<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
<channel>
  <title>CVE Daily – WordPress</title>
  <link>https://cvedaily.com/pages/tags/wordpress.html</link>
  <atom:link href="https://cvedaily.com/feed-tags/wordpress.xml" rel="self" type="application/rss+xml"/>
  <description>CVE Daily – WordPress</description>
  <language>en</language>
  <lastBuildDate>Wed, 03 Jun 2026 21:26:32 +0000</lastBuildDate>
  <item>
    <title>[Medium] CVE-2026-9732 – The EmergencyWP – Dead Man's switch &amp; legacy deliverance plugin for WordPress is...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-9732</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-9732</guid>
    <pubDate>Wed, 03 Jun 2026 00:16:45 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-9732</strong></p>
  <p>The EmergencyWP – Dead Man's switch & legacy deliverance plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.4.2. This is due to missing or incorrect nonce validation on the form_settings_ui (settings save handler, procedural include scope) function. This makes it possible for unauthenticated attackers to modify plugin settings including the mi…</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-352</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-9732">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-7421 – The Passeum Ticketing plugin for WordPress is vulnerable to Stored Cross-Site Sc...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-7421</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-7421</guid>
    <pubDate>Wed, 03 Jun 2026 00:16:44 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-7421</strong></p>
  <p>The Passeum Ticketing plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 1.0. This is due to the `get_shop_url()` method returning the `shop_name` setting value without sanitization when it begins with "http", combined with insufficient validation in the `validate_shop_name()` function which only checks for empty values and string type. This ma…</p>
  <p><strong>CVSS:</strong> 4.4 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-7421">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-5076 – The ARMember Premium plugin for WordPress is vulnerable to an insecure password ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-5076</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-5076</guid>
    <pubDate>Tue, 02 Jun 2026 20:16:40 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-5076</strong></p>
  <p>The ARMember Premium plugin for WordPress is vulnerable to an insecure password reset mechanism in all versions up to, and including, 7.3.1. The plugin stores a plaintext copy of the password reset key in the `arm_reset_password_key` user meta field when a user requests a password reset. This is in addition to the hashed key that WordPress core stores securely in `wp_users.user_activation_key`. T…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-287</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-5076">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-5074 – The ARMember Premium plugin for WordPress is vulnerable to SQL Injection via the...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-5074</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-5074</guid>
    <pubDate>Tue, 02 Jun 2026 20:16:40 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-5074</strong></p>
  <p>The ARMember Premium plugin for WordPress is vulnerable to SQL Injection via the 'sSortDir_0' parameter of the `get_private_content_data` AJAX action in all versions up to, and including, 7.3.1. This is due to insufficient sanitization of the user-supplied parameter which is concatenated directly into the ORDER BY clause of an SQL query without a whitelist check. This makes it possible for authen…</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-5074">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-5073 – The ARMember Premium plugin for WordPress is vulnerable to SQL Injection via the...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-5073</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-5073</guid>
    <pubDate>Tue, 02 Jun 2026 20:16:40 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-5073</strong></p>
  <p>The ARMember Premium plugin for WordPress is vulnerable to SQL Injection via the 'order' parameter of the 'arm_directory_paging_action' AJAX action in all versions up to, and including, 7.3.1. This is due to insufficient escaping on the user-supplied 'order' and 'orderby' parameters and the lack of sufficient preparation on the existing SQL query in the `arm_get_directory_members()` function. Thi…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-5073">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-1829 – The Content Visibility for Divi Builder plugin for WordPress is vulnerable to Re...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-1829</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-1829</guid>
    <pubDate>Tue, 02 Jun 2026 20:16:33 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-1829</strong></p>
  <p>The Content Visibility for Divi Builder plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 4.02 via the 'et_pb_text' shortcode 'cvdb_content_visibility_check' parameter. This makes it possible for authenticated attackers, with Contributor-level access and above, to execute code on the server.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-94</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-1829">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-5191 – The Tiled Gallery Carousel Without JetPack plugin for WordPress is vulnerable to...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-5191</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-5191</guid>
    <pubDate>Tue, 02 Jun 2026 10:16:25 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-5191</strong></p>
  <p>The Tiled Gallery Carousel Without JetPack plugin for WordPress is vulnerable to stored cross-site scripting via the 'data-image-title' parameter in all versions up to, and including, 3.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor level access and above, to inject arbitrary web scripts in pages that will execute…</p>
  <p><strong>CVSS:</strong> 5.4 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-5191">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-9730 – The Remove NoFollow Commenter URL plugin for WordPress is vulnerable to Cross-Si...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-9730</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-9730</guid>
    <pubDate>Tue, 02 Jun 2026 09:16:17 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-9730</strong></p>
  <p>The Remove NoFollow Commenter URL plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0. This is due to missing or incorrect nonce validation on the gmz_comment_settings_save function. This makes it possible for unauthenticated attackers to modify the plugin's comment-display setting via a forged request via a forged request granted they can tr…</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-352</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-9730">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-9723 – The Google Plus One Bottom plugin for WordPress is vulnerable to Cross-Site Requ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-9723</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-9723</guid>
    <pubDate>Tue, 02 Jun 2026 09:16:17 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-9723</strong></p>
  <p>The Google Plus One Bottom plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 0.0.2. This is due to missing or incorrect nonce validation on the googlePlusOneAdmin function. This makes it possible for unauthenticated attackers to modify the plugin's settings, including the plusone-lang, plusone-callback, and plusone-url options stored in the dat…</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-352</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-9723">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-9722 – The Laiser Tag plugin for WordPress is vulnerable to Cross-Site Request Forgery ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-9722</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-9722</guid>
    <pubDate>Tue, 02 Jun 2026 09:16:17 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-9722</strong></p>
  <p>The Laiser Tag plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.2.5. This is due to missing or incorrect nonce validation on the addOptionsPageFields function. This makes it possible for unauthenticated attackers to update the plugin's settings, including the API key, tag blacklist, relevance threshold, batch size, and tagging toggles, via a…</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-352</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-9722">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-9599 – The Tectite Forms plugin for WordPress is vulnerable to Cross-Site Request Forge...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-9599</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-9599</guid>
    <pubDate>Tue, 02 Jun 2026 09:16:17 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-9599</strong></p>
  <p>The Tectite Forms plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.3. This is due to missing or incorrect nonce validation on the admin_init function. This makes it possible for unauthenticated attackers to modify the plugin's settings, including the tectite_forms_button option, via a forged request via a forged request granted they can tric…</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-352</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-9599">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-9234 – The JTL-Connector for WooCommerce plugin for WordPress is vulnerable to Missing ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-9234</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-9234</guid>
    <pubDate>Tue, 02 Jun 2026 09:16:17 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-9234</strong></p>
