Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
6.4 MEDIUM
CVE-2026-1187 — ZoomifyWP Free <= 1.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'fil…

The ZoomifyWP Free plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'filename' parameter of the 'zoomify' shortcode in all versions up to, and including, 1.1 due to insuffici…

Remote | Cross-Site Scripting
Feb 14, 2026 Feb 18, 2026
Feb 14, 2026
Feb 18, 2026
6.4 MEDIUM
CVE-2026-1096 — Best-wp-google-map <= 2.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via …

The Best-wp-google-map plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'latitude' and 'longitudinal' parameters of the 'google_map_view' shortcode in all versions up to, and…

Remote | Cross-Site Scripting
Feb 14, 2026 Feb 18, 2026
Feb 14, 2026
Feb 18, 2026
7.2 HIGH
CVE-2026-0753 — Super Simple Contact Form <= 1.6.2 - Reflected Cross-Site Scripting via 'sscf_name' Param…

The Super Simple Contact Form plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'sscf_name' parameter in all versions up to, and including, 1.6.2 due to insufficient input …

Remote | Cross-Site Scripting
Feb 14, 2026 Feb 18, 2026
Feb 14, 2026
Feb 18, 2026
6.4 MEDIUM
CVE-2026-0751 — Payment Page | Payment Form for Stripe <= 1.4.6 - Authenticated (Author+) Stored Cross-Si…

The Payment Page | Payment Form for Stripe plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'pricing_plan_select_text_font_family' parameter in all versions up to, and includ…

Remote | Cross-Site Scripting
Feb 14, 2026 Feb 18, 2026
Feb 14, 2026
Feb 18, 2026
7.2 HIGH
CVE-2026-0745 — User Language Switch <= 1.6.10 - Authenticated (Administrator+) Server-Side Request Forge…

The User Language Switch plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 1.6.10 due to missing URL validation on the 'download_language()' func…

Remote | Server-Side Request Forgery
Feb 14, 2026 Feb 18, 2026
Feb 14, 2026
Feb 18, 2026
6.4 MEDIUM
CVE-2026-0736 — Chatbot for WordPress by Collect.chat ⚡️ <= 2.4.8 - Authenticated (Contributor+) Stored C…

The Chatbot for WordPress by Collect.chat plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the '_inpost_head_script[synth_header_script]' post meta field in all versions up to, a…

collect.chat | Remote | Cross-Site Scripting
Feb 14, 2026 Feb 18, 2026
Feb 14, 2026
Feb 18, 2026
4.4 MEDIUM
CVE-2026-0735 — User Language Switch <= 1.6.10 - Authenticated (Administrator+) Stored Cross-Site Scripti…

The User Language Switch plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'tab_color_picker_language_switch' parameter in all versions up to, and including, 1.6.10 due to ins…

Remote | Cross-Site Scripting
Feb 14, 2026 Feb 18, 2026
Feb 14, 2026
Feb 18, 2026
5.4 MEDIUM
CVE-2026-0727 — Accordion and Accordion Slider <= 1.4.5 - Missing Authorization to Authenticated (Contrib…

The Accordion and Accordion Slider plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.4.5. This is due to the plugin not properly verifying that a user…

Remote | Authorization
Feb 14, 2026 Feb 18, 2026
Feb 14, 2026
Feb 18, 2026
4.4 MEDIUM
CVE-2026-0693 — Allow HTML in Category Descriptions <= 1.2.4 - Authenticated (Administrator+) Stored Cros…

The Allow HTML in Category Descriptions plugin for WordPress is vulnerable to Stored Cross-Site Scripting via category descriptions in all versions up to, and including, 1.2.4. This is due to the plu…

Remote | Cross-Site Scripting
Feb 14, 2026 Feb 18, 2026
Feb 14, 2026
Feb 18, 2026
6.4 MEDIUM
CVE-2026-0559 — MasterStudy LMS WordPress Plugin – for Online Courses and Education <= 3.7.11 - Authentic…

The MasterStudy LMS WordPress Plugin – for Online Courses and Education plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'stm_lms_courses_grid_display' shortcode in …

masterstudy_lms | Remote | Cross-Site Scripting
Feb 14, 2026 Feb 18, 2026
Feb 14, 2026
Feb 18, 2026
6.4 MEDIUM
CVE-2026-0557 — WP Data Access <= 5.5.63 - Authenticated (Contributor+) Stored Cross-Site Scripting via '…

