VYPR

Vendor CVEs

WordPress

All CVEs

36,919 total · sorted by risk
  • CVE-2026-11881MedJul 30, 2026
    risk 0.00cvss 6.1epss 0.00

    The Fluent Forms WordPress plugin before 6.2.6 does not sanitise and escape one of its form field configuration settings before outputting it inside an inline script when a form is rendered, which could allow users with a role as low as Contributor (with delegated…

  • CVE-2026-11870MedJul 30, 2026
    risk 0.00cvss 5.4epss 0.00

    The WP Ghost (Hide My WP Ghost) WordPress plugin before 7.0.05 does not verify that client IP information comes from a trusted proxy before trusting attacker-controllable HTTP headers, allowing unauthenticated attackers to spoof their IP address to bypass the WP Ghost (Hide My…

  • CVE-2026-11867MedJul 30, 2026
    risk 0.00cvss 6.5epss 0.00

    The Frontend Admin by DynamiApps WordPress plugin before 3.29.7 does not perform capability checks on its taxonomy term creation, modification, and deletion operations, allowing authenticated users with low privileges (such as Subscribers) to create, rename, and delete arbitrary…

  • CVE-2026-11782MedJul 30, 2026
    risk 0.00cvss 5.9epss 0.00

    The Points and Rewards for WooCommerce WordPress plugin before 2.10.1 does not have authorisation checks in place on a wallet and points update action that is available to unauthenticated users, and does not verify that the requester owns the account being changed, allowing…

  • CVE-2026-1360HigJul 30, 2026
    risk 0.00cvss 7.5epss 0.01

    The BuddyPress plugin for WordPress is vulnerable to Deserialization of Untrusted Data in all versions up to, and including, 14.5.0 This is due to the `bp_unserialize_profile_field()` function using `@unserialize()` without the `allowed_classes` parameter on user-controlled…

  • CVE-2026-16610CriJul 30, 2026
    risk 0.00cvss 9.8epss 0.01

    The Admin and Site Enhancements (ASE) Pro plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 8.9.0 via the recursive_html function. This is due to the frontend save handler enforces only a publicly emitted nonce with no…

  • CVE-2026-14356HigJul 30, 2026
    risk 0.00cvss 8.8epss 0.00

    The FleekDash V2 plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 2.6.2.2. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers, with…

  • CVE-2026-1982MedJul 30, 2026
    risk 0.00cvss 5.3epss 0.00

    The Persian Elementor (المنتور فارسی) plugin for WordPress is vulnerable to Price Manipulation in all versions up to, and including, 2.8.1. This is due to the plugin trusting a user-supplied payment amount without server-side validation against the configured…

  • CVE-2026-16092MedJul 30, 2026
    risk 0.00cvss 6.5epss 0.00

    The Improved Save Button plugin for WordPress is vulnerable to second-order SQL Injection via 'meta_key' Custom Field via 'Save and Duplicate' Action in all versions up to, and including, 1.2.1 due to insufficient escaping on the user supplied parameter and lack of sufficient…

  • CVE-2026-14270HigJul 29, 2026
    risk 0.00cvss 8.8epss 0.01

    The Extra Checkout Options (addon for Extra Product Options & Add-Ons for WooCommerce) plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 2.3.2. This is due to missing authorization and nonce validation in the eco_save_settings()…

  • CVE-2026-8791MedJul 29, 2026
    risk 0.00cvss 6.4epss 0.00

    The Booking System Trafft plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `bookingWebsiteUrl` setting in all versions up to, and including, 1.0.17 due to a missing capability check on the `set_options` AJAX action when the plugin is operating in agency…

  • CVE-2026-7436MedJul 29, 2026
    risk 0.00cvss 6.4epss 0.00

    The WPC Badge Management for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'text' attribute of the `wpcbm_best_seller` shortcode in all versions up to, and including, 3.1.6 due to insufficient input sanitization and output escaping on user…

