Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
6.1 MEDIUM
CVE-2026-8420 — BLOGCHAT Chat System <= 1.3.6.3 - Cross-Site Request Forgery to Stored Cross-Site Scripti…

The BLOGCHAT Chat System plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.3.6.3. This is due to missing or incorrect nonce validation on a func…

Remote | Cross-Site Request Forgery
May 20, 2026 May 20, 2026
May 20, 2026
May 20, 2026
4.3 MEDIUM
CVE-2026-8419 — Amazon Scraper <= 1.1 - Cross-Site Request Forgery to Stored Cross-Site Scripting via Set…

The Amazon Scraper plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.1. This is due to missing or incorrect nonce validation on a function. This…

Remote | Cross-Site Request Forgery
May 20, 2026 May 20, 2026
May 20, 2026
May 20, 2026
4.3 MEDIUM
CVE-2026-8418 — Games Catalog <= 1.2.0 - Cross-Site Request Forgery to Arbitrary Game/Post Deletion

The Games Catalog plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.2.0. This is due to missing or incorrect nonce validation on the gc_crud() funct…

Remote | Cross-Site Request Forgery
May 20, 2026 May 20, 2026
May 20, 2026
May 20, 2026
6.4 MEDIUM
CVE-2026-8038 — Faces of Users <= 0.0.3 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'd…

The Faces of Users plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'default' shortcode attribute in the 'facesofusers' shortcode in all versions up to, and including, 0.0.3 …

Remote | Cross-Site Scripting
May 20, 2026 May 20, 2026
May 20, 2026
May 20, 2026
4.9 MEDIUM
CVE-2026-7472 — Read More & Accordion <= 3.5.7 - Authenticated (Administrator+) SQL Injection via 'orderb…

The Read More & Accordion plugin for WordPress is vulnerable to time-based blind SQL Injection via the 'orderby' parameter in all versions up to, and including, 3.5.7. This is due to the use of esc_s…

Remote | Injection
May 20, 2026 May 20, 2026
May 20, 2026
May 20, 2026
8.8 HIGH
CVE-2026-7467 — Read More & Accordion <= 3.5.7 - Privilege Escalation via importData

The Read More & Accordion plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 3.5.7. This is due to the 'RadMoreAjax::importData' function not restricting…

Remote | Authentication
May 20, 2026 May 20, 2026
May 20, 2026
May 20, 2026
6.1 MEDIUM
CVE-2026-7462 — VatanSMS WP SMS <= 1.01 - Reflected Cross-Site Scripting via 'page' Parameter

The VatanSMS WP SMS plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the `page` parameter in all versions up to, and including, 1.01. This is due to insufficient input sanitiz…

Remote | Cross-Site Scripting
May 20, 2026 May 20, 2026
May 20, 2026
May 20, 2026
9.8 CRITICAL
CVE-2026-7284 — Easy Elements for Elementor <= 1.4.4 - Unauthenticated Privilege Escalation via easyel_ha…

The Easy Elements for Elementor – Addons & Website Templates plugin for WordPress is vulnerable to privilege escalation via user registration in all versions up to, and including, 1.4.4. This is due …

Remote | Authorization
May 20, 2026 May 20, 2026
May 20, 2026
May 20, 2026
9.8 CRITICAL
CVE-2026-6555 — ProSolution WP Client <= 2.0.0 - Unauthenticated Arbitrary File Upload via 'files'

The ProSolution WP Client plugin for WordPress is vulnerable to Arbitrary File Upload in versions up to, and including, 2.0.0. This is due to an array validation mismatch where only the first file in…

Remote | Authentication
May 20, 2026 May 20, 2026
May 20, 2026
May 20, 2026
6.4 MEDIUM
CVE-2026-6549 — Logo Manager For Enamad <= 0.7.4 - Authenticated (Contributor+) Stored Cross-Site Scripti…

The Logo Manager For Enamad plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'title' attribute of the `vc_enamad_namad`, `vc_enamad_shamed`, and `vc_enamad_custom` shortcodes…

