VYPR

Vendor CVEs

WordPress

All CVEs

36,918 total · sorted by risk
  • CVE-2026-14190MedJul 27, 2026
    risk 0.00cvss 6.1epss 0.00

    The Sina Extension for Elementor WordPress plugin before 3.10.2 does not escape a value reconstructed from request input in one of its unauthenticated AJAX handlers before reflecting it into the HTML response, allowing unauthenticated attackers to execute arbitrary JavaScript in…

  • CVE-2026-14189LowJul 27, 2026
    risk 0.00cvss 3.8epss 0.00

    The WPBot WordPress plugin before 8.5.2 does not validate administrator-configured field identifiers before using them in a SQL query, allowing users with administrator access to perform SQL injection that executes when a visitor triggers a search.

  • CVE-2026-13726HigJul 27, 2026
    risk 0.00cvss 7.1epss 0.00

    The MPG WordPress plugin before 4.1.8 does not sanitise and escape a parameter before reflecting it back in the response, allowing unauthenticated attackers to perform Reflected Cross-Site Scripting against a victim who is induced to send a crafted request.

  • CVE-2026-13714CriJul 27, 2026
    risk 0.00cvss 9.8epss 0.01

    The Realtyna Organic IDX plugin + WPL Real Estate WordPress plugin before 5.3.0 does not validate the type of uploaded files, and its file upload functionality is gated only by an API that is enabled by default and authenticated with hardcoded credentials shipped identically…

  • CVE-2026-13597CriJul 27, 2026
    risk 0.00cvss 9.1epss 0.00

    The 微信二维码登陆 WordPress plugin through 1.3 does not properly validate WeChat webhook requests, as its signature check always passes, and it discloses the generated login code in the webhook response. This allows an unauthenticated attacker to forge a login event for…

  • CVE-2026-13400MedJul 27, 2026
    risk 0.00cvss 6.1epss 0.00

    Simply Schedule Appointments is vulnerable to unauthenticated Stored Cross-Site Scripting in all versions up to and including 1.6.12.2. The root cause is a sanitization-ordering defect: the rendered notification content is decoded back into live HTML after it has already passed…

  • CVE-2026-13390MedJul 27, 2026
    risk 0.00cvss 5.3epss 0.00

    The Events Calendar WordPress plugin before 6.16.5.1 does not perform an authorization check on one of its Event Aggregator import REST API routes and skips an integrity check for a particular status value, allowing unauthenticated attackers to mark existing import records as…

  • CVE-2026-13332CriJul 27, 2026
    risk 0.00cvss 9.1epss 0.00

    The Masteriyo LMS WordPress plugin before 2.3.1 does not correctly verify authorization on an unauthenticated AJAX action used to clear user sessions, allowing unauthenticated attackers to terminate the active sessions (force-logout) of any user on the site, including…

  • CVE-2026-13152HigJul 27, 2026
    risk 0.00cvss 8.1epss 0.00

    The Custom Fields Account Registration For Woocommerce WordPress plugin before 1.4 does not prevent its custom registration fields from writing to the user capabilities meta key on sites that use a non-default database table prefix, so an unauthenticated user who registers an…

  • CVE-2026-12982MedJul 27, 2026
    risk 0.00cvss 6.1epss 0.00

    The Document Gallery WordPress plugin before 5.1.1 does not properly sanitise and escape user input before reflecting it back in the response of an unauthenticated AJAX action, leading to a Reflected Cross-Site Scripting vulnerability which can be exploited against…

  • CVE-2026-12493HigJul 27, 2026
    risk 0.00cvss 7.5epss 0.00

    The Clover Payment Gateway by Zaytech for WooCommerce WordPress plugin before 1.3.6 does not verify that an approved external payment record actually belongs to the WooCommerce order being completed, nor that the paid amount matches the order total, allowing unauthenticated…

  • CVE-2026-12394CriJul 27, 2026
    risk 0.00cvss 9.8epss 0.01

    The MemberGlut WordPress plugin before 1.1.5 does not validate the role chosen during front-end registration, allowing unauthenticated users to register an account with an arbitrary role, including administrator, leading to full site compromise.