  <p>The JTL-Connector for WooCommerce plugin for WordPress is vulnerable to Missing Authorization in versions up to, and including, 2.4.1. This is due to missing capability checks and nonce verification on the admin_post_settings_save_woo-jtl-connector action (handled by JtlConnectorAdmin::save()) and on the wp_ajax_downloadJTLLogs and wp_ajax_clearJTLLogs AJAX actions (handled by the global download…</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-862</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-9234">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-8885 – The DeMomentSomTres Shortcodes plugin for WordPress is vulnerable to Stored Cros...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-8885</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-8885</guid>
    <pubDate>Tue, 02 Jun 2026 09:16:16 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-8885</strong></p>
  <p>The DeMomentSomTres Shortcodes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'callout' shortcode in all versions up to, and including, 1.1.1. This is due to insufficient input sanitization and output escaping on the 'width' and 'align' shortcode attributes within the st_callout() function, which concatenates the attribute values directly into an HTML style att…</p>
  <p><strong>CVSS:</strong> 6.4 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-8885">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-8422 – The Remove meta boxes per user role plugin for WordPress is vulnerable to Cross-...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-8422</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-8422</guid>
    <pubDate>Tue, 02 Jun 2026 09:16:16 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-8422</strong></p>
  <p>The Remove meta boxes per user role plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.01. This is due to missing or incorrect nonce validation on the 'remove-meta-boxes-per-user-role' page. This makes it possible for unauthenticated attackers to modify or reset the plugin's per-role meta box visibility settings via a forged request granted th…</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-352</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-8422">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-4081 – The ZeM STL plugin for WordPress is vulnerable to Stored Cross-Site Scripting vi...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-4081</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-4081</guid>
    <pubDate>Tue, 02 Jun 2026 09:16:16 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-4081</strong></p>
  <p>The ZeM STL plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the [zemstl] shortcode in all versions up to and including 1.0. This is due to insufficient input sanitization and output escaping on user-supplied shortcode attributes, specifically the 'url', 'color', and 'bgcolor' parameters. These attribute values are directly interpolated into HTML attribute context without bei…</p>
  <p><strong>CVSS:</strong> 6.4 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-4081">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-4080 – The Easy Cart plugin for WordPress is vulnerable to Stored Cross-Site Scripting ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-4080</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-4080</guid>
    <pubDate>Tue, 02 Jun 2026 09:16:16 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-4080</strong></p>
  <p>The Easy Cart plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'add_to_cart' shortcode in all versions up to and including 1.8. This is due to insufficient input sanitization and output escaping on user-supplied shortcode attributes. Specifically, the ectp_add_to_cart() function uses sanitize_text_field() on shortcode attributes like 'itemid', 'product_name', 'product_des…</p>
  <p><strong>CVSS:</strong> 6.4 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-4080">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-4071 – The BirdSeed plugin for WordPress is vulnerable to Cross-Site Request Forgery in...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-4071</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-4071</guid>
    <pubDate>Tue, 02 Jun 2026 09:16:16 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-4071</strong></p>
  <p>The BirdSeed plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.2.0. This is due to missing nonce validation in the birdseed_plugin_settings_page() function. The function processes the 'birdseed_token' GET parameter and saves it to the database via update_option() without verifying a nonce. This makes it possible for unauthenticated attackers…</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-352</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-4071">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-3620 – The Word Replacer plugin for WordPress is vulnerable to Stored Cross-Site Script...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-3620</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-3620</guid>
    <pubDate>Tue, 02 Jun 2026 09:16:16 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-3620</strong></p>
  <p>The Word Replacer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'replacement' parameter in all versions up to, and including, 0.4. This is due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Administrator-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user ac…</p>
  <p><strong>CVSS:</strong> 4.4 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-3620">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-2425 – The hiWeb Migration Simple plugin for WordPress is vulnerable to Reflected Cross...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-2425</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-2425</guid>
    <pubDate>Tue, 02 Jun 2026 09:16:15 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-2425</strong></p>
  <p>The hiWeb Migration Simple plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'new_domain' parameter in all versions up to, and including, 2.0.0.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick an administrator into perfor…</p>
  <p><strong>CVSS:</strong> 6.1 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-2425">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-2382 – The FPW Category Thumbnails plugin for WordPress is vulnerable to Stored Cross-S...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-2382</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-2382</guid>
    <pubDate>Tue, 02 Jun 2026 09:16:15 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-2382</strong></p>
  <p>The FPW Category Thumbnails plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'id' parameter of the 'fpw_fs_get_file' AJAX action in all versions up to, and including, 1.9.5. This is due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Subscriber-level access and above, to inject arbitrary web scripts in pages…</p>
  <p><strong>CVSS:</strong> 6.4 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-2382">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-1451 – The rognone plugin for WordPress is vulnerable to Reflected Cross-Site Scripting...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-1451</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-1451</guid>
    <pubDate>Tue, 02 Jun 2026 09:16:15 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-1451</strong></p>
  <p>The rognone plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'a' parameter in versions up to, and including, 0.6.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a lin…</p>
  <p><strong>CVSS:</strong> 6.1 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-1451">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-1450 – The rognone plugin for WordPress is vulnerable to Reflected Cross-Site Scripting...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-1450</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-1450</guid>
    <pubDate>Tue, 02 Jun 2026 09:16:15 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-1450</strong></p>
  <p>The rognone plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'mode' parameter in versions up to, and including, 0.6.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a…</p>
  <p><strong>CVSS:</strong> 6.1 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-1450">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-5085 – The WP Nano AD plugin for WordPress is vulnerable to Stored Cross-Site Scripting...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-5085</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-5085</guid>
    <pubDate>Tue, 02 Jun 2026 09:16:15 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-5085</strong></p>
  <p>The WP Nano AD plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘blogrole_link’ parameter in all versions up to, and including, 1.31 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level access, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected…</p>
  <p><strong>CVSS:</strong> 5.5 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-5085">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-8293 – The Really Simple Security  WordPress plugin before 9.5.10.1 does not enforce th...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-8293</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-8293</guid>
    <pubDate>Tue, 02 Jun 2026 07:16:13 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-8293</strong></p>
  <p>The Really Simple Security  WordPress plugin before 9.5.10.1 does not enforce the second-factor challenge in two of its two-factor authentication REST endpoints, allowing an attacker who knows a user's password to obtain a WordPress authentication session for that user without completing the email OTP challenge.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-287</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-8293">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-8206 – The Kirki – Freeform Page Builder, Website Builder &amp; Customizer plugin for WordP...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-8206</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-8206</guid>
    <pubDate>Tue, 02 Jun 2026 04:17:03 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-8206</strong></p>
