VYPR

Vendor CVEs

WordPress

All CVEs

36,868 total · sorted by risk
  • CVE-2026-57723HigJul 1, 2026
    risk 0.00cvss 7.4epss 0.00

    Cross-Site Request Forgery (CSRF) vulnerability in e4jvikwp VikBooking Hotel Booking Engine & PMS allows Path Traversal. This issue affects VikBooking Hotel Booking Engine & PMS: from n/a through 1.8.12.

  • CVE-2026-57722MedJul 1, 2026
    risk 0.00cvss 5.9epss 0.00

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ShortPixel Enable Media Replace allows Stored XSS. This issue affects Enable Media Replace: from n/a through 4.2.1.

  • CVE-2026-57721MedJul 1, 2026
    risk 0.00cvss 5.3epss 0.00

    Missing Authorization vulnerability in WP Reloaded ApplyOnline allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects ApplyOnline: from n/a through 2.6.7.6.

  • CVE-2026-57720MedJul 1, 2026
    risk 0.00cvss 4.3epss 0.00

    Missing Authorization vulnerability in Codexpert Inc ThumbPress allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects ThumbPress: from n/a through 6.3.2.

  • CVE-2026-27409MedJul 1, 2026
    risk 0.00cvss 5.3epss 0.00

    Missing Authorization vulnerability in Webba Plugins Webba Booking allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Webba Booking: from n/a through 6.4.13.

  • CVE-2026-57692CriJul 1, 2026
    risk 0.00cvss 9.8epss 0.01

    Incorrect Privilege Assignment vulnerability in LCweb PrivateContent allows Privilege Escalation. This issue affects PrivateContent: from n/a through 9.9.2.

  • CVE-2026-12142HigJul 1, 2026
    risk 0.00cvss 7.2epss 0.01

    The NEX-Forms – Ultimate Forms Plugin for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via '_name[]' Array Parameter in all versions up to, and including, 9.2.2 due to insufficient input sanitization and output escaping. This makes it possible…

  • CVE-2026-27435MedJul 1, 2026
    risk 0.00cvss 5.3epss 0.00

    Missing Authorization vulnerability in WofficeIO Woffice allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Woffice: from n/a before 5.4.33.

  • CVE-2026-12754MedJul 1, 2026
    risk 0.00cvss 6.1epss 0.00

    The VikBooking Hotel Booking Engine & PMS plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'layoutstyle' parameter in all versions up to, and including, 1.8.12 due to insufficient input sanitization and output escaping. This makes it possible for…

  • CVE-2026-13733MedJul 1, 2026
    risk 0.00cvss 6.4epss 0.00

    The Download Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'no_data_msg' Shortcode Attribute in all versions up to, and including, 3.3.60 due to insufficient input sanitization and output escaping. This makes it possible for authenticated…

  • CVE-2026-12732MedJul 1, 2026
    risk 0.00cvss 6.4epss 0.00

    The LearnPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'class_wrapper_form' shortcode attribute in versions up to, and including, 4.4.0. This is due to insufficient input sanitization and output escaping in the FilterCourseTemplate::sections()…

  • CVE-2026-12435MedJul 1, 2026
    risk 0.00cvss 4.3epss 0.00

    The Motors – Car Dealership & Classified Listings Plugin plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.4.111. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it…

  • CVE-2026-12408MedJul 1, 2026
    risk 0.00cvss 4.3epss 0.00

    The Slim SEO – A Fast & Automated SEO Plugin For WordPress plugin for WordPress is vulnerable to Unauthorized Private Content Disclosure in all versions up to, and including, 4.9.8 via the `/wp-json/slim-seo/meta-tags/ai` REST API endpoint. This is due to the endpoint's…

  • CVE-2026-12224HigJul 1, 2026
    risk 0.00cvss 8.8epss 0.00

    The Dokan Pro plugin for WordPress is vulnerable to privilege escalation via update_capabilities REST Endpoint in all versions up to, and including, 5.0.4. This is due to the `update_capabilities()` REST handler accepting arbitrary capability strings from the request body and…

  • CVE-2026-12158HigJul 1, 2026
    risk 0.00cvss 8.8epss 0.00

    The RegistrationMagic – User Registration Forms Plugin plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 6.0.9.1. This is due to missing or incorrect nonce validation on the process_request function. This makes it possible…

  • CVE-2026-11387CriJul 1, 2026
    risk 0.00cvss 9.8epss 0.02

    The SMS Alert – SMS & OTP for WooCommerce, Order Notifications & Abandoned Cart Recovery plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 3.9.5. This is due to the plugin not properly validating a user's…

  • CVE-2026-10096MedJul 1, 2026
    risk 0.00cvss 4.3epss 0.00

    The Qi Blocks plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 1.4.9 via the 'page_id' parameter due to missing validation on a user controlled key. This makes it possible for authenticated attackers, with author-level…

  • CVE-2026-1239HigJul 1, 2026
    risk 0.00cvss 7.5epss 0.00

    The Ninja Forms – The Contact Form Builder That Grows With You plugin for WordPress is vulnerable to unauthorized access of data due to a missing authorization check on the 'ninja-forms-views/token/refresh' REST callback in all versions up to, and including, 3.14.1. This makes…

