Vendor CVEs
WordPress
All CVEs
36,828 total · sorted by risk| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2026-40738 | Hig | 0.00 | 8.1 | 0.00 | Jun 17, 2026 | Unauthenticated PHP Object Injection in Eldon <= 1.4.1 versions. | ||
| CVE-2026-40733 | Hig | 0.00 | 8.1 | 0.00 | Jun 17, 2026 | Unauthenticated PHP Object Injection in ShiftUp <= 1.3 versions. | ||
| CVE-2026-40720 | Hig | 0.00 | 7.1 | 0.00 | Jun 17, 2026 | Unauthenticated Cross Site Scripting (XSS) in Royal Elementor Addons Pro < 1.7.1041 versions. | ||
| CVE-2026-39590 | Hig | 0.00 | 8.1 | 0.00 | Jun 17, 2026 | Unauthenticated Local File Inclusion in Atomlab <= 2.4.5 versions. | ||
| CVE-2026-39576 | Hig | 0.00 | 8.1 | 0.00 | Jun 17, 2026 | Unauthenticated PHP Object Injection in SingleMalt <= 1.5 versions. | ||
| CVE-2026-39560 | Hig | 0.00 | 8.1 | 0.00 | Jun 17, 2026 | Unauthenticated PHP Object Injection in Hiroshi <= 1.5.1 versions. | ||
| CVE-2026-39559 | Hig | 0.00 | 8.1 | 0.00 | Jun 17, 2026 | Unauthenticated Local File Inclusion in Uppercase < 1.2.2 versions. | ||
| CVE-2026-39556 | Hig | 0.00 | 8.1 | 0.00 | Jun 17, 2026 | Unauthenticated PHP Object Injection in Konsept <= 1.9 versions. | ||
| CVE-2026-39523 | Hig | 0.00 | 8.1 | 0.00 | Jun 17, 2026 | Unauthenticated Local File Inclusion in Solene Core <= 2.3.2 versions. | ||
| CVE-2026-39445 | Hig | 0.00 | 8.1 | 0.00 | Jun 17, 2026 | Unauthenticated PHP Object Injection in Alukas < 3.0.0 versions. | ||
| CVE-2026-39442 | Hig | 0.00 | 8.1 | 0.00 | Jun 17, 2026 | Unauthenticated PHP Object Injection in PressMart <= 1.2.26 versions. | ||
| CVE-2025-69189 | Hig | 0.00 | 7.3 | 0.00 | Jun 17, 2026 | Missing Authorization vulnerability in EMV JobBank allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects JobBank: from n/a through 1.2.3. | ||
| CVE-2025-69175 | Hig | 0.00 | 8.1 | 0.00 | Jun 17, 2026 | Unauthenticated Local File Inclusion in Line Agency <= 1.3.1 versions. | ||
| CVE-2025-69174 | Hig | 0.00 | 8.1 | 0.00 | Jun 17, 2026 | Unauthenticated Local File Inclusion in Etude <= 1.6 versions. | ||
| CVE-2025-69170 | Hig | 0.00 | 8.1 | 0.00 | Jun 17, 2026 | Unauthenticated Local File Inclusion in Eventicity <= 1.5 versions. | ||
| CVE-2025-69166 | Hig | 0.00 | 8.1 | 0.00 | Jun 17, 2026 | Unauthenticated Local File Inclusion in Gunslinger <= 1.7 versions. | ||
| CVE-2025-69164 | Hig | 0.00 | 8.1 | 0.00 | Jun 17, 2026 | Unauthenticated Local File Inclusion in Skyward <= 1.10 versions. | ||
| CVE-2025-69158 | Hig | 0.00 | 8.1 | 0.00 | Jun 17, 2026 | Unauthenticated Local File Inclusion in Granola <= 1.13 versions. | ||
| CVE-2025-69157 | Hig | 0.00 | 8.1 | 0.00 | Jun 17, 2026 | Unauthenticated Local File Inclusion in Gamic <= 1.15 versions. | ||
| CVE-2025-69144 | Hig | 0.00 | 8.1 | 0.00 | Jun 17, 2026 | Unauthenticated Local File Inclusion in Preservation <= 1.10 versions. | ||
| CVE-2025-69140 | Hig | 0.00 | 7.1 | 0.00 | Jun 17, 2026 | Unauthenticated Cross Site Scripting (XSS) in SweetDate Core < 1.1.5 versions. | ||
| CVE-2025-69130 | Hig | 0.00 | 8.8 | 0.00 | Jun 17, 2026 | Subscriber PHP Object Injection in Entrepreneur - Booking for Small Businesses WordPress Theme <= 3.1.3 versions. | ||
| CVE-2025-69128 | Hig | 0.00 | 8.6 | 0.00 | Jun 17, 2026 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in EMV JobCareer allows Path Traversal. This issue affects JobCareer: from n/a through 7.3. | ||