  <p>The Kirki – Freeform Page Builder, Website Builder & Customizer plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions 6.0.0 to 6.0.6. This is due to the plugin accepting an arbitrary email address when a username is used in the password reset request. This makes it possible for unauthenticated attackers to send a password reset link for any user registere…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-269</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-8206">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-3722 – The Auto Image Attributes From Filename With Bulk Updater (Add Alt Text, Image T...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-3722</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-3722</guid>
    <pubDate>Tue, 02 Jun 2026 03:16:16 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-3722</strong></p>
  <p>The Auto Image Attributes From Filename With Bulk Updater (Add Alt Text, Image Title For Image SEO) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the attachment metadata in all versions up to, and including, 4.9 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Author-level access and above, to inject arbit…</p>
  <p><strong>CVSS:</strong> 6.4 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-3722">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-10100 – The Simple Custom Login Page plugin for WordPress is vulnerable to Stored Cross-...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-10100</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-10100</guid>
    <pubDate>Tue, 02 Jun 2026 03:16:15 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-10100</strong></p>
  <p>The Simple Custom Login Page plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the color settings fields (Page Background, Form Background, Text Color, Link Color) in versions up to and including 1.0.3. This is due to insufficient input sanitization of the color option values (they were registered with register_setting() and stored via the Settings API/update_option() with no…</p>
  <p><strong>CVSS:</strong> 4.4 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-10100">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-9050 – The Slider Revolution plugin for WordPress in versions 6.0.0-6.7.55 and 7.0.0-7...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-9050</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-9050</guid>
    <pubDate>Tue, 02 Jun 2026 00:16:50 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-9050</strong></p>
  <p>The Slider Revolution plugin for WordPress in versions 6.0.0-6.7.55 and 7.0.0-7.0.14 is vulnerable to unauthorized modification of data. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers, with Contributor-level access and above, to deactivate any active plugin installed on the site.</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-862</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-9050">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-9048 – The Slider Revolution plugin for WordPress is vulnerable to Sensitive Informatio...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-9048</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-9048</guid>
    <pubDate>Tue, 02 Jun 2026 00:16:49 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-9048</strong></p>
  <p>The Slider Revolution plugin for WordPress is vulnerable to Sensitive Information Exposure in versions 7.0.0 - 7.0.14, via the 'slider.get.full' AJAX Action. This makes it possible for authenticated attackers, with Contributor-level access and above, to extract sensitive data including raw social media API credentials: the Instagram OAuth token, Flickr API key, YouTube Data API key, and Facebook…</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-863</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-9048">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2018-25434 – WP AutoSuggest 0.24 contains an SQL injection vulnerability that allows unauthen...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2018-25434</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2018-25434</guid>
    <pubDate>Mon, 01 Jun 2026 22:16:16 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2018-25434</strong></p>
  <p>WP AutoSuggest 0.24 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the wpas_keys parameter. Attackers can send GET requests to autosuggest.php with crafted wpas_keys values to extract sensitive database information from WordPress posts and other tables.</p>
  <p><strong>CVSS:</strong> 8.2 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-25434">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-8382 – The Advanced Custom Fields (ACF®) plugin for WordPress is vulnerable to authoriz...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-8382</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-8382</guid>
    <pubDate>Sun, 31 May 2026 04:16:19 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-8382</strong></p>
  <p>The Advanced Custom Fields (ACF®) plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 6.8.1. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for unauthenticated attackers to overwrite the post_title and post_content of any post bound to a publicly accessible acf_form() instance by…</p>
  <p><strong>CVSS:</strong> 5.3 · <strong>CWE:</strong> CWE-862</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-8382">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-9757 – The GEO my WP plugin for WordPress is vulnerable to SQL Injection via the 'swlat...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-9757</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-9757</guid>
    <pubDate>Sat, 30 May 2026 10:16:23 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-9757</strong></p>
  <p>The GEO my WP plugin for WordPress is vulnerable to SQL Injection via the 'swlatlng' and 'nelatlng' parameters in all versions up to, and including, 4.5.5 The parameters are read from $_SERVER['QUERY_STRING'] via parse_str() (bypassing WordPress's wp_magic_quotes protection, which only covers $_POST/$_GET/$_COOKIE/$_REQUEST), then each is split on ',' via explode() and the resulting fragments are…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-9757">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-7465 – The Spectra Gutenberg Blocks – Website Builder for the Block Editor plugin for W...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-7465</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-7465</guid>
    <pubDate>Sat, 30 May 2026 10:16:23 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-7465</strong></p>
  <p>The Spectra Gutenberg Blocks – Website Builder for the Block Editor plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 2.19.25. This makes it possible for authenticated attackers, with Contributor-level access and above, to execute code on the server. Exploitation requires a two-block payload embedded in post content: the first block registers a fake…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-269</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-7465">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-7459 – The Simple History – Track, Log, and Audit WordPress Changes plugin for WordPres...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-7459</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-7459</guid>
    <pubDate>Sat, 30 May 2026 10:16:22 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-7459</strong></p>
  <p>The Simple History – Track, Log, and Audit WordPress Changes plugin for WordPress is vulnerable to authenticated (Subscriber+) account takeover in all versions up to, and including, 5.26.0 via the event reaction endpoints (react_to_event() / unreact_to_event()). The endpoints register get_items_permissions_check() as their permission_callback, which only verifies the requester is logged in and do…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-640</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-7459">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-4290 – The WP Travel Pro plugin for WordPress is vulnerable to arbitrary user deletion ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-4290</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-4290</guid>
    <pubDate>Fri, 29 May 2026 15:16:24 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-4290</strong></p>
  <p>The WP Travel Pro plugin for WordPress is vulnerable to arbitrary user deletion via the /wp-json/wp-travel/v1/travel-guide/{user_id} REST API endpoint in all versions up to, and including, 10.6.0. This is due to the check_permission() callback unconditionally returning true and the Database::delete() method passing the user ID directly to wp_delete_user() without any role validation. This makes i…</p>
  <p><strong>CVSS:</strong> 9.1 · <strong>CWE:</strong> CWE-862</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-4290">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-12714 – The Rank Math SEO – AI SEO Tools to Dominate SEO Rankings plugin for WordPress i...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-12714</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-12714</guid>
    <pubDate>Fri, 29 May 2026 11:16:15 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-12714</strong></p>
  <p>The Rank Math SEO – AI SEO Tools to Dominate SEO Rankings plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the update_site_editor_homepage function in all versions up to, and including, 1.0.271. This makes it possible for unauthenticated attackers to modify several plugin settings including homepage title, meta description, breadcrumbs label, and soci…</p>
  <p><strong>CVSS:</strong> 5.3 · <strong>CWE:</strong> CWE-862</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-12714">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-9189 – The Contact Form 7 – PayPal &amp; Stripe Add-on plugin for WordPress is vulnerable t...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-9189</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-9189</guid>
    <pubDate>Fri, 29 May 2026 09:16:18 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-9189</strong></p>
  <p>The Contact Form 7 – PayPal & Stripe Add-on plugin for WordPress is vulnerable to Payment Bypass via Insufficient Verification of Data Authenticity in all versions up to, and including, 2.4.9. Although `cf7pp_paypal_ipn_handler()` correctly validates IPN authenticity by posting back to PayPal with `cmd=_notify-validate`, it fails to compare the IPN payload's `mc_gross` (payment amount), `mc_curre…</p>
