VYPR

Vendor CVEs

WordPress

All CVEs

36,918 total · sorted by risk
  • CVE-2025-68081MedJul 23, 2026
    risk 0.00cvss 5.9epss 0.00

    Administrator Cross Site Scripting (XSS) in WP-Polls <= 2.77.3 versions.

  • CVE-2026-16078MedJul 23, 2026
    risk 0.00cvss 6.5epss 0.01

    The WCPOS – Point of Sale (POS) plugin for WooCommerce plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 1.9.8 via the 'type' parameter parameter. This makes it possible for authenticated attackers, with shop manager-level access…

  • CVE-2026-15906MedJul 23, 2026
    risk 0.00cvss 6.5epss 0.00

    The Premium Packages – Sell Digital Products Securely plugin for WordPress is vulnerable to generic SQL Injection via the 'orderby' parameter in all versions up to, and including, 7.0.4 due to insufficient escaping on the user supplied parameter and lack of sufficient…

  • CVE-2026-15827MedJul 23, 2026
    risk 0.00cvss 5.3epss 0.01

    The GutenKit Blocks plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the /wp-json/gutenkit/v1/mailchimp/get/lists and /wp-json/gutenkit/v1/mailchimp/get/interests REST API endpoints in versions up to, and including, 2.4.12.…

  • CVE-2026-15794MedJul 23, 2026
    risk 0.00cvss 6.4epss 0.00

    The Grid/List View for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'position' Shortcode Attribute in all versions up to, and including, 3.0.9 due to insufficient input sanitization and output escaping. This makes it possible for…

  • CVE-2026-15786MedJul 23, 2026
    risk 0.00cvss 4.4epss 0.00

    The WP Encryption – One Click Free SSL Certificate & SSL / HTTPS Redirect, Security & SSL Scan plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 7.8.6.6 via the 'imploded' parameter parameter. This makes it possible for…

  • CVE-2026-15761MedJul 23, 2026
    risk 0.00cvss 6.5epss 0.00

    The Tickera – Sell Tickets & Manage Events plugin for WordPress is vulnerable to generic SQL Injection via the 'tc_event_filter' parameter in all versions up to, and including, 3.6.0.1 due to insufficient escaping on the user supplied parameter and lack of sufficient…

  • CVE-2026-15647MedJul 23, 2026
    risk 0.00cvss 4.4epss 0.00

    The Brands for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'br_brand_tooltip' Term Meta Field in all versions up to, and including, 3.8.8 due to insufficient input sanitization and output escaping. This makes it possible for authenticated…

  • CVE-2026-15646MedJul 23, 2026
    risk 0.00cvss 6.4epss 0.00

    The Brands for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'style' Shortcode Attribute in all versions up to, and including, 3.8.8 due to insufficient input sanitization and output escaping. This makes it possible for authenticated…

  • CVE-2026-15448MedJul 23, 2026
    risk 0.00cvss 6.5epss 0.00

    The Tickera – Sell Tickets & Manage Events plugin for WordPress is vulnerable to generic SQL Injection via the 'tc_order_status_filter' parameter in all versions up to, and including, 3.6.0.1 due to insufficient escaping on the user supplied parameter and lack of sufficient…

  • CVE-2026-15404MedJul 23, 2026
    risk 0.00cvss 6.4epss 0.00

    The Lpagery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via post titles in versions up to, and including, 2.5.7. This is due to insufficient input sanitization and output escaping in the lpagery_add_filter_text_template_post() function, which is hooked to…

  • CVE-2026-15394MedJul 23, 2026
    risk 0.00cvss 6.4epss 0.00

    The Header Footer Script Adder – Insert Code in Header, Body & Footer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'asm_code' Snippet Meta in all versions up to, and including, 2.1 due to insufficient input sanitization and output escaping. This makes…

  • CVE-2026-15348MedJul 23, 2026
    risk 0.00cvss 6.3epss 0.01

    The Premium Packages – Sell Digital Products Securely plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 7.0.4 via the `wpdmppdl` parameter. This is due to the `download()` function — hooked to the unauthenticated WordPress `wp`…