| CVE-2025-69127 | Cri | 0.00 | 9.8 | 0.00 | Jun 17, 2026 | Unauthenticated PHP Object Injection in Plumbing <= 1.6 versions. | ||
| CVE-2025-69126 | Hig | 0.00 | 8.1 | 0.00 | Jun 17, 2026 | Unauthenticated Local File Inclusion in Fortius <= 2.3.0 versions. | ||
| CVE-2025-69123 | Hig | 0.00 | 8.1 | 0.00 | Jun 17, 2026 | Unauthenticated Local File Inclusion in Snow Club <= 1.1 versions. | ||
| CVE-2025-69120 | Hig | 0.00 | 8.1 | 0.00 | Jun 17, 2026 | Unauthenticated Local File Inclusion in Dazzle <= 1.0.0 versions. | ||
| CVE-2025-69115 | Hig | 0.00 | 8.1 | 0.00 | Jun 17, 2026 | Unauthenticated Local File Inclusion in LuxMed | Medicine & Healthcare Doctor WordPress Theme <= 1.2.2 versions. | ||
| CVE-2025-69111 | Cri | 0.00 | 9.8 | 0.00 | Jun 17, 2026 | Unauthenticated PHP Object Injection in Reisen <= 1.4.1 versions. | ||
| CVE-2025-69106 | Hig | 0.00 | 8.1 | 0.00 | Jun 17, 2026 | Unauthenticated Local File Inclusion in Imba <= 1.5.0 versions. | ||
| CVE-2025-68524 | Hig | 0.00 | 7.1 | 0.00 | Jun 17, 2026 | Unauthenticated Cross Site Scripting (XSS) in Avante < 3.0.5 versions. | ||
| CVE-2025-60236 | Cri | 0.00 | 9.8 | 0.00 | Jun 17, 2026 | Deserialization of Untrusted Data vulnerability in EMV Creatify allows Object Injection. This issue affects Creatify: from n/a through 1.5. | ||
| CVE-2025-60231 | Cri | 0.00 | 9.8 | 0.00 | Jun 17, 2026 | Deserialization of Untrusted Data vulnerability in EMV The Hospital nrghospital allows Object Injection. This issue affects The Hospital: from n/a through 1.8.1. | ||
| CVE-2025-60230 | Cri | 0.00 | 9.8 | 0.00 | Jun 17, 2026 | Deserialization of Untrusted Data vulnerability in Themeton The Barber Shop allows Object Injection. This issue affects The Barber Shop: from n/a through 1.9. | ||
| CVE-2025-60229 | Cri | 0.00 | 9.8 | 0.00 | Jun 17, 2026 | Deserialization of Untrusted Data vulnerability in Themeton Lagom allows Object Injection. This issue affects Lagom: from n/a through 2.0. | ||
| CVE-2025-59554 | Cri | 0.00 | 9.3 | 0.00 | Jun 17, 2026 | Unauthenticated SQL Injection in Advanced Ads – Tracking < 3.0.7 versions. | ||
| CVE-2025-15657 | Med | 0.00 | 5.3 | 0.00 | Jun 17, 2026 | Unauthenticated Insecure Direct Object References (IDOR) in School Management <= 93.1.0 versions. | ||
| CVE-2025-15546 | 0.00 | — | 0.00 | Jun 14, 2026 | The Iptanus File Upload WordPress plugin before 5.1.7 does not implement proper file handling when the duplicatepolicy setting is configured to "maintain both." Due to a Time-of-Check to Time-of-Use (TOCTOU) race condition between the file existence check and the actual file… | |||
| CVE-2025-7504 | Hig | 0.00 | 7.5 | 0.01 | Jul 12, 2025 | The Friends plugin for WordPress is vulnerable to PHP Object Injection in version 3.5.1 via deserialization of untrusted input of the query_vars parameter This makes it possible for authenticated attackers, with subscriber-level access and above, to inject a PHP Object. No known… | ||
| CVE-2024-10222 | Med | 0.00 | 6.4 | 0.00 | Feb 21, 2025 | The SVG Support plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 2.5.10 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Author-level… | ||
| CVE-2024-23825 | Low | 0.00 | 3.0 | 0.01 | Jan 30, 2024 | TablePress is a table plugin for Wordpress. For importing tables, TablePress makes external HTTP requests based on a URL that is provided by the user. That user input is filtered insufficiently, which makes it is possible to send requests to unintended network locations and… | ||