  <p><strong>CVSS:</strong> 5.3 · <strong>CWE:</strong> CWE-345</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-9189">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-6075 – The Media Library Assistant plugin for WordPress is vulnerable to Cross-Site Req...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-6075</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-6075</guid>
    <pubDate>Fri, 29 May 2026 09:16:18 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-6075</strong></p>
  <p>The Media Library Assistant plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 3.35 This is due to missing nonce verification on the bulk action handlers in the settings tab handlers. This makes it possible for unauthenticated attackers to trick an administrator into performing bulk delete, edit, or purge operations on plugin settings and attachment…</p>
  <p><strong>CVSS:</strong> 8.1 · <strong>CWE:</strong> CWE-352</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-6075">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-10039 – The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to generic S...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-10039</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-10039</guid>
    <pubDate>Fri, 29 May 2026 09:16:16 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-10039</strong></p>
  <p>The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to generic SQL Injection via the 'order' parameter in all versions up to, and including, 3.28.28 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with administrator-level access and above, to append additio…</p>
  <p><strong>CVSS:</strong> 4.9 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-10039">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-9243 – The Plus Addons for Elementor plugin for WordPress is vulnerable to Stored Cross...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-9243</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-9243</guid>
    <pubDate>Fri, 29 May 2026 08:16:19 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-9243</strong></p>
  <p>The Plus Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'carousel_direction' parameter of the Carousel Anything widget in versions up to, and including, 6.4.15 This is due to insufficient output escaping in the render() function, where the carousel_direction value is placed into an unquoted HTML attribute (dir=) allowing attribute injection despite…</p>
  <p><strong>CVSS:</strong> 6.4 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-9243">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-3655 – The OTP Login With Phone Number, OTP Verification plugin for WordPress is vulner...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-3655</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-3655</guid>
    <pubDate>Fri, 29 May 2026 08:16:18 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-3655</strong></p>
  <p>The OTP Login With Phone Number, OTP Verification plugin for WordPress is vulnerable to authentication bypass in versions 1.8.50 through 1.8.60. This is due to the Firebase verification flow in the `lwp_ajax_register` AJAX handler not binding the Firebase session to the phone number supplied in the request. The `idehweb_lwp_activate_through_firebase()` function validates that a Firebase OTP sessi…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-287</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-3655">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-11262 – The Link Whisper Free plugin for WordPress is vulnerable to Stored Cross-Site Sc...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-11262</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-11262</guid>
    <pubDate>Fri, 29 May 2026 08:16:17 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-11262</strong></p>
  <p>The Link Whisper Free plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the user_id parameter in all versions up to, and including, 0.9.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-11262">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-9714 – The Simple Divi Shortcode plugin for WordPress is vulnerable to Stored Cross-Sit...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-9714</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-9714</guid>
    <pubDate>Fri, 29 May 2026 07:16:14 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-9714</strong></p>
  <p>The Simple Divi Shortcode plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'id' parameter of the [showmodule] shortcode in versions up to, and including, 1.2 This is due to insufficient input sanitization and output escaping in the showmodule_shortcode() function, which concatenates the 'id' shortcode attribute directly into a dynamically constructed shortcode string with…</p>
  <p><strong>CVSS:</strong> 6.4 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-9714">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-8732 – The WP Maps Pro plugin for WordPress is vulnerable to Privilege Escalation via A...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-8732</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-8732</guid>
    <pubDate>Fri, 29 May 2026 07:16:14 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-8732</strong></p>
  <p>The WP Maps Pro plugin for WordPress is vulnerable to Privilege Escalation via Administrator Account Creation in all versions up to, and including, 6.1.0. This is due to the wpgmp_temp_access_ajax AJAX action being registered with wp_ajax_nopriv_ and protected only by a nonce check using the fc-call-nonce nonce, which is publicly embedded into every frontend page via wp_localize_script as the non…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-306</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-8732">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-6275 – The StatCounter – Free Real Time Visitor Stats plugin for WordPress is vulnerabl...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-6275</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-6275</guid>
    <pubDate>Fri, 29 May 2026 07:16:14 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-6275</strong></p>
  <p>The StatCounter – Free Real Time Visitor Stats plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.1.1 This is due to insufficient output escaping on the post author's nickname in the statcounter_addToTags() function. The function is hooked to wp_head and fires on every single post page. It retrieves the post author's nickname via the_author_meta(…</p>
  <p><strong>CVSS:</strong> 6.4 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-6275">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-14042 – The Automotive Car Dealership Business WordPress Theme for WordPress is vulnerab...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-14042</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-14042</guid>
    <pubDate>Fri, 29 May 2026 07:16:14 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-14042</strong></p>
  <p>The Automotive Car Dealership Business WordPress Theme for WordPress is vulnerable to Stored Cross-Site Scripting via the 'Project Details' custom field in Portfolio Items in all versions up to, and including, 13.4.1. This is due to insufficient input sanitization and output escaping on user-supplied attributes in the 'project_details' custom field. This makes it possible for authenticated attack…</p>
  <p><strong>CVSS:</strong> 6.4 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-14042">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-11993 – The WooCommerce Infinite Scroll and Ajax Pagination plugin for WordPress is vuln...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-11993</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-11993</guid>
    <pubDate>Fri, 29 May 2026 07:16:13 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-11993</strong></p>
  <p>The WooCommerce Infinite Scroll and Ajax Pagination plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.8 via the 'settings' parameter in the 'import_settings' function. This is due to deserialization of untrusted data supplied via the import configuration feature without capability checks. This makes it possible for authenticated attackers, with Sub…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-502</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-11993">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-2128 – The Breeze plugin for WordPress is vulnerable to Exposure of Sensitive Informati...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-2128</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-2128</guid>
    <pubDate>Fri, 29 May 2026 05:16:19 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-2128</strong></p>
  <p>The Breeze plugin for WordPress is vulnerable to Exposure of Sensitive Information to an Unauthorized Actor in all versions up to, and including, 2.5.2 This is due to improper verification of the `wordpress_logged_in_` cookie in the `inc/cache/execute-cache.php` file when the "Cache Logged-in Users" setting is enabled. The plugin parses the username directly from the cookie value (e.g., `username…</p>
  <p><strong>CVSS:</strong> 5.3 · <strong>CWE:</strong> CWE-200</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-2128">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-8995 – The Poll Maker – Versus Polls, Anonymous Polls, Image Polls plugin for WordPress...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-8995</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-8995</guid>
    <pubDate>Fri, 29 May 2026 04:17:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-8995</strong></p>
  <p>The Poll Maker – Versus Polls, Anonymous Polls, Image Polls plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to and including 6.3.7. This is due to insufficient access controls on the 'ays_poll_get_user_information' AJAX action, which serializes and returns the complete WP_User object — including the user_pass (bcrypt password hash), user_email, user_login, user…</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-200</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-8995">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-7430 – The Post Snippets plugin for WordPress is vulnerable to Stored Cross-Site Script...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-7430</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-7430</guid>
