Vendor CVEs
WordPress
All CVEs
36,868 total · sorted by risk| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2026-54839 | Hig | 0.00 | 7.5 | 0.00 | Jun 26, 2026 | Unauthenticated Sensitive Data Exposure in Trinity Backup – Backup, Migrate, Restore, Clone & Schedule Backups <= 2.0.9 versions. | ||
| CVE-2026-54837 | Hig | 0.00 | 7.5 | 0.00 | Jun 26, 2026 | Unauthenticated Broken Access Control in Intranet & Private Site – All-In-One Intranet <= 1.8.1 versions. | ||
| CVE-2026-54835 | Hig | 0.00 | 7.5 | 0.00 | Jun 26, 2026 | Unauthenticated Broken Access Control in Five Star Restaurant Menu <= 2.5.2 versions. | ||
| CVE-2026-54834 | Hig | 0.00 | 7.5 | 0.00 | Jun 26, 2026 | Unauthenticated Sensitive Data Exposure in Object Cache 4 everyone <= 2.3.2 versions. | ||
| CVE-2026-54833 | Hig | 0.00 | 7.4 | 0.00 | Jun 26, 2026 | Unauthenticated Backdoor in Enable CORS <= 2.0.3 versions. | ||
| CVE-2026-54832 | Hig | 0.00 | 7.5 | 0.00 | Jun 26, 2026 | Unauthenticated Broken Access Control in Gutenverse Companion <= 2.5.0 versions. | ||
| CVE-2026-54831 | Cri | 0.00 | 9.3 | 0.00 | Jun 26, 2026 | Unauthenticated SQL Injection in GeoDirectory <= 2.8.162 versions. | ||
| CVE-2026-54827 | Cri | 0.00 | 9.3 | 0.00 | Jun 26, 2026 | Unauthenticated SQL Injection in Real Estate 7 <= 3.5.9 versions. | ||
| CVE-2026-54826 | Hig | 0.00 | 7.6 | 0.00 | Jun 26, 2026 | Subscriber Insecure Direct Object References (IDOR) in SupportCandy <= 3.4.6 versions. | ||
| CVE-2026-54825 | Cri | 0.00 | 9.3 | 0.00 | Jun 26, 2026 | Unauthenticated SQL Injection in wpDataTables <= 7.4 versions. | ||
| CVE-2026-54824 | Hig | 0.00 | 7.5 | 0.00 | Jun 26, 2026 | Unauthenticated Sensitive Data Exposure in Ads by WPQuads <= 3.0.3 versions. | ||
| CVE-2026-54820 | Cri | 0.00 | 9.3 | 0.00 | Jun 26, 2026 | Unauthenticated SQL Injection in JetBooking <= 4.0.4.1 versions. | ||
| CVE-2026-52701 | Med | 0.00 | 6.5 | 0.00 | Jun 26, 2026 | Unauthenticated Broken Access Control in User Registration <= 5.2.2 versions. | ||
| CVE-2026-24547 | Med | 0.00 | 5.3 | 0.00 | Jun 26, 2026 | Unauthenticated Broken Access Control in SiteGround Email Marketing <= 1.7.5 versions. | ||
| CVE-2025-68075 | Med | 0.00 | 6.5 | 0.00 | Jun 26, 2026 | Contributor Cross Site Scripting (XSS) in BNE Testimonials <= 2.0.8 versions. | ||
| CVE-2025-68074 | Med | 0.00 | 6.5 | 0.00 | Jun 26, 2026 | Contributor Cross Site Scripting (XSS) in Image Carousel <= 1.0.0.41 versions. | ||
| CVE-2025-68064 | Hig | 0.00 | 7.5 | 0.00 | Jun 26, 2026 | Contributor Local File Inclusion in Goya Core < 1.0.9.4 versions. | ||
| CVE-2025-68063 | Hig | 0.00 | 7.5 | 0.00 | Jun 26, 2026 | Contributor Local File Inclusion in Splash - Sport Club WordPress Theme for Basketball, Football, Hockey <= 4.4.3 versions. | ||
| CVE-2025-68052 | Hig | 0.00 | 8.8 | 0.00 | Jun 26, 2026 | Unauthenticated Cross Site Request Forgery (CSRF) in Eagle Booking <= 1.3.4.3 versions. | ||
| CVE-2025-66123 | Med | 0.00 | 5.3 | 0.00 | Jun 26, 2026 | Unauthenticated Insecure Direct Object References (IDOR) in BookPro <= 1.1.0 versions. | ||
