<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
<channel>
  <title>CVE Daily – WordPress (High+Critical)</title>
  <link>https://cvedaily.com/pages/tags/wordpress.html</link>
  <atom:link href="https://cvedaily.com/feed-tags/wordpress-severe.xml" rel="self" type="application/rss+xml"/>
  <description>CVE Daily – WordPress (High+Critical)</description>
  <language>en</language>
  <lastBuildDate>Wed, 03 Jun 2026 21:26:32 +0000</lastBuildDate>
  <item>
    <title>[Critical] CVE-2026-5076 – The ARMember Premium plugin for WordPress is vulnerable to an insecure password ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-5076</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-5076</guid>
    <pubDate>Tue, 02 Jun 2026 20:16:40 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-5076</strong></p>
  <p>The ARMember Premium plugin for WordPress is vulnerable to an insecure password reset mechanism in all versions up to, and including, 7.3.1. The plugin stores a plaintext copy of the password reset key in the `arm_reset_password_key` user meta field when a user requests a password reset. This is in addition to the hashed key that WordPress core stores securely in `wp_users.user_activation_key`. T…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-287</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-5076">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-5073 – The ARMember Premium plugin for WordPress is vulnerable to SQL Injection via the...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-5073</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-5073</guid>
    <pubDate>Tue, 02 Jun 2026 20:16:40 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-5073</strong></p>
  <p>The ARMember Premium plugin for WordPress is vulnerable to SQL Injection via the 'order' parameter of the 'arm_directory_paging_action' AJAX action in all versions up to, and including, 7.3.1. This is due to insufficient escaping on the user-supplied 'order' and 'orderby' parameters and the lack of sufficient preparation on the existing SQL query in the `arm_get_directory_members()` function. Thi…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-5073">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-1829 – The Content Visibility for Divi Builder plugin for WordPress is vulnerable to Re...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-1829</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-1829</guid>
    <pubDate>Tue, 02 Jun 2026 20:16:33 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-1829</strong></p>
  <p>The Content Visibility for Divi Builder plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 4.02 via the 'et_pb_text' shortcode 'cvdb_content_visibility_check' parameter. This makes it possible for authenticated attackers, with Contributor-level access and above, to execute code on the server.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-94</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-1829">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-8293 – The Really Simple Security  WordPress plugin before 9.5.10.1 does not enforce th...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-8293</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-8293</guid>
    <pubDate>Tue, 02 Jun 2026 07:16:13 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-8293</strong></p>
  <p>The Really Simple Security  WordPress plugin before 9.5.10.1 does not enforce the second-factor challenge in two of its two-factor authentication REST endpoints, allowing an attacker who knows a user's password to obtain a WordPress authentication session for that user without completing the email OTP challenge.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-287</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-8293">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-8206 – The Kirki – Freeform Page Builder, Website Builder &amp; Customizer plugin for WordP...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-8206</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-8206</guid>
    <pubDate>Tue, 02 Jun 2026 04:17:03 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-8206</strong></p>
  <p>The Kirki – Freeform Page Builder, Website Builder & Customizer plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions 6.0.0 to 6.0.6. This is due to the plugin accepting an arbitrary email address when a username is used in the password reset request. This makes it possible for unauthenticated attackers to send a password reset link for any user registere…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-269</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-8206">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2018-25434 – WP AutoSuggest 0.24 contains an SQL injection vulnerability that allows unauthen...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2018-25434</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2018-25434</guid>
    <pubDate>Mon, 01 Jun 2026 22:16:16 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2018-25434</strong></p>
  <p>WP AutoSuggest 0.24 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the wpas_keys parameter. Attackers can send GET requests to autosuggest.php with crafted wpas_keys values to extract sensitive database information from WordPress posts and other tables.</p>
  <p><strong>CVSS:</strong> 8.2 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-25434">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-9757 – The GEO my WP plugin for WordPress is vulnerable to SQL Injection via the 'swlat...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-9757</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-9757</guid>
    <pubDate>Sat, 30 May 2026 10:16:23 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-9757</strong></p>
  <p>The GEO my WP plugin for WordPress is vulnerable to SQL Injection via the 'swlatlng' and 'nelatlng' parameters in all versions up to, and including, 4.5.5 The parameters are read from $_SERVER['QUERY_STRING'] via parse_str() (bypassing WordPress's wp_magic_quotes protection, which only covers $_POST/$_GET/$_COOKIE/$_REQUEST), then each is split on ',' via explode() and the resulting fragments are…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-9757">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-7465 – The Spectra Gutenberg Blocks – Website Builder for the Block Editor plugin for W...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-7465</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-7465</guid>
    <pubDate>Sat, 30 May 2026 10:16:23 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-7465</strong></p>
  <p>The Spectra Gutenberg Blocks – Website Builder for the Block Editor plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 2.19.25. This makes it possible for authenticated attackers, with Contributor-level access and above, to execute code on the server. Exploitation requires a two-block payload embedded in post content: the first block registers a fake…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-269</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-7465">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-7459 – The Simple History – Track, Log, and Audit WordPress Changes plugin for WordPres...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-7459</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-7459</guid>
    <pubDate>Sat, 30 May 2026 10:16:22 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-7459</strong></p>
  <p>The Simple History – Track, Log, and Audit WordPress Changes plugin for WordPress is vulnerable to authenticated (Subscriber+) account takeover in all versions up to, and including, 5.26.0 via the event reaction endpoints (react_to_event() / unreact_to_event()). The endpoints register get_items_permissions_check() as their permission_callback, which only verifies the requester is logged in and do…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-640</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-7459">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-4290 – The WP Travel Pro plugin for WordPress is vulnerable to arbitrary user deletion ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-4290</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-4290</guid>
    <pubDate>Fri, 29 May 2026 15:16:24 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-4290</strong></p>
  <p>The WP Travel Pro plugin for WordPress is vulnerable to arbitrary user deletion via the /wp-json/wp-travel/v1/travel-guide/{user_id} REST API endpoint in all versions up to, and including, 10.6.0. This is due to the check_permission() callback unconditionally returning true and the Database::delete() method passing the user ID directly to wp_delete_user() without any role validation. This makes i…</p>
  <p><strong>CVSS:</strong> 9.1 · <strong>CWE:</strong> CWE-862</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-4290">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-6075 – The Media Library Assistant plugin for WordPress is vulnerable to Cross-Site Req...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-6075</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-6075</guid>
    <pubDate>Fri, 29 May 2026 09:16:18 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-6075</strong></p>
  <p>The Media Library Assistant plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 3.35 This is due to missing nonce verification on the bulk action handlers in the settings tab handlers. This makes it possible for unauthenticated attackers to trick an administrator into performing bulk delete, edit, or purge operations on plugin settings and attachment…</p>
  <p><strong>CVSS:</strong> 8.1 · <strong>CWE:</strong> CWE-352</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-6075">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-3655 – The OTP Login With Phone Number, OTP Verification plugin for WordPress is vulner...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-3655</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-3655</guid>
    <pubDate>Fri, 29 May 2026 08:16:18 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-3655</strong></p>
