VYPR

Vendor CVEs

WordPress

All CVEs

36,918 total · sorted by risk
  • CVE-2026-15782MedJul 21, 2026
    risk 0.00cvss 4.9epss 0.00

    The WPForms – AI Form Builder for WordPress – Contact Forms, Payment Forms, Survey Form, Quiz & More plugin for WordPress is vulnerable to Stored Cross-Site Scripting via OptinMonster Integration data-sitekey Attribute in Post Content in all versions up to, and including,…

  • CVE-2026-15156MedJul 21, 2026
    risk 0.00cvss 6.4epss 0.00

    The Essential Addons for Elementor – Popular Elementor Templates & Widgets plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Reading Progress Global Color Settings in all versions up to, and including, 6.6.11 due to insufficient input sanitization and…

  • CVE-2026-12900MedJul 20, 2026
    risk 0.00cvss 6.4epss 0.00

    The Spectra Gutenberg Blocks – Website Builder for the Block Editor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `uagb/image` block in all versions up to, and including, 2.19.28 due to insufficient input sanitization and output escaping. This makes…

  • CVE-2026-9833HigJul 20, 2026
    risk 0.00cvss 7.1epss 0.00

    The Tag Groups is the Advanced Way to Display Your Taxonomy Terms WordPress plugin before 2.2.0 does not properly escape one of its AJAX parameters before reflecting it in the response body served with an HTML content type, allowing unauthenticated attackers to execute arbitrary…

  • CVE-2026-8825MedJul 20, 2026
    risk 0.00cvss 4.9epss 0.00

    The Elementor Website Builder WordPress plugin before 4.1.4 does not properly check user permissions before returning post data through one of its REST endpoints, allowing authenticated users with Contributor-level access and above to retrieve the title, body and metadata of…

  • CVE-2026-13432MedJul 20, 2026
    risk 0.00cvss 5.4epss 0.00

    The ThumbPress WordPress plugin before 6.2.2 does not perform a capability check on one of its AJAX actions, allowing authenticated users with subscriber-level access or higher to deactivate the ThumbPress WordPress plugin before 6.2.2, disrupting the site's image-handling…

  • CVE-2026-13156MedJul 20, 2026
    risk 0.00cvss 5.4epss 0.00

    The MailerSend WordPress plugin before 1.0.8 does not perform a nonce check on its configuration-delete action (it verifies the manage_options capability but ignores the nonce), so an attacker can trick a logged-in administrator into visiting a crafted page that wipes the…

  • CVE-2026-13147CriJul 20, 2026
    risk 0.00cvss 9.1epss 0.01

    The Kirki WordPress plugin before 6.0.12 does not validate a user-supplied URL before requesting it server-side, allowing unauthenticated attackers to make the site issue HTTP requests to arbitrary hosts (Server-Side Request Forgery).

  • CVE-2026-13142HigJul 20, 2026
    risk 0.00cvss 8.1epss 0.00

    The Social Login, Passkeys, Magic Link & Email OTP WordPress plugin before 1.4.1 does not enforce rate limiting or a working attempt lockout on its passwordless email one-time-password verification, and stores the short numeric codes in plaintext, allowing an unauthenticated…

  • CVE-2026-12973MedJul 20, 2026
    risk 0.00cvss 6.5epss 0.00

    The PayPlus Payment Gateway WordPress plugin before 8.2.2 does not perform authorization or order-ownership validation in one of its AJAX actions available to unauthenticated users, allowing them to disclose the secret order key of arbitrary WooCommerce orders and, under some…

  • CVE-2026-12972MedJul 20, 2026
    risk 0.00cvss 5.3epss 0.00

    The PayPlus Payment Gateway WordPress plugin before 8.2.2 does not perform authorization or order-ownership validation in one of its AJAX actions available to unauthenticated users, allowing them to tamper with the payment-related metadata of arbitrary WooCommerce orders.