| CVE-2025-64637 | Med | 0.00 | 5.3 | 0.00 | Jun 26, 2026 | Unauthenticated Content Injection in Auros Core <= 5.3.1 versions. | ||
| CVE-2025-64636 | Med | 0.00 | 5.3 | 0.00 | Jun 26, 2026 | Unauthenticated Broken Access Control in Donation Thermometer <= 2.2.7 versions. | ||
| CVE-2025-63079 | Med | 0.00 | 4.3 | 0.00 | Jun 26, 2026 | Contributor Broken Access Control in Live Copy Paste for Elementor <= 1.5.3 versions. | ||
| CVE-2025-63078 | Med | 0.00 | 4.3 | 0.00 | Jun 26, 2026 | Subscriber Broken Access Control in Restaurant Menu by MotoPress <= 2.4.11 versions. | ||
| CVE-2025-63041 | Med | 0.00 | 5.4 | 0.00 | Jun 26, 2026 | Contributor Broken Access Control in Forget About Shortcode Buttons <= 2.1.3 versions. | ||
| CVE-2026-57620 | Med | 0.00 | 6.5 | 0.00 | Jun 26, 2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Tim Strifler Exclusive Addons Elementor allows Stored XSS. This issue affects Exclusive Addons Elementor: from n/a through 2.7.9.8. | ||
| CVE-2026-1869 | Med | 0.00 | 6.5 | 0.00 | Jun 26, 2026 | The User Registration & Membership – Free & Paid Memberships, Subscriptions, Content Restriction, User Profile, Custom User Registration & Login Builder plugin for WordPress is vulnerable to unauthorized modification of data due to missing validation checks in the… | ||
| CVE-2026-8380 | Med | 0.00 | 6.5 | 0.00 | Jun 26, 2026 | The Frontend File Manager Plugin WordPress plugin through 23.6 does not properly verify ownership of every targeted post before permanent deletion, allowing authenticated users with author-level access and above to permanently delete arbitrary posts and pages. When the Frontend… | ||
| CVE-2026-10835 | Hig | 0.00 | 7.7 | 0.00 | Jun 26, 2026 | The SALESmanago & Leadoo WordPress plugin before 3.11.3 does not properly sanitise and escape a parameter passed to one of its AJAX actions before using it in a SQL statement, and fails to enforce authorisation on that action, allowing authenticated users with minimal… | ||
| CVE-2026-10823 | Hig | 0.00 | 7.5 | 0.02 | Jun 26, 2026 | The YMC Filter WordPress plugin before 3.11.3 does not properly authorize access to one of its REST API endpoints and does not validate a user-supplied query parameter, allowing unauthenticated attackers to retrieve the titles and content of private, draft, and other non-public… | ||
| CVE-2025-10268 | Med | 0.00 | 5.3 | 0.00 | Jun 26, 2026 | The Printcart Web to Print Product Designer for WooCommerce WordPress plugin through 2.4.8 is vulnerable to path traversal which makes it possible for the attacker to retrieve the directory listing for arbitrary directories on the server. | ||
| CVE-2026-13226 | Med | 0.00 | 6.5 | 0.00 | Jun 26, 2026 | The Groundhogg — CRM, Newsletters, and Marketing Automation plugin for WordPress is vulnerable to generic SQL Injection via the 'after' parameter in all versions up to, and including, 4.5.4 due to insufficient escaping on the user supplied parameter and lack of sufficient… | ||
| CVE-2026-57700 | Cri | 0.00 | 10.0 | 0.01 | Jun 25, 2026 | Unrestricted Upload of File with Dangerous Type vulnerability in Daan.Dev OMGF Pro allows Using Malicious Files. This issue affects OMGF Pro: from n/a through 5.2.6. | ||
