VulnSea

Tagged “cve.org”

CVEs tagged cve.org, newest first.

15745 CVEsRSS

CVE-2026-5410Medium· 6.4
1w ago

The Redux Framework plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the spinner field in versions up to, and including, 4.5.13 This is due to insufficient input sanitization and output escaping

The Redux Framework plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the spinner field in versions up to, and including, 4.5.13 This is due to insufficient input sanitization and output escaping. In the user_meta_sav…

▾ Sunlitdavidanderson · Redux FrameworkEPSS 0.38%via NVD
CVE-2026-8354Medium· 6.4
1w ago

The Gum Addon for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'pop_tag' parameter in all versions up to, and including, 1.3.15 due to insufficient input sanitization and output escaping

The Gum Addon for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'pop_tag' parameter in all versions up to, and including, 1.3.15 due to insufficient input sanitization and output escaping. This makes…

▾ Sunlitcelomitan · Gum Addon for ElementorEPSS 0.35%via NVD
CVE-2026-1255High· 7.5
1w ago

The YS LeadGen plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.1.4 due to the 'ysleadgen_get_captured_data' AJAX action being accessible to unauthenticated users

The YS LeadGen plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.1.4 due to the 'ysleadgen_get_captured_data' AJAX action being accessible to unauthenticated users. This makes it…

▾ Twilightysinnovations · YS LeadGen – Popup Builder, Popup Maker & Form Builder for WordPress | Lead Generation, Email Marketing, Sales, Conversions, Opt-Ins & SubscribersEPSS 0.29%via NVD
CVE-2026-9289Medium· 5.3
1w ago

The WordLift – AI powered SEO – Schema plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.54.10 via the JSON-LD REST API endpoints

The WordLift – AI powered SEO – Schema plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.54.10 via the JSON-LD REST API endpoints. This is due to the plugin registering the /word…

▾ Sunlitwordlift · WordLift – AI powered SEO – SchemaEPSS 0.62%via NVD
CVE-2026-18346Medium· 5.3
1w ago

The TikTok plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.4.1

The TikTok plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.4.1. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible fo…

▾ Sunlittiktokbusinessplugin · TikTokEPSS 0.26%via NVD
CVE-2026-1256Medium· 6.4
1w ago

The YS LeadGen plugin for WordPress is vulnerable to authorization bypass and Stored Cross-Site Scripting via multiple AJAX endpoints in all versions up to, and including, 2.1.4 due to missing capability checks on popup management action…

The YS LeadGen plugin for WordPress is vulnerable to authorization bypass and Stored Cross-Site Scripting via multiple AJAX endpoints in all versions up to, and including, 2.1.4 due to missing capability checks on popup management action…

▾ Sunlitysinnovations · YS LeadGen – Popup Builder, Popup Maker & Form Builder for WordPress | Lead Generation, Email Marketing, Sales, Conversions, Opt-Ins & SubscribersEPSS 0.20%via NVD
CVE-2026-9858Medium· 4.3
1w ago

The Partial Shipment for Woocommerce plugin for WordPress is vulnerable to Missing Authorization in versions up to, and including, 3.4 via the wxp_order_shipment, wxp_order_item_shipment, and wxp_order_set_shipped AJAX actions

The Partial Shipment for Woocommerce plugin for WordPress is vulnerable to Missing Authorization in versions up to, and including, 3.4 via the wxp_order_shipment, wxp_order_item_shipment, and wxp_order_set_shipped AJAX actions. This is d…

▾ Sunlitwpexpertshub · Partial Shipment for WooCommerceEPSS 0.35%via NVD
CVE-2026-9766Medium· 4.3
1w ago

The Empik for Woocommerce plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.5.1

The Empik for Woocommerce plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.5.1. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes…

▾ Sunlitempik · Empik for WoocommerceEPSS 0.40%via NVD
CVE-2026-76579Medium· 4.7
1w ago

The LiteSpeed Cache plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'esi' parameter in all versions up to, and including, 7.9 due to insufficient input sanitization and output escaping