  <p>The OTP Login With Phone Number, OTP Verification plugin for WordPress is vulnerable to authentication bypass in versions 1.8.50 through 1.8.60. This is due to the Firebase verification flow in the `lwp_ajax_register` AJAX handler not binding the Firebase session to the phone number supplied in the request. The `idehweb_lwp_activate_through_firebase()` function validates that a Firebase OTP sessi…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-287</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-3655">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-11262 – The Link Whisper Free plugin for WordPress is vulnerable to Stored Cross-Site Sc...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-11262</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-11262</guid>
    <pubDate>Fri, 29 May 2026 08:16:17 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-11262</strong></p>
  <p>The Link Whisper Free plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the user_id parameter in all versions up to, and including, 0.9.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-11262">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-8732 – The WP Maps Pro plugin for WordPress is vulnerable to Privilege Escalation via A...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-8732</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-8732</guid>
    <pubDate>Fri, 29 May 2026 07:16:14 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-8732</strong></p>
  <p>The WP Maps Pro plugin for WordPress is vulnerable to Privilege Escalation via Administrator Account Creation in all versions up to, and including, 6.1.0. This is due to the wpgmp_temp_access_ajax AJAX action being registered with wp_ajax_nopriv_ and protected only by a nonce check using the fc-call-nonce nonce, which is publicly embedded into every frontend page via wp_localize_script as the non…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-306</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-8732">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-11993 – The WooCommerce Infinite Scroll and Ajax Pagination plugin for WordPress is vuln...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-11993</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-11993</guid>
    <pubDate>Fri, 29 May 2026 07:16:13 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-11993</strong></p>
  <p>The WooCommerce Infinite Scroll and Ajax Pagination plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.8 via the 'settings' parameter in the 'import_settings' function. This is due to deserialization of untrusted data supplied via the import configuration feature without capability checks. This makes it possible for authenticated attackers, with Sub…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-502</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-11993">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-8809 – The Advanced Custom Fields: Extended plugin for WordPress is vulnerable to Privi...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-8809</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-8809</guid>
    <pubDate>Thu, 28 May 2026 23:16:44 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-8809</strong></p>
  <p>The Advanced Custom Fields: Extended plugin for WordPress is vulnerable to Privilege Escalation via Validation Bypass in all versions up to and including 0.9.2.5. The vulnerability exists due to the after_validate_save_post() function unconditionally trusting the attacker-controlled _acf_post_id POST parameter — with no authentication or integrity verification — to select a cleanup branch that si…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-269</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-8809">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-6226 – The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to unauthent...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-6226</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-6226</guid>
    <pubDate>Thu, 28 May 2026 09:16:47 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-6226</strong></p>
  <p>The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to unauthenticated privilege escalation in versions up to and including 3.29.2. This is due to insecure form submission handling that accepts arbitrary form definitions from user input instead of securely loading them from the backend. When $_POST['_acf_form'] is an array (rather than a form ID), the validate_form() function bypa…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-269</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-6226">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-9227 – The GutenBee – Gutenberg Blocks plugin for WordPress is vulnerable to Arbitrary ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-9227</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-9227</guid>
    <pubDate>Thu, 28 May 2026 08:16:37 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-9227</strong></p>
  <p>The GutenBee – Gutenberg Blocks plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 2.20.1 via the gutenbee_file_and_ext_json function. This is due to a flawed strpos() substring check that only verifies whether the filename contains the string '.json' rather than confirming the filename ends with a .json extension, allowing double-extension filenames…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-434</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-9227">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-7862 – The Eupago Gateway For Woocommerce WordPress plugin before 4.7.2 does not proper...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-7862</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-7862</guid>
    <pubDate>Thu, 28 May 2026 08:16:37 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-7862</strong></p>
  <p>The Eupago Gateway For Woocommerce WordPress plugin before 4.7.2 does not properly restrict access to its refund request handler, allowing unauthenticated attackers to initiate refunds against any WooCommerce order using the merchant's payment gateway credentials, and for applicable payment methods, to redirect refunded funds to an attacker-controlled bank account.</p>
  <p><strong>CVSS:</strong> 8.6 · <strong>CWE:</strong> CWE-284</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-7862">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-7797 – The Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin p...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-7797</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-7797</guid>
    <pubDate>Thu, 28 May 2026 08:16:37 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-7797</strong></p>
  <p>The Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin plugin for WordPress is vulnerable to time-based blind SQL Injection via the 'append_where_sql' parameter in all versions up to, and including, 1.6.11.8 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated at…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-7797">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-7634 – The SlimStat Analytics plugin for WordPress is vulnerable to Stored Cross-Site S...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-7634</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-7634</guid>
    <pubDate>Thu, 28 May 2026 08:16:36 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-7634</strong></p>
  <p>The SlimStat Analytics plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'User-Agent' header in all versions up to, and including, 5.4.11 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. The show_complete_user…</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-7634">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-7052 – The HT Contact Form – Drag &amp; Drop Form Builder for WordPress plugin for WordPres...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-7052</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-7052</guid>
    <pubDate>Thu, 28 May 2026 08:16:36 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-7052</strong></p>
  <p>The HT Contact Form – Drag & Drop Form Builder for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'file_upload' parameter in all versions up to, and including, 2.8.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses…</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-7052">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-6455 – The WP Contact Form 7 DB Handler plugin for WordPress is vulnerable to Cross-Sit...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-6455</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-6455</guid>
    <pubDate>Thu, 28 May 2026 08:16:36 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-6455</strong></p>
  <p>The WP Contact Form 7 DB Handler plugin for WordPress is vulnerable to Cross-Site Request Forgery leading to Arbitrary File Deletion via SQL Injection and PHP Object Injection in versions up to and including 3.0. This is due to a missing nonce verification in the process_bulk_action() function, the nonce check is only executed when _wpnonce is present in the POST body, allowing it to be trivially…</p>
  <p><strong>CVSS:</strong> 8.1 · <strong>CWE:</strong> CWE-352</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-6455">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-9009 – The Crawlomatic Multipage Scraper Post Generator plugin for WordPress is vulnera...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-9009</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-9009</guid>
    <pubDate>Thu, 28 May 2026 06:16:28 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-9009</strong></p>
  <p>The Crawlomatic Multipage Scraper Post Generator plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 2.7.2 via the filter_content function. This is due to passing the attacker-supplied 'callback_raw' shortcode attribute directly into call_user_func() with no sanitization or allowlist validation, relying solely on an is_callable() check that permits da…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-434</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-9009">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-7802 – The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to authoriza...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-7802</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-7802</guid>
    <pubDate>Thu, 28 May 2026 05:16:38 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-7802</strong></p>
