Super Edit plugin <= 2.5.4 cve-2021-47965 wordpress file-upload rce
2r 2t 1c
high advisory

CVE-2026-6403: Quick Playground Plugin for WordPress Path Traversal Vulnerability

The Quick Playground plugin for WordPress, versions up to 1.3.3, is vulnerable to a path traversal vulnerability (CVE-2026-6403) in the qckply_zip_theme() function, allowing unauthenticated attackers to create ZIP archives containing arbitrary server files, including wp-config.

Quick Playground plugin for WordPress path-traversal wordpress cve-2026-6403 initial-access
2r 1t 1c
critical advisory

WordPress Form Notify Plugin Authentication Bypass Vulnerability (CVE-2026-5229)

The Form Notify plugin for WordPress is vulnerable to CVE-2026-5229, an authentication bypass, due to trusting user-controlled cookie data after a LINE OAuth login, allowing unauthenticated attackers to gain administrative access.

Form Notify <= 1.1.10 authentication-bypass wordpress plugin CVE-2026-5229
2r 1t 1c
high advisory

CVE-2026-4031 - Database Backup for WordPress Plugin Authorization Bypass

CVE-2026-4031 is an authorization bypass vulnerability in the Database Backup for WordPress plugin (<= 2.5.2) that allows unauthenticated attackers to intercept database backup files by manipulating the backup directory via the wp_db_temp_dir parameter, leading to sensitive information exposure.

Database Backup for WordPress plugin <= 2.5.2 wordpress authorization-bypass sensitive-data-exposure cve
2r 1t 1c
high advisory

Database Backup for WordPress Plugin Arbitrary File Read and Deletion Vulnerability (CVE-2026-4030)

The Database Backup for WordPress plugin before 2.5.3 is vulnerable to unauthenticated arbitrary file read and deletion due to improper authorization checks and user-controlled backup directories, leading to sensitive information exposure and potential site takeover on WordPress Multisite environments.

Database Backup for WordPress plugin <= 2.5.2 wordpress file_read file_deletion cve
2r 1c
high advisory

CVE-2026-4029: Database Backup for WordPress Plugin Unauthorized Database Export

The Database Backup for WordPress plugin up to version 2.5.2 is vulnerable to unauthorized database export due to improper authorization enforcement, allowing unauthenticated attackers to export database tables in WordPress Multisite environments.

Database Backup for WordPress plugin <= 2.5.2 cve wordpress database backup unauthenticated access data exfiltration
2r 1t 1c
critical advisory

InfusedWoo Pro Plugin for WordPress Authorization Bypass (CVE-2026-6512)

The InfusedWoo Pro plugin for WordPress is vulnerable to an authorization bypass (CVE-2026-6512) in versions up to 5.1.2, allowing unauthenticated attackers to delete posts, pages, products, orders, comments, and change post statuses.

InfusedWoo Pro plugin for WordPress <= 5.1.2 cve wordpress authorization bypass web application plugin vulnerability
2r 1t 1c
high advisory

CVE-2026-6506: InfusedWoo Pro WordPress Plugin Privilege Escalation

The InfusedWoo Pro plugin for WordPress is vulnerable to privilege escalation in versions up to 5.1.2 due to missing authorization checks in the infusedwoo_gdpr_upddata() function, allowing authenticated attackers to grant themselves administrator privileges.

InfusedWoo Pro plugin <= 5.1.2 privilege-escalation wordpress plugin
2r 1t 1c
high threat

Fluent Forms WordPress Plugin IDOR Vulnerability (CVE-2026-5395)

The Fluent Forms WordPress plugin through 6.2.0 is vulnerable to Insecure Direct Object Reference (IDOR), allowing authenticated users with manager-level access or higher to bypass form-level access controls, export arbitrary database tables, and enumerate table names via error messages, as tracked by CVE-2026-5395.

Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder plugin <= 6.2.0 insecure-direct-object-reference wordpress fluentforms cve-2026-5395
2r 2t 1c
medium advisory

CVE-2026-3892 - WordPress Motors Plugin Arbitrary File Deletion

The Motors – Car Dealership & Classified Listings Plugin plugin for WordPress is vulnerable to arbitrary file deletion in versions up to 1.4.107 due to insufficient file path validation in the become-dealer logo upload flow, allowing authenticated attackers with subscriber level access and above to delete arbitrary files on the server.

The Motors – Car Dealership & Classified Listings Plugin <= 1.4.107 arbitrary-file-deletion wordpress plugin
1r 1t 1c
medium advisory

ManageWP Worker Plugin Vulnerable to Stored XSS via HTTP Header

The ManageWP Worker plugin for WordPress is vulnerable to Stored Cross-Site Scripting (XSS) via the 'MWP-Key-Name' HTTP request header, allowing unauthenticated attackers to inject arbitrary web scripts that execute when an administrator visits the plugin's connection management page with debug parameters; this affects all versions up to and including 4.9.31.

ManageWP Worker plugin <= 4.9.31 wordpress xss cve-2026-3718
2r 1t 1c
critical advisory

CVE-2026-6510: InfusedWoo Pro WordPress Plugin Privilege Escalation

The InfusedWoo Pro plugin for WordPress is vulnerable to privilege escalation due to missing nonce verification and capability checks in the iwar_save_recipe() AJAX handler, allowing unauthenticated attackers to create malicious automation recipes for auto-login actions.

InfusedWoo Pro plugin <= 5.1.2 privilege-escalation initial-access wordpress
1r 1t 1c
high threat

Fluent Forms Plugin Authorization Bypass via User-Controlled Key (CVE-2026-5396)

The Fluent Forms plugin for WordPress is vulnerable to authorization bypass via a user-controlled key (CVE-2026-5396), allowing authenticated attackers with restricted access to specific forms to manipulate submissions of unauthorized forms by spoofing the 'form_id' parameter.

Fluent Forms plugin <= 6.1.21 authorization-bypass wordpress plugin
2r 2t 1c
critical advisory

Burst Statistics WordPress Plugin Authentication Bypass (CVE-2026-8181)

The Burst Statistics plugin for WordPress is vulnerable to authentication bypass, allowing unauthenticated attackers with knowledge of an administrator username to impersonate that administrator by supplying a random Basic Authentication password, leading to privilege escalation.

Burst Statistics – Privacy-Friendly WordPress Analytics authentication-bypass privilege-escalation wordpress
1r 1t 1c
high advisory

CVE-2026-4609: ProfileGrid WordPress Plugin Authentication Bypass Vulnerability

The ProfileGrid WordPress plugin versions up to 5.9.8.4 contain an authentication bypass vulnerability (CVE-2026-4609) that allows authenticated users with subscriber-level privileges to add themselves or others to arbitrary groups, including paid groups, without proper authorization, leading to privilege escalation and potential financial impact.

ProfileGrid – User Profiles, Groups and Communities plugin for WordPress <= 5.9.8.4 authentication bypass wordpress plugin privilege escalation cve-2026-4609
1r 1t 1c
medium advisory

CVE-2026-6177 - Custom Twitter Feeds WordPress Plugin Stored XSS

The Custom Twitter Feeds plugin for WordPress is vulnerable to stored cross-site scripting (XSS) in versions up to and including 2.5.4 due to insufficient output escaping, allowing unauthenticated attackers to inject arbitrary web scripts.

Custom Twitter Feeds plugin <= 2.5.4 xss wordpress CVE-2026-6177
2r 1t 1c
high advisory

RTMKit Addons for Elementor WordPress Plugin LFI Vulnerability (CVE-2026-3425)

The RTMKit Addons for Elementor plugin for WordPress is vulnerable to local file inclusion (LFI) via the 'path' parameter in the 'get_content' AJAX action, allowing authenticated attackers with Author-level access or higher to include and execute arbitrary PHP files, leading to potential code execution.

