VYPR

Vendor CVEs

WordPress

All CVEs

36,868 total · sorted by risk
  • CVE-2026-11581MedJun 30, 2026
    risk 0.00cvss 5.9epss 0.00

    The Kali Forms — Contact Form & Drag-and-Drop Builder WordPress plugin before 2.4.13 does not sanitise a form field's caption before outputting it as a column header on the administrator form-entries screen, allowing users with Contributor-level access or above to store…

  • CVE-2026-8944MedJun 30, 2026
    risk 0.00cvss 4.3epss 0.00

    The Plugin for Google Analytics by IO technologies plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.1. This is due to missing or incorrect nonce validation on the Google Analytics settings page (ga.php). This makes it possible…

  • CVE-2026-12560MedJun 30, 2026
    risk 0.00cvss 4.4epss 0.00

    The Editorial Rating – Product Review & Rating System plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'Link URL' Field in all versions up to, and including, 4.0.5 due to insufficient input sanitization and output escaping. This makes it possible for…

  • CVE-2026-12349MedJun 30, 2026
    risk 0.00cvss 5.3epss 0.00

    The Premium Addons for KingComposer plugin for WordPress is vulnerable to unauthorized modification and loss of data in versions up to, and including, 1.1.1. This is due to missing authorization and capability checks on the add_custom_sidebar() and remove_custom_sidebar() AJAX…

  • CVE-2026-12073CriJun 30, 2026
    risk 0.00cvss 9.8epss 0.01

    The ProfileGrid – User Profiles, Groups and Communities plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 5.9.9.5. This is due to the plugin not validating a `user_login` on registration forms that don't…

  • CVE-2026-11367MedJun 30, 2026
    risk 0.00cvss 6.5epss 0.01

    The PixMagix – WordPress Image Editor plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 1.7.2 via the move_image_on_server function. This makes it possible for authenticated attackers, with author-level access and above, to write…

  • CVE-2026-12114MedJun 30, 2026
    risk 0.00cvss 4.4epss 0.00

    The Team Members – Multi Language Supported Team Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 8.7 due to insufficient input sanitization and output escaping. This makes it possible for…

  • CVE-2026-57341MedJun 29, 2026
    risk 0.00cvss 6.5epss 0.00

    Unauthenticated Insecure Direct Object References (IDOR) in Colissimo Officiel : Méthodes de livraison pour WooCommerce <= 2.9.0 versions.

  • CVE-2026-57340MedJun 29, 2026
    risk 0.00cvss 6.5epss 0.00

    Unauthenticated Broken Access Control in Japanized For WooCommerce <= 2.9.12 versions.

  • CVE-2026-57339MedJun 29, 2026
    risk 0.00cvss 6.5epss 0.00

    Unauthenticated Broken Access Control in Business Directory <= 6.4.23 versions.

  • CVE-2026-57338HigJun 29, 2026
    risk 0.00cvss 7.1epss 0.00

    Unauthenticated Cross Site Scripting (XSS) in ARForms <= 7.1.2 versions.

  • CVE-2026-57337HigJun 29, 2026
    risk 0.00cvss 7.1epss 0.00

    Unauthenticated Cross Site Scripting (XSS) in Landing Page Builder <= 1.5.3.5 versions.

  • CVE-2026-57336HigJun 29, 2026
    risk 0.00cvss 7.1epss 0.00

    Unauthenticated Cross Site Scripting (XSS) in Jobify <= 4.3.2 versions.

  • CVE-2026-57335MedJun 29, 2026
    risk 0.00cvss 6.5epss 0.00

    Subscriber Broken Access Control in Ads by WPQuads <= 3.0.3 versions.

  • CVE-2026-57334MedJun 29, 2026
    risk 0.00cvss 6.5epss 0.00

    Unauthenticated Broken Access Control in WP User Frontend <= 4.3.7 versions.

  • CVE-2026-57333HigJun 29, 2026
    risk 0.00cvss 7.1epss 0.00

    Unauthenticated Cross Site Scripting (XSS) in Link Whisper Free <= 0.9.4 versions.

  • CVE-2026-57332HigJun 29, 2026
    risk 0.00cvss 7.1epss 0.00

    Subscriber Broken Access Control in Wallet System for WooCommerce <= 2.7.6 versions.

  • CVE-2026-57331CriJun 29, 2026
    risk 0.00cvss 9.9epss 0.01

    Performer Arbitrary File Deletion in Paid Videochat Turnkey Site <= 7.4.8 versions.

