Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
0.0 NA
CVE-2026-6549 — Logo Manager For Enamad <= 0.7.4 - Authenticated (Contributor+) Stored Cross-Site Scripti…

The Logo Manager For Enamad plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'title' attribute of the `vc_enamad_namad`, `vc_enamad_shamed`, and `vc_enamad_custom` shortcodes…

| Cross-Site Scripting
May 20, 2026 May 20, 2026
May 20, 2026
May 20, 2026
0.0 NA
CVE-2026-8038 — Faces of Users <= 0.0.3 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'd…

The Faces of Users plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'default' shortcode attribute in the 'facesofusers' shortcode in all versions up to, and including, 0.0.3 …

| Cross-Site Scripting
May 20, 2026 May 20, 2026
May 20, 2026
May 20, 2026
0.0 NA
CVE-2026-6395 — Word 2 Cash <= 0.9.2 - Cross-Site Request Forgeryto Stored Cross-Site Scripting via Setti…

The Word 2 Cash plugin for WordPress is vulnerable to Cross-Site Request Forgery leading to Stored Cross-Site Scripting in versions up to and including 0.9.2. This is due to the complete absence of n…

| Cross-Site Request Forgery
May 20, 2026 May 20, 2026
May 20, 2026
May 20, 2026
0.0 NA
CVE-2026-6400 — Child Height Predictor by Ostheimer <= 1.3 - Cross-Site Request Forgery to Settings Updat…

The Child Height Predictor by Ostheimer plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to and including 1.3. This is due to missing nonce verification in the opti…

| Cross-Site Request Forgery
May 20, 2026 May 20, 2026
May 20, 2026
May 20, 2026
0.0 NA
CVE-2026-6401 — Bottom Bar <= 0.1.7 - Cross-Site Request Forgery to Settings Update

The Bottom Bar plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to and including 0.1.7. This is due to missing nonce verification on the plugin's settings update fo…

| Cross-Site Request Forgery
May 20, 2026 May 20, 2026
May 20, 2026
May 20, 2026
0.0 NA
CVE-2026-6399 — General Options <= 1.1.0 - Authenticated (Administrator+) Stored Cross-Site Scripting via…

The General Options plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to and including 1.1.0. This is due to the use of sanitize_text_field() for output escaping in the…

| Cross-Site Scripting
May 20, 2026 May 20, 2026
May 20, 2026
May 20, 2026
0.0 NA
CVE-2026-7472 — Read More & Accordion <= 3.5.7 - Authenticated (Administrator+) SQL Injection via 'orderb…

The Read More & Accordion plugin for WordPress is vulnerable to time-based blind SQL Injection via the 'orderby' parameter in all versions up to, and including, 3.5.7. This is due to the use of esc_s…

| Injection
May 20, 2026 May 20, 2026
May 20, 2026
May 20, 2026
0.0 NA
CVE-2026-6072 — Oliver POS <= 2.4.2.6 - Unauthenticated Authorization Bypass Through User-Controlled Key …

The Oliver POS – A WooCommerce Point of Sale (POS) plugin for WordPress is vulnerable to Authorization Bypass Through User-Controlled Key in all versions up to and including 2.4.2.6. The plugin prote…

| Authorization
May 20, 2026 May 20, 2026
May 20, 2026
May 20, 2026
0.0 NA
CVE-2026-8419 — Amazon Scraper <= 1.1 - Cross-Site Request Forgery to Stored Cross-Site Scripting via Set…

The Amazon Scraper plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.1. This is due to missing or incorrect nonce validation on a function. This…

| Cross-Site Request Forgery
May 20, 2026 May 20, 2026
May 20, 2026
May 20, 2026
0.0 NA
CVE-2026-8424 — Remove Yellow BGBOX <= 1.0 - Cross-Site Request Forgery