  <p>The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 3.29.2. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers, with subscriber-level access and above, to overwrite an administrator's user_pass, user_email, first_name, last_…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-862</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-7802">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-2374 – The Login No Captcha reCAPTCHA plugin for WordPress is vulnerable to Stored Cros...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-2374</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-2374</guid>
    <pubDate>Thu, 28 May 2026 05:16:34 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-2374</strong></p>
  <p>The Login No Captcha reCAPTCHA plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `$_SERVER['PHP_SELF']` superglobal in all versions up to, and including, 1.8.0. This is due to the `authenticate()` function storing the unsanitized output of `basename($_SERVER['PHP_SELF'])` in the `login_nocaptcha_error` WordPress option when a login attempt is made from a non-standard login…</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-2374">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-8832 – The WPCode - Insert Headers and Footers + Custom Code Snippets - WordPress Code ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-8832</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-8832</guid>
    <pubDate>Wed, 27 May 2026 08:16:45 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-8832</strong></p>
  <p>The WPCode - Insert Headers and Footers + Custom Code Snippets - WordPress Code Manager plugin for WordPress is vulnerable to Remote Code Execution in versions up to, and including, 2.3.5 This is due to the 'wpcode' custom post type being registered without a custom capability_type or capability restrictions in the wpcode_register_post_type() function, allowing WordPress core to fall back to stan…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-94</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-8832">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-8143 – The HBook plugin for WordPress is vulnerable to Stored Cross-Site Scripting via ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-8143</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-8143</guid>
    <pubDate>Wed, 27 May 2026 08:16:45 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-8143</strong></p>
  <p>The HBook plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'hb_country_iso', 'hb_usa_state_iso', and 'hb_canada_province_iso' parameters in all versions up to, and including, 2.1.6 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user acces…</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-8143">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-6169 – The affiliate-toolkit plugin for WordPress is vulnerable to remote code executio...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-6169</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-6169</guid>
    <pubDate>Wed, 27 May 2026 08:16:44 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-6169</strong></p>
  <p>The affiliate-toolkit plugin for WordPress is vulnerable to remote code execution in all versions up to, and including, 3.8.5. This is due to the plugin using the BladeOne templating engine's runString() method which compiles user-supplied template content into PHP code and executes it via eval() without sanitization or sandboxing. This makes it possible for authenticated attackers, with Editor-l…</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> CWE-94</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-6169">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-3375 – The LiteSpeed Cache plugin for WordPress is vulnerable to Stored Cross-Site Scri...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-3375</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-3375</guid>
    <pubDate>Wed, 27 May 2026 08:16:40 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-3375</strong></p>
  <p>The LiteSpeed Cache plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the /wp-json/litespeed/v1/notify_ccss and /wp-json/litespeed/v1/notify_ucss REST API endpoints in all versions up to, and including, 7.7. These endpoints accept CSS content from QUIC.cloud callback notifications and store it to disk without sanitization. The stored content is later rendered inline frontend p…</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-3375">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-9200 – The Query Shortcode plugin for WordPress is vulnerable to Local File Inclusion i...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-9200</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-9200</guid>
    <pubDate>Wed, 27 May 2026 07:16:19 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-9200</strong></p>
  <p>The Query Shortcode plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 0.2.1 via the shortcode function. This makes it possible for authenticated attackers, with contributor-level access and above, to include and execute arbitrary .php files on the server, allowing the execution of any PHP code in those files. This can be used to bypass access control…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-98</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-9200">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-8994 – The Login with NEAR plugin for WordPress is vulnerable to Authentication Bypass ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-8994</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-8994</guid>
    <pubDate>Wed, 27 May 2026 07:16:18 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-8994</strong></p>
  <p>The Login with NEAR plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 0.3.3. The `ajaxLoginWithNear()` function — registered as a `wp_ajax_nopriv` action and therefore reachable by unauthenticated users — accepts an attacker-supplied `account` POST parameter and issues a valid WordPress authentication cookie based solely on a substring check for `.n…</p>
  <p><strong>CVSS:</strong> 8.1 · <strong>CWE:</strong> CWE-287</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-8994">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-8787 – The Firebase Support &amp; Chat Management plugin for WordPress is vulnerable to pri...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-8787</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-8787</guid>
    <pubDate>Wed, 27 May 2026 07:16:15 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-8787</strong></p>
  <p>The Firebase Support & Chat Management plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 3.1.1. This is due to the `firebase_auth()` function authenticating the request as the WordPress user whose email is supplied in the `user_email` POST parameter without verifying ownership of that email (no Firebase ID token signature/issuer/audience verification…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-269</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-8787">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-8760 – The Login with OTP plugin for WordPress is vulnerable to authentication bypass i...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-8760</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-8760</guid>
    <pubDate>Wed, 27 May 2026 07:16:14 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-8760</strong></p>
  <p>The Login with OTP plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 1.6. This is due to an incomplete fix for CVE-2024-11178: the rate-limit/lockout check added to `otpl_login_action()` was placed only inside the OTP-generation branch and is never evaluated on the OTP-validation branch, and the generated 6-digit OTP additionally has no expiration.…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-307</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-8760">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-6268 – The EventPress WordPress theme before 22.2 does not sanitize or escape the 'id' ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-6268</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-6268</guid>
    <pubDate>Wed, 27 May 2026 07:16:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-6268</strong></p>
  <p>The EventPress WordPress theme before 22.2 does not sanitize or escape the 'id' parameter in the eventpress_customizer_notify_dismiss_action AJAX handler before outputting it back in the response, allowing unauthenticated attackers to perform Reflected Cross-Site Scripting attacks against logged-in users.</p>
  <p><strong>CVSS:</strong> 7.1 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-6268">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2018-25352 – WordPress Ultimate Form Builder Lite plugin version 1.3.7 and below contains an ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2018-25352</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2018-25352</guid>
    <pubDate>Sat, 23 May 2026 19:16:55 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2018-25352</strong></p>
  <p>WordPress Ultimate Form Builder Lite plugin version 1.3.7 and below contains an SQL injection vulnerability that allows authenticated attackers to manipulate database queries by injecting SQL code through the entry_id POST parameter. Attackers can send POST requests to the admin-ajax.php endpoint with the ufbl_get_entry_detail_action action to extract, modify, or escalate privileges within the Wo…</p>
  <p><strong>CVSS:</strong> 7.1 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-25352">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2018-25347 – WordPress Contact Form Maker Plugin 1.12.20 contains SQL injection vulnerabiliti...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2018-25347</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2018-25347</guid>
    <pubDate>Sat, 23 May 2026 19:16:54 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2018-25347</strong></p>
  <p>WordPress Contact Form Maker Plugin 1.12.20 contains SQL injection vulnerabilities that allow authenticated attackers to manipulate database queries through the FormMakerSQLMapping and generete_csv_fmc AJAX actions. Attackers can inject malicious SQL code via the 'name' and 'search_labels' parameters to extract sensitive database information or escalate privileges.</p>
  <p><strong>CVSS:</strong> 7.1 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-25347">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2018-25346 – WordPress Form Maker Plugin 1.12.24 and below contains SQL injection vulnerabili...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2018-25346</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2018-25346</guid>