Remote | Cross-Site Scripting
May 20, 2026 May 20, 2026
May 20, 2026
May 20, 2026
8.8 HIGH
CVE-2026-6456 — Account Switcher <= 1.0.2 - Authenticated (Subscriber+) Authentication Bypass to Privileg…

The Account Switcher plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.0.2. This is due to the `rememberLogin` REST API endpoint using a loose compari…

Remote | Authentication
May 20, 2026 May 20, 2026
May 20, 2026
May 20, 2026
4.3 MEDIUM
CVE-2026-6452 — Bigfishgames Syndicate <= 1.2 - Cross-Site Request Forgery to Settings Reset and Update

The Bigfishgames Syndicate plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.2. This is due to missing or incorrect nonce validation on the bigf…

Remote | Cross-Site Request Forgery
May 20, 2026 May 20, 2026
May 20, 2026
May 20, 2026
4.4 MEDIUM
CVE-2026-6404 — Anomify AI <= 0.3.6 - Authenticated (Administrator+) Stored Cross-Site Scripting via 'ano…

The Anomify AI – Anomaly Detection and Alerting plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'anomify_api_key' parameter in versions up to and including 0.3.6. This is du…

Remote | Cross-Site Scripting
May 20, 2026 May 20, 2026
May 20, 2026
May 20, 2026
4.3 MEDIUM
CVE-2026-6401 — Bottom Bar <= 0.1.7 - Cross-Site Request Forgery to Settings Update

The Bottom Bar plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to and including 0.1.7. This is due to missing nonce verification on the plugin's settings update fo…

Remote | Cross-Site Request Forgery
May 20, 2026 May 20, 2026
May 20, 2026
May 20, 2026
4.3 MEDIUM
CVE-2026-6400 — Child Height Predictor by Ostheimer <= 1.3 - Cross-Site Request Forgery to Settings Updat…

The Child Height Predictor by Ostheimer plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to and including 1.3. This is due to missing nonce verification in the opti…

Remote | Cross-Site Request Forgery
May 20, 2026 May 20, 2026
May 20, 2026
May 20, 2026
4.4 MEDIUM
CVE-2026-6399 — General Options <= 1.1.0 - Authenticated (Administrator+) Stored Cross-Site Scripting via…

The General Options plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to and including 1.1.0. This is due to the use of sanitize_text_field() for output escaping in the…

Remote | Cross-Site Scripting
May 20, 2026 May 20, 2026
May 20, 2026
May 20, 2026
6.4 MEDIUM
CVE-2026-6397 — Sticky <= 2.5.6 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'readmoret…

The Sticky plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `cvmh-sticky` shortcode `readmoretext` attribute in versions up to and including 2.5.6. This is due to insufficien…

Remote | Cross-Site Scripting
May 20, 2026 May 20, 2026
May 20, 2026
May 20, 2026
6.1 MEDIUM
CVE-2026-6395 — Word 2 Cash <= 0.9.2 - Cross-Site Request Forgeryto Stored Cross-Site Scripting via Setti…

The Word 2 Cash plugin for WordPress is vulnerable to Cross-Site Request Forgery leading to Stored Cross-Site Scripting in versions up to and including 0.9.2. This is due to the complete absence of n…

Remote | Cross-Site Request Forgery
May 20, 2026 May 20, 2026
May 20, 2026
May 20, 2026
5.4 MEDIUM
CVE-2026-6394 — Nexa Blocks <= 1.1.1 - Unauthenticated Blind Server-Side Request Forgery via 'demo_json_f…

The Nexa Blocks – Gutenberg Blocks, Page Builder for Gutenberg Editor & FSE plugin for WordPress is vulnerable to Server-Side Request Forgery (SSRF) in versions up to and including 1.1.1. This is due…

Remote | Server-Side Request Forgery
May 20, 2026 May 20, 2026
May 20, 2026
May 20, 2026
6.1 MEDIUM
CVE-2026-6391 — Sentence To SEO (keywords, description and tags) <= 1.0 - Cross-Site Request Forgery to S…

The Sentence To SEO (keywords, description and tags) plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0. This is due to missing or incorrect no…

Remote | Cross-Site Request Forgery
May 20, 2026 May 20, 2026
May 20, 2026
May 20, 2026
Showing 20 of 6414 Results