Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
0.0 NA
CVE-2026-92767 — Twenty20 Image Before-After <= 2.0.5 - Authenticated (Contributor+) Stored Cross-Site Scr…

The Twenty20 Image Before-After plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'offset' Shortcode Attribute in all versions up to, and including, 2.0.5 due to insufficient inpu…

| Cross-Site Scripting
Oct 03, 2026 Oct 03, 2026
Oct 03, 2026
Oct 03, 2026
0.0 NA
CVE-2026-92084 — Beaver Builder Page Builder <= 2.11.0.5 - Unauthenticated Arbitrary Shortcode Execution v…

The The Beaver Builder Page Builder – Drag and Drop Website Builder plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 2.11.0.5. This is due to …

| Injection
Oct 03, 2026 Oct 03, 2026
Oct 03, 2026
Oct 03, 2026
7.2 HIGH
CVE-2026-97660 — WPC Product Options for WooCommerce <= 4.0.5 - Unauthenticated Stored Cross-Site Scriptin…

The WPC Product Options for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via wpcpo-* Array Key via Multipart Field Name in all versions up to, and including, 4.0.5 du…

Remote | Cross-Site Scripting
Oct 03, 2026 Oct 03, 2026
Oct 03, 2026
Oct 03, 2026
4.3 MEDIUM
CVE-2026-97343 — Burst Statistics <= 3.7.1 - Improper Authentication to Account Persistence via Share-Link…

The Burst Statistics – Simple WordPress Analytics (Google Analytics Alternative) plugin for WordPress is vulnerable to Improper Authentication leading to Account Persistence in all versions up to, an…

Remote | Authentication
Oct 03, 2026 Oct 03, 2026
Oct 03, 2026
Oct 03, 2026
7.5 HIGH
CVE-2026-96267 — WP Visitor Statistics (Real Time Traffic) <= 8.7 - Unauthenticated SQL Injection via 'ful…

The WP Visitor Statistics (Real Time Traffic) plugin for WordPress is vulnerable to generic SQL Injection via the 'fullRef' parameter in all versions up to, and including, 8.7 due to insufficient esc…

visitor_statistics | Remote | Injection
Oct 03, 2026 Oct 03, 2026
Oct 03, 2026
Oct 03, 2026
8.1 HIGH
CVE-2026-94505 — Nelio Content <= 4.5.0 - Missing Authorization to Authenticated (Contributor+) Arbitrary …

The Nelio Content – Editorial Calendar & Social Media Auto-Posting plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 4.5.0 This is due to the plugin not…

Remote | Authorization
Oct 03, 2026 Oct 03, 2026
Oct 03, 2026
Oct 03, 2026
6.1 MEDIUM
CVE-2026-93896 — WPFront Notification Bar <= 3.5.1 - Reflected Cross-Site Scripting via REQUEST_URI

The WPFront Notification Bar plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 3.5.1. This is due to the debug-log output path (write_debug_logs) …

wpfront_notification_bar | Remote | Cross-Site Scripting
Oct 03, 2026 Oct 03, 2026
Oct 03, 2026
Oct 03, 2026
7.2 HIGH
CVE-2026-93889 — Mail logging <= 2.1.12 - Unauthenticated Stored Cross-Site Scripting via PHPMailer 'wp_ma…

The Mail logging – WP Mail Catcher plugin for WordPress is vulnerable to Stored Cross-Site Scripting via PHPMailer 'wp_mail_failed' Error Message in all versions up to, and including, 2.1.12 due to i…

Remote | Cross-Site Scripting
Oct 03, 2026 Oct 03, 2026
Oct 03, 2026
Oct 03, 2026
6.1 MEDIUM
CVE-2026-92974 — Photo Gallery by 10Web <= 1.8.46 - Reflected Cross-Site Scripting via 'thumb_url' Paramet…

The Photo Gallery by 10Web – Mobile-Friendly Image Gallery plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'thumb_url' parameter in all versions up to, and including, 1.8…

photo_gallery | Remote | Cross-Site Scripting
Oct 03, 2026 Oct 03, 2026
Oct 03, 2026
Oct 03, 2026
9.1 CRITICAL
CVE-2026-87115 — VikAppointments Services Booking Calendar <= 1.2.21 - Unauthenticated Arbitrary File Dele…

The VikAppointments Services Booking Calendar plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the extract function in all versions up to, and…

Remote | Path Traversal
Oct 03, 2026 Oct 03, 2026
Oct 03, 2026
Oct 03, 2026
7.5 HIGH
CVE-2026-75028 — WPCafe <= 3.0.18 - Authenticated (Contributor+) Local File Inclusion via 'food_menu_style…