  • CVE-2026-12970HigJul 20, 2026
    risk 0.00cvss 7.1epss 0.00

    The LearnPress WordPress plugin before 4.4.1 does not escape a search parameter before reflecting it into an HTML attribute, leading to Reflected Cross-Site Scripting that executes in the browser of a logged-in instructor or administrator who is tricked into opening a crafted…

  • CVE-2026-12898MedJul 20, 2026
    risk 0.00cvss 6.5epss 0.01

    The All-in-One WP Migration and Backup WordPress plugin before 7.106 does not properly sanitise a user-supplied value before using it to build a file path, allowing unauthenticated attackers to create or append a log file in arbitrary locations outside its intended storage…

  • CVE-2026-12724MedJul 20, 2026
    risk 0.00cvss 4.3epss 0.00

    The Kirki WordPress plugin before 6.0.12 does not sanitise or escape the email subject and body values supplied in a request before including them in the password-reset email it sends as HTML, allowing unauthenticated users to inject arbitrary HTML into the message delivered to…

  • CVE-2026-12723MedJul 20, 2026
    risk 0.00cvss 5.3epss 0.00

    The Kirki WordPress plugin before 6.0.12 does not perform any authorisation check on one of its REST routes, allowing unauthenticated users to overwrite the content of arbitrary existing comments and to create pre-approved comments under a spoofed identity, bypassing comment…

  • CVE-2026-12592HigJul 20, 2026
    risk 0.00cvss 7.5epss 0.00

    The SlimStat Analytics WordPress plugin before 5.5.0 does not escape a visitor-controlled geolocation value before outputting it in its admin analytics reports, allowing unauthenticated visitors to store a cross-site scripting payload that executes in the browser of an…

  • CVE-2026-11868MedJul 20, 2026
    risk 0.00cvss 5.3epss 0.00

    The WP Travel WordPress plugin before 11.7.1 does not perform capability or ownership checks on its booking cancellation action, which is also exposed to unauthenticated users, allowing them to cancel arbitrary bookings on the site.

  • CVE-2026-11349HigJul 20, 2026
    risk 0.00cvss 8.6epss 0.00

    The Modern Event Calendar Pro WordPress plugin before 7.34.0, Modern Events Calendar Lite WordPress plugin before 7.34.0 do not sanitise and escape a request parameter before using it in a SQL statement, through an AJAX action available to unauthenticated users, leading to an…

  • CVE-2026-10755LowJul 20, 2026
    risk 0.00cvss 2.7epss 0.00

    The All in One SEO WordPress plugin before 4.9.9 does not correctly restrict access to some of its AI integration REST API endpoints, allowing users with low-level privileges such as Contributors to overwrite or reset the site-wide AI integration state.

  • CVE-2026-10724MedJul 20, 2026
    risk 0.00cvss 4.8epss 0.00

    The Reviews Feed WordPress plugin before 2.6.5 does not neutralize WordPress shortcodes contained in third-party review content before rendering it through its dynamic block, allowing unauthenticated attackers to execute arbitrary shortcodes on pages that display the feed by…

  • CVE-2026-10081HigJul 20, 2026
    risk 0.00cvss 8.8epss 0.00

    The Unlimited Elements For Elementor WordPress plugin before 2.0.11 does not sanitize or escape Google review content fetched from the Serp API before rendering it in the Google Reviews widget output, allowing unauthenticated attackers who submit a malicious review on the…

  • CVE-2026-57857MedJul 18, 2026
    risk 0.00cvss 4.3epss 0.00

    The Flow Payment plugin for WordPress (flow.cl) version 3.0.8 is vulnerable to reflected cross-site scripting on the WooCommerce checkout page. When the plugin handles an order cancellation, the error_message GET parameter is passed directly to wc_add_notice() in…

  • CVE-2026-9734MedJul 18, 2026
    risk 0.00cvss 4.3epss 0.00

    The W3SC Elementor to Zoho CRM plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.2.0. This is due to missing or incorrect nonce validation on the storeInfo function. This makes it possible for unauthenticated attackers to…

