VYPR

Vendor CVEs

WordPress

All CVEs

36,888 total · sorted by risk
  • CVE-2026-12108MedJul 10, 2026
    risk 0.00cvss 4.4epss 0.00

    The Highlighting Code Block plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 2.2.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with…

  • CVE-2026-11992MedJul 10, 2026
    risk 0.00cvss 4.3epss 0.00

    The Easy Appointments plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 3.12.27. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers,…

  • CVE-2025-11977MedJul 10, 2026
    risk 0.00cvss 6.6epss 0.01

    The Happyforms – Form Builder for WordPress: Drag & Drop Contact Forms, Surveys, Payments & Multipurpose Forms plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1.26.12 via the happyforms_get_form_partial() function. This makes it…

  • CVE-2026-13347HigJul 10, 2026
    risk 0.00cvss 7.5epss 0.01

    The Hide My WP Lite plugin for WordPress is vulnerable to Arbitrary File Read in versions up to and including 1.3 via the he_wrapper_js and he_wrapper_css query parameters processed by the elementor_assets_filter() function. This is due to the function concatenating…

  • CVE-2026-12685HigJul 10, 2026
    risk 0.00cvss 7.5epss 0.00

    The EscortWP escortwp WordPress theme through 3.6.2 was distributed with a vendor-authored, obfuscated backdoor that lets an unauthenticated attacker who supplies a hard-coded, per-build key permanently delete all of the site's content, and that covertly transmits the site URL,…

  • CVE-2026-12276MedJul 10, 2026
    risk 0.00cvss 5.3epss 0.00

    The LA-Studio Element Kit for Elementor WordPress plugin before 1.6.1 does not check whether user registration is enabled on the site before creating an account through one of its unauthenticated AJAX actions, allowing unauthenticated attackers to register new accounts even when…

  • CVE-2026-15302MedJul 10, 2026
    risk 0.00cvss 5.3epss 0.01

    The ARMember plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 4.0.27 via the 'X-FILENAME' HTTP header. This makes it possible for unauthenticated attackers to upload and overwrite certain files (e.g., CSS) to directories outside the…

  • CVE-2026-15301MedJul 10, 2026
    risk 0.00cvss 6.4epss 0.00

    The BuddyHolis TableSearch plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘placeholder’ parameter in all versions up to, and including, 1.1.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated…

  • CVE-2026-15300CriJul 10, 2026
    risk 0.00cvss 9.1epss 0.01

    The GEO my WP plugin for WordPress was vulnerable to SQL Injection via the 'distance', 'lat', and 'lng' parameters in versions up to, and including, 4.5.4. The values were read from $_SERVER['QUERY_STRING'] via parse_str() (bypassing wp_magic_quotes, which does not cover…

  • CVE-2026-15299MedJul 10, 2026
    risk 0.00cvss 6.4epss 0.00

    The Animation Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'weather_style' and 'move_direction' parameters of the Weather widget in all versions up to, and including, 2.6.3. This is due to insufficient output escaping in the…

  • CVE-2026-15298HigJul 10, 2026
    risk 0.00cvss 7.2epss 0.00

    The TelSender plugin for WordPress is vulnerable to DOM-Based Cross-Site Scripting in all versions up to, and including, 1.14.14. This is due to insufficient input sanitization when processing Telegram API responses containing attacker-controlled chat titles. This makes it…

  • CVE-2026-15297MedJul 10, 2026
    risk 0.00cvss 6.1epss 0.00

    The Newsletter, SMTP, Email marketing and Subscribe forms by Brevo (formely Sendinblue) plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the page parameter in all versions up to, and including, 3.1.77 due to insufficient input sanitization and output…

  • CVE-2026-15296MedJul 10, 2026
    risk 0.00cvss 6.4epss 0.00

    The affiliate-toolkit – WP Affiliate Plugin with Amazon plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'atkp_product' shortcode in all versions up to, and including, 3.7.0 due to insufficient input sanitization and output escaping on user…

  • CVE-2026-15293HigJul 10, 2026
    risk 0.00cvss 8.0epss 0.01

    The WP Business Intelligence Lite plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 3.2.0. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated…

  • CVE-2026-15292MedJul 10, 2026
    risk 0.00cvss 6.4epss 0.00

    The Sudoku Shortcode plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'background' parameter in the 'sudoku-sc' shortcode in all versions up to, and including, 1.0.0 due to insufficient input sanitization and output escaping. This makes it possible for…

  • CVE-2026-15291HigJul 10, 2026
    risk 0.00cvss 7.5epss 0.01

    The Chat Help – Click to Chat Button & Form plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.1.3 via the REST API endpoints /wp-json/chat-help/v1/leads and /wp-json/chat-help/v1/leads/{id}. This is due to the plugin…

  • CVE-2026-15290HigJul 10, 2026
    risk 0.00cvss 7.5epss 0.01

    The Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin plugin for WordPress is vulnerable to blind SQL Injection via the search parameter in all versions up to, and including, 2.10.1 due to insufficient escaping on…