  • CVE-2026-12255HigJul 27, 2026
    risk 0.00cvss 8.1epss 0.00

    The MainWP Child WordPress plugin before 6.1.2 does not verify the requester's identity in its site-registration request handler when password authentication has been disabled for the targeted account, allowing an unauthenticated attacker to obtain a valid authentication…

  • CVE-2026-10082MedJul 27, 2026
    risk 0.00cvss 6.1epss 0.00

    The Advanced Ads WordPress plugin before 2.0.23 does not sanitize and escape a shortcode parameter before outputting it in the page, allowing users with the Contributor role and above to inject arbitrary web scripts that execute when the affected content is viewed, including by…

  • CVE-2025-15662HigJul 27, 2026
    risk 0.00cvss 8.6epss 0.00

    The Printcart Web to Print Product Designer for WooCommerce WordPress plugin before 2.5.3 does not restrict a user-supplied URL before fetching it server-side and does not enforce a valid authorization check, allowing unauthenticated attackers to read arbitrary local files…

  • CVE-2026-15962HigJul 26, 2026
    risk 0.00cvss 8.8epss 0.00

    The Fluent Forms Pro Add On Pack plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 6.2.6 via deserialization of untrusted input. This makes it possible for authenticated attackers, with Subscriber-level access and above, to inject a…

  • CVE-2026-15425MedJul 25, 2026
    risk 0.00cvss 6.4epss 0.00

    The Yoast SEO – Advanced SEO with real-time guidance and built-in AI plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Post Slug (post_name) in all versions up to, and including, 28.0 due to insufficient input sanitization and output escaping. This makes it…

  • CVE-2026-14955MedJul 25, 2026
    risk 0.00cvss 6.5epss 0.01

    The Checkout Field Editor for WooCommerce (Pro) plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 3.7.7 via the 'thwcfe_legacy_file' parameter. This makes it possible for authenticated attackers, with subscriber-level access and…

  • CVE-2026-10818HigJul 25, 2026
    risk 0.00cvss 8.1epss 0.01

    The WPForms Pro plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 1.10.1.1 via the ajax_chunk_upload_finalize function. This is due to the file type validation occurring after chunk metadata and file contents have already been…

  • CVE-2026-8789HigJul 24, 2026
    risk 0.00cvss 8.1epss 0.00

    The Easy Appointments plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check and missing nonce verification on the `ea_delete_multiple_connections` AJAX action in all versions up to, and including, 3.12.27. This makes it…

  • CVE-2026-15663MedJul 24, 2026
    risk 0.00cvss 4.9epss 0.00

    The Ninja Forms – The Contact Form Builder That Grows With You plugin for WordPress is vulnerable to generic SQL Injection via Import File 'settings' Key in all versions up to, and including, 3.14.9 due to insufficient escaping on the user supplied parameter and lack of…

  • CVE-2026-15401HigJul 24, 2026
    risk 0.00cvss 7.2epss 0.00

    The VikBooking Hotel Booking Engine & PMS plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'vbfX' parameter in all versions up to, and including, 1.8.13 due to insufficient input sanitization and output escaping. This makes it possible for…

  • CVE-2026-10033HigJul 24, 2026
    risk 0.00cvss 7.3epss 0.00

    The EventON Action User plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 2.5.14. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for unauthenticated attackers…

  • CVE-2026-15821MedJul 24, 2026
    risk 0.00cvss 6.4epss 0.00

    The SureDash – Community, Courses & Member Dashboard plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Shortcode Attributes in all versions up to, and including, 1.10.0 due to insufficient input sanitization and output escaping. This makes it possible for…

