Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
6.4 MEDIUM
CVE-2026-1901 — QuestionPro Surveys <= 1.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via…

The QuestionPro Surveys plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'questionpro' shortcode in all versions up to, and including, 1.0 due to insufficient input sanitizat…

Remote | Cross-Site Scripting
Feb 14, 2026 Feb 18, 2026
Feb 14, 2026
Feb 18, 2026
6.1 MEDIUM
CVE-2026-1796 — StyleBidet <= 1.0.0 - Reflected Cross-Site Scripting

The StyleBidet plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the URL path in all versions up to, and including, 1.0.0 due to insufficient input sanitization and output esca…

Remote | Cross-Site Scripting
Feb 14, 2026 Feb 18, 2026
Feb 14, 2026
Feb 18, 2026
6.1 MEDIUM
CVE-2026-1795 — Address Bar Ads <= 1.0.0 - Reflected Cross-Site Scripting

The Address Bar Ads plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the URL Path in all versions up to, and including, 1.0.0 due to insufficient input sanitization and output…

Remote | Cross-Site Scripting
Feb 14, 2026 Feb 18, 2026
Feb 14, 2026
Feb 18, 2026
6.1 MEDIUM
CVE-2026-1792 — Geo Widet <= 1.0 - Reflected Cross-Site Scripting

The Geo Widget plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the URL path in all versions up to, and including, 1.0 due to insufficient input sanitization and output escaping.…

Remote | Cross-Site Scripting
Feb 14, 2026 Feb 18, 2026
Feb 14, 2026
Feb 18, 2026
4.3 MEDIUM
CVE-2026-1394 — WP Quick Contact Us <= 1.0 - Cross-Site Request Forgery to Settings Update

The WP Quick Contact Us plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0. This is due to missing nonce validation on the settings update func…

Remote | Cross-Site Request Forgery
Feb 14, 2026 Feb 18, 2026
Feb 14, 2026
Feb 18, 2026
9.8 CRITICAL
CVE-2026-1306 — midi-Synth <= 1.1.0 - Unauthenticated Arbitrary File Upload via 'export' AJAX Action

The midi-Synth plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type and file extension validation in the 'export' AJAX action in all versions up to, and including, 1.…

Remote | Authentication
Feb 14, 2026 Feb 18, 2026
Feb 14, 2026
Feb 18, 2026
5.3 MEDIUM
CVE-2026-1303 — MailChimp Campaigns <= 3.2.4 - Missing Authorization to Authenticated (Subscriber+) MailC…

The MailChimp Campaigns plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 3.2.4. This is due to missing capability checks on the `mailchimp_campaigns_m…

Remote | Authorization
Feb 14, 2026 Feb 18, 2026
Feb 14, 2026
Feb 18, 2026
6.4 MEDIUM
CVE-2026-1187 — ZoomifyWP Free <= 1.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'fil…

The ZoomifyWP Free plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'filename' parameter of the 'zoomify' shortcode in all versions up to, and including, 1.1 due to insuffici…

Remote | Cross-Site Scripting
Feb 14, 2026 Feb 18, 2026
Feb 14, 2026
Feb 18, 2026
6.4 MEDIUM
CVE-2026-1096 — Best-wp-google-map <= 2.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via …

The Best-wp-google-map plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'latitude' and 'longitudinal' parameters of the 'google_map_view' shortcode in all versions up to, and…

Remote | Cross-Site Scripting
Feb 14, 2026 Feb 18, 2026
Feb 14, 2026
Feb 18, 2026
7.2 HIGH
CVE-2026-0753 — Super Simple Contact Form <= 1.6.2 - Reflected Cross-Site Scripting via 'sscf_name' Param…

The Super Simple Contact Form plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'sscf_name' parameter in all versions up to, and including, 1.6.2 due to insufficient input …

Remote | Cross-Site Scripting
Feb 14, 2026 Feb 18, 2026
Feb 14, 2026
Feb 18, 2026
6.4 MEDIUM
CVE-2026-0751 — Payment Page | Payment Form for Stripe <= 1.4.6 - Authenticated (Author+) Stored Cross-Si…