RTMKit Addons for Elementor plugin <= 2.0.2 lfi wordpress plugin cve-2026-3425
1r 2t 1c
high advisory

CVE-2026-4798 - Avada Builder Plugin SQL Injection Vulnerability

The Avada Builder plugin for WordPress is vulnerable to time-based SQL Injection (CVE-2026-4798) via the ‘product_order’ parameter in versions up to 3.15.1, potentially allowing unauthenticated attackers to extract sensitive database information if WooCommerce was previously used and deactivated.

Avada Builder plugin +1 sql-injection wordpress avada-builder cve-2026-4798
2r 1t 1c
high threat

JoomSport WordPress Plugin Vulnerable to Time-Based Blind SQL Injection (CVE-2026-6929)

The JoomSport plugin for WordPress is vulnerable to time-based blind SQL Injection (CVE-2026-6929) via the 'sortf' parameter in versions up to 5.7.7, allowing unauthenticated attackers to extract sensitive information from the database.

JoomSport – for Sports: Team & League, Football, Hockey & more plugin <= 5.7.7 sqli wordpress cve-2026-6929 joomsport injection
2r 1t 1c
medium advisory

coreActivity: Activity Logging for WordPress Plugin Vulnerable to PHP Object Injection (CVE-2026-7635)

The coreActivity: Activity Logging for WordPress plugin for WordPress is vulnerable to PHP Object Injection (CVE-2026-7635), allowing unauthenticated attackers to inject a crafted PHP serialized payload via the User-Agent header, leading to a persistent Denial of Service condition.

coreActivity: Activity Logging for WordPress plugin <= 3.0 cve wordpress php object injection denial of service
2r 1t 1c
high advisory

WordPress Court Reservation Plugin SQL Injection Vulnerability (CVE-2026-1250)

The Court Reservation – Manage Your Court Bookings Online plugin for WordPress versions 1.10.11 and earlier are vulnerable to SQL injection via the 'id' parameter, enabling unauthenticated attackers to extract sensitive database information.

The Court Reservation – Manage Your Court Bookings Online plugin for WordPress <= 1.10.11 sql-injection wordpress plugin CVE-2026-1250 web-application
2r 1t 1c
medium advisory

CVE-2026-6690: LifePress WordPress Plugin Stored XSS Vulnerability

The LifePress plugin for WordPress is vulnerable to stored cross-site scripting (XSS) due to insufficient input sanitization and output escaping within the `lp_update_mds` AJAX action, allowing unauthenticated attackers to inject arbitrary web scripts via the 'n' parameter that execute when a user accesses the injected page; this affects versions up to and including 2.2.2.

LifePress plugin <= 2.2.2 wordpress xss cve-2026-6690 lifepress stored-xss plugin
2r 1t 1c
high threat

CVE-2021-47941: WordPress Survey & Poll Plugin SQL Injection Vulnerability

WordPress Plugin Survey & Poll version 1.5.7.3 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the wp_sap cookie parameter, potentially leading to sensitive data extraction.

Survey & Poll plugin cve cve-2021-47941 wordpress sql injection web application
2r 1t 1c
critical advisory

CVE-2021-47933 - WordPress MStore API Arbitrary File Upload

WordPress MStore API 2.0.6 contains an arbitrary file upload vulnerability, allowing unauthenticated attackers to upload malicious files via POST requests to the REST API, leading to remote code execution.

MStore API plugin for WordPress cve wordpress file upload remote code execution
2r 1t 1c
critical advisory

CVE-2021-47932: WordPress TheCartPress Unauthenticated Privilege Escalation

WordPress TheCartPress version 1.5.3.6 contains an unauthenticated privilege escalation vulnerability, CVE-2021-47932, allowing attackers to create administrator accounts via crafted POST requests to the AJAX handler.