    <pubDate>Sat, 23 May 2026 19:16:54 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2018-25346</strong></p>
  <p>WordPress Form Maker Plugin 1.12.24 and below contains SQL injection vulnerabilities that allow authenticated attackers to manipulate database queries by injecting SQL code through the FormMakerSQLMapping and generete_csv actions. Attackers can submit POST requests with malicious SQL payloads in the name and search_labels parameters to extract, modify, or escalate privileges within the WordPress…</p>
  <p><strong>CVSS:</strong> 7.1 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-25346">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-9284 – The WooCommerce PayPal Payments plugin for WordPress is vulnerable to unauthoriz...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-9284</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-9284</guid>
    <pubDate>Sat, 23 May 2026 05:16:34 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-9284</strong></p>
  <p>The WooCommerce PayPal Payments plugin for WordPress is vulnerable to unauthorized order manipulation and information disclosure due to missing authorization checks on the `ppc-create-order` and `ppc-get-order` WC-AJAX endpoints in all versions up to, and including, 4.0.1. The `ppc-create-order` endpoint accepts an arbitrary WooCommerce order ID in the `pay-now` context without validating order o…</p>
  <p><strong>CVSS:</strong> 8.2 · <strong>CWE:</strong> CWE-862</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-9284">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-6898 – The Wishlist Member plugin for WordPress is vulnerable to unauthorized modificat...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-6898</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-6898</guid>
    <pubDate>Sat, 23 May 2026 05:16:34 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-6898</strong></p>
  <p>The Wishlist Member plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'WishListMember3_Hooks::generate_api_key' function in all versions up to, and including, 3.30.1. This makes it possible for authenticated attackers, with Subscriber-level access and above, to update the REST API Secret Key, which can be used to create a new membersh…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-269</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-6898">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-6897 – The Wishlist Member plugin for WordPress is vulnerable to unauthorized modificat...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-6897</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-6897</guid>
    <pubDate>Sat, 23 May 2026 05:16:34 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-6897</strong></p>
  <p>The Wishlist Member plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'WishListMember\Features\Team_Accounts::save_settings' function in all versions up to, and including, 3.30.1. This makes it possible for authenticated attackers, with Subscriber-level access and above, to update arbitrary plugin options, includes the REST API Secret…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-269</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-6897">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-6895 – The WishList Member plugin for WordPress is vulnerable to Missing Authorization ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-6895</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-6895</guid>
    <pubDate>Sat, 23 May 2026 05:16:34 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-6895</strong></p>
  <p>The WishList Member plugin for WordPress is vulnerable to Missing Authorization leading to Sensitive Information Disclosure and Privilege Escalation in versions up to and including 3.30.1. This is due to the missing capability checks in the 'export_settings' function. This function returns the REST API Secret Key to the attacker in the AJAX JSON response. An attacker who obtains this key can auth…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-269</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-6895">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-6419 – The WishList Member plugin for WordPress is vulnerable to Privilege Escalation v...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-6419</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-6419</guid>
    <pubDate>Sat, 23 May 2026 05:16:34 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-6419</strong></p>
  <p>The WishList Member plugin for WordPress is vulnerable to Privilege Escalation via Missing Authorization in versions up to and including 3.30.1. This is due to the missing capability and nonce check in the ajax_get_screen() function. This makes it possible for authenticated attackers, with Subscriber-level access and above, to supply an arbitrary admin screen identifier via the data[url] paramete…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-269</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-6419">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-9011 – The Ditty – Responsive News Tickers, Sliders, and Lists plugin for WordPress is ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-9011</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-9011</guid>
    <pubDate>Fri, 22 May 2026 09:16:33 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-9011</strong></p>
  <p>The Ditty – Responsive News Tickers, Sliders, and Lists plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 3.1.65. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for unauthenticated attackers to retrieve the full item content of non-public Dittys — including drafts, pending, sche…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-862</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-9011">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-8679 – The AudioIgniter plugin for WordPress is vulnerable to Insecure Direct Object Re...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-8679</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-8679</guid>
    <pubDate>Fri, 22 May 2026 09:16:32 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-8679</strong></p>
  <p>The AudioIgniter plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions up to, and including, 2.0.2. This is due to the handle_playlist_endpoint() function (hooked to template_redirect) accepting a user-controlled playlist ID via the audioigniter_playlist_id query var or the /audioigniter/playlist/{id}/ rewrite rule and returning playlist track data without performing…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-639</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-8679">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-9018 – The Easy Elements for Elementor – Addons &amp; Website Templates plugin for WordPres...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-9018</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-9018</guid>
    <pubDate>Fri, 22 May 2026 05:16:28 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-9018</strong></p>
  <p>The Easy Elements for Elementor – Addons & Website Templates plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.4.5 via the `easyel_handle_register()` function. This is due to the `wp_ajax_nopriv_eel_register` AJAX handler iterating the attacker-controlled `custom_meta` POST array and writing every supplied key-value pair to the newly created user's…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-269</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-9018">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-4834 – The WP ERP Pro plugin for WordPress is vulnerable to SQL Injection via the 'sear...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-4834</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-4834</guid>
    <pubDate>Fri, 22 May 2026 04:16:26 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-4834</strong></p>
  <p>The WP ERP Pro plugin for WordPress is vulnerable to SQL Injection via the 'search_key' parameter in all versions up to, and including, 1.5.1. This is due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can b…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-4834">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-6960 – The BookingPress Pro plugin for WordPress is vulnerable to arbitrary file upload...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-6960</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-6960</guid>
    <pubDate>Thu, 21 May 2026 22:16:48 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-6960</strong></p>
  <p>The BookingPress Pro plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'bookingpress_validate_submitted_booking_form_func' function in all versions up to, and including, 5.6. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's server which may make remote code execution possible. Note: The vuln…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-434</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-6960">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-5118 – The Divi Form Builder plugin for WordPress is vulnerable to privilege escalation...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-5118</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-5118</guid>
    <pubDate>Thu, 21 May 2026 13:16:20 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-5118</strong></p>
  <p>The Divi Form Builder plugin for WordPress is vulnerable to privilege escalation in versions up to, and including, 5.1.2. This is due to the plugin accepting a user-controlled 'role' parameter from POST data during user registration without validating it against the form's configured default_user_role setting. This makes it possible for unauthenticated attackers to create administrator accounts b…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-269</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-5118">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-6279 – The Avada Builder (fusion-builder) plugin for WordPress is vulnerable to Unauthe...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-6279</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-6279</guid>
    <pubDate>Thu, 21 May 2026 05:16:23 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-6279</strong></p>
