Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
6.4 MEDIUM
CVE-2026-1373 — Easy Author Image <= 1.7 - Authenticated (Subscriber+) Stored Cross-Site Scripting via Pr…

The Easy Author Image plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'author_profile_picture_url' parameter in all versions up to, and including, 1.7 due to insufficient in…

Remote | Cross-Site Scripting
Feb 19, 2026 Feb 19, 2026
Feb 19, 2026
Feb 19, 2026
4.4 MEDIUM
CVE-2026-1055 — TalkJS <= 0.1.15 - Authenticated (Administrator+) Stored Cross-Site Scripting via 'welcom…

The TalkJS plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 0.1.15 due to insufficient input sanitization and output escaping…

Remote | Cross-Site Scripting
Feb 19, 2026 Feb 19, 2026
Feb 19, 2026
Feb 19, 2026
4.4 MEDIUM
CVE-2026-1047 — salavat counter Plugin <= 0.9.5 - Authenticated (Administrator+) Stored Cross-Site Script…

The salavat counter Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'image_url' parameter in all versions up to, and including, 0.9.5 due to insufficient input saniti…

Remote | Cross-Site Scripting
Feb 19, 2026 Feb 19, 2026
Feb 19, 2026
Feb 19, 2026
4.4 MEDIUM
CVE-2026-1044 — Tennis Court Bookings <= 1.2.7 - Authenticated (Administrator+) Stored Cross-Site Scripti…

The Tennis Court Bookings plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 1.2.7 due to insufficient input sanitization and o…

Remote | Cross-Site Scripting
Feb 19, 2026 Feb 19, 2026
Feb 19, 2026
Feb 19, 2026
4.4 MEDIUM
CVE-2026-1043 — PostmarkApp Email Integrator <= 2.4 - Authenticated (Administrator+) Stored Cross-Site Sc…

The PostmarkApp Email Integrator plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin settings in versions up to, and including, 2.4. This is due to insufficient input san…

Remote | Cross-Site Scripting
Feb 19, 2026 Feb 19, 2026
Feb 19, 2026
Feb 19, 2026
8.8 HIGH
CVE-2026-0974 — Orderable <= 1.20.0 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Plug…

The Orderable – WordPress Restaurant Online Ordering System and Food Ordering Plugin plugin for WordPress is vulnerable to unauthorized plugin installation due to a missing capability check on the 'i…

Remote | Authentication
Feb 19, 2026 Feb 19, 2026
Feb 19, 2026
Feb 19, 2026
9.8 CRITICAL
CVE-2026-0926 — Prodigy Commerce <= 3.2.9 - Unauthenticated Local File Inclusion via parameters[template_…

The Prodigy Commerce plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 3.2.9 via the 'parameters[template_name]' parameter. This makes it possible for u…

Remote | Path Traversal
Feb 19, 2026 Feb 19, 2026
Feb 19, 2026
Feb 19, 2026
8.8 HIGH
CVE-2026-0912 — Toret Manager <= 1.2.7 - Authenticated (Subscriber+) Arbitrary Options Update via AJAX ac…

The Toret Manager plugin for WordPress is vulnerable to unauthorized modification of data that can lead to privilege escalation due to a missing capability check on the 'trman_save_option' function a…

Remote | Authorization
Feb 19, 2026 Feb 19, 2026
Feb 19, 2026
Feb 19, 2026
6.5 MEDIUM
CVE-2026-0722 — Shield Security <= 21.0.8 - Cross-Site Request Forgery to SQL Injection

The Shield Security plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 21.0.8. This is due to the plugin allowing nonce verification to be bypassed…

Remote | Cross-Site Request Forgery
Feb 19, 2026 Feb 19, 2026
Feb 19, 2026
Feb 19, 2026
6.1 MEDIUM
CVE-2026-0561 — Shield Security <= 21.0.8 - Unauthenticated Reflected Cross-Site Scripting via 'message' …

The Shield Security plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'message' parameter in all versions up to, and including, 21.0.8 due to insufficient input sanitizatio…

Remote | Cross-Site Scripting
Feb 19, 2026 Feb 19, 2026
Feb 19, 2026
Feb 19, 2026
6.4 MEDIUM
CVE-2026-0556 — XO Event Calendar <= 3.2.10 - Authenticated (Contributor+) Stored Cross-Site Scripting vi…