TheCartPress 1.5.3.6 wordpress privilege-escalation unauthenticated CVE-2021-47932
2r 1t 1c
medium advisory

WordPress Auto Affiliate Links Plugin Stored XSS Vulnerability (CVE-2026-7330)

The Auto Affiliate Links plugin for WordPress is vulnerable to Stored Cross-Site Scripting (XSS) in versions up to 6.8.8 due to insufficient input sanitization and output escaping, allowing unauthenticated attackers to inject arbitrary web scripts into the admin statistics page.

Auto Affiliate Links plugin <= 6.8.8 wordpress xss plugin
2r 1t 1c
high advisory

WordPress User Frontend Plugin Deserialization Vulnerability (CVE-2026-5127)

The User Frontend WordPress plugin is vulnerable to authenticated deserialization, allowing subscriber-level attackers to inject PHP objects for potential arbitrary code execution.

User Frontend: AI Powered Frontend Posting, User Directory, Profile, Membership & User Registration plugin <= 4.3.1 deserialization wordpress plugin cve-2026-5127
2r 1t 1c
critical advisory

WordPress Slider Revolution Plugin Arbitrary File Upload Vulnerability

The Slider Revolution plugin for WordPress is vulnerable to arbitrary file upload due to insufficient file type validation, allowing authenticated attackers with subscriber-level access or higher to upload executable files, potentially leading to remote code execution.

Slider Revolution plugin wordpress file-upload rce plugin
2r 1t 1c
high advisory

BetterDocs Pro Plugin SQL Injection Vulnerability

The BetterDocs Pro plugin for WordPress is vulnerable to SQL Injection via the `get_current_letter_docs` and `docs_sort_by_letter` AJAX actions, allowing unauthenticated attackers to extract sensitive information from the database.

BetterDocs Pro plugin sqli wordpress plugin cve-2026-4348
2r 1t 1c
high advisory

webonyx/graphql-php Unbounded Recursion Vulnerability

The webonyx/graphql-php library has an unbounded recursion vulnerability in its parser that can lead to a stack overflow, causing a denial of service by terminating the PHP process with a SIGSEGV.

graphql-php +4 graphql denial-of-service recursion php
2r 1t
high advisory

WordPress Backup Migration Plugin Unauthenticated Database Backup Download

WordPress Plugin Backup Migration 1.2.8 contains an information disclosure vulnerability allowing unauthenticated attackers to download complete database backups by accessing predictable file paths.

Backup Migration plugin information-disclosure wordpress cve-2023-54346
2r 1t 1c
high advisory

Forminator Forms Plugin Path Traversal Vulnerability

The Forminator Forms WordPress plugin is vulnerable to an unauthenticated path traversal that allows reading arbitrary files on the server when specific features are enabled.

Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin path-traversal wordpress plugin
2r 1t 1c
high advisory

AWP Classifieds WordPress Plugin SQL Injection Vulnerability

The AWP Classifieds plugin for WordPress is vulnerable to SQL Injection via the 'regions' parameter array keys in versions up to, and including, 4.4.5, potentially allowing unauthenticated attackers to extract sensitive information from the database.

AWP Classifieds plugin for WordPress sql-injection wordpress plugin
2r 1t 1c
critical advisory

WordPress Mentoring Plugin Privilege Escalation Vulnerability

The Mentoring plugin for WordPress is vulnerable to privilege escalation, allowing unauthenticated attackers to register with administrator-level user accounts due to improper role restriction in the mentoring_process_registration() function.

Mentoring plugin for WordPress privilege-escalation wordpress plugin
2r 1t 1c
medium advisory

Contact Form 7 WordPress Plugin Uncontrolled Resource Consumption Vulnerability

The Contact Form 7 WordPress plugin through version 2.6.7 is vulnerable to uncontrolled resource consumption, allowing unauthenticated attackers to exhaust server memory and crash the PHP process by supplying an arbitrarily large integer value to the REST API endpoint, leading to unbounded loop execution.