| CVE-2026-57619 | Med | 0.00 | 6.5 | 0.00 | Jun 25, 2026 | Contributor Sensitive Data Exposure in Elementor Website Builder <= 4.1.3 versions. | ||
| CVE-2026-57429 | Med | 0.00 | 6.5 | 0.00 | Jun 25, 2026 | Contributor Broken Access Control in Slim SEO <= 4.6.2 versions. | ||
| CVE-2026-56071 | Hig | 0.00 | 7.1 | 0.00 | Jun 25, 2026 | Unauthenticated Cross Site Scripting (XSS) in Forminator <= 1.53.1 versions. | ||
| CVE-2026-56054 | Hig | 0.00 | 7.7 | 0.00 | Jun 25, 2026 | Subscriber Arbitrary File Deletion in JS Help Desk <= 3.1.1 versions. | ||
| CVE-2026-56053 | Hig | 0.00 | 8.8 | 0.01 | Jun 25, 2026 | Subscriber PHP Object Injection in EventPrime <= 4.3.4.1 versions. | ||
| CVE-2026-56051 | Hig | 0.00 | 7.1 | 0.00 | Jun 25, 2026 | Unauthenticated Cross Site Scripting (XSS) in TablePress <= 3.3.1 versions. | ||
| CVE-2026-56050 | Med | 0.00 | 6.5 | 0.00 | Jun 25, 2026 | Improper Access Control vulnerability in Themeisle PPOM for WooCommerce allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects PPOM for WooCommerce: from n/a through 33.0.18. | ||
| CVE-2026-56049 | Hig | 0.00 | 8.5 | 0.01 | Jun 25, 2026 | Contributor Remote Code Execution (RCE) in Post Snippets <= 4.0.19 versions. | ||
| CVE-2026-56042 | Hig | 0.00 | 7.1 | 0.00 | Jun 25, 2026 | Customer Cross Site Scripting (XSS) in Advanced Order Export For WooCommerce <= 4.0.9 versions. | ||
| CVE-2026-56023 | Med | 0.00 | 5.4 | 0.00 | Jun 25, 2026 | Customer Broken Access Control in UPI QR Code Payment Gateway for WooCommerce <= 1.6.2 versions. | ||
| CVE-2026-56014 | Hig | 0.00 | 7.1 | 0.00 | Jun 25, 2026 | Unauthenticated Cross Site Scripting (XSS) in Master Slider <= 3.11.2 versions. | ||
| CVE-2026-56013 | Med | 0.00 | 6.5 | 0.00 | Jun 25, 2026 | Unauthenticated Insecure Direct Object References (IDOR) in License Manager for WooCommerce <= 3.0.15 versions. | ||
| CVE-2026-56006 | Hig | 0.00 | 7.1 | 0.00 | Jun 25, 2026 | Unauthenticated Cross Site Scripting (XSS) in H5P <= 1.17.6 versions. | ||
| CVE-2026-56005 | Hig | 0.00 | 7.1 | 0.00 | Jun 25, 2026 | Subscriber Cross Site Scripting (XSS) in WP Activity Log <= 5.6.3.1 versions. | ||
| CVE-2026-54849 | Cri | 0.00 | 9.3 | 0.00 | Jun 25, 2026 | Unauthenticated SQL Injection in Premmerce Wishlist for WooCommerce <= 1.1.11 versions. | ||
| CVE-2026-54848 | Hig | 0.00 | 8.3 | 0.00 | Jun 25, 2026 | Insertion of Sensitive Information Into Sent Data vulnerability in Saad Iqbal APIExperts Square for WooCommerce allows Retrieve Embedded Sensitive Data. This issue affects APIExperts Square for WooCommerce: from n/a through 4.7.3. | ||
| CVE-2026-54845 | Hig | 0.00 | 8.1 | 0.00 | Jun 25, 2026 | Unauthenticated Local File Inclusion in MDTF <= 1.3.8 versions. |
- risk 0.00cvss 7.5epss 0.00
Unauthenticated Sensitive Data Exposure in Trinity Backup – Backup, Migrate, Restore, Clone & Schedule Backups <= 2.0.9 versions.
- risk 0.00cvss 7.5epss 0.00
Unauthenticated Broken Access Control in Intranet & Private Site – All-In-One Intranet <= 1.8.1 versions.