The XO Event Calendar plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'xo_event_field' shortcode in all versions up to, and including, 3.2.10 due to insufficient in…

Remote | Cross-Site Scripting
Feb 19, 2026 Feb 19, 2026
Feb 19, 2026
Feb 19, 2026
6.4 MEDIUM
CVE-2026-0549 — Groups <= 3.10.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'groups_g…

The Groups plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'groups_group_info' shortcode in all versions up to, and including, 3.10.0 due to insufficient input sani…

Remote | Cross-Site Scripting
Feb 19, 2026 Feb 19, 2026
Feb 19, 2026
Feb 19, 2026
7.8 HIGH
CVE-2025-4960 — macOS Local Privilege Escalation via Improper Authorization Handling in EPSON Printer Con…

The com.epson.InstallNavi.helper tool, deployed with the EPSON printer driver installer, contains a local privilege escalation vulnerability due to multiple flaws in its implementation. It fails to p…

Feb 19, 2026 Feb 19, 2026
Feb 19, 2026
Feb 19, 2026
8.8 HIGH
CVE-2025-4521 — IDonate 2.1.5 - 2.1.9 - Missing Authorization to Authenticated (Subscriber+) Account Take…

The IDonate – Blood Donation, Request And Donor Management System plugin for WordPress is vulnerable to Privilege Escalation due to a missing capability check on the idonate_donor_profile() function …

idonate | Remote | Authorization
Feb 19, 2026 Feb 19, 2026
Feb 19, 2026
Feb 19, 2026
10.0 CRITICAL
CVE-2025-15586 — Apache OGP Authentication Bypass

OGP-Website installs prior git commit 52f865a4fba763594453068acf8fa9e3fc38d663 are affected by a type juggling flaw which if exploited can result in authentication bypass without knowledge of the vic…

Remote | Authentication
Feb 19, 2026 Feb 19, 2026
Feb 19, 2026
Feb 19, 2026
7.2 HIGH
CVE-2025-15041 — BackWPup <= 5.6.2 - Authenticated (BackWPup Helper+) Privilege Escalation via Arbitrary O…

The BackWPup – WordPress Backup & Restore Plugin plugin for WordPress is vulnerable to unauthorized modification of data that can lead to privilege escalation due to a missing capability check on the…

backwpup | Remote | Authorization
Feb 19, 2026 Feb 19, 2026
Feb 19, 2026
Feb 19, 2026
6.4 MEDIUM
CVE-2025-14983 — Advanced Custom Fields: Font Awesome <= 5.0.1 - Authenticated (Contributor+) Stored Cross…

The Advanced Custom Fields: Font Awesome Field plugin for WordPress is vulnerable to Cross-Site Scripting in all versions up to, and including, 5.0.1 due to insufficient input sanitization and output…

Remote | Cross-Site Scripting
Feb 19, 2026 Feb 19, 2026
Feb 19, 2026
Feb 19, 2026
4.3 MEDIUM
CVE-2025-14864 — Virusdie <= 1.1.7 - Missing Authorization to Authenticated (Subscriber+) API Key Disclosu…

The Virusdie - One-click website security plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.1.7. This is due to missing capability checks on…

Remote | Information Disclosure
Feb 19, 2026 Feb 19, 2026
Feb 19, 2026
Feb 19, 2026
6.4 MEDIUM
CVE-2025-14851 — YaMaps for WordPress <= 0.6.40 - Authenticated (Contributor+) Stored Cross-Site Scripting…

The YaMaps for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `yamap` shortcode parameters in all versions up to, and including, 0.6.40 due to insufficient input …

yamaps | Remote | Cross-Site Scripting
Feb 19, 2026 Feb 19, 2026
Feb 19, 2026
Feb 19, 2026
7.2 HIGH
CVE-2025-14452 — WP Customer Reviews <= 3.7.5 - Reflected Cross-Site Scripting via 'wpcr3_fname' Parameter

The WP Customer Reviews plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'wpcr3_fname' parameter in all versions up to, and including, 3.7.5 due to insufficient input sani…

wp_customer_reviews | Remote | Cross-Site Scripting
Feb 19, 2026 Feb 19, 2026
Feb 19, 2026
Feb 19, 2026
Showing 20 of 5068 Results