    <pubDate>Fri, 29 May 2026 04:17:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-7430</strong></p>
  <p>The Post Snippets plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 4.0.19. This is due to insufficient output escaping of imported snippet content when rendering JavaScript variables in the post editor. Specifically, the `jqueryUiDialog()` method in `WPEditor.php` embeds snippet content directly into JavaScript string literals without escapin…</p>
  <p><strong>CVSS:</strong> 4.4 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-7430">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-8809 – The Advanced Custom Fields: Extended plugin for WordPress is vulnerable to Privi...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-8809</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-8809</guid>
    <pubDate>Thu, 28 May 2026 23:16:44 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-8809</strong></p>
  <p>The Advanced Custom Fields: Extended plugin for WordPress is vulnerable to Privilege Escalation via Validation Bypass in all versions up to and including 0.9.2.5. The vulnerability exists due to the after_validate_save_post() function unconditionally trusting the attacker-controlled _acf_post_id POST parameter — with no authentication or integrity verification — to select a cleanup branch that si…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-269</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-8809">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-9015 – The Equalize Digital Accessibility Checker – WCAG, ADA, EAA and Section 508 comp...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-9015</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-9015</guid>
    <pubDate>Thu, 28 May 2026 09:16:49 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-9015</strong></p>
  <p>The Equalize Digital Accessibility Checker – WCAG, ADA, EAA and Section 508 compliance plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.42.0. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers, with subscriber-level access and above, to modify the igno…</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-862</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-9015">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-8689 – The Visualizer: Tables and Charts Manager for WordPress plugin for WordPress is ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-8689</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-8689</guid>
    <pubDate>Thu, 28 May 2026 09:16:48 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-8689</strong></p>
  <p>The Visualizer: Tables and Charts Manager for WordPress plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 3.11.14. This is due to a missing capability check on the renderChartPages() and uploadData() functions, where the wp_ajax_visualizer-create-chart and wp_ajax_visualizer-edit-chart AJAX actions invoke renderChartPages() without any current_user_…</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-862</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-8689">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-7526 – The PDF Embedder plugin for WordPress is vulnerable to Sensitive Information Exp...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-7526</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-7526</guid>
    <pubDate>Thu, 28 May 2026 09:16:48 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-7526</strong></p>
  <p>The PDF Embedder plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 4.9.3 via the enqueue_block_assets. This makes it possible for authenticated attackers, with contributor-level access and above, to extract configuration data. License key exposure occurs when the premium add-on is also installed and has saved a key; on Lite-only installatio…</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-200</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-7526">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-7048 – The Photo Gallery by 10Web – Mobile-Friendly Image Gallery plugin for WordPress ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-7048</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-7048</guid>
    <pubDate>Thu, 28 May 2026 09:16:48 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-7048</strong></p>
  <p>The Photo Gallery by 10Web – Mobile-Friendly Image Gallery plugin for WordPress is vulnerable to time-based blind SQL Injection via the 'order_by' parameter in all versions up to, and including, 1.8.40 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with contributor-level…</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-7048">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-6937 – The Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin p...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-6937</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-6937</guid>
    <pubDate>Thu, 28 May 2026 09:16:48 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-6937</strong></p>
  <p>The Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 1.6.11.8 due to the plugin not properly verifying that a user is authorized to perform an action via the bulk appointments REST API endpoint. This makes it possible for unauthenticated attackers to modify arbitrary appoint…</p>
  <p><strong>CVSS:</strong> 5.3 · <strong>CWE:</strong> CWE-862</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-6937">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-6226 – The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to unauthent...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-6226</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-6226</guid>
    <pubDate>Thu, 28 May 2026 09:16:47 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-6226</strong></p>
  <p>The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to unauthenticated privilege escalation in versions up to and including 3.29.2. This is due to insecure form submission handling that accepts arbitrary form definitions from user input instead of securely loading them from the backend. When $_POST['_acf_form'] is an array (rather than a form ID), the validate_form() function bypa…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-269</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-6226">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-4334 – The Shariff Wrapper plugin for WordPress is vulnerable to Stored Cross-Site Scri...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-4334</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-4334</guid>
    <pubDate>Thu, 28 May 2026 09:16:45 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-4334</strong></p>
  <p>The Shariff Wrapper plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'headline' parameter in the [shariff] shortcode in all versions up to, and including, 4.6.20 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute…</p>
  <p><strong>CVSS:</strong> 6.4 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-4334">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-9618 – The PeachPay — Payments &amp; Express Checkout for WooCommerce (supports Stripe, Pay...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-9618</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-9618</guid>
    <pubDate>Thu, 28 May 2026 08:16:37 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-9618</strong></p>
  <p>The PeachPay — Payments & Express Checkout for WooCommerce (supports Stripe, PayPal, Square, Authorize.net, NMI) plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.120.46. This is due to missing or incorrect nonce validation on the peachpay_stripe_handle_admin_actions function. This makes it possible for unauthenticated attackers to permanentl…</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-352</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-9618">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-9227 – The GutenBee – Gutenberg Blocks plugin for WordPress is vulnerable to Arbitrary ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-9227</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-9227</guid>
    <pubDate>Thu, 28 May 2026 08:16:37 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-9227</strong></p>
  <p>The GutenBee – Gutenberg Blocks plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 2.20.1 via the gutenbee_file_and_ext_json function. This is due to a flawed strpos() substring check that only verifies whether the filename contains the string '.json' rather than confirming the filename ends with a .json extension, allowing double-extension filenames…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-434</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-9227">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-8682 – The 3D Viewer – 3D Model Viewer – Augmented Reality – Virtual Try On plugin for ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-8682</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-8682</guid>
    <pubDate>Thu, 28 May 2026 08:16:37 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-8682</strong></p>
  <p>The 3D Viewer – 3D Model Viewer – Augmented Reality – Virtual Try On plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 2.0.1. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers, with subscriber-level access and above, to modify all plugin settings by writ…</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-862</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-8682">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-7862 – The Eupago Gateway For Woocommerce WordPress plugin before 4.7.2 does not proper...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-7862</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-7862</guid>
    <pubDate>Thu, 28 May 2026 08:16:37 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-7862</strong></p>
  <p>The Eupago Gateway For Woocommerce WordPress plugin before 4.7.2 does not properly restrict access to its refund request handler, allowing unauthenticated attackers to initiate refunds against any WooCommerce order using the merchant's payment gateway credentials, and for applicable payment methods, to redirect refunded funds to an attacker-controlled bank account.</p>