  • CVE-2026-15289MedJul 10, 2026
    risk 0.00cvss 5.9epss 0.00

    The Booking calendar, Appointment Booking System plugin for WordPress is vulnerable to time-based SQL Injection via the ‘wpdevart_id’ parameter in all versions up to, and including, 3.2.17 due to insufficient escaping on the user supplied parameter and lack of sufficient…

  • CVE-2026-15288HigJul 10, 2026
    risk 0.00cvss 7.5epss 0.00

    The SureForms – Drag and Drop Form Builder for WordPress plugin for WordPress is vulnerable to Improper Input Validation in all versions up to, and including, 2.2.1. This is due to the plugin accepting the payment amount directly from user-controlled POST data in the…

  • CVE-2026-15287MedJul 10, 2026
    risk 0.00cvss 6.5epss 0.00

    The rtMedia for WordPress, BuddyPress and bbPress plugin for WordPress is vulnerable to time-based SQL Injection via the order_by parameter in all versions up to, and including, 4.6.18 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation…

  • CVE-2026-15286MedJul 10, 2026
    risk 0.00cvss 4.3epss 0.00

    The Gutenberg Blocks with AI by Kadence WP – Page Builder Features plugin for WordPress is vulnerable to unauthorized post publication in all versions up to, and including, 3.5.32 due to a misconfigured capability check on the 'get_items_permission_check' function permission…

  • CVE-2026-15285MedJul 10, 2026
    risk 0.00cvss 6.4epss 0.00

    The Plus Addons for Elementor plugin for WordPress was vulnerable to Authenticated (Contributor+) Stored Cross-Site Scripting via the Button widget's `custom_attributes` setting in versions up to and including 6.4.11. The `render` function in `modules/widgets/tp_button.php`…

  • CVE-2026-15284MedJul 10, 2026
    risk 0.00cvss 6.4epss 0.00

    The King Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'form_page_id' parameter in versions up to, and including, 51.1.62 This is due to insufficient input sanitization in the add_to_submissions() function, which applies…

  • CVE-2026-15283MedJul 10, 2026
    risk 0.00cvss 4.4epss 0.00

    The WPvivid Backup for MainWP plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 0.9.33 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with…

  • CVE-2026-15282CriJul 10, 2026
    risk 0.00cvss 9.8epss 0.01

    The Instant Appointment plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'insapp_upload_image_as_attachment' function in all versions up to, and including, 1.2. This makes it possible for unauthenticated attackers to upload…

  • CVE-2026-5069MedJul 10, 2026
    risk 0.00cvss 5.4epss 0.00

    The Fluent Forms plugin for WordPress is vulnerable to incorrect authorization via the 'subscription_id' parameter in versions up to, and including, 6.2.1. This is due to insufficient ownership authorization checks in the payment cancellation AJAX flow. This makes it possible…

  • CVE-2026-15070HigJul 10, 2026
    risk 0.00cvss 8.8epss 0.00

    The Salon Booking System – Free Version plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 10.30.32. This is due to missing or incorrect nonce validation on the setCustomText function. This makes it possible for…

  • CVE-2026-14894CriJul 10, 2026
    risk 0.00cvss 9.8epss 0.03

    The Super Forms – Drag & Drop Form Builder plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 6.3.313 via the submit_form function. This is due to missing file type validation and the absence of any capability check on the…

  • CVE-2026-13430HigJul 10, 2026
    risk 0.00cvss 7.2epss 0.01

    The Post Export Import with Media plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 1.13.1 via the import_media_file_secure function. This is due to insufficient file extension validation caused by a trailing-dot filename bypass,…

  • CVE-2026-11818MedJul 10, 2026
    risk 0.00cvss 5.4epss 0.00

    The WPCafe – Restaurant Menu, Online Food Ordering & Table Booking System plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 3.0.14. This is due to the plugin not properly verifying that a user is authorized to perform an action.…

  • CVE-2026-11392MedJul 10, 2026
    risk 0.00cvss 6.1epss 0.00

    The WP Hotel Booking plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'check_in_date' and 'check_out_date' parameters in all versions up to, and including, 2.3.1 due to insufficient input sanitization and output escaping. This makes it possible for…

  • CVE-2026-12598HigJul 10, 2026
    risk 0.00cvss 8.1epss 0.01

    The LoginPress Pro plugin for WordPress is vulnerable to authentication bypass in versions up to and including 6.2.3 via the Spotify Social Login addon. This is due to the loginpress_on_spotify_login() function trusting the unverified 'email' field returned by Spotify's /v1/me…

  • CVE-2026-12597HigJul 10, 2026
    risk 0.00cvss 8.1epss 0.01

    The LoginPress Pro plugin for WordPress is vulnerable to Authentication Bypass via the GitHub OAuth callback in versions up to, and including, 6.2.3. The vulnerability exists in the loginpress_on_github_login() function, which blindly trusts the first element…