  • CVE-2026-9656MedJul 17, 2026
    risk 0.00cvss 4.3epss 0.00

    The HubSpot All-In-One Marketing – Forms, Popups, Live Chat plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 11.3.62 via the wp_localize_script() / window.leadinConfig JavaScript object. This makes it possible for…

  • CVE-2026-9810CriJul 17, 2026
    risk 0.00cvss 9.8epss 0.01

    The AI Copilot WordPress plugin before 1.5.4 does not bind OAuth access tokens to a WordPress user, and accepts any valid token as an administrator session, allowing unauthenticated attackers who complete the public OAuth flow to execute privileged MCP tools as an…

  • CVE-2026-13402MedJul 17, 2026
    risk 0.00cvss 5.3epss 0.00

    The Royal Addons for Elementor WordPress plugin before 1.7.1063 does not check the post status of menu items or the templates they reference in one of its REST endpoints, allowing unauthenticated users to retrieve the rendered HTML content of private or draft Elementor…

  • CVE-2026-12393MedJul 17, 2026
    risk 0.00cvss 5.4epss 0.00

    The WPS Bookings for WooCommerce WordPress plugin before 3.11.7 does not verify that a booking order belongs to the requesting user before cancelling it, allowing any authenticated user, such as a Subscriber or Customer, to cancel and void other customers' booking orders.

  • CVE-2026-11966MedJul 17, 2026
    risk 0.00cvss 5.3epss 0.00

    The User Registration & Membership WordPress plugin before 5.2.3 does not perform a capability check for unauthenticated callers on one of its membership payment actions and acts on a caller-supplied user identifier, allowing unauthenticated attackers to delete…

  • CVE-2026-11961HigJul 17, 2026
    risk 0.00cvss 8.1epss 0.00

    The User Registration & Membership WordPress plugin before 5.2.3 does not validate that the membership tier submitted during public registration is one of the tiers allowed by the registration form before assigning that tier's associated user role, allowing unauthenticated…

  • CVE-2026-11575HigJul 17, 2026
    risk 0.00cvss 7.5epss 0.00

    The PhonePe Payment Solutions WordPress plugin before 3.1.0 does not properly verify the authenticity of incoming payment callbacks: the secret used to validate the callback signature is empty on sites configured through the current setup flow, so the expected signature reduces…

  • CVE-2026-10525MedJul 17, 2026
    risk 0.00cvss 6.1epss 0.00

    The NEX-Forms WordPress plugin before 9.2.3 does not sanitise and escape some submitted form data before storing it and outputting it back in the admin dashboard, leading to a Stored Cross-Site Scripting vulnerability which could allow unauthenticated users to perform Stored…

  • CVE-2026-15982CriJul 17, 2026
    risk 0.00cvss 9.8epss 0.00

    The Aimogen Pro - All-in-One AI Content Writer, Editor, ChatBot & Automation Toolkit plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 2.8.4. This is due to due to a missing capability check on the 'aiomatic_call_google_ai_function'…

  • CVE-2026-15094MedJul 17, 2026
    risk 0.00cvss 6.1epss 0.01

    The WP Hotel Booking plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'check_in_date' parameter in all versions up to, and including, 2.3.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated…

  • CVE-2026-15759MedJul 17, 2026
    risk 0.00cvss 6.4epss 0.00

    The ChatHelp – Click to Chat Button, WooCommerce Chat to Order & Floating Chat Form plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'number' and 'group' Shortcode Attributes in all versions up to, and including, 3.5.1 due to insufficient input…

  • CVE-2026-15457MedJul 17, 2026
    risk 0.00cvss 4.9epss 0.01

    The Kirki – Freeform Page Builder, Website Builder & Customizer plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 6.0.13 via the 'family' parameter. This makes it possible for authenticated attackers, with editor-level access and…

  • CVE-2026-15349MedJul 17, 2026
    risk 0.00cvss 4.3epss 0.00

    The ERP: Complete HR, Accounting & CRM Suite Built for WooCommerce plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.17.6. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes…