  <p><strong>CVSS:</strong> 8.6 · <strong>CWE:</strong> CWE-284</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-7862">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-7797 – The Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin p...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-7797</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-7797</guid>
    <pubDate>Thu, 28 May 2026 08:16:37 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-7797</strong></p>
  <p>The Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin plugin for WordPress is vulnerable to time-based blind SQL Injection via the 'append_where_sql' parameter in all versions up to, and including, 1.6.11.8 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated at…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-7797">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-7660 – The Easy Updates Manager plugin for WordPress is vulnerable to Reflected Cross-S...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-7660</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-7660</guid>
    <pubDate>Thu, 28 May 2026 08:16:37 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-7660</strong></p>
  <p>The Easy Updates Manager plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'paged' parameter in versions up to, and including, 9.0.20 This is due to insufficient input sanitization and output escaping in the pagination() function. This makes it possible for attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page gra…</p>
  <p><strong>CVSS:</strong> 6.1 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-7660">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-7651 – The User Registration &amp; Membership – Free &amp; Paid Memberships, Subscriptions, Con...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-7651</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-7651</guid>
    <pubDate>Thu, 28 May 2026 08:16:37 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-7651</strong></p>
  <p>The User Registration & Membership – Free & Paid Memberships, Subscriptions, Content Restriction, User Profile, Custom User Registration & Login Builder plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 5.1.5. This is due to missing ownership validation on a user-controlled attachment ID, allowing the plugin to store and subsequently dele…</p>
  <p><strong>CVSS:</strong> 5.3 · <strong>CWE:</strong> CWE-639</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-7651">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-7634 – The SlimStat Analytics plugin for WordPress is vulnerable to Stored Cross-Site S...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-7634</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-7634</guid>
    <pubDate>Thu, 28 May 2026 08:16:36 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-7634</strong></p>
  <p>The SlimStat Analytics plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'User-Agent' header in all versions up to, and including, 5.4.11 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. The show_complete_user…</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-7634">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-7621 – The SMTP2GO for WordPress – Email Made Easy plugin for WordPress is vulnerable t...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-7621</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-7621</guid>
    <pubDate>Thu, 28 May 2026 08:16:36 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-7621</strong></p>
  <p>The SMTP2GO for WordPress – Email Made Easy plugin for WordPress is vulnerable to unauthorized access in all versions up to, and including, 1.16.0. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers, with subscriber-level access and above, to truncate all SMTP2GO log records from the database or downl…</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-862</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-7621">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-7552 – The Geo Mashup plugin for WordPress is vulnerable to authorization bypass in all...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-7552</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-7552</guid>
    <pubDate>Thu, 28 May 2026 08:16:36 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-7552</strong></p>
  <p>The Geo Mashup plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.13.19. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for unauthenticated attackers to expose sensitive plugin configuration data, including Google Maps API keys and GeoNames service credentials, to unauthenticat…</p>
  <p><strong>CVSS:</strong> 5.3 · <strong>CWE:</strong> CWE-862</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-7552">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-7052 – The HT Contact Form – Drag &amp; Drop Form Builder for WordPress plugin for WordPres...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-7052</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-7052</guid>
    <pubDate>Thu, 28 May 2026 08:16:36 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-7052</strong></p>
  <p>The HT Contact Form – Drag & Drop Form Builder for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'file_upload' parameter in all versions up to, and including, 2.8.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses…</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-7052">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-6455 – The WP Contact Form 7 DB Handler plugin for WordPress is vulnerable to Cross-Sit...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-6455</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-6455</guid>
    <pubDate>Thu, 28 May 2026 08:16:36 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-6455</strong></p>
  <p>The WP Contact Form 7 DB Handler plugin for WordPress is vulnerable to Cross-Site Request Forgery leading to Arbitrary File Deletion via SQL Injection and PHP Object Injection in versions up to and including 3.0. This is due to a missing nonce verification in the process_bulk_action() function, the nonce check is only executed when _wpnonce is present in the POST body, allowing it to be trivially…</p>
  <p><strong>CVSS:</strong> 8.1 · <strong>CWE:</strong> CWE-352</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-6455">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-6427 – The a3 Lazy Load plugin for WordPress is vulnerable to Stored Cross-Site Scripti...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-6427</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-6427</guid>
    <pubDate>Thu, 28 May 2026 08:16:36 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-6427</strong></p>
  <p>The a3 Lazy Load plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 2.7.6 This is due to a regex bug in the _filter_videos() method that breaks HTML attribute quoting when processing crafted <video> elements, combined with unescaped output in the admin/views/form-data.php template. An authenticated attacker with Contributor-level access can ins…</p>
  <p><strong>CVSS:</strong> 6.4 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-6427">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-9644 – The LiveSmart Video Chat Live Video Chat plugin for WordPress is vulnerable to S...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-9644</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-9644</guid>
    <pubDate>Thu, 28 May 2026 06:16:29 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-9644</strong></p>
  <p>The LiveSmart Video Chat Live Video Chat plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'livesmart_widget' shortcode in all versions up to, and including, 1.2 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web…</p>
  <p><strong>CVSS:</strong> 6.4 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-9644">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-9009 – The Crawlomatic Multipage Scraper Post Generator plugin for WordPress is vulnera...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-9009</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-9009</guid>
    <pubDate>Thu, 28 May 2026 06:16:28 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-9009</strong></p>
  <p>The Crawlomatic Multipage Scraper Post Generator plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 2.7.2 via the filter_content function. This is due to passing the attacker-supplied 'callback_raw' shortcode attribute directly into call_user_func() with no sanitization or allowlist validation, relying solely on an is_callable() check that permits da…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-434</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-9009">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-7533 – The Easy Digital Downloads plugin for WordPress is vulnerable to Cross-Site Requ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-7533</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-7533</guid>
    <pubDate>Thu, 28 May 2026 06:16:28 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-7533</strong></p>
  <p>The Easy Digital Downloads plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.6.7. This is due to missing nonce verification in the `handle_oauth_redirect()` function, which is registered on the `admin_init` hook and processes Square OAuth tokens from a user-supplied GET parameter without any CSRF token validation. This makes it possible for u…</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-352</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-7533">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-3173 – The Meta Field Block plugin for WordPress is vulnerable to Insecure Direct Objec...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-3173</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-3173</guid>
    <pubDate>Thu, 28 May 2026 06:16:26 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-3173</strong></p>