  <p>The Avada Builder (fusion-builder) plugin for WordPress is vulnerable to Unauthenticated Remote Code Execution via PHP Function Injection in versions up to and including 3.15.2. This is due to the `wp_conditional_tags` case in `Fusion_Builder_Conditional_Render_Helper::get_value()` passing attacker-controlled values from a base64-decoded JSON blob directly to `call_user_func()` without any allowl…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-74</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-6279">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-7613 – The Cost of Goods by PixelYourSite plugin for WordPress is vulnerable to Stored ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-7613</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-7613</guid>
    <pubDate>Wed, 20 May 2026 17:16:29 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-7613</strong></p>
  <p>The Cost of Goods by PixelYourSite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'csvdata[0][cost_of_goods_value]' parameter in versions up to, and including, 1.2.12 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injec…</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-7613">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-9065 – SureCart version prior to 4.2.1 are vulnerable to authenticated SQL injection vi...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-9065</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-9065</guid>
    <pubDate>Wed, 20 May 2026 09:16:27 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-9065</strong></p>
  <p>SureCart version prior to 4.2.1 are vulnerable to authenticated SQL injection via multiple parameters ('model_name', 'model_id', 'integration_id', 'provider') on the REST API endpoint '/surecart/v1/integrations/{id}'.  The root cause is a flawed escaping bypass in the query builder ('wp-query-builder'). Values passed to the 'where()' method are only sanitized via '$wpdb->prepare()' when they do *…</p>
  <p><strong>CVSS:</strong> 9.3 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-9065">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-5200 – The AcyMailing – An Ultimate Newsletter Plugin and Marketing Automation Solution...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-5200</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-5200</guid>
    <pubDate>Wed, 20 May 2026 08:16:22 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-5200</strong></p>
  <p>The AcyMailing – An Ultimate Newsletter Plugin and Marketing Automation Solution for WordPress plugin for WordPress is vulnerable to Missing Authorization in versions up to, and including, 10.8.2. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers, with subscriber-level access and above, to modify pri…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-862</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-5200">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-7522 – The Advanced Database Cleaner – Premium plugin for WordPress is vulnerable to Lo...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-7522</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-7522</guid>
    <pubDate>Wed, 20 May 2026 05:16:22 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-7522</strong></p>
  <p>The Advanced Database Cleaner – Premium plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 4.1.0 via the 'template' parameter. This makes it possible for authenticated attackers, with Subscriber-level access and above, to include and execute arbitrary .php files on the server, allowing the execution of any PHP code in those files. This can be used to bypa…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-98</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-7522">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-9010 – The Boost plugin for WordPress is vulnerable to time-based SQL Injection via the...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-9010</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-9010</guid>
    <pubDate>Wed, 20 May 2026 04:16:59 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-9010</strong></p>
  <p>The Boost plugin for WordPress is vulnerable to time-based SQL Injection via the 'current_url' and 'user_name' parameters in versions up to, and including, 2.0.3 due to insufficient escaping on the user supplied parameters and lack of sufficient preparation on the existing SQL queries. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing quer…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-9010">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-7637 – The Boost plugin for WordPress is vulnerable to PHP Object Injection in versions...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-7637</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-7637</guid>
    <pubDate>Wed, 20 May 2026 04:16:56 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-7637</strong></p>
  <p>The Boost plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 2.0.3 via deserialization of untrusted input in the STYXKEY-BOOST_USER_LOCATION cookie. This makes it possible for unauthenticated attackers to inject a PHP Object. No known POP chain is present in the vulnerable software, which means this vulnerability has no impact unless another plugin or the…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-502</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-7637">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-7467 – The Read More &amp; Accordion plugin for WordPress is vulnerable to Privilege Escala...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-7467</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-7467</guid>
    <pubDate>Wed, 20 May 2026 02:16:39 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-7467</strong></p>
  <p>The Read More & Accordion plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 3.5.7. This is due to the 'RadMoreAjax::importData' function not restricting which database tables can be written to during import and not properly validating the imported data. This makes it possible for authenticated attackers, with permission granted by the site owner thro…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-269</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-7467">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-7284 – The Easy Elements for Elementor – Addons &amp; Website Templates plugin for WordPres...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-7284</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-7284</guid>
    <pubDate>Wed, 20 May 2026 02:16:39 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-7284</strong></p>
  <p>The Easy Elements for Elementor – Addons & Website Templates plugin for WordPress is vulnerable to privilege escalation via user registration in all versions up to, and including, 1.4.4. This is due to the 'easyel_handle_register' function not restricting what user roles a user can register with. This makes it possible for unauthenticated attackers to supply the 'administrator' role during regist…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-269</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-7284">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-6555 – The ProSolution WP Client plugin for WordPress is vulnerable to Arbitrary File U...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-6555</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-6555</guid>
    <pubDate>Wed, 20 May 2026 02:16:38 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-6555</strong></p>
  <p>The ProSolution WP Client plugin for WordPress is vulnerable to Arbitrary File Upload in versions up to, and including, 2.0.0. This is due to an array validation mismatch where only the first file in the upload array undergoes extension and MIME type validation, while all files are processed and uploaded to a web-accessible directory. This makes it possible for unauthenticated attackers to upload…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-434</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-6555">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-6456 – The Account Switcher plugin for WordPress is vulnerable to Privilege Escalation ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-6456</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-6456</guid>
    <pubDate>Wed, 20 May 2026 02:16:38 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-6456</strong></p>
  <p>The Account Switcher plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.0.2. This is due to the `rememberLogin` REST API endpoint using a loose comparison (`!=` instead of `!==`) for secret validation at `app/RestAPI.php:111`, combined with no validation that the secret is non-empty. When a target user has never used the "Remember me" feature, their…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-287</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-6456">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-3985 – The Creative Mail – Easier WordPress &amp; WooCommerce Email Marketing plugin for Wo...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-3985</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-3985</guid>
    <pubDate>Wed, 20 May 2026 02:16:35 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-3985</strong></p>
  <p>The Creative Mail – Easier WordPress & WooCommerce Email Marketing plugin for WordPress is vulnerable to SQL Injection via the 'checkout_uuid' parameter in all versions up to, and including, 1.6.9. This is due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query in the `has_checkout_consent()` method. This makes it possible for unaut…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-3985">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-8073 – The Kirki – Freeform Page Builder, Website Builder &amp; Customizer plugin for WordP...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-8073</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-8073</guid>
    <pubDate>Tue, 19 May 2026 19:16:51 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-8073</strong></p>
  <p>The Kirki – Freeform Page Builder, Website Builder & Customizer plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation and missing capability check in the 'downloadZIP' function in all versions up to, and including, 6.0.6. This makes it possible for unauthenticated attackers to read and delete arbitrary files limited in the WordPress uploads base di…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-23</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-8073">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-8912 – The Contest Gallery plugin for WordPress is vulnerable to SQL Injection via the ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-8912</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-8912</guid>