  • CVE-2026-11887MedJul 1, 2026
    risk 0.00cvss 4.3epss 0.00

    The Salon Booking System WordPress plugin before 10.30.20 does not have proper authorisation checks on one of its AJAX actions, allowing any authenticated user, such as a subscriber, to modify a Salon Booking System WordPress plugin before 10.30.20 setting and bypass the…

  • CVE-2026-11883HigJul 1, 2026
    risk 0.00cvss 7.2epss 0.01

    The WebAuthn Provider for Two Factor WordPress plugin before 2.5.6 does not correctly validate the second-factor authentication response, allowing an attacker who already knows a user's password to bypass the two-factor authentication requirement by submitting a malformed…

  • CVE-2026-11880LowJul 1, 2026
    risk 0.00cvss 3.1epss 0.00

    The Fluent Forms WordPress plugin before 6.2.1 does not properly verify ownership before processing a subscription cancellation request, allowing authenticated users with a low-privilege account to cancel subscriptions belonging to other users.

  • CVE-2026-11823HigJul 1, 2026
    risk 0.00cvss 7.5epss 0.00

    The BookingPress Appointment Booking Pro plugin for WordPress is vulnerable to SQL Injection via the 'store_service_date' parameter of the bpa_assign_staffmember_to_slots() function in versions up to and including 5.7.1. This is due to the explicit use of stripslashes_deep() on…

  • CVE-2026-11794HigJul 1, 2026
    risk 0.00cvss 8.1epss 0.00

    The Advanced Form Integration — Connect Forms to 200+ Apps WordPress plugin before 2.1.1 does not restrict the WordPress role assigned when it creates a user from a public form submission, allowing unauthenticated visitors to create an administrator account when an active…

  • CVE-2026-11570MedJul 1, 2026
    risk 0.00cvss 4.2epss 0.00

    The User Submitted Posts WordPress plugin before 20260608 does not escape a submitted value before outputting it in an admin-configured display template, leading to a Stored Cross-Site Scripting that can be triggered by unauthenticated users when a non-default display option is…

  • CVE-2026-11568HigJul 1, 2026
    risk 0.00cvss 7.5epss 0.00

    The Product Configurator for WooCommerce WordPress plugin before 1.7.3 does not perform any authorisation or post-status check before returning WooCommerce product data through a public AJAX action, allowing unauthenticated users to retrieve the data (title, price, weight, stock…

  • CVE-2026-11562MedJul 1, 2026
    risk 0.00cvss 4.3epss 0.00

    The WS Form LITE WordPress plugin before 1.11.8 does not have a capability check on one of its settings-update actions, allowing authenticated users with subscriber-level access and above to modify the WS Form LITE WordPress plugin before 1.11.8's settings.

  • CVE-2026-10750HigJul 1, 2026
    risk 0.00cvss 8.1epss 0.00

    The Royal MCP WordPress plugin before 1.4.26 does not perform capability checks on the majority of its MCP tools after token authentication, allowing authenticated users with a low-privileged role such as Subscriber to read private content, enumerate all users and their roles,…

  • CVE-2026-9107MedJul 1, 2026
    risk 0.00cvss 6.4epss 0.00

    The Kali Forms — Contact Form & Drag-and-Drop Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'meta[kaliforms_field_components]' parameter in all versions up to, and including, 2.4.13 due to insufficient input sanitization and output escaping.…

  • CVE-2026-7517HigJul 1, 2026
    risk 0.00cvss 7.2epss 0.00

    The Custom Payment Gateways for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'alg_wc_cpg_input_fields' parameter in all versions up to, and including, 2.1.0 due to insufficient input sanitization and output escaping. This makes it…

  • CVE-2026-6070CriJul 1, 2026
    risk 0.00cvss 9.1epss 0.01

    The WP-BusinessDirectory plugin for WordPress is vulnerable to Unauthenticated Arbitrary File Deletion in versions up to and including 4.0.1. This is due to insufficient path validation in the remove() method of the JBusinessDirectoryControllerUpload class. The…

  • CVE-2026-2387MedJul 1, 2026
    risk 0.00cvss 6.4epss 0.00

    The Event Organiser plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 3.12.9. This is due to the 'eo_events' shortcode accepting attacker-controlled 'no_events' content and rendering it in event list templates without output…

  • CVE-2026-13731HigJul 1, 2026
    risk 0.00cvss 7.2epss 0.01

    The WPBot – AI ChatBot for Live Support, Lead Generation, AI Services plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'conversation' parameter in all versions up to, and including, 8.4.9 due to insufficient input sanitization and output escaping. This…

  • CVE-2026-13468HigJul 1, 2026
    risk 0.00cvss 7.5epss 0.01

    The Visualizer – Tables & Charts Manager with Built-in AI Generator plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 4.0.3. This is due to the plugin not properly verifying that a user is authorized to perform an action. This…