| CVE-2022-0402 | Med | 0.00 | 6.1 | 0.00 | Jan 16, 2024 | The Super Forms - Drag & Drop Form Builder WordPress plugin before 6.0.4 does not escape the bob_czy_panstwa_sprawa_zostala_rozwiazana parameter before outputting it back in an attribute via the super_language_switcher AJAX action, leading to a Reflected Cross-Site Scripting.… | ||
| CVE-2023-51700 | Med | 0.00 | 6.4 | 0.01 | Dec 27, 2023 | Unofficial Mobile BankID Integration for WordPress lets users employ Mobile BankID to authenticate themselves on your WordPress site. Prior to 1.0.1, WP-Mobile-BankID-Integration is affected by a vulnerability classified as a Deserialization of Untrusted Data vulnerability,… | ||
| CVE-2023-48300 | Med | 0.00 | 6.3 | 0.01 | Nov 20, 2023 | The `Embed Privacy` plugin for WordPress that prevents the loading of embedded external content is vulnerable to Stored Cross-Site Scripting via `embed_privacy_opt_out` shortcode in versions up to, and including, 1.8.0 due to insufficient input sanitization and output escaping… | ||
| CVE-2023-1979 | Med | 0.00 | 4.9 | 0.00 | May 8, 2023 | The Web Stories for WordPress plugin supports the WordPress built-in functionality of protecting content with a password. The content is then only accessible to website visitors after entering the password. In WordPress, users with the "Author" role can create stories, but don't… | ||
| CVE-2017-20183 | Low | 0.00 | 3.5 | 0.01 | May 5, 2023 | A vulnerability was found in External Media without Import Plugin up to 1.0.0 on WordPress. It has been declared as problematic. This vulnerability affects the function print_media_new_panel of the file external-media-without-import.php. The manipulation of the argument… | ||
| CVE-2023-30616 | Med | 0.00 | 6.5 | 0.00 | Apr 20, 2023 | Form block is a wordpress plugin designed to make form creation easier. Versions prior to 1.0.2 are subject to a Cross-Site Request Forgery due to a missing nonce check. There is potential for a Cross Site Request Forgery for all form blocks, since it allows to send requests to… | ||
| CVE-2017-20177 | Low | 0.00 | 3.5 | 0.01 | Feb 6, 2023 | A vulnerability, which was classified as problematic, has been found in WangGuard Plugin 1.8.0 on WordPress. Affected by this issue is the function wangguard_users_info of the file wangguard-user-info.php of the component WGG User List Handler. The manipulation of the argument… | ||
| CVE-2022-4631 | Low | 0.00 | 3.5 | 0.00 | Dec 21, 2022 | A vulnerability, which was classified as problematic, was found in WP-Ban. Affected is an unknown function of the file ban-options.php. The manipulation leads to cross site scripting. It is possible to launch the attack remotely. The name of the patch is… | ||
| CVE-2021-4252 | Low | 0.00 | 3.5 | 0.00 | Dec 18, 2022 | A vulnerability, which was classified as problematic, has been found in WP-Ban. This issue affects the function toggle_checkbox of the file ban-options.php. The manipulation of the argument $_SERVER["HTTP_USER_AGENT"] leads to cross site scripting. The attack may be initiated… |
- risk 0.00cvss 8.1epss 0.00
Unauthenticated PHP Object Injection in Eldon <= 1.4.1 versions.
- risk 0.00cvss 8.1epss 0.00
Unauthenticated PHP Object Injection in ShiftUp <= 1.3 versions.
- risk 0.00cvss 7.1epss 0.00
Unauthenticated Cross Site Scripting (XSS) in Royal Elementor Addons Pro < 1.7.1041 versions.