The Remove Yellow BGBOX plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0. This is due to missing or incorrect nonce validation on the 'rybb_a…

| Cross-Site Request Forgery
May 20, 2026 May 20, 2026
May 20, 2026
May 20, 2026
0.0 NA
CVE-2026-5293 — 診断ジェネレータ作成プラグイン <= 1.4.16 - Authenticated (Subscriber+) Stored Cross-Site Scripting via '…

The 診断ジェネレータ作成プラグイン (Diagnosis Generator) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'js' parameter in versions up to and including 1.4.16. This is due to missing autho…

| Cross-Site Scripting
May 20, 2026 May 20, 2026
May 20, 2026
May 20, 2026
0.0 NA
CVE-2026-6394 — Nexa Blocks <= 1.1.1 - Unauthenticated Blind Server-Side Request Forgery via 'demo_json_f…

The Nexa Blocks – Gutenberg Blocks, Page Builder for Gutenberg Editor & FSE plugin for WordPress is vulnerable to Server-Side Request Forgery (SSRF) in versions up to and including 1.1.1. This is due…

| Server-Side Request Forgery
May 20, 2026 May 20, 2026
May 20, 2026
May 20, 2026
0.0 NA
CVE-2026-7467 — Read More & Accordion <= 3.5.7 - Privilege Escalation via importData

The Read More & Accordion plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 3.5.7. This is due to the 'RadMoreAjax::importData' function not restricting…

| Authentication
May 20, 2026 May 20, 2026
May 20, 2026
May 20, 2026
0.0 NA
CVE-2026-6391 — Sentence To SEO (keywords, description and tags) <= 1.0 - Cross-Site Request Forgery to S…

The Sentence To SEO (keywords, description and tags) plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0. This is due to missing or incorrect no…

| Cross-Site Request Forgery
May 20, 2026 May 20, 2026
May 20, 2026
May 20, 2026
0.0 NA
CVE-2026-8420 — BLOGCHAT Chat System <= 1.3.6.3 - Cross-Site Request Forgery to Stored Cross-Site Scripti…

The BLOGCHAT Chat System plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.3.6.3. This is due to missing or incorrect nonce validation on a func…

| Cross-Site Request Forgery
May 20, 2026 May 20, 2026
May 20, 2026
May 20, 2026
0.0 NA
CVE-2026-6456 — Account Switcher <= 1.0.2 - Authenticated (Subscriber+) Authentication Bypass to Privileg…

The Account Switcher plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.0.2. This is due to the `rememberLogin` REST API endpoint using a loose compari…

| Authentication
May 20, 2026 May 20, 2026
May 20, 2026
May 20, 2026
0.0 NA
CVE-2026-7462 — VatanSMS WP SMS <= 1.01 - Reflected Cross-Site Scripting via 'page' Parameter

The VatanSMS WP SMS plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the `page` parameter in all versions up to, and including, 1.01. This is due to insufficient input sanitiz…

| Cross-Site Scripting
May 20, 2026 May 20, 2026
May 20, 2026
May 20, 2026
0.0 NA
CVE-2026-8610 — TypeSquare Webfonts for ConoHa <= 2.0.4 - Missing Authorization to Authenticated (Subscri…

The TypeSquare Webfonts for ConoHa plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 2.0.4. This is due to the plugin not properly verifying that a user…

| Authorization
May 20, 2026 May 20, 2026
May 20, 2026
May 20, 2026
0.0 NA
CVE-2026-8626 — SponsorMe <= 0.5.2 - Reflected Cross-Site Scripting via PHP_SELF Parameter

The SponsorMe plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via PHP_SELF Parameter in all versions up to, and including, 0.5.2 due to insufficient input sanitization and output…

| Cross-Site Scripting
May 20, 2026 May 20, 2026
May 20, 2026
May 20, 2026
0.0 NA
CVE-2026-8423 — JaviBola Custom Theme Test <= 2.0.5 - Cross-Site Request Forgery

The JaviBola Custom Theme Test plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.0.5. This is due to missing or incorrect nonce validation on th…

| Cross-Site Request Forgery
May 20, 2026 May 20, 2026
May 20, 2026
May 20, 2026
Showing 20 of 6422 Results