The WPCafe – Restaurant Menu, Online Food Ordering & Table Booking System plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 3.0.18 via the (template sco…

wpcafe | Remote | Path Traversal
Oct 03, 2026 Oct 03, 2026
Oct 03, 2026
Oct 03, 2026
8.8 HIGH
CVE-2026-18443 — Smart Manager <= 8.97.0 - Authenticated (Subscriber+) SQL Injection to Privilege Escalati…

The Smart Manager – Advanced WooCommerce Bulk Edit & Inventory Management plugin for WordPress is vulnerable to generic SQL Injection via the 'access_privileges' parameter in all versions up to, and …

Remote | Injection
Oct 03, 2026 Oct 03, 2026
Oct 03, 2026
Oct 03, 2026
6.4 MEDIUM
CVE-2026-15795 — Responsive Plus <= 3.5.3 - Authenticated (Contributor+) Stored Cross-Site Scripting via S…

The Responsive Plus – Elementor Templates & Starter Sites plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Shortcode Attributes in all versions up to, and including, 3.5.3 due to…

Remote | Cross-Site Scripting
Oct 03, 2026 Oct 03, 2026
Oct 03, 2026
Oct 03, 2026
5.3 MEDIUM
CVE-2026-11601 — WPCafe <= 3.0.19 - Missing Authorization to Unauthenticated Arbitrary Email Notification …

The WPCafe – Restaurant Menu, Online Food Ordering & Table Booking System plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 3.0.19. This is due to the p…

wpcafe | Remote | Authorization
Oct 03, 2026 Oct 03, 2026
Oct 03, 2026
Oct 03, 2026
6.1 MEDIUM
CVE-2026-104313 — WPC Estimated Delivery Date for WooCommerce <= 4.0.1 - Reflected Cross-Site Scripting via…

The WPC Estimated Delivery Date for WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'rule_data' parameter in all versions up to, and including, 4.0.1 due to i…

Remote | Cross-Site Scripting
Oct 03, 2026 Oct 03, 2026
Oct 03, 2026
Oct 03, 2026
5.4 MEDIUM
CVE-2026-103519 — WP Ultimate Review <= 2.4.3 - Authenticated (Subscriber+) Arbitrary Shortcode Execution v…

The The WP Ultimate Review plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 2.4.3. This is due to the software allowing users to execute an ac…

wp_ultimate_review | Remote | Injection
Oct 03, 2026 Oct 03, 2026
Oct 03, 2026
Oct 03, 2026
5.4 MEDIUM
CVE-2026-103421 — WPMobile.App <= 11.84 - Unauthenticated Stored Cross-Site Scripting via '/android_json/se…

The WPMobile.App – Android and iOS App Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'REQUEST_URI (path segment after /android_json/search/)' parameter in all vers…

Remote | Cross-Site Scripting
Oct 03, 2026 Oct 03, 2026
Oct 03, 2026
Oct 03, 2026
6.5 MEDIUM
CVE-2026-100157 — WP Ultimate Review <= 2.4.3 - Unauthenticated Arbitrary Shortcode Execution via 'xs_reviw…

The The WP Ultimate Review plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 2.4.3. This is due to the software allowing users to execute an ac…

wp_ultimate_review | Remote | Injection
Oct 03, 2026 Oct 03, 2026
Oct 03, 2026
Oct 03, 2026
6.4 MEDIUM
CVE-2026-97344 — Wp Social Login and Register Social Counter <= 3.2.1 - Authenticated (Subscriber+) Stored…

The Wp Social Login and Register Social Counter plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Avatar Alt Attribute via Arbitrary User Meta Write in all versions up to, and inc…

wp_social_login_and_register_social_counter | Remote | Cross-Site Scripting
Oct 03, 2026 Oct 03, 2026
Oct 03, 2026
Oct 03, 2026
7.2 HIGH
CVE-2026-97341 — Visitor Traffic Real Time Statistics <= 8.16 - Unauthenticated Stored DOM-Based Cross-Sit…

The Visitor Traffic Real Time Statistics plugin for WordPress is vulnerable to Stored DOM-Based Cross-Site Scripting via 'X-Real-IP' HTTP Header in all versions up to, and including, 8.16 due to insu…

visitor_traffic_real_time_statistics | Remote | Cross-Site Scripting
Oct 03, 2026 Oct 03, 2026
Oct 03, 2026
Oct 03, 2026
Showing 20 of 15037 Results