Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
4.4 MEDIUM
CVE-2026-4142 — Sentence To SEO (keywords, description and tags) <= 1.0 - Authenticated (Administrator+) …

The Sentence To SEO (keywords, description and tags) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'Permanent keywords' field in all versions up to and including 1.0. This…

Remote | Cross-Site Scripting
Apr 22, 2026 Apr 22, 2026
Apr 22, 2026
Apr 22, 2026
4.3 MEDIUM
CVE-2026-4140 — Ni WooCommerce Order Export <= 3.1.6 - Cross-Site Request Forgery to Settings Update via …

The Ni WooCommerce Order Export plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to and including 3.1.6. This is due to missing nonce validation in the ni_order_exp…

Remote | Cross-Site Request Forgery
Apr 22, 2026 Apr 22, 2026
Apr 22, 2026
Apr 22, 2026
4.3 MEDIUM
CVE-2026-4139 — mCatFilter <= 0.5.2 - Cross-Site Request Forgery via compute_post() Function

The mCatFilter plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to and including 0.5.2. This is due to the complete absence of nonce verification and capability che…

Remote | Cross-Site Request Forgery
Apr 22, 2026 Apr 22, 2026
Apr 22, 2026
Apr 22, 2026
4.3 MEDIUM
CVE-2026-4138 — DX Unanswered Comments <= 1.7 - Cross-Site Request Forgery via Settings Update

The DX Unanswered Comments plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.7. This is due to missing nonce validation on the plugin's settings…

Remote | Cross-Site Request Forgery
Apr 22, 2026 Apr 22, 2026
Apr 22, 2026
Apr 22, 2026
4.3 MEDIUM
CVE-2026-4133 — TextP2P Texting Widget <= 1.7 - Cross-Site Request Forgery to Settings Update

The TextP2P Texting Widget plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to and including 1.7. This is due to missing nonce validation in the imTextP2POptionPage…

Remote | Cross-Site Request Forgery
Apr 22, 2026 Apr 22, 2026
Apr 22, 2026
Apr 22, 2026
7.2 HIGH
CVE-2026-4132 — HTTP Headers <= 1.19.2 - Authenticated (Administrator+) External Control of File Name or …

The HTTP Headers plugin for WordPress is vulnerable to External Control of File Name or Path leading to Remote Code Execution in all versions up to and including 1.19.2. This is due to insufficient v…

Remote | Path Traversal
Apr 22, 2026 Apr 22, 2026
Apr 22, 2026
Apr 22, 2026
6.1 MEDIUM
CVE-2026-4131 — WP Responsive Popup + Optin <= 1.4 - Cross-Site Request Forgery to Stored Cross-Site Scri…

The WP Responsive Popup + Optin plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to and including 1.4. This is due to the settings form on the admin page (wpo_admin…

Remote | Cross-Site Request Forgery
Apr 22, 2026 Apr 22, 2026
Apr 22, 2026
Apr 22, 2026
4.3 MEDIUM
CVE-2026-4128 — TP Restore Categories And Taxonomies <= 1.0.1 - Missing Authorization to Authenticated (S…

The TP Restore Categories And Taxonomies plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 1.0.1. The delete_term() function, which handles the 'tpmcat…

Remote | Authorization
Apr 22, 2026 Apr 22, 2026
Apr 22, 2026
Apr 22, 2026
4.3 MEDIUM
CVE-2026-4126 — Table Manager <= 1.0.0 - Authenticated (Contributor+) Sensitive Information Exposure via …

The Table Manager plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.0.0 via the 'table_manager' shortcode. The shortcode handler `tablemanag…

Remote | Information Disclosure
Apr 22, 2026 Apr 22, 2026
Apr 22, 2026
Apr 22, 2026
6.4 MEDIUM
CVE-2026-4125 — WPMK Block <= 1.0.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortc…

The WPMK Block plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'class' shortcode attribute in all versions up to and including 1.0.1. This is due to insufficient input sanit…

Remote | Cross-Site Scripting
Apr 22, 2026 Apr 22, 2026
Apr 22, 2026
Apr 22, 2026
4.3 MEDIUM
CVE-2026-4121 — Kcaptcha <= 1.0.1 - Cross-Site Request Forgery to Settings Update