The LiteSpeed Cache plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'esi' parameter in all versions up to, and including, 7.9 due to insufficient input sanitization and output escaping. This makes it possible…

▾ Sunlitlitespeedtech · LiteSpeed CacheEPSS 0.38%via NVD
CVE-2026-9613Medium· 4.3
1w ago

The Datalogics Ecommerce Delivery – Datalogics plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 2.6.65

The Datalogics Ecommerce Delivery – Datalogics plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 2.6.65. This is due to the plugin not properly verifying that a user is authorized to perform…

▾ Sunlitdatalogics · Datalogics Ecommerce Delivery – DatalogicsEPSS 0.60%via NVD
CVE-2026-93742Critical· 9.9PoC
1w ago

A weakness has been identified in Totolink A3002MU Hh-B20211125.1046

A weakness has been identified in Totolink A3002MU Hh-B20211125.1046. Affected by this issue is the function formWsc of the file /boafrm/formWsc. This manipulation of the argument localPin causes command injection. The attack can be init…

▾ AbyssalTotolink · A3002MUEPSS 2.3%via NVD
CVE-2026-11608Medium· 6.1
1w ago

The WP Customer Reviews plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'wpcr3_fname' parameter in all versions up to, and including, 3.7.8 due to insufficient input sanitization and output escaping

The WP Customer Reviews plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'wpcr3_fname' parameter in all versions up to, and including, 3.7.8 due to insufficient input sanitization and output escaping. This mak…

▾ Sunlitbompus · WP Customer ReviewsEPSS 0.33%via NVD
CVE-2026-9615Medium· 4.3
1w ago

The Flex Import plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 3.0

The Flex Import plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 3.0. This is due to the license_activate_fleximp() and license_deactivate_fleximp() functions, hooked to the wp_ajax_licens…

▾ Sunlitflextheme · Flex ImportEPSS 0.43%via NVD
CVE-2026-15947Medium· 4.3
1w ago

The Metasync plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the save_instant_indexing_settings() function in versions up to, and including, 2.6.23

The Metasync plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the save_instant_indexing_settings() function in versions up to, and including, 2.6.23. This function is registered…

▾ Sunlitshahrukhlinkgraph · Search Atlas SEO – OTTO AI SEO Automation for WordPressEPSS 0.21%via NVD
CVE-2026-15664High· 7.2
1w ago

The Quill Forms | Conversational Multi Step Forms, Surveys & quizzes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Multiple Choice 'Other' Value in all versions up to, and including, 5.7.1 due to insufficient inpu…

The Quill Forms | Conversational Multi Step Forms, Surveys & quizzes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Multiple Choice 'Other' Value in all versions up to, and including, 5.7.1 due to insufficient inpu…

▾ Twilightmdmag · Quill Forms | Conversational Multi Step Forms, Surveys & quizzesEPSS 0.39%via NVD
CVE-2026-4792Medium· 5.3
1w ago

The Bread plugin for WordPress is vulnerable to information exposure in versions up to and including 2.9.12

The Bread plugin for WordPress is vulnerable to information exposure in versions up to and including 2.9.12. This is due to the lack of authentication and authorization checks on the settings export functionality (download_settings funct…

▾ Sunlitradius314 · BreadEPSS 0.58%via NVD
CVE-2026-2278Medium· 4.3
1w ago

The VW Writer Blog theme for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'vw_writer_blog_reset_all_settings' function in all versions up to, and including, 1.3.8

The VW Writer Blog theme for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'vw_writer_blog_reset_all_settings' function in all versions up to, and including, 1.3.8. This makes it po…

▾ Sunlitvowelweb · VW Writer BlogEPSS 0.20%via NVD
CVE-2026-11899Medium· 4.3
1w ago

The PDF Builder for WooCommerce

The PDF Builder for WooCommerce. Create invoices,packing slips and more plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 2.0.11. This is due to the plugin not properly verifying that a user…