The Payment Page | Payment Form for Stripe plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'pricing_plan_select_text_font_family' parameter in all versions up to, and includ…

Remote | Cross-Site Scripting
Feb 14, 2026 Feb 18, 2026
Feb 14, 2026
Feb 18, 2026
7.2 HIGH
CVE-2026-0745 — User Language Switch <= 1.6.10 - Authenticated (Administrator+) Server-Side Request Forge…

The User Language Switch plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 1.6.10 due to missing URL validation on the 'download_language()' func…

Remote | Server-Side Request Forgery
Feb 14, 2026 Feb 18, 2026
Feb 14, 2026
Feb 18, 2026
6.4 MEDIUM
CVE-2026-0736 — Chatbot for WordPress by Collect.chat ⚡️ <= 2.4.8 - Authenticated (Contributor+) Stored C…

The Chatbot for WordPress by Collect.chat plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the '_inpost_head_script[synth_header_script]' post meta field in all versions up to, a…

collect.chat | Remote | Cross-Site Scripting
Feb 14, 2026 Feb 18, 2026
Feb 14, 2026
Feb 18, 2026
4.4 MEDIUM
CVE-2026-0735 — User Language Switch <= 1.6.10 - Authenticated (Administrator+) Stored Cross-Site Scripti…

The User Language Switch plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'tab_color_picker_language_switch' parameter in all versions up to, and including, 1.6.10 due to ins…

Remote | Cross-Site Scripting
Feb 14, 2026 Feb 18, 2026
Feb 14, 2026
Feb 18, 2026
5.4 MEDIUM
CVE-2026-0727 — Accordion and Accordion Slider <= 1.4.5 - Missing Authorization to Authenticated (Contrib…

The Accordion and Accordion Slider plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.4.5. This is due to the plugin not properly verifying that a user…

Remote | Authorization
Feb 14, 2026 Feb 18, 2026
Feb 14, 2026
Feb 18, 2026
4.4 MEDIUM
CVE-2026-0693 — Allow HTML in Category Descriptions <= 1.2.4 - Authenticated (Administrator+) Stored Cros…

The Allow HTML in Category Descriptions plugin for WordPress is vulnerable to Stored Cross-Site Scripting via category descriptions in all versions up to, and including, 1.2.4. This is due to the plu…

Remote | Cross-Site Scripting
Feb 14, 2026 Feb 18, 2026
Feb 14, 2026
Feb 18, 2026
6.4 MEDIUM
CVE-2026-0559 — MasterStudy LMS WordPress Plugin – for Online Courses and Education <= 3.7.11 - Authentic…

The MasterStudy LMS WordPress Plugin – for Online Courses and Education plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'stm_lms_courses_grid_display' shortcode in …

masterstudy_lms | Remote | Cross-Site Scripting
Feb 14, 2026 Feb 18, 2026
Feb 14, 2026
Feb 18, 2026
6.4 MEDIUM
CVE-2026-0557 — WP Data Access <= 5.5.63 - Authenticated (Contributor+) Stored Cross-Site Scripting via '…

The WP Data Access plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'wpda_app' shortcode in all versions up to, and including, 5.5.63 due to insufficient input sanit…

Remote | Cross-Site Scripting
Feb 14, 2026 Feb 18, 2026
Feb 14, 2026
Feb 18, 2026
5.3 MEDIUM
CVE-2025-6792 — One to one user Chat by WPGuppy <= 1.1.4 - Unauthenticated Information Disclosure via Cha…

The One to one user Chat by WPGuppy plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the /wp-json/guppylite/v2/channel-authorize rest endpoint in…

Remote | Authorization
Feb 14, 2026 Feb 18, 2026
Feb 14, 2026
Feb 18, 2026
4.4 MEDIUM
CVE-2025-15483 — Link Hopper <= 2.5 - Authenticated (Administrator+) Stored Cross-Site Scripting via 'hop_…

The Link Hopper plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘hop_name’ parameter in all versions up to, and including, 2.5 due to insufficient input sanitization and out…

Remote | Cross-Site Scripting
Feb 14, 2026 Feb 18, 2026
Feb 14, 2026
Feb 18, 2026
Showing 20 of 5031 Results