Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
6.4 MEDIUM
CVE-2026-7796 — EmbedPress <= 4.5.3 - Authenticated (Contributor+) Stored Cross-Site Scripting via Block …

The EmbedPress – PDF Embedder, Embed PDF viewer, YouTube Videos, 3D FlipBook, Social feeds & more plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the block 'url' attribute in al…

Remote | Cross-Site Scripting
Jun 06, 2026 Jun 06, 2026
Jun 06, 2026
Jun 06, 2026
6.4 MEDIUM
CVE-2026-7795 — Click to Chat <= 4.39 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'num…

The Click to Chat – WA Widget plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the [chat] shortcode 'num' parameter in all versions up to, and including, 4.38. This is due to ins…

Remote | Cross-Site Scripting
Jun 06, 2026 Jun 06, 2026
Jun 06, 2026
Jun 06, 2026
5.3 MEDIUM
CVE-2026-7792 — WPForms <= 1.10.0.4 - Unauthenticated Insufficient Verification of Data Authenticity via …

The WPForms – Easy Form Builder for WordPress – Contact Forms, Payment Forms, Surveys, & More plugin for WordPress is vulnerable to Insufficient Verification of Data Authenticity in versions up to an…

wpforms | Remote | Authentication
Jun 06, 2026 Jun 06, 2026
Jun 06, 2026
Jun 06, 2026
5.3 MEDIUM
CVE-2026-7665 — Essential Addons for Elementor <= 6.6.4 - Missing Authorization to Unauthenticated Inform…

The Essential Addons for Elementor – Popular Elementor Templates & Widgets plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 6.6.4 via the ajax_load_mor…

essential_addons_for_elementor | Remote | Information Disclosure
Jun 06, 2026 Jun 06, 2026
Jun 06, 2026
Jun 06, 2026
6.6 MEDIUM
CVE-2026-7566 — LearnPress – Backup & Migration Tool <= 4.1.4 - Authenticated (Administrator+) PHP Object…

The LearnPress – Backup & Migration Tool plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 4.1.4 via deserialization of untrusted input . This makes it …

learnpress_export_import | Remote | Injection
Jun 06, 2026 Jun 06, 2026
Jun 06, 2026
Jun 06, 2026
4.9 MEDIUM
CVE-2026-7565 — LearnPress <= 4.1.4 - Authenticated (Administrator+) Path Traversal to Arbitrary File Rea…

The LearnPress – Backup & Migration Tool plugin for WordPress is vulnerable to Arbitrary File Read via Directory Traversal in all versions up to, and including, 4.1.4 via the 'import-user-file' param…

learnpress_export_import | Remote | Path Traversal
Jun 06, 2026 Jun 06, 2026
Jun 06, 2026
Jun 06, 2026
7.2 HIGH
CVE-2026-7537 — MDJM Event Management <= 1.7.8.3 - Authenticated (Administrator+) Arbitrary File Upload v…

The MDJM Event Management plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 1.7.8.3 via the mdjm_send_comm_email function. This is due to no file type,…

Remote | Authentication
Jun 06, 2026 Jun 06, 2026
Jun 06, 2026
Jun 06, 2026
4.4 MEDIUM
CVE-2026-2500 — Quick Playground <= 1.3.4 - Authenticated (Administrator+) Arbitrary File Read via 'filen…

The Quick Playground plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 1.3.4. This is due to the `qckply_data()` function passing the user-supplied `filename`…

Remote | Path Traversal
Jun 06, 2026 Jun 06, 2026
Jun 06, 2026
Jun 06, 2026
6.4 MEDIUM
CVE-2026-9281 — Master Addons For Elementor <= 3.1.0 - Authenticated (Author+) Stored Cross-Site Scriptin…

The Master Addons For Elementor – Widgets, Extensions, Theme Builder, Popup Builder & Template Kits plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'jtlma_custom_js' Page Settin…

master_addons | Remote | Cross-Site Scripting
Jun 06, 2026 Jun 06, 2026
Jun 06, 2026
Jun 06, 2026
4.3 MEDIUM
CVE-2026-9008 — Page-list <= 6.2 - Missing Authorization to Authenticated (Contributor+) Sensitive Inform…

The Page-list plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 6.2. This is due to the pagelist_unqprfx_ext_shortcode() function (the [pagelist_ext] /…

Remote | Authorization
Jun 06, 2026 Jun 06, 2026
Jun 06, 2026
Jun 06, 2026
7.2 HIGH
CVE-2026-8901 — Integration for Freshsales <= 1.0.15 - Unauthenticated Stored Cross-Site Scripting via Fo…