- risk 0.00cvss 7.5epss 0.00
Unauthenticated Broken Access Control in Five Star Restaurant Menu <= 2.5.2 versions.
- risk 0.00cvss 7.5epss 0.00
Unauthenticated Sensitive Data Exposure in Object Cache 4 everyone <= 2.3.2 versions.
- risk 0.00cvss 7.4epss 0.00
Unauthenticated Backdoor in Enable CORS <= 2.0.3 versions.
- risk 0.00cvss 7.5epss 0.00
Unauthenticated Broken Access Control in Gutenverse Companion <= 2.5.0 versions.
- risk 0.00cvss 9.3epss 0.00
Unauthenticated SQL Injection in GeoDirectory <= 2.8.162 versions.
- risk 0.00cvss 9.3epss 0.00
Unauthenticated SQL Injection in Real Estate 7 <= 3.5.9 versions.
- risk 0.00cvss 7.6epss 0.00
Subscriber Insecure Direct Object References (IDOR) in SupportCandy <= 3.4.6 versions.
- risk 0.00cvss 9.3epss 0.00
Unauthenticated SQL Injection in wpDataTables <= 7.4 versions.
- risk 0.00cvss 7.5epss 0.00
Unauthenticated Sensitive Data Exposure in Ads by WPQuads <= 3.0.3 versions.
- risk 0.00cvss 9.3epss 0.00
Unauthenticated SQL Injection in JetBooking <= 4.0.4.1 versions.
- risk 0.00cvss 6.5epss 0.00
Unauthenticated Broken Access Control in User Registration <= 5.2.2 versions.
- risk 0.00cvss 5.3epss 0.00
Unauthenticated Broken Access Control in SiteGround Email Marketing <= 1.7.5 versions.
- risk 0.00cvss 6.5epss 0.00
Contributor Cross Site Scripting (XSS) in BNE Testimonials <= 2.0.8 versions.
- risk 0.00cvss 6.5epss 0.00
Contributor Cross Site Scripting (XSS) in Image Carousel <= 1.0.0.41 versions.
- risk 0.00cvss 7.5epss 0.00
Contributor Local File Inclusion in Goya Core < 1.0.9.4 versions.
- risk 0.00cvss 7.5epss 0.00
Contributor Local File Inclusion in Splash - Sport Club WordPress Theme for Basketball, Football, Hockey <= 4.4.3 versions.
- risk 0.00cvss 8.8epss 0.00
Unauthenticated Cross Site Request Forgery (CSRF) in Eagle Booking <= 1.3.4.3 versions.
- risk 0.00cvss 5.3epss 0.00
Unauthenticated Insecure Direct Object References (IDOR) in BookPro <= 1.1.0 versions.
- risk 0.00cvss 5.3epss 0.00
Unauthenticated Content Injection in Auros Core <= 5.3.1 versions.
- risk 0.00cvss 5.3epss 0.00
Unauthenticated Broken Access Control in Donation Thermometer <= 2.2.7 versions.
- risk 0.00cvss 4.3epss 0.00
Contributor Broken Access Control in Live Copy Paste for Elementor <= 1.5.3 versions.
- risk 0.00cvss 4.3epss 0.00
Subscriber Broken Access Control in Restaurant Menu by MotoPress <= 2.4.11 versions.
- risk 0.00cvss 5.4epss 0.00
Contributor Broken Access Control in Forget About Shortcode Buttons <= 2.1.3 versions.
- risk 0.00cvss 6.5epss 0.00
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Tim Strifler Exclusive Addons Elementor allows Stored XSS. This issue affects Exclusive Addons Elementor: from n/a through 2.7.9.8.