  • CVE-2026-6089MedJul 29, 2026
    risk 0.00cvss 4.9epss 0.00

    The WP CTA plugin for WordPress is vulnerable to Server-Side Request Forgery via the 'sticky_s_media' parameter in imported JSON files in all versions up to, and including, 2.1.2. This is due to the import_sidebars() function passing user-supplied URLs from imported JSON data to…

  • CVE-2026-5060MedJul 29, 2026
    risk 0.00cvss 6.5epss 0.00

    The MasterStudy LMS WordPress Plugin – for Online Courses and Education plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 3.7.14. This is due to the `stm_lms_delete_cover()` function lacking ownership validation on the…

  • CVE-2026-4604MedJul 29, 2026
    risk 0.00cvss 5.3epss 0.00

    The Klubraum Membership Request plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the `kr_mr_store_settings()` function in all versions up to, and including, 1.1.0. This makes it possible for unauthenticated attackers to…

  • CVE-2026-16655HigJul 29, 2026
    risk 0.00cvss 7.2epss 0.00

    The Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Name Field Nested `password` Member in all versions up to, and including, 6.2.7 due to insufficient input…

  • CVE-2026-16597HigJul 29, 2026
    risk 0.00cvss 7.2epss 0.00

    The GTM4WP – A Google Tag Manager (GTM) plugin for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via WooCommerce Billing Fields in all versions up to, and including, 1.22.3 due to insufficient input sanitization and output escaping. This makes it…

  • CVE-2026-14900CriJul 29, 2026
    risk 0.00cvss 9.8epss 0.01

    The Cost Calculator Builder PRO plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 4.0.3 via the js_to_php function. This is due to insufficient sanitization of the orderDetails[*].originalValue field, which is injected verbatim…

  • CVE-2026-14488CriJul 29, 2026
    risk 0.00cvss 9.1epss 0.00

    The Meta Box AIO plugin for WordPress is vulnerable to Missing Authorization via the template_redirect dispatcher in the MB Frontend Submission extension in versions up to, and including, 3.8.0. This is due to the handle_request() function routing the mbfs_delete action without…

  • CVE-2025-10656CriJul 29, 2026
    risk 0.00cvss 9.8epss 0.00

    The Spreadsheet Price Changer for WooCommerce and WP E-commerce – Light plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 2.4.37 vi the user_filter function. This makes it possible for unauthenticated attackers to create admin…

  • CVE-2026-9720MedJul 29, 2026
    risk 0.00cvss 4.3epss 0.00

    The Facturación Electrónica Costa Rica plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.0.2. This is due to missing or incorrect nonce validation on the (global scope, included by fvcr_admin_page_html) function. This…

  • CVE-2026-13425HigJul 29, 2026
    risk 0.00cvss 7.2epss 0.00

    The Database for CF7 plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Array Form Field Values in all versions up to, and including, 1.2.6 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to…

  • CVE-2026-14300HigJul 29, 2026
    risk 0.00cvss 8.1epss 0.00

    The miniOrange Social Login and Register (Discord, Google, Twitter, LinkedIn) WordPress plugin before 7.8.0 does not bind the one-time code used by its optional email-verification (Profile Completion) feature to the account it was issued for, allowing unauthenticated attackers…

  • CVE-2026-14234HigJul 29, 2026
    risk 0.00cvss 7.1epss 0.00

    The WOLF WordPress plugin before 1.1.0 does not perform a nonce or capability check on one of its AJAX actions, allowing an unauthenticated attacker to trick a logged-in administrator into writing arbitrary content, including a malicious script, into a post via a cross-site…

  • CVE-2026-13690HigJul 29, 2026
    risk 0.00cvss 7.4epss 0.00

    The UsersWP WordPress plugin before 1.2.67 does not validate the selected authentication provider in its two-factor login handler, allowing an attacker who already knows a user's credentials to bypass the second authentication factor and log in as that user.