  • CVE-2026-15017HigJul 23, 2026
    risk 0.00cvss 8.8epss 0.00

    The MDJM Event Management plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.7.8.4. This is due to missing capability checks and nonce verification in the `MDJM_Permissions::set_permissions()` and `MDJM_Employee_Manager::init()`…

  • CVE-2026-15015CriJul 23, 2026
    risk 0.00cvss 9.8epss 0.01

    The MountDev AI MCP Connector for WordPress plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.6.1. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for…

  • CVE-2026-15011CriJul 23, 2026
    risk 0.00cvss 9.8epss 0.00

    The Customer Support Ticket System & Helpdesk plugin for WordPress is vulnerable to Code Injection via the 'path' parameter in all versions up to, and including, 6.0.5 due to the use of dynamic function invocation on an attacker-controlled value with insufficient validation.…

  • CVE-2026-14481MedJul 23, 2026
    risk 0.00cvss 6.4epss 0.00

    The Equalize Digital Accessibility Checker – WCAG, ADA, EAA and Section 508 compliance plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'html' parameter in all versions up to, and including, 1.46.0 due to insufficient input sanitization and output…

  • CVE-2026-14282CriJul 23, 2026
    risk 0.00cvss 9.8epss 0.01

    The GoDAM – Organize WordPress Media Library & File Manager with Unlimited Folders for Images, Videos & more plugin for WordPress is vulnerable to arbitrary file uploads in versions up to, and including, 1.12.2. This is due to insufficient file type validation in the…

  • CVE-2026-13119MedJul 23, 2026
    risk 0.00cvss 6.5epss 0.00

    The Registrations For The Events Calendar plugin for WordPress is vulnerable to SQL Injection via JSON keys in the 'standard' parameter handled by the rtec_records_edit AJAX action in versions up to and including 3.2. The handler decodes attacker-controlled JSON from…

  • CVE-2026-13009MedJul 23, 2026
    risk 0.00cvss 6.5epss 0.00

    The AI Copilot – Content Generator plugin for WordPress is vulnerable to generic SQL Injection via 'order[0][dir]' Parameter in all versions up to, and including, 1.5.4 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the…

  • CVE-2026-9729MedJul 23, 2026
    risk 0.00cvss 6.4epss 0.00

    The Webpushr Push Notifications plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'webpushr_notification_title' and 'webpushr_notification_body' parameters in versions up to, and including, 4.39.0. This is due to insufficient input sanitization in the…

  • CVE-2026-9713HigJul 23, 2026
    risk 0.00cvss 7.5epss 0.00

    The Lumise Product Designer for WooCommerce plugin for WordPress is vulnerable to SQL Injection via the 'id' and 'table' parameters in the uploaded cart JSON file processed by the checkout AJAX action in versions up to, and including, 2.1.1. This is due to insufficient escaping…

  • CVE-2026-9635MedJul 23, 2026
    risk 0.00cvss 6.4epss 0.00

    The WP Shortcode by MyThemeShop plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'title' parameter of the [tab] shortcode in versions up to, and including, 1.4.17. This is due to insufficient input sanitization and output escaping in the mts_tabs()…

  • CVE-2026-12421HigJul 23, 2026
    risk 0.00cvss 7.2epss 0.00

    The ARforms plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'password' Field Values in all versions up to, and including, 7.2.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject…

  • CVE-2026-9577MedJul 23, 2026
    risk 0.00cvss 4.8epss 0.00

    The Post Status Notifier Lite WordPress plugin before 1.13.0 does not properly escape the `mod` URL parameter before reflecting it into the admin settings page (`admin.php?page=post-status-notifier-lite`), leading to a Reflected Cross-Site Scripting vulnerability that fires in…

  • CVE-2026-9066MedJul 23, 2026
    risk 0.00cvss 6.1epss 0.00

    The WP Compress WordPress plugin before 7.10.04 does not validate the value of a query parameter that controls the asset CDN host before using it to build the URLs of JavaScript files emitted on the page, leading to Reflected XSS. When a visitor follows a crafted link, the WP…