Contact Form 7 WordPress plugin wordpress resource-exhaustion denial-of-service cve-2026-25863
2r 1t 1c
high advisory

WordPress Easy PayPal Events & Tickets Plugin Information Disclosure Vulnerability

An information disclosure vulnerability in the Easy PayPal Events & Tickets WordPress plugin (versions 1.3 and earlier) allows unauthenticated attackers to enumerate and retrieve all customer order records via the scan_qr.php endpoint.

Easy PayPal Events & Tickets plugin wordpress info-disclosure cve-2026-41471 unauthenticated enumeration
2r 1t 1c
high advisory

WordPress Easy PayPal Events & Tickets Plugin Authentication Bypass Vulnerability

An unauthenticated remote attacker can exploit a hardcoded authentication bypass vulnerability in the Easy PayPal Events & Tickets plugin for WordPress (versions 1.3 and earlier) by providing 'test' as the hash parameter, allowing retrieval of sensitive order details.

Easy PayPal Events & Tickets plugin wordpress authentication bypass vulnerability
2r 1t 1c 1i
medium advisory

NEX-Forms WordPress Plugin Vulnerable to Stored Cross-Site Scripting (CVE-2026-5063)

The NEX-Forms WordPress plugin is vulnerable to stored XSS via POST parameter key names, allowing unauthenticated attackers to inject arbitrary web scripts.

NEX-Forms – Ultimate Forms Plugin for WordPress plugin <= 9.1.11 wordpress xss stored-xss cve-2026-5063
2r 1t 1c
high advisory

WordPress WCFM Plugin Vulnerable to IDOR Leading to Account Deletion

The WCFM plugin for WordPress is vulnerable to an Insecure Direct Object Reference (IDOR) that allows authenticated attackers with Vendor-level access or higher to delete arbitrary users, including administrators.

WCFM – Frontend Manager for WooCommerce along with Bookings Subscription Listings Compatible plugin <= 6.7.25 idor wordpress woocommerce account-deletion
2r 1t 1c
high advisory

Salon Booking System WordPress Plugin Arbitrary File Read Vulnerability

The Salon Booking System WordPress plugin is vulnerable to arbitrary file read, allowing unauthenticated attackers to exfiltrate local files by manipulating file-field values in booking confirmation emails.

Salon Booking System – Free Version plugin for WordPress <= 10.30.25 arbitrary-file-read wordpress plugin-vulnerability cve
2r 1t 1c
high advisory

Paid Memberships Pro Plugin Vulnerability Allows Unauthorized Stripe Webhook Modification

The Paid Memberships Pro plugin for WordPress is vulnerable to unauthorized modification of Stripe webhook configurations due to missing capability checks, allowing authenticated attackers with Subscriber-level access to disrupt payment processing.

Paid Memberships Pro plugin wordpress stripe webhook vulnerability plugin
2r 3t 1c
high advisory

Geo Mashup WordPress Plugin Vulnerable to Time-Based SQL Injection (CVE-2026-4062)

The Geo Mashup WordPress plugin is vulnerable to Time-Based SQL Injection due to insufficient input sanitization, allowing unauthenticated attackers to extract sensitive database information.

Geo Mashup plugin <= 1.13.18 sqli wordpress plugin
2r 1t 1c
high advisory

Geo Mashup WordPress Plugin Vulnerable to Time-Based SQL Injection (CVE-2026-4061)

A time-based SQL injection vulnerability (CVE-2026-4061) exists in the Geo Mashup WordPress plugin (<= 1.13.18) due to insufficient sanitization of the 'map_post_type' parameter, enabling unauthenticated attackers to extract sensitive information via time-based blind SQL injection if the Geo Search feature is enabled.

Geo Mashup plugin sql-injection wordpress plugin
2r 1t 1c
critical advisory

WordPress Widget Options Plugin Remote Code Execution Vulnerability (CVE-2026-2052)

The Widget Options plugin for WordPress is vulnerable to Remote Code Execution (CVE-2026-2052) due to insufficient input sanitization in the Display Logic feature, allowing authenticated attackers with Contributor-level access and above to execute arbitrary code on the server.