  • CVE-2026-13605MedJul 29, 2026
    risk 0.00cvss 6.8epss 0.00

    The PhotoSwipe WordPress plugin through 4.1.1.1 uses the title attribute of author-supplied link markup as a lightbox caption that is written into the page DOM without escaping. Because the title attribute survives the post-content sanitization applied to users who lack the…

  • CVE-2026-13423CriJul 29, 2026
    risk 0.00cvss 9.8epss 0.01

    The Streamit WordPress theme through 4.5.0 does not perform any authorization or nonce verification on one of its unauthenticated AJAX routes, which invokes an attacker-supplied PHP function with an attacker-supplied argument array, allowing unauthenticated attackers to call…

  • CVE-2026-11351MedJul 29, 2026
    risk 0.00cvss 5.3epss 0.00

    The ShinyStat Analytics WordPress plugin before 1.0.17 does not perform any authorization check on one of its REST API endpoints, allowing unauthenticated users to retrieve information about non-published (e.g. draft, pending or private) WooCommerce products.

  • CVE-2026-18072CriJul 29, 2026
    risk 0.00cvss 9.8epss 0.01

    The Advanced Responsive Video Embedder for Rumble, Odysee, YouTube, Vimeo, Kick … plugin for WordPress is vulnerable to Authentication Bypass via a Hardcoded Backdoor in version 10.8.7. The vulnerability exists because the `_arve_uc_init()` function — registered on…

  • CVE-2026-5626MedJul 29, 2026
    risk 0.00cvss 4.3epss 0.00

    The Survey Form Block plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the get_all_data() function in all versions up to, and including, 1.0.1. This makes it possible for authenticated attackers, with Subscriber-level access…

  • CVE-2026-15344MedJul 29, 2026
    risk 0.00cvss 4.9epss 0.00

    The WP Photo Album Plus plugin for WordPress is vulnerable to generic SQL Injection via the 'table' parameter in all versions up to, and including, 9.2.04.002 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL…

  • CVE-2026-17166MedJul 29, 2026
    risk 0.00cvss 4.3epss 0.00

    The Event Booking Manager for WooCommerce – Sell Tickets, Event Registration, RSVP & Event Calendar plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 5.3.7. This is due to the plugin not properly verifying that a user is…

  • CVE-2026-17162MedJul 29, 2026
    risk 0.00cvss 6.4epss 0.00

    The WowStore – Store Builder & Product Blocks for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'currentPostId' Block Attribute in all versions up to, and including, 4.4.24 due to insufficient input sanitization and output escaping. This…

  • CVE-2026-17161MedJul 29, 2026
    risk 0.00cvss 6.4epss 0.00

    The WowStore – Store Builder & Product Blocks for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'filterMobileText' Block Attribute in all versions up to, and including, 4.4.24 due to insufficient input sanitization and output escaping. This…

  • CVE-2026-15735MedJul 29, 2026
    risk 0.00cvss 6.4epss 0.00

    The Contact Form to Any API plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'cf7anyapi_form_field' Post Meta in all versions up to, and including, 3.0.6 due to insufficient input sanitization and output escaping. This makes it possible for authenticated…

  • CVE-2026-12939MedJul 29, 2026
    risk 0.00cvss 6.4epss 0.00

    The Newsletters Lite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'link' attribute of the post_thumbnail (and newsletters_post_thumbnail) shortcodes in versions up to and including 4.15. This is due to insufficient input sanitization and output…

  • CVE-2026-12938MedJul 29, 2026
    risk 0.00cvss 6.4epss 0.00

    The Newsletters Lite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'target' attribute of the [newsletters_post] shortcode in versions up to and including 4.15. This is due to insufficient input sanitization and output escaping in the posts_single()…

  • CVE-2026-12144HigJul 29, 2026
    risk 0.00cvss 8.8epss 0.00

    The Wholesale for WooCommerce plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 2.0.5. This is due to the `save_requests_meta()` function applying only `sanitize_text_field()` to the `user_role_set` POST parameter before passing it…