    <pubDate>Tue, 19 May 2026 13:16:20 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-8912</strong></p>
  <p>The Contest Gallery plugin for WordPress is vulnerable to SQL Injection via the 'form_input' parameter in versions up to, and including, 28.1.6. This is due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query inside the unauthenticated 'post_cg_gallery_form_upload' AJAX action (specifically the 'cb' branch of the included users-uplo…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-8912">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-4883 – The Piotnet Forms plugin for WordPress is vulnerable to arbitrary file upload du...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-4883</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-4883</guid>
    <pubDate>Tue, 19 May 2026 13:16:19 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-4883</strong></p>
  <p>The Piotnet Forms plugin for WordPress is vulnerable to arbitrary file upload due to missing file type validation in the 'piotnetforms_ajax_form_builder' function in all versions up to, and including, 2.1.40. The plugin uses an incomplete extension blacklist that only blocks php, phpt, php5, php7, and exe extensions, while allowing dangerous extensions such as .phar or .phtml to be uploaded. This…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-434</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-4883">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-4885 – The Piotnet Addons for Elementor Pro plugin for WordPress is vulnerable to arbit...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-4885</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-4885</guid>
    <pubDate>Tue, 19 May 2026 08:16:16 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-4885</strong></p>
  <p>The Piotnet Addons for Elementor Pro plugin for WordPress is vulnerable to arbitrary file upload due to missing file type validation in the 'pafe_ajax_form_builder' function in all versions up to, and including, 7.1.70. The plugin uses an incomplete extension blacklist that only blocks php, phpt, php5, php7, and exe extensions, while allowing dangerous extensions such as .phar or .phtml to be upl…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-434</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-4885">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-15609 – The Fortis for WooCommerce WordPress plugin before 1.3.1 may leak sensitive API ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-15609</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-15609</guid>
    <pubDate>Tue, 19 May 2026 07:16:29 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-15609</strong></p>
  <p>The Fortis for WooCommerce WordPress plugin before 1.3.1 may leak sensitive API keys to unauthenticated attackers, allowing them to query Fortis' API and retrieve sensitive customer information, like past orders, PII, etc.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-15609">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-6495 – The Ajax Load More  WordPress plugin before 7.8.4 does not sanitise and escape a...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-6495</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-6495</guid>
    <pubDate>Mon, 18 May 2026 07:16:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-6495</strong></p>
  <p>The Ajax Load More  WordPress plugin before 7.8.4 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin</p>
  <p><strong>CVSS:</strong> 7.1 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-6495">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-6381 – The WP Maps  WordPress plugin before 4.9.3 does not properly sanitize a paramete...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-6381</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-6381</guid>
    <pubDate>Mon, 18 May 2026 07:16:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-6381</strong></p>
  <p>The WP Maps  WordPress plugin before 4.9.3 does not properly sanitize a parameter before using it in a file path, allowing authenticated users to perform Local File Inclusion attacks.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-6381">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-6379 – The WP Photo Album Plus WordPress plugin before 9.1.11.001 does not properly san...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-6379</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-6379</guid>
    <pubDate>Mon, 18 May 2026 07:16:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-6379</strong></p>
  <p>The WP Photo Album Plus WordPress plugin before 9.1.11.001 does not properly sanitize and escape a parameter before using it in a SQL query, allowing unauthenticated users to perform SQL injection attacks.</p>
  <p><strong>CVSS:</strong> 8.6 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-6379">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-3220 – The Autoptimize WordPress plugin before 3.1.15, Clearfy Cache  WordPress plugin ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-3220</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-3220</guid>
    <pubDate>Mon, 18 May 2026 07:16:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-3220</strong></p>
  <p>The Autoptimize WordPress plugin before 3.1.15, Clearfy Cache  WordPress plugin before 2.4.2, Speed Optimizer  WordPress plugin before 7.7.9 are vulnerable to unauthenticated Stored Cross-Site Scripting (XSS) due to a predictable replacement hash used during the HTML minification process and abusing a regular expression. This allows an attacker to inject arbitrary HTML attributes in the final HTM…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-3220">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2018-25335 – WordPress Plugin Peugeot Music 1.0 contains an arbitrary file upload vulnerabili...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2018-25335</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2018-25335</guid>
    <pubDate>Sun, 17 May 2026 13:16:45 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2018-25335</strong></p>
  <p>WordPress Plugin Peugeot Music 1.0 contains an arbitrary file upload vulnerability that allows unauthenticated attackers to upload malicious files by sending POST requests to the upload.php endpoint. Attackers can upload files with arbitrary extensions by manipulating the 'name' parameter to execute code from the uploads directory.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-306</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-25335">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2018-25329 – WordPress Plugin WP with Spritz 1.0 contains a remote file inclusion vulnerabili...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2018-25329</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2018-25329</guid>
    <pubDate>Sun, 17 May 2026 13:16:44 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2018-25329</strong></p>
  <p>WordPress Plugin WP with Spritz 1.0 contains a remote file inclusion vulnerability that allows unauthenticated attackers to read arbitrary files by injecting file paths into the url parameter. Attackers can send GET requests to wp.spritz.content.filter.php with malicious url values to access sensitive files like system configuration and credentials.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-98</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-25329">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2018-25326 – Google Drive for WordPress 2.2 contains a path traversal vulnerability that allo...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2018-25326</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2018-25326</guid>
    <pubDate>Sun, 17 May 2026 13:16:44 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2018-25326</strong></p>
  <p>Google Drive for WordPress 2.2 contains a path traversal vulnerability that allows unauthenticated attackers to read arbitrary files by injecting directory traversal sequences in the file_name parameter. Attackers can send POST requests to gdrive-ajaxs.php with the ajaxstype parameter set to del_fl_bkp and file_name containing traversal sequences ../../wp-config.php to access sensitive configurat…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-25326">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-8719 – The AI Engine – The Chatbot, AI Framework &amp; MCP for WordPress plugin for WordPre...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-8719</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-8719</guid>
    <pubDate>Sun, 17 May 2026 04:16:42 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-8719</strong></p>
  <p>The AI Engine – The Chatbot, AI Framework & MCP for WordPress plugin for WordPress is vulnerable to Privilege Escalation in version 3.4.9. This is due to missing WordPress capability enforcement in the MCP OAuth bearer-token authorization path, where any valid OAuth token causes MCP access to be granted without verifying administrator privileges. This makes it possible for authenticated (Subscrib…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-269</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-8719">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2021-47979 – WordPress Plugin Backup and Restore 1.0.3 contains an arbitrary file deletion vu...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-47979</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-47979</guid>
    <pubDate>Sat, 16 May 2026 16:16:23 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2021-47979</strong></p>
  <p>WordPress Plugin Backup and Restore 1.0.3 contains an arbitrary file deletion vulnerability that allows authenticated attackers to delete files by manipulating parameters in AJAX requests. Attackers can send POST requests to admin-ajax.php with crafted file_name and folder_name parameters to delete arbitrary files from the WordPress installation directory.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-47979">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2021-47977 – WordPress Plugin Anti-Malware Security and Bruteforce Firewall 4.20.59 contains ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-47977</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-47977</guid>