The Widget Options – Advanced Conditional Visibility for Gutenberg Blocks & Classic Widgets plugin <= 4.2.2 wordpress rce plugin
2r 1t 1c
high threat

PixelYourSite Pro WordPress Plugin SSRF Vulnerability (CVE-2026-7049)

The PixelYourSite Pro WordPress plugin is vulnerable to server-side request forgery (SSRF), allowing unauthenticated attackers to make arbitrary web requests from the server, potentially querying or modifying internal services.

PixelYourSite Pro – Your smart PIXEL ssrf wordpress plugin
2r 1t 1c
medium advisory

Gravity Forms Plugin Stored XSS Vulnerability (CVE-2026-5113)

The Gravity Forms plugin for WordPress is vulnerable to stored cross-site scripting (XSS) via Consent field hidden inputs, allowing unauthenticated attackers to inject arbitrary web scripts that execute when an administrator views the entries list page.

Gravity Forms plugin <= 2.10.0 xss wordpress gravityforms cve-2026-5113 stored-xss
2r 2t 1c
high advisory

WP Mail Gateway Plugin Vulnerability Leads to Privilege Escalation

The WP Mail Gateway plugin for WordPress is vulnerable to unauthorized access due to a missing capability check, allowing authenticated attackers to modify SMTP settings and escalate privileges.

WP Mail Gateway plugin wordpress privilege-escalation plugin-vulnerability
2r 1t 1c
high advisory

WordPress Import and Export Users Plugin Privilege Escalation Vulnerability

A privilege escalation vulnerability exists in the Import and export users and customers plugin for WordPress (versions <= 2.0.8) due to an incomplete blocklist allowing authenticated users to gain administrator privileges on subsites within a Multisite network.

Import and export users and customers plugin privilege-escalation wordpress cloud
2r 1t 1c
critical advisory

WordPress User Registration Advanced Fields Plugin Arbitrary File Upload Vulnerability

The User Registration Advanced Fields plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation, allowing unauthenticated attackers to upload arbitrary files leading to potential remote code execution.

User Registration Advanced Fields plugin <= 1.6.20 wordpress file-upload rce
2r 1t 1c
high advisory

WP Editor Plugin CSRF Vulnerability

The WP Editor plugin for WordPress is vulnerable to Cross-Site Request Forgery (CSRF) in versions up to 1.2.9.2, allowing unauthenticated attackers to overwrite arbitrary plugin and theme PHP files with malicious code by tricking a site administrator into clicking a link.

WP Editor plugin <= 1.2.9.2 csrf wordpress plugin vulnerability
2r 1t 1c
critical advisory

WordPress Temporary Login Plugin Authentication Bypass (CVE-2026-7567)

The Temporary Login plugin for WordPress versions up to 1.0.0 is vulnerable to authentication bypass due to improper input validation, allowing unauthenticated attackers to log in as arbitrary temporary users by sending a specially crafted GET request.

Temporary Login plugin authentication bypass wordpress plugin vulnerability cve-2026-7567 cloud
2r 1t 1c
high advisory

Otter Blocks Plugin Purchase Verification Bypass Vulnerability (CVE-2026-2892)

CVE-2026-2892 is a purchase verification bypass vulnerability in the Otter Blocks plugin for WordPress, affecting versions up to 3.1.4, that allows unauthenticated attackers to access restricted content by forging a cookie used for purchase validation.

Otter Blocks plugin wordpress plugin purchase-bypass CVE-2026-2892 defense-evasion
3r 1t 1c
high advisory

DirectoryPress WordPress Plugin Vulnerable to SQL Injection (CVE-2026-3489)

The DirectoryPress WordPress plugin before 3.6.26 is vulnerable to unauthenticated SQL Injection via the 'packages' parameter, allowing attackers to extract sensitive database information.