- risk 0.00cvss 6.5epss 0.00
The User Registration & Membership – Free & Paid Memberships, Subscriptions, Content Restriction, User Profile, Custom User Registration & Login Builder plugin for WordPress is vulnerable to unauthorized modification of data due to missing validation checks in the…
- risk 0.00cvss 6.5epss 0.00
The Frontend File Manager Plugin WordPress plugin through 23.6 does not properly verify ownership of every targeted post before permanent deletion, allowing authenticated users with author-level access and above to permanently delete arbitrary posts and pages. When the Frontend…
- risk 0.00cvss 7.7epss 0.00
The SALESmanago & Leadoo WordPress plugin before 3.11.3 does not properly sanitise and escape a parameter passed to one of its AJAX actions before using it in a SQL statement, and fails to enforce authorisation on that action, allowing authenticated users with minimal…
- risk 0.00cvss 7.5epss 0.02
The YMC Filter WordPress plugin before 3.11.3 does not properly authorize access to one of its REST API endpoints and does not validate a user-supplied query parameter, allowing unauthenticated attackers to retrieve the titles and content of private, draft, and other non-public…
- risk 0.00cvss 5.3epss 0.00
The Printcart Web to Print Product Designer for WooCommerce WordPress plugin through 2.4.8 is vulnerable to path traversal which makes it possible for the attacker to retrieve the directory listing for arbitrary directories on the server.
- risk 0.00cvss 6.5epss 0.00
The Groundhogg — CRM, Newsletters, and Marketing Automation plugin for WordPress is vulnerable to generic SQL Injection via the 'after' parameter in all versions up to, and including, 4.5.4 due to insufficient escaping on the user supplied parameter and lack of sufficient…
- risk 0.00cvss 10.0epss 0.01
Unrestricted Upload of File with Dangerous Type vulnerability in Daan.Dev OMGF Pro allows Using Malicious Files. This issue affects OMGF Pro: from n/a through 5.2.6.
- risk 0.00cvss 6.5epss 0.00
Contributor Sensitive Data Exposure in Elementor Website Builder <= 4.1.3 versions.
- risk 0.00cvss 6.5epss 0.00
Contributor Broken Access Control in Slim SEO <= 4.6.2 versions.
- risk 0.00cvss 7.1epss 0.00
Unauthenticated Cross Site Scripting (XSS) in Forminator <= 1.53.1 versions.
- risk 0.00cvss 7.7epss 0.00
Subscriber Arbitrary File Deletion in JS Help Desk <= 3.1.1 versions.
- risk 0.00cvss 8.8epss 0.01
Subscriber PHP Object Injection in EventPrime <= 4.3.4.1 versions.
- risk 0.00cvss 7.1epss 0.00
Unauthenticated Cross Site Scripting (XSS) in TablePress <= 3.3.1 versions.
- risk 0.00cvss 6.5epss 0.00
Improper Access Control vulnerability in Themeisle PPOM for WooCommerce allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects PPOM for WooCommerce: from n/a through 33.0.18.
- risk 0.00cvss 8.5epss 0.01
Contributor Remote Code Execution (RCE) in Post Snippets <= 4.0.19 versions.
- risk 0.00cvss 7.1epss 0.00
Customer Cross Site Scripting (XSS) in Advanced Order Export For WooCommerce <= 4.0.9 versions.
- risk 0.00cvss 5.4epss 0.00
Customer Broken Access Control in UPI QR Code Payment Gateway for WooCommerce <= 1.6.2 versions.
- risk 0.00cvss 7.1epss 0.00
Unauthenticated Cross Site Scripting (XSS) in Master Slider <= 3.11.2 versions.
- risk 0.00cvss 6.5epss 0.00
Unauthenticated Insecure Direct Object References (IDOR) in License Manager for WooCommerce <= 3.0.15 versions.
- risk 0.00cvss 7.1epss 0.00
Unauthenticated Cross Site Scripting (XSS) in H5P <= 1.17.6 versions.
- risk 0.00cvss 7.1epss 0.00
Subscriber Cross Site Scripting (XSS) in WP Activity Log <= 5.6.3.1 versions.
- risk 0.00cvss 9.3epss 0.00
Unauthenticated SQL Injection in Premmerce Wishlist for WooCommerce <= 1.1.11 versions.
- risk 0.00cvss 8.3epss 0.00
Insertion of Sensitive Information Into Sent Data vulnerability in Saad Iqbal APIExperts Square for WooCommerce allows Retrieve Embedded Sensitive Data. This issue affects APIExperts Square for WooCommerce: from n/a through 4.7.3.
- risk 0.00cvss 8.1epss 0.00
Unauthenticated Local File Inclusion in MDTF <= 1.3.8 versions.
Page 722 of 738