  <p>The Meta Field Block plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 1.5.1. This is due to the plugin allowing users to specify arbitrary object IDs and object types via block attributes without validating whether the authenticated user has permission to access the requested object's metadata. This makes it possible for authenticated at…</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-639</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-3173">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-9241 – The FOX – Currency Switcher Professional for WooCommerce plugin for WordPress is...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-9241</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-9241</guid>
    <pubDate>Thu, 28 May 2026 05:16:39 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-9241</strong></p>
  <p>The FOX – Currency Switcher Professional for WooCommerce plugin for WordPress is vulnerable to Authorization Bypass Through User-Controlled Key in all versions up to and including 1.4.6. This is due to the `get_value()` function in `classes/fixed/fixed_user_role.php` trusting the attacker-controlled `$_REQUEST['wooc_order_user_roles']` parameter to determine the user's role context for role-based…</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-639</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-9241">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-9228 – The Timetable and Event Schedule by MotoPress plugin for WordPress is vulnerable...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-9228</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-9228</guid>
    <pubDate>Thu, 28 May 2026 05:16:39 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-9228</strong></p>
  <p>The Timetable and Event Schedule by MotoPress plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 2.4.16 via the action_get_event_data due to missing validation on a user controlled key. This makes it possible for authenticated attackers, with contributor-level access and above, to enumerate timeslot IDs and read the full WP_Post object — i…</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-639</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-9228">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-7802 – The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to authoriza...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-7802</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-7802</guid>
    <pubDate>Thu, 28 May 2026 05:16:38 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-7802</strong></p>
  <p>The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 3.29.2. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers, with subscriber-level access and above, to overwrite an administrator's user_pass, user_email, first_name, last_…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-862</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-7802">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-5737 – The Independent Analytics plugin for WordPress is vulnerable to Server-Side Requ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-5737</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-5737</guid>
    <pubDate>Thu, 28 May 2026 05:16:38 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-5737</strong></p>
  <p>The Independent Analytics plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 2.14.9. This is due to a public tracking route at /wp-json/iawp/search that accepts attacker-controlled referrer_url values when the signature matches, combined with a scheduled favicon fetcher that performs unrestricted cURL requests to stored domains. The signature v…</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-918</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-5737">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-2374 – The Login No Captcha reCAPTCHA plugin for WordPress is vulnerable to Stored Cros...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-2374</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-2374</guid>
    <pubDate>Thu, 28 May 2026 05:16:34 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-2374</strong></p>
  <p>The Login No Captcha reCAPTCHA plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `$_SERVER['PHP_SELF']` superglobal in all versions up to, and including, 1.8.0. This is due to the `authenticate()` function storing the unsanitized output of `basename($_SERVER['PHP_SELF'])` in the `login_nocaptcha_error` WordPress option when a login attempt is made from a non-standard login…</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-2374">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-4888 – The Everest Forms – Contact Form, Payment Form, Quiz, Survey &amp; Custom Form Build...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-4888</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-4888</guid>
    <pubDate>Thu, 28 May 2026 00:16:43 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-4888</strong></p>
  <p>The Everest Forms – Contact Form, Payment Form, Quiz, Survey & Custom Form Builder plugin for WordPress is vulnerable to unauthorized email sending due to a missing capability check on the send_test_email() function in all versions up to, and including, 3.4.7. This makes it possible for authenticated attackers, with Subscriber-level access and above, to send test emails to arbitrary addresses fro…</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-862</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-4888">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-42726 – Missing Authorization vulnerability in Strategy11 Team AWP Classifieds another-w...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-42726</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-42726</guid>
    <pubDate>Wed, 27 May 2026 11:16:18 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-42726</strong></p>
  <p>Missing Authorization vulnerability in Strategy11 Team AWP Classifieds another-wordpress-classifieds-plugin allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects AWP Classifieds: from n/a through <= 4.4.5.</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-862</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-42726">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-3349 – The MinhNhut Link Gateway plugin for WordPress is vulnerable to Reflected Cross-...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-3349</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-3349</guid>
    <pubDate>Wed, 27 May 2026 11:16:18 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-3349</strong></p>
  <p>The MinhNhut Link Gateway plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'url' parameter on the redirect page in all versions up to, and including, 3.6.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into perfo…</p>
  <p><strong>CVSS:</strong> 6.1 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-3349">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-3348 – The MinhNhut Link Gateway plugin for WordPress is vulnerable to Stored Cross-Sit...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-3348</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-3348</guid>
    <pubDate>Wed, 27 May 2026 11:16:18 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-3348</strong></p>
  <p>The MinhNhut Link Gateway plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's settings (Description, Title, and other fields) in all versions up to, and including, 3.6.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Administrator-level access and above, to inject arbitrary web scripts in pages th…</p>
  <p><strong>CVSS:</strong> 4.4 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-3348">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-2288 – The myLinksDump plugin for WordPress is vulnerable to Stored Cross-Site Scriptin...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-2288</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-2288</guid>
    <pubDate>Wed, 27 May 2026 11:16:17 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-2288</strong></p>
  <p>The myLinksDump plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'link_title' parameter in all versions up to, and including, 1.6 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an in…</p>
  <p><strong>CVSS:</strong> 4.8 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-2288">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-2280 – The rexCrawler plugin for WordPress is vulnerable to Stored Cross-Site Scripting...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-2280</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-2280</guid>
    <pubDate>Wed, 27 May 2026 11:16:17 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-2280</strong></p>
  <p>The rexCrawler plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 1.0.15 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injecte…</p>
  <p><strong>CVSS:</strong> 4.8 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-2280">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-0898 – The Xpro Elementor Addons - Pro plugin for WordPress is vulnerable to Arbitrary ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-0898</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-0898</guid>
    <pubDate>Wed, 27 May 2026 11:16:16 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-0898</strong></p>
  <p>The Xpro Elementor Addons - Pro plugin for WordPress is vulnerable to Arbitrary File Reading in all versions up to, and including, 1.4.7 via the Draw SVG widget. This makes it possible for authenticated attackers, with Contributor-level access and above, to read the contents of arbitrary files on the server, which can contain sensitive information.</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-73</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-0898">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-8942 – The MetaMagic SEO Plugin plugin for WordPress is vulnerable to Cross-Site Reques...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-8942</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-8942</guid>
    <pubDate>Wed, 27 May 2026 08:16:45 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-8942</strong></p>