DirectoryPress +1 wordpress sql-injection cve-2026-3489
2r 1t 1c
medium advisory

Prismatic WordPress Plugin Stored XSS Vulnerability

The Prismatic plugin for WordPress versions 3.7.3 and earlier is vulnerable to stored cross-site scripting (XSS) via the 'prismatic_encoded' pseudo-shortcode, allowing unauthenticated attackers to inject arbitrary web scripts into pages.

Prismatic plugin +1 wordpress xss plugin prismatic
2r 1t 1c
critical advisory

WordPress Advanced Members for ACF Plugin Arbitrary File Deletion Vulnerability

The Advanced Members for ACF plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the create_crop function, allowing authenticated attackers with Subscriber-level access or higher to delete arbitrary files, potentially leading to remote code execution.

WordPress +1 file-deletion remote-code-execution cve-2026-3243
2r 1t 1c
high advisory

Royal Elementor Addons Plugin SSRF Vulnerability

The Royal Elementor Addons plugin for WordPress is vulnerable to Server-Side Request Forgery (SSRF) allowing authenticated attackers with Contributor-level access or higher to make arbitrary requests and retrieve sensitive information from internal services.

Royal Elementor Addons <= 1.7.1057 wordpress ssrf cve-2026-6229 plugin
2r 1t 1c
high advisory

WordPress Drag and Drop File Upload Plugin Vulnerable to Arbitrary File Upload (CVE-2026-5364)

The Drag and Drop File Upload for Contact Form 7 plugin for WordPress is vulnerable to arbitrary file upload in versions up to 1.1.3, allowing unauthenticated attackers to upload arbitrary PHP files by manipulating the file type parameter and exploiting extension sanitization vulnerabilities.

Drag and Drop File Upload for Contact Form 7 plugin wordpress file-upload rce plugin CVE-2026-5364
2r 1t 1c
critical advisory

WordPress Profile Builder Pro Plugin PHP Object Injection Vulnerability (CVE-2026-7647)

An unauthenticated PHP Object Injection vulnerability exists in the Profile Builder Pro WordPress plugin (versions up to 3.14.5) due to the insecure use of `maybe_unserialize()` on the 'args' POST parameter in the `wppb_request_users_pins_action_callback()` AJAX handler, potentially leading to arbitrary code execution.

Profile Builder Pro plugin php-object-injection wordpress plugin rce
2r 1t 1c
critical advisory

MoreConvert Pro WordPress Plugin Authentication Bypass Vulnerability

The MoreConvert Pro plugin for WordPress versions 1.9.14 and earlier is vulnerable to authentication bypass due to improper handling of guest waitlist verification tokens, allowing unauthenticated attackers to potentially gain administrative access.

MoreConvert Pro plugin wordpress authentication-bypass plugin cve-2026-5722
2r 1t 1c
medium advisory

LatePoint WordPress Plugin Stored XSS Vulnerability

The LatePoint WordPress plugin is vulnerable to stored XSS via the booking_form_page_url parameter, allowing unauthenticated attackers to inject arbitrary web scripts in pages that execute when a user accesses the injected page.

LatePoint – Calendar Booking Plugin for Appointments and Events plugin <= 5.5.0 wordpress xss stored-xss cve-2026-7332 plugin
2r 1c
medium advisory

Gravity Forms Plugin Unauthenticated Stored XSS Vulnerability

The Gravity Forms plugin for WordPress is vulnerable to unauthenticated stored cross-site scripting (XSS) in versions up to 2.10.0, allowing attackers to inject arbitrary JavaScript code into the product name field within repeater fields, which executes when an administrator views the affected entry.