  • CVE-2026-57330MedJun 29, 2026
    risk 0.00cvss 6.5epss 0.00

    Subscriber Cross Site Scripting (XSS) in MasterStudy LMS <= 3.7.27 versions.

  • CVE-2026-57329MedJun 29, 2026
    risk 0.00cvss 6.5epss 0.00

    Subscriber Cross Site Scripting (XSS) in WooCommerce Designer Pro <= 1.9.34 versions.

  • CVE-2026-57328MedJun 29, 2026
    risk 0.00cvss 6.5epss 0.00

    Subscriber Cross Site Scripting (XSS) in Business Directory <= 6.4.22 versions.

  • CVE-2026-57327MedJun 29, 2026
    risk 0.00cvss 6.3epss 0.00

    Subscriber Broken Access Control in MainWP <= 6.1.1 versions.

  • CVE-2026-57326MedJun 29, 2026
    risk 0.00cvss 6.1epss 0.00

    Unauthenticated Cross Site Scripting (XSS) in Business Directory <= 6.4.22 versions.

  • CVE-2026-57320HigJun 29, 2026
    risk 0.00cvss 7.1epss 0.00

    Unauthenticated Cross Site Scripting (XSS) in BEAR <= 1.1.8 versions.

  • CVE-2026-57346HigJun 29, 2026
    risk 0.00cvss 7.1epss 0.00

    Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Epiphyt Embed Privacy allows Path Traversal. This issue affects Embed Privacy: from n/a through 1.12.3.

  • CVE-2026-57676MedJun 29, 2026
    risk 0.00cvss 4.3epss 0.00

    Authorization Bypass Through User-Controlled Key vulnerability in Matteo Manna Simple User Avatar allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Simple User Avatar: from n/a through 4.9.

  • CVE-2026-9676MedJun 29, 2026
    risk 0.00cvss 4.3epss 0.00

    The F4 Post Tree WordPress plugin before 2.0.5 does not perform capability checks or CSRF/nonce verification on one of its AJAX actions, allowing authenticated users with Subscriber-level access and above to modify the parent and menu order of arbitrary posts.

  • CVE-2026-10083HigJun 29, 2026
    risk 0.00cvss 7.5epss 0.00

    The APCu Manager WordPress plugin before 4.5.0 does not escape APCu object-cache keys before rendering them in an admin-area page, leading to a Stored Cross-Site Scripting vulnerability. When a persistent object cache is enabled, cache keys derived from unsanitised user input…

  • CVE-2026-8095HigJun 28, 2026
    risk 0.00cvss 8.1epss 0.01

    The Frontend File Manager Plugin plugin for WordPress is vulnerable to Authenticated Arbitrary File Deletion in versions up to and including 23.6. This is due to a case-sensitive bypass of the wpfm_dir_path parameter sanitization in the wpfm_file_meta_update AJAX handler, where…

  • CVE-2026-9242MedJun 27, 2026
    risk 0.00cvss 5.3epss 0.00

    The RegistrationMagic – Custom Registration Forms, User Registration, Payment, and User Login plugin for WordPress is vulnerable to Authentication Bypass via Insufficient Verification of Data Authenticity in all versions up to and including 6.0.8.6. This is due to the PayPal…

  • CVE-2026-9233MedJun 27, 2026
    risk 0.00cvss 4.3epss 0.00

    The Quiz and Survey Master (QSM) – Easy Quiz and Survey Maker plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 11.1.4. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it…

  • CVE-2026-3462MedJun 27, 2026
    risk 0.00cvss 6.5epss 0.00

    The Frisbii Pay plugin for WordPress is vulnerable to unauthorized modification of data due to missing capability checks on the 'upload_csv' and 'process_batch' functions in all versions up to, and including, 1.8.9. This makes it possible for authenticated attackers, with…

  • CVE-2026-13295MedJun 27, 2026
    risk 0.00cvss 6.4epss 0.00

    The Page Builder by SiteOrigin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via panels_data Parameter in all versions up to, and including, 2.34.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers,…

  • CVE-2026-12471MedJun 27, 2026
    risk 0.00cvss 4.3epss 0.00

    The Spexo theme for WordPress is vulnerable to unauthorized access due to a missing capability check on the activate_plugin function in all versions up to, and including, 2.0.11. This makes it possible for authenticated attackers, with Subscriber-level access and above, to…

  • CVE-2026-12432MedJun 27, 2026
    risk 0.00cvss 5.3epss 0.01

    The WP Full Stripe Free plugin for WordPress is vulnerable to Missing Authorization in versions up to, and including, 8.4.3 via the wpfs_update_failed_payment_status AJAX action. The handler is registered through both wp_ajax_ and wp_ajax_nopriv_ hooks and the underlying…