- risk 0.00cvss 8.1epss 0.00
Unauthenticated Local File Inclusion in Atomlab <= 2.4.5 versions.
- risk 0.00cvss 8.1epss 0.00
Unauthenticated PHP Object Injection in SingleMalt <= 1.5 versions.
- risk 0.00cvss 8.1epss 0.00
Unauthenticated PHP Object Injection in Hiroshi <= 1.5.1 versions.
- risk 0.00cvss 8.1epss 0.00
Unauthenticated Local File Inclusion in Uppercase < 1.2.2 versions.
- risk 0.00cvss 8.1epss 0.00
Unauthenticated PHP Object Injection in Konsept <= 1.9 versions.
- risk 0.00cvss 8.1epss 0.00
Unauthenticated Local File Inclusion in Solene Core <= 2.3.2 versions.
- risk 0.00cvss 8.1epss 0.00
Unauthenticated PHP Object Injection in Alukas < 3.0.0 versions.
- risk 0.00cvss 8.1epss 0.00
Unauthenticated PHP Object Injection in PressMart <= 1.2.26 versions.
- risk 0.00cvss 7.3epss 0.00
Missing Authorization vulnerability in EMV JobBank allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects JobBank: from n/a through 1.2.3.
- risk 0.00cvss 8.1epss 0.00
Unauthenticated Local File Inclusion in Line Agency <= 1.3.1 versions.
- risk 0.00cvss 8.1epss 0.00
Unauthenticated Local File Inclusion in Etude <= 1.6 versions.
- risk 0.00cvss 8.1epss 0.00
Unauthenticated Local File Inclusion in Eventicity <= 1.5 versions.
- risk 0.00cvss 8.1epss 0.00
Unauthenticated Local File Inclusion in Gunslinger <= 1.7 versions.
- risk 0.00cvss 8.1epss 0.00
Unauthenticated Local File Inclusion in Skyward <= 1.10 versions.
- risk 0.00cvss 8.1epss 0.00
Unauthenticated Local File Inclusion in Granola <= 1.13 versions.
- risk 0.00cvss 8.1epss 0.00
Unauthenticated Local File Inclusion in Gamic <= 1.15 versions.
- risk 0.00cvss 8.1epss 0.00
Unauthenticated Local File Inclusion in Preservation <= 1.10 versions.
- risk 0.00cvss 7.1epss 0.00
Unauthenticated Cross Site Scripting (XSS) in SweetDate Core < 1.1.5 versions.
- risk 0.00cvss 8.8epss 0.00
Subscriber PHP Object Injection in Entrepreneur - Booking for Small Businesses WordPress Theme <= 3.1.3 versions.
- risk 0.00cvss 8.6epss 0.00
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in EMV JobCareer allows Path Traversal. This issue affects JobCareer: from n/a through 7.3.
- risk 0.00cvss 9.8epss 0.00
Unauthenticated PHP Object Injection in Plumbing <= 1.6 versions.
- risk 0.00cvss 8.1epss 0.00
Unauthenticated Local File Inclusion in Fortius <= 2.3.0 versions.
- risk 0.00cvss 8.1epss 0.00
Unauthenticated Local File Inclusion in Snow Club <= 1.1 versions.
- risk 0.00cvss 8.1epss 0.00
Unauthenticated Local File Inclusion in Dazzle <= 1.0.0 versions.
- risk 0.00cvss 8.1epss 0.00
Unauthenticated Local File Inclusion in LuxMed | Medicine & Healthcare Doctor WordPress Theme <= 1.2.2 versions.
- risk 0.00cvss 9.8epss 0.00
Unauthenticated PHP Object Injection in Reisen <= 1.4.1 versions.
- risk 0.00cvss 8.1epss 0.00
Unauthenticated Local File Inclusion in Imba <= 1.5.0 versions.
- risk 0.00cvss 7.1epss 0.00
Unauthenticated Cross Site Scripting (XSS) in Avante < 3.0.5 versions.
- risk 0.00cvss 9.8epss 0.00
Deserialization of Untrusted Data vulnerability in EMV Creatify allows Object Injection. This issue affects Creatify: from n/a through 1.5.
- risk 0.00cvss 9.8epss 0.00
Deserialization of Untrusted Data vulnerability in EMV The Hospital nrghospital allows Object Injection. This issue affects The Hospital: from n/a through 1.8.1.