    <pubDate>Sat, 16 May 2026 16:16:23 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2021-47977</strong></p>
  <p>WordPress Plugin Anti-Malware Security and Bruteforce Firewall 4.20.59 contains a directory traversal vulnerability that allows unauthenticated attackers to read arbitrary files by manipulating the file parameter. Attackers can send requests to the duplicator_download action via admin-ajax.php with path traversal sequences to access sensitive system files outside the intended directory.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-47977">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2021-47965 – WordPress Plugin WP Super Edit 2.5.4 and earlier contains an unrestricted file u...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-47965</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-47965</guid>
    <pubDate>Fri, 15 May 2026 19:16:56 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2021-47965</strong></p>
  <p>WordPress Plugin WP Super Edit 2.5.4 and earlier contains an unrestricted file upload vulnerability in the FCKeditor component that allows attackers to upload dangerous file types without validation. Attackers can upload arbitrary files through the filemanager upload endpoint to achieve remote code execution and complete system compromise.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-434</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-47965">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2021-47959 – WordPress Plugin WPGraphQL 1.3.5 contains a denial of service vulnerability that...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-47959</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-47959</guid>
    <pubDate>Fri, 15 May 2026 19:16:55 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2021-47959</strong></p>
  <p>WordPress Plugin WPGraphQL 1.3.5 contains a denial of service vulnerability that allows unauthenticated attackers to exhaust server resources by sending batched GraphQL queries with duplicated fields. Attackers can send POST requests to the GraphQL endpoint with amplified field duplication payloads to trigger server out-of-memory conditions and MySQL connection errors.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-770</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-47959">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-6403 – The Quick Playground plugin for WordPress is vulnerable to Path Traversal in ver...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-6403</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-6403</guid>
    <pubDate>Fri, 15 May 2026 09:16:16 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-6403</strong></p>
  <p>The Quick Playground plugin for WordPress is vulnerable to Path Traversal in versions up to and including 1.3.3. This is due to insufficient path validation in the qckply_zip_theme() function, which appends a user-controlled 'stylesheet' parameter directly to the theme root directory path without sanitizing directory traversal sequences. This makes it possible for unauthenticated attackers to tri…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-6403">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-6228 – The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to Privilege...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-6228</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-6228</guid>
    <pubDate>Fri, 15 May 2026 09:16:16 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-6228</strong></p>
  <p>The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to Privilege Escalation in versions up to and including 3.28.36. This is due to insufficient authorization checks in the role field update mechanism combined with overly permissive capabilities for the admin_form post type. The admin_form custom post type uses 'capability_type' => 'page', which grants editors the ability to creat…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-269</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-6228">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-5229 – The Form Notify plugin for WordPress is vulnerable to Authentication Bypass in v...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-5229</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-5229</guid>
    <pubDate>Fri, 15 May 2026 09:16:16 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-5229</strong></p>
  <p>The Form Notify plugin for WordPress is vulnerable to Authentication Bypass in versions up to and including 1.1.10. This is due to the plugin trusting user-controlled cookie data to determine which WordPress account to authenticate after a LINE OAuth login. When LINE doesn't provide an email address (which is common), the plugin falls back to reading the 'form_notify_line_email' cookie value with…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-287</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-5229">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-4094 – The FOX – Currency Switcher Professional for WooCommerce plugin for WordPress is...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-4094</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-4094</guid>
    <pubDate>Fri, 15 May 2026 07:16:20 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-4094</strong></p>
  <p>The FOX – Currency Switcher Professional for WooCommerce plugin for WordPress is vulnerable to unauthorized data loss due to a missing capability check on the 'admin_head' function in all versions up to, and including, 1.4.5. This makes it possible for authenticated attackers, with Contributor-level access and above, to delete the entire multi-currency configuration by visiting any wp-admin page…</p>
  <p><strong>CVSS:</strong> 8.1 · <strong>CWE:</strong> CWE-862</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-4094">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-4031 – The Database Backup for WordPress plugin for WordPress is vulnerable to authoriz...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-4031</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-4031</guid>
    <pubDate>Thu, 14 May 2026 13:16:20 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-4031</strong></p>
  <p>The Database Backup for WordPress plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 2.5.2. This is due to the plugin not restricting access to the wp_db_temp_dir parameter, which controls where database backups are written. This makes it possible for unauthenticated attackers to send a request to wp-cron.php with a poisoned wp_db_temp_dir value point…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-862</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-4031">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-4030 – The Database Backup for WordPress plugin for WordPress is vulnerable to unauthor...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-4030</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-4030</guid>
    <pubDate>Thu, 14 May 2026 13:16:20 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-4030</strong></p>
  <p>The Database Backup for WordPress plugin for WordPress is vulnerable to unauthorized arbitrary file read and deletion in all versions up to, and including, 2.5.2. This is due to the plugin not properly enforcing the return value of its authorization check combined with a user-controlled backup directory parameter. This makes it possible for unauthenticated attackers to read and delete arbitrary f…</p>
  <p><strong>CVSS:</strong> 8.1 · <strong>CWE:</strong> CWE-862</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-4030">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-4029 – The Database Backup for WordPress plugin for WordPress is vulnerable to unauthor...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-4029</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-4029</guid>
    <pubDate>Thu, 14 May 2026 13:16:20 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-4029</strong></p>
  <p>The Database Backup for WordPress plugin for WordPress is vulnerable to unauthorized database export in all versions up to, and including, 2.5.2. This is due to the plugin not properly enforcing the return value of its authorization check. This makes it possible for unauthenticated attackers to export database tables, leading to Sensitive Information Exposure. Note: This vulnerability is only exp…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-862</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-4029">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-6514 – The InfusedWoo Pro plugin for WordPress is vulnerable to Arbitrary File Read in ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-6514</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-6514</guid>
    <pubDate>Thu, 14 May 2026 09:16:28 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-6514</strong></p>
  <p>The InfusedWoo Pro plugin for WordPress is vulnerable to Arbitrary File Read in all versions up to, and including, 5.1.2 via the popup_submit. This makes it possible for unauthenticated attackers to make web requests to arbitrary locations originating from the web application and can be used to query and modify information from internal services.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-918</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-6514">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-6512 – The InfusedWoo Pro plugin for WordPress is vulnerable to authorization bypass in...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-6512</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-6512</guid>
    <pubDate>Thu, 14 May 2026 09:16:27 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-6512</strong></p>
  <p>The InfusedWoo Pro plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 5.1.2. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for unauthenticated attackers to permanently delete arbitrary posts, pages, products, or orders, mass-delete all comments on any post, and change any post's…</p>
  <p><strong>CVSS:</strong> 9.1 · <strong>CWE:</strong> CWE-862</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-6512">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-6510 – The InfusedWoo Pro plugin for WordPress is vulnerable to privilege escalation vi...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-6510</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-6510</guid>
    <pubDate>Thu, 14 May 2026 07:16:21 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-6510</strong></p>