  • CVE-2026-12595HigJul 10, 2026
    risk 0.00cvss 8.1epss 0.01

    The LoginPress Pro plugin for WordPress is vulnerable to Authentication Bypass via Unverified OAuth Email in all versions up to and including 6.2.3. The vulnerability exists in the loginpress_on_discord_login() Discord OAuth callback handler, which accepts the email field…

  • CVE-2026-9253HigJul 9, 2026
    risk 0.00cvss 7.2epss 0.00

    The WP Cost Estimation & Payment Forms Builder (E&P Forms) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'customerInfos' parameter in all versions up to, and including, 10.5.97 due to insufficient input sanitization and output escaping. This makes it…

  • CVE-2026-9240MedJul 9, 2026
    risk 0.00cvss 4.3epss 0.00

    The Colissimo Officiel : Méthodes de livraison pour WooCommerce plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the updateShippingMethod() function (registered to the wp_ajax_lpc_order_affect AJAX action) in versions…

  • CVE-2026-9237MedJul 9, 2026
    risk 0.00cvss 4.3epss 0.00

    The Employee, Leave and Recruitment Management System – Crew HRM plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.2.2. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes…

  • CVE-2026-9235MedJul 9, 2026
    risk 0.00cvss 4.3epss 0.00

    The DHL eCommerce (Benelux) for WooCommerce plugin for WordPress is vulnerable to unauthorized modification and loss of data due to a missing capability check and missing nonce verification on the create_label() and delete_label() functions in versions up to, and including,…

  • CVE-2026-9028MedJul 9, 2026
    risk 0.00cvss 5.3epss 0.00

    The CorvusPay WooCommerce Payment Gateway plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 2.7.4. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for…

  • CVE-2026-9027MedJul 9, 2026
    risk 0.00cvss 5.3epss 0.00

    The CorvusPay WooCommerce Payment Gateway plugin for WordPress is vulnerable to Payment Bypass via Improper Verification of Cryptographic Signature in all versions up to, and including, 2.7.4. The `corvuspay_success_handler` function registers the REST endpoint `POST…

  • CVE-2026-9021MedJul 9, 2026
    risk 0.00cvss 5.3epss 0.01

    The Easy Invoice plugin for WordPress is vulnerable to Missing Authorization in versions up to, and including, 2.1.19. This is due to the plugin registering the easy_invoice_accept_quote and easy_invoice_decline_quote AJAX actions via wp_ajax_nopriv_ hooks and relying solely on…

  • CVE-2026-4298MedJul 9, 2026
    risk 0.00cvss 4.3epss 0.00

    The DSGVO All in one for WP plugin for WordPress is vulnerable to Missing Authorization in all versions up to and including 4.9. This is due to the dsgvo_reset_policy_service_func() function lacking both capability checks and nonce verification while processing user-supplied…

  • CVE-2026-4275HigJul 9, 2026
    risk 0.00cvss 8.8epss 0.00

    The Divi Torque Lite – Divi Theme, Divi Builder & Extra Theme plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 4.2.3. This is due to the use of '__return_true' as the permission_callback for the /install_plugin and…

  • CVE-2026-13441HigJul 9, 2026
    risk 0.00cvss 7.2epss 0.00

    The EventPrime – Events Calendar, Bookings and Tickets plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'new_event_type_background_color' parameter in all versions up to, and including, 4.3.4.2 due to insufficient input sanitization and output…

  • CVE-2026-12428MedJul 9, 2026
    risk 0.00cvss 6.5epss 0.00

    The Blocks for ACF Fields plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the get_all_values() function in the /wp-json/acf-field-blocks/v1/values REST endpoint in versions up to, and including, 1.6.2. The…

  • CVE-2026-15158CriJul 9, 2026
    risk 0.00cvss 9.8epss 0.01

    The Blocksy Companion plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 2.1.46 via the save_attachments function. This is due to the Custom Fonts extension registering a wp_check_filetype_and_ext filter that approves any filename…

  • CVE-2026-12433MedJul 9, 2026
    risk 0.00cvss 4.3epss 0.00

    The Hydra Booking – Appointment Scheduling & Booking Calendar plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions up to, and including, 1.2.1 via the /wp-json/hydra-booking/v1/booking/details/{id} REST endpoint. This is due to the…

  • CVE-2026-8996MedJul 9, 2026
    risk 0.00cvss 6.5epss 0.00

    The Backup and Staging by WP Time Capsule plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.22.26 via the download_recent_decrypted_file_wptc. This makes it possible for authenticated attackers, with subscriber-level…

  • CVE-2026-8848HigJul 9, 2026
    risk 0.00cvss 7.2epss 0.01

    The Popup Maker – Boost Sales, Conversions, Optins, Subscribers with the Ultimate WP Popup Builder plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.22.0. This is due to the plugin not properly verifying that a user is…

  • CVE-2026-7558MedJul 9, 2026
    risk 0.00cvss 5.3epss 0.00

    The Age Verification & Identity Verification by Token of Trust plugin for WordPress is vulnerable to unauthorized access in all versions up to and including 4.0.2. This is due to the handle_export_table() function being registered on the WordPress 'init' hook, which fires for…

Page 713 of 738