- risk 0.00cvss 9.8epss 0.00
Deserialization of Untrusted Data vulnerability in Themeton The Barber Shop allows Object Injection. This issue affects The Barber Shop: from n/a through 1.9.
- risk 0.00cvss 9.8epss 0.00
Deserialization of Untrusted Data vulnerability in Themeton Lagom allows Object Injection. This issue affects Lagom: from n/a through 2.0.
- risk 0.00cvss 9.3epss 0.00
Unauthenticated SQL Injection in Advanced Ads – Tracking < 3.0.7 versions.
- risk 0.00cvss 5.3epss 0.00
Unauthenticated Insecure Direct Object References (IDOR) in School Management <= 93.1.0 versions.
- CVE-2025-15546Jun 14, 2026risk 0.00cvss —epss 0.00
The Iptanus File Upload WordPress plugin before 5.1.7 does not implement proper file handling when the duplicatepolicy setting is configured to "maintain both." Due to a Time-of-Check to Time-of-Use (TOCTOU) race condition between the file existence check and the actual file…
- risk 0.00cvss 7.5epss 0.01
The Friends plugin for WordPress is vulnerable to PHP Object Injection in version 3.5.1 via deserialization of untrusted input of the query_vars parameter This makes it possible for authenticated attackers, with subscriber-level access and above, to inject a PHP Object. No known…
- risk 0.00cvss 6.4epss 0.00
The SVG Support plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 2.5.10 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Author-level…
- risk 0.00cvss 3.0epss 0.01
TablePress is a table plugin for Wordpress. For importing tables, TablePress makes external HTTP requests based on a URL that is provided by the user. That user input is filtered insufficiently, which makes it is possible to send requests to unintended network locations and…
- risk 0.00cvss 6.1epss 0.00
The Super Forms - Drag & Drop Form Builder WordPress plugin before 6.0.4 does not escape the bob_czy_panstwa_sprawa_zostala_rozwiazana parameter before outputting it back in an attribute via the super_language_switcher AJAX action, leading to a Reflected Cross-Site Scripting.…
- risk 0.00cvss 6.4epss 0.01
Unofficial Mobile BankID Integration for WordPress lets users employ Mobile BankID to authenticate themselves on your WordPress site. Prior to 1.0.1, WP-Mobile-BankID-Integration is affected by a vulnerability classified as a Deserialization of Untrusted Data vulnerability,…
- risk 0.00cvss 6.3epss 0.01
The `Embed Privacy` plugin for WordPress that prevents the loading of embedded external content is vulnerable to Stored Cross-Site Scripting via `embed_privacy_opt_out` shortcode in versions up to, and including, 1.8.0 due to insufficient input sanitization and output escaping…
- risk 0.00cvss 4.9epss 0.00
The Web Stories for WordPress plugin supports the WordPress built-in functionality of protecting content with a password. The content is then only accessible to website visitors after entering the password. In WordPress, users with the "Author" role can create stories, but don't…
- risk 0.00cvss 3.5epss 0.01
A vulnerability was found in External Media without Import Plugin up to 1.0.0 on WordPress. It has been declared as problematic. This vulnerability affects the function print_media_new_panel of the file external-media-without-import.php. The manipulation of the argument…
- risk 0.00cvss 6.5epss 0.00
Form block is a wordpress plugin designed to make form creation easier. Versions prior to 1.0.2 are subject to a Cross-Site Request Forgery due to a missing nonce check. There is potential for a Cross Site Request Forgery for all form blocks, since it allows to send requests to…
- risk 0.00cvss 3.5epss 0.01
A vulnerability, which was classified as problematic, has been found in WangGuard Plugin 1.8.0 on WordPress. Affected by this issue is the function wangguard_users_info of the file wangguard-user-info.php of the component WGG User List Handler. The manipulation of the argument…
- risk 0.00cvss 3.5epss 0.00
A vulnerability, which was classified as problematic, was found in WP-Ban. Affected is an unknown function of the file ban-options.php. The manipulation leads to cross site scripting. It is possible to launch the attack remotely. The name of the patch is…
- risk 0.00cvss 3.5epss 0.00
A vulnerability, which was classified as problematic, has been found in WP-Ban. This issue affects the function toggle_checkbox of the file ban-options.php. The manipulation of the argument $_SERVER["HTTP_USER_AGENT"] leads to cross site scripting. The attack may be initiated…
Page 723 of 737