The Integration for Freshsales – Contact Form 7, WPForms, Elementor, Gravity Forms and More plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Form Submission Data in all versions …

Remote | Cross-Site Scripting
Jun 06, 2026 Jun 06, 2026
Jun 06, 2026
Jun 06, 2026
7.2 HIGH
CVE-2026-8438 — All-In-One Security (AIOS) <= 5.4.7 - Unauthenticated Stored Cross-Site Scripting via RES…

The All-In-One Security (AIOS) – Security and Firewall plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to and including 5.4.7. This is due to insufficient input sanit…

all-in-one_security | Remote | Cross-Site Scripting
Jun 06, 2026 Jun 06, 2026
Jun 06, 2026
Jun 06, 2026
4.3 MEDIUM
CVE-2026-9719 — LatePoint <= 5.6.0 - Cross-Site Request Forgery via invoices__change_status Action

The LatePoint – Calendar Booking Plugin for Appointments and Events plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 5.6.0. This is due to missin…

Remote | Cross-Site Request Forgery
Jun 06, 2026 Jun 06, 2026
Jun 06, 2026
Jun 06, 2026
7.5 HIGH
CVE-2026-9290 — WP User Manager <= 2.9.17 - Unauthenticated Path Traversal to Local File Inclusion via 't…

The WP User Manager – User Profile Builder & Membership plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 2.9.17 via the (profile template scope) functi…

wp_user_manager | Remote | Path Traversal
Jun 06, 2026 Jun 06, 2026
Jun 06, 2026
Jun 06, 2026
4.3 MEDIUM
CVE-2026-8976 — RSS Aggregator by Feedzy <= 5.1.7 - Missing Authorization to Authenticated (Contributor+)…

The RSS Aggregator by Feedzy – Feed to Post, Autoblogging, News & YouTube Video Feeds Aggregator plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 5.1.7…

rss_aggregator_by_feedzy | Remote | Authorization
Jun 06, 2026 Jun 06, 2026
Jun 06, 2026
Jun 06, 2026
6.4 MEDIUM
CVE-2026-8900 — Simple SEO Slideshow <= 1.2.8 - Authenticated (Contributor+) Stored Cross-Site Scripting …

The Simple SEO Slideshow plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Shortcode Attributes in all versions up to, and including, 1.2.8 due to insufficient input sanitization …

Remote | Cross-Site Scripting
Jun 06, 2026 Jun 06, 2026
Jun 06, 2026
Jun 06, 2026
6.4 MEDIUM
CVE-2026-8893 — Express Payment For Stripe <= 1.28.0 - Authenticated (Contributor+) Stored Cross-Site Scr…

The Express Payment For Stripe plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'type' attribute of the [stripe-express] shortcode in versions up to, and including, 1.28.0. T…

Remote | Cross-Site Scripting
Jun 06, 2026 Jun 06, 2026
Jun 06, 2026
Jun 06, 2026
5.3 MEDIUM
CVE-2026-8608 — Event Monster <= 2.1.0 - Unauthenticated Insufficient Verification of Data Authenticity t…

The Event Monster – Event Management, Events Calendar, Tickets plugin for WordPress is vulnerable to Insufficient Verification of Data Authenticity in versions up to, and including, 2.1.0. This is du…

Remote | Authentication
Jun 06, 2026 Jun 06, 2026
Jun 06, 2026
Jun 06, 2026
4.3 MEDIUM
CVE-2026-7047 — Frontend User Notes <= 2.1.1 - Cross-Site Request Forgery to Note Content Modification vi…

The Frontend User Notes plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.1.1. This is due to missing or incorrect nonce validation on the funp_…

Remote | Cross-Site Request Forgery
Jun 06, 2026 Jun 06, 2026
Jun 06, 2026
Jun 06, 2026
4.9 MEDIUM
CVE-2026-6448 — Quiz and Survey Master (QSM) <= 11.1.2 - Authenticated (Admin+) SQL Injection via 'order'…

The Quiz and Survey Master (QSM) – Easy Quiz and Survey Maker plugin for WordPress is vulnerable to time-based blind SQL Injection via the 'order' parameter in all versions up to, and including, 11.1…

quiz_and_survey_master | Remote | Injection
Jun 06, 2026 Jun 06, 2026
Jun 06, 2026
Jun 06, 2026
Showing 20 of 7172 Results