  • CVE-2026-15739MedJul 24, 2026
    risk 0.00cvss 6.4epss 0.00

    The Rich Showcase for Google Reviews plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'pagination' Shortcode Attribute in all versions up to, and including, 6.9.9 due to insufficient input sanitization and output escaping. This makes it possible for…

  • CVE-2026-15346MedJul 24, 2026
    risk 0.00cvss 6.1epss 0.00

    The VikBooking Hotel Booking Engine & PMS plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'category_id' parameter in all versions up to, and including, 1.8.13 due to insufficient input sanitization and output escaping. This makes it possible for…

  • CVE-2026-15755MedJul 24, 2026
    risk 0.00cvss 6.4epss 0.00

    The Open User Map – Interactive Leaflet Maps plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Shortcode Attributes in all versions up to, and including, 1.4.45 due to insufficient input sanitization and output escaping. This makes it possible for…

  • CVE-2026-15665MedJul 24, 2026
    risk 0.00cvss 6.4epss 0.00

    The Fluent Support – Helpdesk & Customer Support Ticket System plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'redirect-to' Shortcode Attribute in all versions up to, and including, 2.3.0 due to insufficient input sanitization and output escaping. This…

  • CVE-2026-15653MedJul 24, 2026
    risk 0.00cvss 6.4epss 0.00

    The Visualizer – Tables & Charts Manager with Built-in AI Generator plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'backend-title' parameter in all versions up to, and including, 4.0.5 due to insufficient input sanitization and output escaping. This…

  • CVE-2026-15648MedJul 24, 2026
    risk 0.00cvss 6.4epss 0.00

    The Brands for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'width' Shortcode Attribute in all versions up to, and including, 3.8.8 due to insufficient input sanitization and output escaping. This makes it possible for authenticated…

  • CVE-2026-15464MedJul 24, 2026
    risk 0.00cvss 6.4epss 0.00

    The WP Hotel Booking plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'widget_search' Shortcode Attribute in all versions up to, and including, 2.3.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated…

  • CVE-2026-15334MedJul 24, 2026
    risk 0.00cvss 6.4epss 0.00

    The Cozy Blocks – Page Builder for Gutenberg Editor & FSE with 600+ Patterns, 58 Blocks & Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'icon.view' Block Attribute in all versions up to, and including, 2.2.11 due to insufficient input…

  • CVE-2026-15333MedJul 24, 2026
    risk 0.00cvss 6.4epss 0.00

    The Cozy Blocks – Page Builder for Gutenberg Editor & FSE with 600+ Patterns, 58 Blocks & Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'cozyCustomFont' Block Attribute in all versions up to, and including, 2.2.11 due to insufficient input…

  • CVE-2026-12654MedJul 24, 2026
    risk 0.00cvss 5.3epss 0.00

    The Payment Plugins for Stripe WooCommerce plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 4.0.7. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for…

  • CVE-2026-14603HigJul 24, 2026
    risk 0.00cvss 7.5epss 0.00

    The WowOptin: Next-Gen Popup Maker WordPress plugin before 1.4.38 does not have proper authorization on a REST endpoint, allowing unauthenticated users to disable all of the site's opt-in forms and insert new template-based opt-in rows into the database.

  • CVE-2026-12981HigJul 24, 2026
    risk 0.00cvss 7.5epss 0.00

    The CAFEHAUS API WordPress plugin through 1.0.0 does not have any authentication or authorisation when updating user passwords, allowing unauthenticated attackers to set the password of any user, including administrators, and fully take over their accounts.