  <p>The InfusedWoo Pro plugin for WordPress is vulnerable to privilege escalation via missing authorization in all versions up to, and including, 5.1.2. This is due to missing nonce verification and capability checks in the iwar_save_recipe() AJAX handler. This makes it possible for unauthenticated attackers to create a malicious automation recipe that pairs an HTTP post trigger with an auto-login ac…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-862</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-6510">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-6506 – The InfusedWoo Pro plugin for WordPress is vulnerable to privilege escalation in...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-6506</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-6506</guid>
    <pubDate>Thu, 14 May 2026 07:16:20 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-6506</strong></p>
  <p>The InfusedWoo Pro plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 5.1.2. This is due to the infusedwoo_gdpr_upddata() function missing authorization and capability checks, as well as lacking restrictions on which user meta keys can be updated. This makes it possible for authenticated attackers, with subscriber-level access and above, to update the…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-862</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-6506">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-6271 – The Career Section plugin for WordPress is vulnerable to Arbitrary File Upload i...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-6271</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-6271</guid>
    <pubDate>Thu, 14 May 2026 07:16:20 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-6271</strong></p>
  <p>The Career Section plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 1.7 via the CV upload handler. This is due to missing file type validation. This makes it possible for unauthenticated attackers to upload files that may be executable, which makes remote code execution possible.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-434</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-6271">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-5395 – The Fluent Forms – Customizable Contact Forms, Survey, Quiz, &amp; Conversational Fo...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-5395</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-5395</guid>
    <pubDate>Thu, 14 May 2026 07:16:20 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-5395</strong></p>
  <p>The Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 6.2.0 via the exportEntries function due to missing validation on a user controlled key. This makes it possible for authenticated attackers, with Fluent Forms manager-level access and above, to bypas…</p>
  <p><strong>CVSS:</strong> 8.2 · <strong>CWE:</strong> CWE-639</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-5395">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-3892 – The Motors – Car Dealership &amp; Classified Listings Plugin plugin for WordPress is...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-3892</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-3892</guid>
    <pubDate>Thu, 14 May 2026 07:16:19 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-3892</strong></p>
  <p>The Motors – Car Dealership & Classified Listings Plugin plugin for WordPress is vulnerable to arbitrary file deletion in all versions up to, and including, 1.4.107. This is due to insufficient file path validation in the become-dealer logo upload flow. The plugin allows any authenticated user to set an arbitrary filesystem path via the profile update handler. This makes it possible for authentic…</p>
  <p><strong>CVSS:</strong> 8.1 · <strong>CWE:</strong> CWE-73</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-3892">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-3718 – The ManageWP Worker plugin for WordPress is vulnerable to Stored Cross-Site Scri...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-3718</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-3718</guid>
    <pubDate>Thu, 14 May 2026 07:16:19 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-3718</strong></p>
  <p>The ManageWP Worker plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'MWP-Key-Name' HTTP request header in all versions up to, and including, 4.9.31. This is due to insufficient input sanitization and output escaping of attacker-controlled header values. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute wheneve…</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-3718">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-8181 – The Burst Statistics – Privacy-Friendly WordPress Analytics (Google Analytics Al...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-8181</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-8181</guid>
    <pubDate>Thu, 14 May 2026 06:16:25 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-8181</strong></p>
  <p>The Burst Statistics – Privacy-Friendly WordPress Analytics (Google Analytics Alternative) plugin for WordPress is vulnerable to Authentication Bypass in versions 3.4.0 to 3.4.1.1. This is due to incorrect return-value handling in the `is_mainwp_authenticated()` function when validating application passwords from the Authorization header. This makes it possible for unauthenticated attackers, with…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-287</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-8181">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-5396 – The Fluent Forms plugin for WordPress is vulnerable to Authorization Bypass Thro...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-5396</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-5396</guid>
    <pubDate>Thu, 14 May 2026 06:16:24 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-5396</strong></p>
  <p>The Fluent Forms plugin for WordPress is vulnerable to Authorization Bypass Through User-Controlled Key in all versions up to, and including, 6.1.21. This is due to the SubmissionPolicy class authorizing submission-level actions (read, modify, delete, add notes) based on a user-supplied `form_id` query parameter. This makes it possible for authenticated attackers, with Fluent Forms Manager access…</p>
  <p><strong>CVSS:</strong> 8.2 · <strong>CWE:</strong> CWE-639</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-5396">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-4609 – The ProfileGrid – User Profiles, Groups and Communities plugin for WordPress is ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-4609</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-4609</guid>
    <pubDate>Wed, 13 May 2026 14:17:58 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-4609</strong></p>
  <p>The ProfileGrid – User Profiles, Groups and Communities plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the pm_invite_user function in all versions up to, and including, 5.9.8.4. This makes it possible for authenticated attackers, with Subscriber-level access and above, to add themselves or any registered user to any ProfileGrid group, including clos…</p>
  <p><strong>CVSS:</strong> 7.1 · <strong>CWE:</strong> CWE-862</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-4609">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-6177 – The Custom Twitter Feeds plugin for WordPress is vulnerable to Stored Cross-Site...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-6177</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-6177</guid>
    <pubDate>Wed, 13 May 2026 13:16:44 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-6177</strong></p>
  <p>The Custom Twitter Feeds plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to and including 2.5.4. This is due to insufficient output escaping in the CTF_Display_Elements::get_post_text() function when rendering cached tweet text. The plugin's ctf_get_more_posts AJAX action is available to unauthenticated users and directly outputs cached tweet data through nl2br()…</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-6177">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-3425 – The RTMKit Addons for Elementor plugin for WordPress is vulnerable to Local File...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-3425</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-3425</guid>
    <pubDate>Wed, 13 May 2026 13:16:41 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-3425</strong></p>
  <p>The RTMKit Addons for Elementor plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 2.0.2 via the 'path' parameter of the 'get_content' AJAX action. This makes it possible for authenticated attackers, with Author-level access and above, to include and execute arbitrary PHP files on the server, allowing the execution of any PHP code in those files. This…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-98</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-3425">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-4798 – The Avada Builder plugin for WordPress is vulnerable to time-based SQL Injection...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-4798</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-4798</guid>
    <pubDate>Wed, 13 May 2026 13:01:55 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-4798</strong></p>
  <p>The Avada Builder plugin for WordPress is vulnerable to time-based SQL Injection via the ‘product_order’ parameter in all versions up to, and including, 3.15.1 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query.  This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-4798">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-6929 – The JoomSport – for Sports: Team &amp; League, Football, Hockey &amp; more plugin for Wo...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-6929</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-6929</guid>
    <pubDate>Wed, 13 May 2026 06:16:14 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-6929</strong></p>
  <p>The JoomSport – for Sports: Team & League, Football, Hockey & more plugin for WordPress is vulnerable to time-based blind SQL Injection via the 'sortf' parameter in all versions up to, and including, 5.7.7 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append addition…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-6929">View on NVD</a></p>
]]>
    </description>
  </item>
</channel>
</rss>