  • CVE-2026-13443MedJul 1, 2026
    risk 0.00cvss 6.4epss 0.00

    The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Lesson Attachment Title in all versions up to, and including, 3.9.13 due to insufficient input sanitization and output escaping. This makes it possible…

  • CVE-2026-13246MedJul 1, 2026
    risk 0.00cvss 6.4epss 0.00

    The GiveWP – Donation Plugin and Fundraising Platform plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'block_id' (and other) shortcode attributes of the 'givewp_campaign_comments' shortcode in versions up to, and including, 4.16.0. This is due to…

  • CVE-2026-13015MedJul 1, 2026
    risk 0.00cvss 6.1epss 0.00

    The Wp Google Places Review Slider plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'place' parameter in versions up to, and including, 18.1. This is due to insufficient input sanitization and output escaping in admin/partials/googlecrawl_dfs.php,…

  • CVE-2026-12923HigJul 1, 2026
    risk 0.00cvss 7.5epss 0.01

    The Youtube Showcase plugin for WordPress is vulnerable to Arbitrary Function Call in versions up to and including 4.0.3. This is due to insufficient validation of the 'path' parameter in the emd_delete_file() AJAX handler in includes/common-functions.php. The user-supplied…

  • CVE-2026-12904MedJul 1, 2026
    risk 0.00cvss 4.3epss 0.00

    The Kadence Blocks – Gutenberg Blocks for Page Builder Features plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions up to and including 3.7.7. This is due to a mismatch between the object used for authorization and the object actually accessed in…

  • CVE-2026-12902MedJul 1, 2026
    risk 0.00cvss 4.3epss 0.00

    The Kadence Blocks — Page Builder Toolkit for Gutenberg Editor plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 3.7.7. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it…

  • CVE-2026-12135MedJul 1, 2026
    risk 0.00cvss 6.4epss 0.00

    The FV Flowplayer Video Player plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'video_player' shortcode 'align' attribute in all versions up to, and including, 7.5.51.7212 due to insufficient input sanitization and output escaping on user supplied…

  • CVE-2026-12133MedJul 1, 2026
    risk 0.00cvss 4.3epss 0.00

    The JoomSport – for Sports: Team & League, Football, Hockey & more plugin for WordPress is vulnerable to Missing Authorization to Arbitrary Group Deletion in versions up to, and including, 5.7.8. This is due to a missing capability check in the joomsport_season_groupdel() AJAX…

  • CVE-2026-12113MedJul 1, 2026
    risk 0.00cvss 4.3epss 0.00

    The Appointment Booking Calendar plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.4.02 via the cpabc_appointments_filter_list. This makes it possible for authenticated attackers, with contributor-level access and above,…

  • CVE-2026-11988MedJul 1, 2026
    risk 0.00cvss 6.5epss 0.00

    The LearnPress – WordPress LMS Plugin for Create and Sell Online Courses plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 4.3.9.1 via the 'userId' parameter due to missing validation on a user controlled key. This…

  • CVE-2026-11981MedJul 1, 2026
    risk 0.00cvss 4.3epss 0.00

    The GiveWP plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 4.15.3 This is due to missing nonce validation on the give_set_notification_status_handler() function. This makes it possible for unauthenticated attackers to disable…

  • CVE-2026-9711CriJun 30, 2026
    risk 0.00cvss 9.8epss 0.01

    The EventON - WordPress Virtual Event Calendar Plugin plugin for WordPress (full) is vulnerable to SQL Injection via the WordPress 'search' parameter in versions up to, and including, 5.0.11 due to insufficient escaping on the user supplied parameter and lack of preparation on…

  • CVE-2026-8141HigJun 30, 2026
    risk 0.00cvss 7.2epss 0.00

    The Ajax Load More - Filters plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'taxonomy_include_children' parameter in all versions up to, and including, 3.4.1 due to insufficient input sanitization and output escaping. This makes it possible for…

  • CVE-2026-9576MedJun 30, 2026
    risk 0.00cvss 4.9epss 0.00

    The Fluent Booking WordPress plugin before 2.1.2 does not verify ownership of the requested group_id before exporting attendee data via the export endpoint, allowing users with at least the Calendar Manager role to retrieve attendees' PII (name, email, phone, address, payment…

  • CVE-2026-12240HigJun 30, 2026
    risk 0.00cvss 8.0epss 0.01

    The Export User Data plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the unserialize function in all versions up to, and including, 2.2.6. This makes it possible for authenticated attackers, with subscriber-level access…

  • CVE-2026-11590HigJun 30, 2026
    risk 0.00cvss 8.6epss 0.00

    The WP Support Plus Responsive Ticket System WordPress plugin through 9.1.2 does not sanitize user-supplied array keys before using them in a SQL statement, allowing unauthenticated users to perform SQL injection attacks.

  • CVE-2026-11589HigJun 30, 2026
    risk 0.00cvss 8.8epss 0.01

    The WP Support Plus Responsive Ticket System WordPress plugin through 9.1.2 does not properly validate uploaded files, allowing unauthenticated users to upload files containing malicious JavaScript (such as HTML or SVG) to a publicly accessible location, leading to Stored…

Page 718 of 738