  • CVE-2026-14291HigJul 23, 2026
    risk 0.00cvss 7.5epss 0.01

    The security-ninja-premium WordPress plugin before 5.290 does not verify the second authentication factor in one of its two-factor authentication code paths, allowing an unauthenticated attacker who knows a user's password to complete authentication without the one-time code and…

  • CVE-2026-12082HigJul 23, 2026
    risk 0.00cvss 7.5epss 0.00

    The Praison AI SEO WordPress plugin before 5.0.7 does not perform authorization checks on several of its REST API routes, allowing unauthenticated users to modify the permalink of any published post and to read Praison AI SEO WordPress plugin before 5.0.7 configuration data.

  • CVE-2026-7534HigJul 23, 2026
    risk 0.00cvss 7.2epss 0.00

    The SUMO Reward Points plugin for WordPress is vulnerable to Unauthenticated Stored Cross-Site Scripting via the REST API endpoint `/wp-json/wc-srp/v1/earning` in versions up to, and including, 32.7.0. This is due to the `user_has_cap` filter in the `SRP_REST_Earning_Controller`…

  • CVE-2026-7232HigJul 23, 2026
    risk 0.00cvss 7.2epss 0.00

    The FormCraft plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the '[parameter name]' parameter in all versions up to, and including, 3.9.14 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to…

  • CVE-2026-15787MedJul 22, 2026
    risk 0.00cvss 6.4epss 0.00

    The Ultimate Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Navigation Menu Widget data-toggle-icon/data-close-icon Attributes in all versions up to, and including, 2.9.1 due to insufficient input sanitization and output escaping. This…

  • CVE-2026-14322MedJul 22, 2026
    risk 0.00cvss 5.3epss 0.00

    The Timetics WordPress plugin before 1.0.57 does not enforce a pending or unpaid status for new bookings created through a payment method other than its recognised gateways, allowing unauthenticated users to create fully-approved bookings for priced appointments without making…

  • CVE-2026-12987HigJul 22, 2026
    risk 0.00cvss 7.5epss 0.00

    The Events Manager WordPress plugin before 7.3.7 does not safely handle booking-registration data on sites using No-User-Account Booking Mode: a booker-supplied registration field is stored as booking meta and later deserialized without restricting allowed classes, enabling PHP…

  • CVE-2026-12968HigJul 22, 2026
    risk 0.00cvss 8.8epss 0.01

    The Product Addons and Product Options With Custom Fields WordPress plugin before 1.6.15 does not restrict an unauthenticated file-upload endpoint and accepts SVG files that are stored and served inline, allowing an unauthenticated attacker to upload a malicious SVG whose…

  • CVE-2026-15802HigJul 22, 2026
    risk 0.00cvss 8.1epss 0.01

    The WP Foodbakery plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the 'delete_locations_backup_file_callback' function in all versions up to, and including, 4.9. This makes it possible for authenticated attackers, with…

  • CVE-2026-65052HigJul 21, 2026
    risk 0.00cvss 7.5epss 0.01

    Ninja Forms WordPress plugin version 3.14.8 and prior contains an improper input validation vulnerability that allows unauthenticated attackers to inject arbitrary numeric values into form calculations and payment totals by submitting values that do not match any configured…

  • CVE-2026-65051MedJul 21, 2026
    risk 0.00cvss 6.5epss 0.00

    Ninja Forms WordPress plugin version 3.14.8 contains a client-side enforcement of server-side security vulnerability that allows unauthenticated attackers to bypass all form validation by merging attacker-controlled field metadata over server-loaded form definitions before…

  • CVE-2026-65050MedJul 21, 2026
    risk 0.00cvss 6.5epss 0.00

    Ninja Forms WordPress plugin version 3.14.8 and prior contains a missing authorization vulnerability in the render callback of the `ninja-forms/submissions-table` Gutenberg block that allows authenticated attackers with Author-level privileges to expose stored form submissions…