The WP Data Access plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'wpda_app' shortcode in all versions up to, and including, 5.5.63 due to insufficient input sanit…

Remote | Cross-Site Scripting
Feb 14, 2026 Feb 18, 2026
Feb 14, 2026
Feb 18, 2026
5.3 MEDIUM
CVE-2025-6792 — One to one user Chat by WPGuppy <= 1.1.4 - Unauthenticated Information Disclosure via Cha…

The One to one user Chat by WPGuppy plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the /wp-json/guppylite/v2/channel-authorize rest endpoint in…

Remote | Authorization
Feb 14, 2026 Feb 18, 2026
Feb 14, 2026
Feb 18, 2026
4.4 MEDIUM
CVE-2025-15483 — Link Hopper <= 2.5 - Authenticated (Administrator+) Stored Cross-Site Scripting via 'hop_…

The Link Hopper plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘hop_name’ parameter in all versions up to, and including, 2.5 due to insufficient input sanitization and out…

Remote | Cross-Site Scripting
Feb 14, 2026 Feb 18, 2026
Feb 14, 2026
Feb 18, 2026
4.3 MEDIUM
CVE-2025-14873 — LatePoint – Calendar Booking Plugin for Appointments and Events <= 5.2.5 - Cross-Site Req…

The LatePoint – Calendar Booking Plugin for Appointments and Events plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 5.2.5. This is due to the 'c…

Remote | Cross-Site Request Forgery
Feb 14, 2026 Feb 18, 2026
Feb 14, 2026
Feb 18, 2026
4.3 MEDIUM
CVE-2025-14852 — MDirector Newsletter <= 4.5.8 - Cross-Site Request Forgery to Plugin Settings Update

The MDirector Newsletter plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 4.5.8. This is due to missing nonce verification on the mdirectorNewsle…

Remote | Cross-Site Request Forgery
Feb 14, 2026 Feb 18, 2026
Feb 14, 2026
Feb 18, 2026
5.3 MEDIUM
CVE-2026-1932 — Appointment Booking Calendar Plugin <= 1.0.2 - Missing Authorization to Unauthenticated A…

The Appointment Booking Calendar Plugin – Bookr plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the update-appointment REST API endpoint i…

Remote | Authorization
Feb 14, 2026 Feb 18, 2026
Feb 14, 2026
Feb 18, 2026
7.6 HIGH
CVE-2026-2469 — Apache Directory Tree IMAP Engine Injection Vulnerability

Versions of the package directorytree/imapengine before 1.22.3 are vulnerable to Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') via the id() functi…

Remote | Injection
Feb 14, 2026 Feb 18, 2026
Feb 14, 2026
Feb 18, 2026
8.1 HIGH
CVE-2026-2144 — Magic Login Mail or QR Code <= 2.05 - Unauthenticated Privilege Escalation via Insecure Q…

The Magic Login Mail or QR Code plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 2.05. This is due to the plugin storing the magic login QR code image …

Remote | Race Condition
Feb 14, 2026 Feb 18, 2026
Feb 14, 2026
Feb 18, 2026
4.4 MEDIUM
CVE-2026-2027 — AMP Enhancer <= 1.0.49 - Authenticated (Administrator+) Stored Cross-Site Scripting via A…

The AMP Enhancer – Compatibility Layer for Official AMP Plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the AMP Custom CSS setting in all versions up to, and including, 1.0.49 d…

Remote | Cross-Site Scripting
Feb 14, 2026 Feb 18, 2026
Feb 14, 2026
Feb 18, 2026
4.3 MEDIUM
CVE-2026-1983 — SEATT: Simple Event Attendance <= 1.5.0 - Cross-Site Request Forgery to Arbitrary Event D…

The SEATT: Simple Event Attendance plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.5.0. This is due to missing nonce validation on the event d…

Remote | Cross-Site Request Forgery
Feb 14, 2026 Feb 18, 2026
Feb 14, 2026
Feb 18, 2026
Showing 20 of 5011 Results