The Kcaptcha plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to and including 1.0.1. This is due to missing nonce validation in the plugin's settings page handler …

Remote | Cross-Site Request Forgery
Apr 22, 2026 Apr 22, 2026
Apr 22, 2026
Apr 22, 2026
9.1 CRITICAL
CVE-2026-4119 — Create DB Tables <= 1.2.1 - Missing Authorization to Authenticated (Subscriber+) Arbitrar…

The Create DB Tables plugin for WordPress is vulnerable to authorization bypass in all versions up to and including 1.2.1. The plugin registers admin_post action hooks for creating tables (admin_post…

Remote | Authorization
Apr 22, 2026 Apr 22, 2026
Apr 22, 2026
Apr 22, 2026
4.3 MEDIUM
CVE-2026-4118 — Call To Action Plugin <= 3.1.3 - Cross-Site Request Forgery via Settings Update

The Call To Action Plugin plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.1.3. This is due to missing nonce validation in the cbox_options_pag…

Remote | Cross-Site Request Forgery
Apr 22, 2026 Apr 22, 2026
Apr 22, 2026
Apr 22, 2026
5.3 MEDIUM
CVE-2026-4117 — CalJ <= 1.5 - Authenticated (Subscriber+) Arbitrary Settings Modification via 'save-obtai…

The CalJ plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 1.5. This is due to a missing capability check in the CalJSettingsPage class constructor, wh…

Remote | Authorization
Apr 22, 2026 Apr 22, 2026
Apr 22, 2026
Apr 22, 2026
6.1 MEDIUM
CVE-2026-4090 — Inquiry cart <= 3.4.2 - Cross-Site Request Forgery via Settings Form

The Inquiry Cart plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.4.2. This is due to missing nonce verification in the rd_ic_settings_page fun…

Remote | Cross-Site Request Forgery
Apr 22, 2026 Apr 22, 2026
Apr 22, 2026
Apr 22, 2026
6.4 MEDIUM
CVE-2026-4089 — Twittee Text Tweet <= 1.0.8 - Authenticated (Contributor+) Stored Cross-Site Scripting vi…

The Twittee Text Tweet plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'id' shortcode attribute in all versions up to and including 1.0.8. This is due to insufficient input …

Remote | Cross-Site Scripting
Apr 22, 2026 Apr 22, 2026
Apr 22, 2026
Apr 22, 2026
6.4 MEDIUM
CVE-2026-4088 — Switch CTA Box <= 1.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shor…

The Switch CTA Box plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'wppw_cta_box' shortcode in all versions up to, and including, 1.1. This is due to insufficient input sani…

Remote | Cross-Site Scripting
Apr 22, 2026 Apr 22, 2026
Apr 22, 2026
Apr 22, 2026
6.4 MEDIUM
CVE-2026-4085 — Easy Social Photos Gallery <= 3.1.2 - Authenticated (Contributor+) Stored Cross-Site Scri…

The Easy Social Photos Gallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'wrapper_class' shortcode attribute of the 'my-instagram-feed' shortcode in all versions up to…

Remote | Cross-Site Scripting
Apr 22, 2026 Apr 22, 2026
Apr 22, 2026
Apr 22, 2026
6.4 MEDIUM
CVE-2026-4082 — ER Swiffy Insert <= 1.0.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via …

The ER Swiffy Insert plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the [swiffy] shortcode in all versions up to and including 1.0.0. This is due to insufficient input sanitiza…

Remote | Cross-Site Scripting
Apr 22, 2026 Apr 22, 2026
Apr 22, 2026
Apr 22, 2026
6.4 MEDIUM
CVE-2026-4076 — Slider Bootstrap Carousel <= 1.0.7 - Authenticated (Contributor+) Stored Cross-Site Scrip…

The Slider Bootstrap Carousel plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'category' and 'template' shortcode attributes in all versions up to and including 1.0.7. This …

Remote | Cross-Site Scripting
Apr 22, 2026 Apr 22, 2026
Apr 22, 2026
Apr 22, 2026
Showing 20 of 6478 Results