  • CVE-2026-12399MedJun 27, 2026
    risk 0.00cvss 4.4epss 0.00

    The Gutenverse – WordPress Blocks, Page Builder & Site Editor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 3.8.0 due to insufficient input sanitization and output escaping. This makes it possible for…

  • CVE-2026-11987MedJun 27, 2026
    risk 0.00cvss 4.3epss 0.00

    The Dokan: AI Powered WooCommerce Multivendor Marketplace Solution – Build Your Own Amazon, eBay, Etsy plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 5.0.4 via the 'id' parameter due to missing validation on a user…

  • CVE-2026-11783MedJun 27, 2026
    risk 0.00cvss 6.4epss 0.00

    The Dokan: AI Powered WooCommerce Multivendor Marketplace Solution – Build Your Own Amazon, eBay, Etsy plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Product SKU in all versions up to, and including, 5.0.4 due to insufficient input sanitization and…

  • CVE-2026-11773MedJun 27, 2026
    risk 0.00cvss 4.3epss 0.00

    The Masteriyo LMS – LMS Course Builder, Quizzes & Certificates plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 2.2.1. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it…

  • CVE-2026-11597MedJun 27, 2026
    risk 0.00cvss 6.4epss 0.00

    The Surbma | Infusionsoft Shortcode plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'infusionsoft-form' shortcode in versions up to, and including, 2.0.1. This is due to insufficient input sanitization and output escaping on user-supplied 'account' and…

  • CVE-2026-9677MedJun 27, 2026
    risk 0.00cvss 4.8epss 0.00

    The Shariff for WordPress Shariff for WordPress plugin through 1.0.11 does not sanitize or escape the shariff_infourl setting before outputting it in the frontend HTML via the generateshariff() function, which could allow high privilege users such as admin to perform Stored…

  • CVE-2026-13245MedJun 27, 2026
    risk 0.00cvss 6.1epss 0.00

    The MaxButtons – Create buttons plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'view' parameter in all versions up to, and including, 9.8.5 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated…

  • CVE-2026-12404MedJun 27, 2026
    risk 0.00cvss 5.3epss 0.00

    The NEX-Forms – Ultimate Forms Plugin for WordPress plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 9.2.2. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible…

  • CVE-2026-10820HigJun 27, 2026
    risk 0.00cvss 8.1epss 0.00

    The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content WordPress plugin before 4.16.17 does not verify that the user performing a subscription action owns the targeted subscription, allowing any authenticated user…

  • CVE-2026-12415CriJun 27, 2026
    risk 0.00cvss 9.8epss 0.01

    The Invoice Generator plugin for WordPress is vulnerable to privilege escalation due to a missing capability check on the pravel_invoice_edit_account() AJAX action in versions up to, and including, 1.0.0. The handler is exposed via wp_ajax_nopriv_pravel_invoice_edit_account,…

  • CVE-2026-13422MedJun 27, 2026
    risk 0.00cvss 4.3epss 0.00

    The HD Quiz plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions 2.2.0 to 2.2.1. This is due to missing or incorrect nonce validation on the hdq_validate_nonce function. This makes it possible for unauthenticated attackers to delete or modify quizzes and…

  • CVE-2026-13335MedJun 27, 2026
    risk 0.00cvss 6.4epss 0.00

    The CodePeople Post Map for Google Maps plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'cpm_point' Post Meta in all versions up to, and including, 1.2.6 due to insufficient input sanitization and output escaping. This makes it possible for authenticated…

  • CVE-2026-13333MedJun 27, 2026
    risk 0.00cvss 6.5epss 0.01

    The Groundhogg — CRM, Newsletters, and Marketing Automation plugin for WordPress is vulnerable to generic SQL Injection via 'query[select]' Parameter in all versions up to, and including, 4.5.5 due to insufficient escaping on the user supplied parameter and lack of sufficient…

  • CVE-2026-13331MedJun 27, 2026
    risk 0.00cvss 6.5epss 0.00

    The Groundhogg — CRM, Newsletters, and Marketing Automation plugin for WordPress is vulnerable to generic SQL Injection via the 'search' parameter in all versions up to, and including, 4.5.5 due to insufficient escaping on the user supplied parameter and lack of sufficient…

  • CVE-2026-11356MedJun 27, 2026
    risk 0.00cvss 4.4epss 0.00

    The Ivory Search – WordPress Search Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'menu_title' and 'menu_magnifier_color' Settings in all versions up to, and including, 5.5.15 due to insufficient input sanitization and output escaping. This makes…

Page 719 of 738