  • CVE-2026-65049CriJul 21, 2026
    risk 0.00cvss 9.3epss 0.00

    Ninja Forms plugin version 3.14.8 and prior for WordPress Multisite contains an incorrect authorization vulnerability that allows a subsite Administrator to trigger network-wide deletion of all Ninja Forms data by exploiting a site-scoped capability check combined with unsafe…

  • CVE-2026-65048CriJul 21, 2026
    risk 0.00cvss 9.3epss 0.01

    Ninja Forms plugin for WordPress versions 3.10.4 through 3.14.9 contains an unauthenticated stored cross-site scripting vulnerability in the Repeatable Fieldset feature where parseSubmissionIndex() accepts arbitrary strings as submission indexes without numeric validation, and…

  • CVE-2026-1771HigJul 21, 2026
    risk 0.00cvss 7.2epss 0.01

    The MapSVG plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the SVGFile constructor in all versions up to, and including, 8.14.0 This is due to an incorrect conditional check that prevents file validation from taking place. This…

  • CVE-2026-1372MedJul 21, 2026
    risk 0.00cvss 4.3epss 0.00

    The Tutor LMS Elementor Addons plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 4.0.0 This is due to missing capability checks on the `activate_tutor_free()` and `activate_elementor_free()` functions registered as `admin_action_*`…

  • CVE-2026-15145MedJul 21, 2026
    risk 0.00cvss 6.4epss 0.00

    The Essential Addons for Elementor – Popular Elementor Templates & Widgets plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Fancy Text Widget in all versions up to, and including, 6.6.11 due to insufficient input sanitization and output escaping. This…

  • CVE-2026-8082HigJul 21, 2026
    risk 0.00cvss 7.5epss 0.00

    The bpost-shipping-platform WordPress plugin before 3.2.3 does not properly sanitize a parameter before using it in a SQL query during WooCommerce order submission, allowing unauthenticated attackers to perform time-based blind SQL injection on stores running this…

  • CVE-2026-14185MedJul 21, 2026
    risk 0.00cvss 4.3epss 0.00

    The WPBot WordPress plugin before 8.2.0 does not perform a capability or nonce check in one of its retrieval-augmented-generation settings handlers, allowing authenticated users with subscriber-level access to modify the WPBot WordPress plugin before 8.2.0's configuration.

  • CVE-2026-14184MedJul 21, 2026
    risk 0.00cvss 5.4epss 0.00

    The Academy LMS WordPress plugin before 3.8.1 does not verify ownership of a user-supplied user identifier in several of its lesson AJAX handlers, allowing authenticated users with subscriber-level access to read and modify other users' lesson notes and mark other users' lesson…

  • CVE-2026-14183MedJul 21, 2026
    risk 0.00cvss 4.3epss 0.00

    The Classified Listing WordPress plugin before 5.3.9 does not verify that the order targeted by its payment-receipt handler belongs to the requesting user, allowing authenticated users with subscriber-level access to read the payment receipt details of any other user's order.

  • CVE-2026-13694MedJul 21, 2026
    risk 0.00cvss 6.5epss 0.00

    The Bit Form WordPress plugin before 3.1.0 does not properly validate its workflow-trigger token once the associated transient has expired, allowing unauthenticated attackers to re-trigger a form's configured workflow actions such as notification emails and integrations.

  • CVE-2026-13693MedJul 21, 2026
    risk 0.00cvss 5.9epss 0.00

    The Bit Form WordPress plugin before 3.1.0 does not restrict a form file-field value to a safe path before reading the file and attaching it to a notification email, allowing unauthenticated attackers to read arbitrary server files such as the WordPress configuration file.

  • CVE-2026-11767HigJul 21, 2026
    risk 0.00cvss 8.8epss 0.01

    The Free Builder for Elementor WordPress plugin before 1.6.7 does not sanitise submitted contact form field values before storing them and outputting them in the admin dashboard, allowing unauthenticated attackers to perform Stored Cross-Site Scripting attacks that execute…

Page 706 of 739