  • CVE-2026-5114MedJul 28, 2026
    risk 0.00cvss 4.9epss 0.00

    The SpeedyCache plugin for WordPress is vulnerable to Arbitrary File Read via Path Traversal in all versions up to, and including, 1.3.8. This is due to a mismatch between CSS URL validation (which allows query strings like `.css?...`) and path resolution (which strips query…

  • CVE-2026-4912MedJul 28, 2026
    risk 0.00cvss 4.1epss 0.00

    The Media Cleaner: Clean your WordPress! plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 7.0.3. This is due to the `get_urls_from_html()` function using `DOMDocument::loadHTMLFile()` to fetch iframe source URLs with an…

  • CVE-2026-15992HigJul 28, 2026
    risk 0.00cvss 8.8epss 0.00

    The WP Password Policy plugin for WordPress is vulnerable to Privilege Escalation in all versions up to and including 3.7.1. This is due to missing authorization checks and nonce verification in the `get_user()` function of the `Module_Password_Hint` class, which unconditionally…

  • CVE-2026-15304MedJul 28, 2026
    risk 0.00cvss 6.5epss 0.00

    The Plugin Organizer plugin for WordPress is vulnerable to SQL Injection via the 'PO_plugin_path' parameter in versions up to, and including, 10.2.4. This is due to insufficient escaping on the user-supplied parameter in the perform_plugin_search() function, where esc_sql()…

  • CVE-2026-15393MedJul 28, 2026
    risk 0.00cvss 6.4epss 0.00

    The Cozy Blocks – Page Builder for Gutenberg Editor & FSE with 600+ Patterns, 58 Blocks & Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'postMeta.font.size' Block Attribute in all versions up to, and including, 2.2.11 due to insufficient input…

  • CVE-2026-15016MedJul 28, 2026
    risk 0.00cvss 6.4epss 0.00

    The Paid Memberships Pro – Content Restriction, User Registration, & Paid Subscriptions plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Readonly User Field via [pmpro_member_profile_edit] Shortcode in all versions up to, and including, 3.8.1 due to…

  • CVE-2026-16774MedJul 28, 2026
    risk 0.00cvss 5.3epss 0.00

    The Chatbot plugin for WordPress is vulnerable to Missing Authorization in versions up to, and including, 8.5.9 via the wpcs_send_email() AJAX handler. This is due to the wpcs_send_email() function being registered on both wp_ajax_wpcs_send_email and…

  • CVE-2026-16773MedJul 28, 2026
    risk 0.00cvss 5.3epss 0.00

    The WPBot – AI ChatBot for Live Support, Lead Generation, AI Services plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 8.5.9 via the wpbot_send_email_transcript_free. This makes it possible for unauthenticated attackers…

  • CVE-2026-15444MedJul 28, 2026
    risk 0.00cvss 4.9epss 0.00

    The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to generic SQL Injection via the 'coupon_code' parameter in all versions up to, and including, 4.0.1 due to insufficient escaping on the user supplied parameter and lack of sufficient…

  • CVE-2026-15411MedJul 28, 2026
    risk 0.00cvss 5.3epss 0.00

    The StoreGrowth: Smart Sales Booster for WooCommerce | BOGO, Upsells, Direct Checkout, Quick View, Side Cart plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 2.1.0. This is due to the plugin not properly verifying that a user is…

  • CVE-2026-15025HigJul 28, 2026
    risk 0.00cvss 7.5epss 0.01

    The Uncanny Automator – Easy Automation, Integration, Webhooks & Workflow Builder plugin for WordPress is vulnerable to Missing Authorization in versions up to, and including, 7.3.2 via the automator_google_contacts_fetch_labels, automator_mautic_segment_fetch,…

  • CVE-2026-13440HigJul 28, 2026
    risk 0.00cvss 7.2epss 0.00

    The StoreGrowth: Smart Sales Booster for WooCommerce | BOGO, Upsells, Direct Checkout, Quick View, Side Cart plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'message_popup' parameter in all versions up to, and including, 2.1.0 due to insufficient input…

Page 699 of 739