  <p>The MetaMagic SEO Plugin plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.6. This is due to missing or incorrect nonce validation on the metamagic_update_options function. This makes it possible for unauthenticated attackers to modify the plugin's SEO settings, including enabling or disabling the plugin and toggling description and keyword m…</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-352</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-8942">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-8906 – The WP Promoter plugin for WordPress is vulnerable to Cross-Site Request Forgery...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-8906</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-8906</guid>
    <pubDate>Wed, 27 May 2026 08:16:45 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-8906</strong></p>
  <p>The WP Promoter plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.3. This is due to missing or incorrect nonce validation on a function. This makes it possible for unauthenticated attackers to update settings and inject malicious web scripts via a forged request granted they can trick a site administrator into performing an action such as cli…</p>
  <p><strong>CVSS:</strong> 6.1 · <strong>CWE:</strong> CWE-352</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-8906">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-8832 – The WPCode - Insert Headers and Footers + Custom Code Snippets - WordPress Code ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-8832</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-8832</guid>
    <pubDate>Wed, 27 May 2026 08:16:45 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-8832</strong></p>
  <p>The WPCode - Insert Headers and Footers + Custom Code Snippets - WordPress Code Manager plugin for WordPress is vulnerable to Remote Code Execution in versions up to, and including, 2.3.5 This is due to the 'wpcode' custom post type being registered without a custom capability_type or capability restrictions in the wpcode_register_post_type() function, allowing WordPress core to fall back to stan…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-94</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-8832">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-8143 – The HBook plugin for WordPress is vulnerable to Stored Cross-Site Scripting via ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-8143</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-8143</guid>
    <pubDate>Wed, 27 May 2026 08:16:45 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-8143</strong></p>
  <p>The HBook plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'hb_country_iso', 'hb_usa_state_iso', and 'hb_canada_province_iso' parameters in all versions up to, and including, 2.1.6 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user acces…</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-8143">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-8042 – The Github Shortcode plugin for WordPress is vulnerable to Stored Cross-Site Scr...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-8042</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-8042</guid>
    <pubDate>Wed, 27 May 2026 08:16:45 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-8042</strong></p>
  <p>The Github Shortcode plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'repo' shortcode attribute in the 'github' shortcode in all versions up to, and including, 0.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execu…</p>
  <p><strong>CVSS:</strong> 6.4 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-8042">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-7618 – The EnvíaloSimple: Email Marketing y Newsletters plugin for WordPress is vulnera...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-7618</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-7618</guid>
    <pubDate>Wed, 27 May 2026 08:16:45 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-7618</strong></p>
  <p>The EnvíaloSimple: Email Marketing y Newsletters plugin for WordPress is vulnerable to time-based blind SQL Injection via the 'orderby' parameter in all versions up to, and including, 2.4.5 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with administrator-level access and…</p>
  <p><strong>CVSS:</strong> 4.9 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-7618">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-6169 – The affiliate-toolkit plugin for WordPress is vulnerable to remote code executio...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-6169</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-6169</guid>
    <pubDate>Wed, 27 May 2026 08:16:44 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-6169</strong></p>
  <p>The affiliate-toolkit plugin for WordPress is vulnerable to remote code execution in all versions up to, and including, 3.8.5. This is due to the plugin using the BladeOne templating engine's runString() method which compiles user-supplied template content into PHP code and executes it via eval() without sanitization or sandboxing. This makes it possible for authenticated attackers, with Editor-l…</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> CWE-94</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-6169">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-3897 – The Livemesh Addons for Beaver Builder plugin for WordPress is vulnerable to Sto...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-3897</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-3897</guid>
    <pubDate>Wed, 27 May 2026 08:16:41 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-3897</strong></p>
  <p>The Livemesh Addons for Beaver Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `labb_admin_ajax` AJAX action in all versions up to, and including, 3.9.2 due to missing authorization checks and insufficient input sanitization. The AJAX handler verifies a nonce but does not check user capabilities. This makes it possible for authenticated attackers with Subscriber-…</p>
  <p><strong>CVSS:</strong> 6.4 · <strong>CWE:</strong> CWE-862</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-3897">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-3896 – The Livemesh SiteOrigin Widgets plugin for WordPress is vulnerable to Stored Cro...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-3896</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-3896</guid>
    <pubDate>Wed, 27 May 2026 08:16:40 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-3896</strong></p>
  <p>The Livemesh SiteOrigin Widgets plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `lsow_admin_ajax` AJAX action in all versions up to, and including, 3.9.2 due to missing authorization checks and insufficient input sanitization. The AJAX handler verifies a nonce but does not check user capabilities. This makes it possible for authenticated attackers with Subscriber-level a…</p>
  <p><strong>CVSS:</strong> 6.4 · <strong>CWE:</strong> CWE-862</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-3896">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-3895 – The WPBakery Page Builder Addons by Livemesh plugin for WordPress is vulnerable ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-3895</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-3895</guid>
    <pubDate>Wed, 27 May 2026 08:16:40 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-3895</strong></p>
  <p>The WPBakery Page Builder Addons by Livemesh plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `lvca_admin_ajax` AJAX action in all versions up to, and including, 3.9.4 due to missing authorization checks and insufficient input sanitization. The AJAX handler verifies a nonce but does not check user capabilities. This makes it possible for authenticated attackers with Subsc…</p>
  <p><strong>CVSS:</strong> 6.4 · <strong>CWE:</strong> CWE-862</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-3895">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-3375 – The LiteSpeed Cache plugin for WordPress is vulnerable to Stored Cross-Site Scri...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-3375</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-3375</guid>
    <pubDate>Wed, 27 May 2026 08:16:40 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-3375</strong></p>
  <p>The LiteSpeed Cache plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the /wp-json/litespeed/v1/notify_ccss and /wp-json/litespeed/v1/notify_ucss REST API endpoints in all versions up to, and including, 7.7. These endpoints accept CSS content from QUIC.cloud callback notifications and store it to disk without sanitization. The stored content is later rendered inline frontend p…</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-3375">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-3279 – The Enable jQuery Migrate Helper plugin for WordPress is vulnerable to unauthori...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-3279</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-3279</guid>
    <pubDate>Wed, 27 May 2026 08:16:40 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-3279</strong></p>
  <p>The Enable jQuery Migrate Helper plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the `downgrade_jquery_version()` function in all versions up to, and including, 1.4.1. This is due to the function only verifying a nonce without checking user capabilities. This makes it possible for authenticated attackers, with Subscriber-level access an…</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-862</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-3279">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-3001 – The Gutenverse plugin for WordPress is vulnerable to Reflected Cross-Site Script...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-3001</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-3001</guid>
    <pubDate>Wed, 27 May 2026 08:16:40 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-3001</strong></p>
  <p>The Gutenverse plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 's' parameter in all versions up to, and including, 3.4.6 due to insufficient input sanitization and output escaping. Specifically, the `render_content()` method in `class-search-result-title.php` outputs the value of `get_query_var('s')` directly into the page HTML without applying `esc_html()` or any oth…</p>
  <p><strong>CVSS:</strong> 6.1 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-3001">View on NVD</a></p>
]]>
    </description>
  </item>
</channel>
</rss>