Gravity Forms plugin <= 2.10.0 xss wordpress gravityforms
2r 1t 1c
critical advisory

Geeky Bot WordPress Plugin Missing Authorization Vulnerability Leads to Remote Code Execution

The Geeky Bot plugin for WordPress is vulnerable to Missing Authorization in versions up to 1.2.2, allowing unauthenticated attackers to perform arbitrary plugin installation and achieve remote code execution by exploiting a nopriv AJAX route and uploading malicious ZIP files.

Geeky Bot plugin for WordPress <= 1.2.2 wordpress plugin rce missing-authorization cve-2026-5294 code-execution
2r 3t 1c
critical advisory

Compromised WordPress Plugin 'Accordion and Accordion Slider' Delivers Backdoor

A malicious actor injected a backdoor into the WordPress 'Accordion and Accordion Slider' plugin version 1.4.6 after purchasing it, allowing for persistence and spam injection.

Accordion and Accordion Slider wordpress backdoor plugin spam cve-2026-6443
2r 2t 1c
critical advisory

Betheme WordPress Theme Arbitrary File Upload Vulnerability

The Betheme theme for WordPress is vulnerable to arbitrary file upload, allowing authenticated attackers with author-level privileges or higher to upload arbitrary files, including PHP, leading to remote code execution.

Betheme theme arbitrary-file-upload rce wordpress betheme
2r 1t 1c
high advisory

ARMember WordPress Plugin Vulnerable to Time-Based Blind SQL Injection (CVE-2026-7649)

A time-based blind SQL Injection vulnerability exists in the ARMember WordPress plugin (<= 4.0.60) due to insufficient input sanitization of the 'orderby' parameter, allowing unauthenticated attackers to extract sensitive database information.

ARMember – Membership Plugin, Content Restriction, Member Levels, User Profile & User signup plugin <= 4.0.60 sql-injection wordpress armember cve-2026-7649
2r 1t 1c
critical advisory

WP-Optimize Plugin Vulnerable to Arbitrary File Deletion

The WP-Optimize plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation, allowing authenticated attackers with author-level access or higher to delete arbitrary files, potentially leading to remote code execution.

WP-Optimize – Cache, Compress images, Minify & Clean database to boost page speed & performance <= 4.5.2 wordpress file-deletion rce
2r 2t 1c
medium advisory

Gravity Forms Plugin Unauthenticated Stored XSS Vulnerability

The Gravity Forms plugin for WordPress is vulnerable to Unauthenticated Stored Cross-Site Scripting (XSS) in versions up to and including 2.10.0, allowing unauthenticated attackers to inject arbitrary web scripts via form submissions that execute when an administrator views the entry detail page.

Gravity Forms plugin xss wordpress gravityforms
2r 1c
high advisory

GeekyBot WordPress Plugin Vulnerable to SQL Injection

The GeekyBot WordPress plugin is vulnerable to SQL Injection, allowing unauthenticated attackers to extract sensitive information from the database by manipulating the 'attributekey' parameter.

The GeekyBot - Generate AI Content Without Prompt, Chatbot and Lead Generation plugin <= 1.2.0 sqli wordpress plugin cve-2026-3456
2r 1t 1c
critical advisory

ExactMetrics WordPress Plugin Vulnerability Leads to Remote Code Execution

The ExactMetrics plugin for WordPress is vulnerable to unauthorized arbitrary plugin installation and activation via a REST API endpoint, potentially leading to remote code execution by authenticated attackers.

ExactMetrics – Google Analytics Dashboard for WordPress wordpress plugin rce cve-2026-5464 exactmetrics
2r 4t 1c
medium advisory

Brizy WordPress Plugin Unauthenticated Stored XSS Vulnerability

The Brizy – Page Builder plugin for WordPress is vulnerable to Unauthenticated Stored Cross-Site Scripting (XSS) in versions up to and including 2.8.11, allowing unauthenticated attackers to inject arbitrary web scripts that execute when an administrator views the form Leads page due to missing nonce verification and improper handling of file upload fields.

Brizy – Page Builder plugin <= 2.8.11 wordpress xss unauthenticated
2r 1t 1c