  • CVE-2026-15161MedJul 17, 2026
    risk 0.00cvss 6.4epss 0.00

    The Ninja Forms - Excel Export plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 3.3.6. This is due to the save_filter() AJAX handler storing the raw $_POST['filter'] array into a WordPress option via update_option() without any…

  • CVE-2026-14503MedJul 17, 2026
    risk 0.00cvss 6.5epss 0.01

    The pCloud WP Backup plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.0.3 via the wp2pcl_ajax_process_request_inner. This makes it possible for authenticated attackers, with subscriber-level access and above, to extract…

  • CVE-2026-13765HigJul 17, 2026
    risk 0.00cvss 7.5epss 0.01

    The LearnPress – WordPress LMS Plugin for Create and Sell Online Courses plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 4.4.1 via the check_answer. This makes it possible for unauthenticated attackers to extract the…

  • CVE-2026-13352HigJul 17, 2026
    risk 0.00cvss 8.8epss 0.01

    The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 4.16.18 via the allowed_mime_types function. This is due…

  • CVE-2026-8616MedJul 17, 2026
    risk 0.00cvss 5.3epss 0.00

    The Fense Proxy & VPN Blocker plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check and missing nonce validation on the fense_bpvt_save_settings() function in versions up to, and including, 3.0.1. The callback is registered to…

  • CVE-2026-15395HigJul 17, 2026
    risk 0.00cvss 7.2epss 0.00

    The Kali Forms — Contact Form & Drag-and-Drop Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'digitalSignature' Field Value in all versions up to, and including, 2.4.18 due to insufficient input sanitization and output escaping. This makes it…

  • CVE-2026-15160MedJul 17, 2026
    risk 0.00cvss 4.3epss 0.01

    The Ninja Forms - Excel Export plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 3.3.6 via the 'spreadsheet_export_tmp_name' parameter. This makes it possible for authenticated attackers, with subscriber-level access and above, to…

  • CVE-2026-15159MedJul 17, 2026
    risk 0.00cvss 4.3epss 0.00

    The Ninja Forms - Excel Export plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 3.3.6 via the 'spreadsheet_export_form_id' parameter due to missing validation on a user controlled key. This makes it possible for…

  • CVE-2026-11324MedJul 17, 2026
    risk 0.00cvss 6.1epss 0.00

    The WooCommerce Placetopay Gateway and PlacetoPay/AvalPay gateway plugins for WordPress are vulnerable to Reflected Cross-Site Scripting via the 'redirect-url' parameter in versions up to, and including, 3.2.2 due to insufficient input sanitization and output escaping. This…

  • CVE-2026-2594MedJul 17, 2026
    risk 0.00cvss 6.4epss 0.00

    The Smart Custom Fields plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 5.0.7. This is due to insufficient input sanitization and output escaping of uploaded image attachment titles. This makes it possible for authenticated…

  • CVE-2026-14956CriJul 17, 2026
    risk 0.00cvss 9.8epss 0.00

    The Bricksforge plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 3.1.8.6. This is due to improper validation of the fieldIds parameter in the Pro Forms registration action, which allows attacker-supplied field IDs to be added to…

  • CVE-2026-14782MedJul 16, 2026
    risk 0.00cvss 4.9epss 0.00

    The Booking for Appointments and Events Calendar – Amelia plugin for WordPress is vulnerable to SQL Injection via the Customer Import in all versions up to, and including, 2.4.3 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on…

  • CVE-2026-7543HigJul 16, 2026
    risk 0.00cvss 7.2epss 0.00

    The Breakdance plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'fields' parameter in versions up to, and including, 2.7.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject…

  • CVE-2026-15727MedJul 16, 2026
    risk 0.00cvss 4.9epss 0.01

    The WP Bulk Delete plugin for WordPress is vulnerable to generic SQL Injection via the 'delete_user_roles' parameter in all versions up to, and including, 1.4.2 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL…

Page 707 of 739