  • CVE-2026-12877CriJul 24, 2026
    risk 0.00cvss 9.1epss 0.00

    The Project Management, Bug and Issue Tracking Plugin WordPress plugin before 5.1.0 does not sanitise and escape user supplied input before using it in a SQL query, allowing unauthenticated attackers to perform SQL injection attacks. This is exploitable in the Project…

  • CVE-2026-12690LowJul 24, 2026
    risk 0.00cvss 3.8epss 0.00

    The ProfileGrid WordPress plugin before 5.9.9.7 does not perform a capability check on its license management actions, relying only on a nonce that is exposed to any logged-in user, allowing authenticated users with Subscriber-level access and above to overwrite the site's…

  • CVE-2026-12689MedJul 24, 2026
    risk 0.00cvss 5.4epss 0.00

    The ProfileGrid WordPress plugin before 5.9.9.7 does not perform any authorization or ownership check on some of its private-message thread actions, allowing authenticated users with Subscriber-level access and above to soft-delete, tamper with the metadata of, and mark as read…

  • CVE-2026-12688MedJul 24, 2026
    risk 0.00cvss 6.5epss 0.00

    The ProfileGrid WordPress plugin before 5.9.9.7 does not verify PayPal IPN notifications before granting paid group membership, allowing unauthenticated attackers to forge a payment notification and mark any user as a paid member of any group without any payment being made.

  • CVE-2026-12497HigJul 24, 2026
    risk 0.00cvss 7.5epss 0.00

    The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content WordPress plugin before 4.16.18 does not consistently enforce the role restriction configured on its front-end registration role-selection field. The set of roles offered…

  • CVE-2026-6454MedJul 24, 2026
    risk 0.00cvss 6.4epss 0.00

    The Firelight Lightbox plugin for WordPress is vulnerable to Stored DOM Cross-Site Scripting in versions up to and including 2.3.20. This is due to insufficient sanitization of the href attribute value within the FancyBox V2 PDF beforeLoad JavaScript callback generated in…

  • CVE-2026-15420MedJul 24, 2026
    risk 0.00cvss 4.3epss 0.01

    The Nexter Blocks – Gutenberg Blocks, Page Builder & AI Website Builder plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 5.0.0 via the 'plus_name' parameter. This makes it possible for authenticated attackers, with…

  • CVE-2026-15100MedJul 24, 2026
    risk 0.00cvss 6.4epss 0.00

    The Post Grid Gutenberg Blocks – PostX plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'searchnoresult' Block Attribute in all versions up to, and including, 5.0.32 due to insufficient input sanitization and output escaping. This makes it possible for…

  • CVE-2026-13464MedJul 24, 2026
    risk 0.00cvss 5.3epss 0.00

    The Kirki – Freeform Page Builder, Website Builder & Customizer plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 6.0.14 via the 'context' parameter due to missing validation on a user controlled key. This makes it…

  • CVE-2026-12736HigJul 24, 2026
    risk 0.00cvss 8.0epss 0.00

    The Wpify Woo plugin for WordPress is vulnerable to Privilege Escalation in versions up to, and including, 5.4.16. This is due to the SettingsApi::save_option() REST route (POST /wp-json/wpify-woo/v1/option) passing the request-supplied 'option' and 'data' parameters directly to…

  • CVE-2026-11354MedJul 24, 2026
    risk 0.00cvss 5.3epss 0.00

    The Participants Database plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.7.8.3 via the 'id' parameter. This makes it possible for unauthenticated attackers to overwrite arbitrary participant records by numeric ID and…

  • CVE-2025-9205MedJul 24, 2026
    risk 0.00cvss 6.4epss 0.00

    The MapSVG plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 8.14.0. This is due to insufficient input sanitization and output escaping on user supplied attributes within the map options. This makes it possible for…

  • CVE-2026-15981CriJul 23, 2026
    risk 0.00cvss 9.8epss 0.01

    The SAML Single Sign On – SSO Login plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 5.4.4. This is due to the mo_saml_validate_signature() function performing a loose boolean check on the raw tri-state integer returned by PHP's…

  • CVE-2026-15212HigJul 23, 2026
    risk 0.00cvss 8.8epss 0.00

    The WPO365 | Login plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 43.2. This is due to the Ajax_Service::verify_ajax_request() helper gating its wp_verify_nonce() call behind the boolean option 'enable_nonce_check', which is…

Page 702 of 739