▾ Sunlitedgarrojas · PDF Builder for WooCommerce. Create invoices,packing slips and moreEPSS 0.21%via NVD
CVE-2026-9832Medium· 5.3
1w ago

The Payment Gateway of Stripe for WooCommerce plugin for WordPress is vulnerable to Improper Verification of Cryptographic Signature in all versions up to, and including, 5.0.8

The Payment Gateway of Stripe for WooCommerce plugin for WordPress is vulnerable to Improper Verification of Cryptographic Signature in all versions up to, and including, 5.0.8. This is due to the publicly accessible `woocommerce_api_wt_…

▾ Sunlitthemehigh · Payment Gateway of Stripe for WooCommerceEPSS 0.38%via NVD
CVE-2026-13191Medium· 6.5
1w ago

The Create plugin for WordPress is vulnerable to generic SQL Injection via the 'order_by' parameter in all versions up to, and including, 2.5.3 due to insufficient escaping on the user supplied parameter and lack of sufficient preparatio…

The Create plugin for WordPress is vulnerable to generic SQL Injection via the 'order_by' parameter in all versions up to, and including, 2.5.3 due to insufficient escaping on the user supplied parameter and lack of sufficient preparatio…

▾ Sunlitmischiefmarmot · CreateEPSS 0.28%via NVD
CVE-2026-13770Medium· 6.4
1w ago

The AppMySite – WordPress & WooCommerce Mobile App Builder (No-Code Android & iOS App Maker) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via save_ams_license_key AJAX Handler in all versions up to, and including, 3.…

The AppMySite – WordPress & WooCommerce Mobile App Builder (No-Code Android & iOS App Maker) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via save_ams_license_key AJAX Handler in all versions up to, and including, 3.…

▾ Sunlitappmysite · AppMySite – WordPress & WooCommerce Mobile App Builder (No-Code Android & iOS App Maker)EPSS 0.20%via NVD
CVE-2026-1242Medium· 4.3
1w ago

The BlockSpare plugin for WordPress is vulnerable to authorization bypass due to incorrect logic in the permission callback in all versions up to, and including, 4.2.6 due to the use of an AND (&&) operator instead of an OR (||) operator…

The BlockSpare plugin for WordPress is vulnerable to authorization bypass due to incorrect logic in the permission callback in all versions up to, and including, 4.2.6 due to the use of an AND (&&) operator instead of an OR (||) operator…

▾ Sunlitblockspare · BlockSpare – Gutenberg Blocks for News, Magazine, Blog & Business WebsitesEPSS 0.18%via NVD
CVE-2026-9232Medium· 6.5
1w ago

The Easy Appointments plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.12.27 via the handle_customers_ajax

The Easy Appointments plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.12.27 via the handle_customers_ajax. This makes it possible for authenticated attackers, with contributor-…

▾ Sunliteasyappointments · Easy AppointmentsEPSS 0.47%via NVD
CVE-2026-6295Medium· 4.9
1w ago

The WP Optimizer plugin for WordPress is vulnerable to SQL Injection via the 's' parameter in all versions up to and including 2.5.0

The WP Optimizer plugin for WordPress is vulnerable to SQL Injection via the 's' parameter in all versions up to and including 2.5.0. This is due to an unsafe subquery-detection branch in the Query::parse_key_compare_field() method that,…

▾ Sunlitsh1zen · WP Optimizer – PageSpeed, Cache, Minify & Core Web VitalsEPSS 0.51%via NVD
CVE-2026-4327High· 8.8
1w ago

The The Welcomizer plugin for WordPress is vulnerable to Remote Code Execution in all versions up to and including 2.8.1

The The Welcomizer plugin for WordPress is vulnerable to Remote Code Execution in all versions up to and including 2.8.1. This is due to missing authorization checks on the twiz_ajax_callback AJAX action's 'savesection' handler combined …

▾ Twilightsebwordpress · The WelcomizerEPSS 0.68%via NVD
CVE-2026-15946Medium· 4.3
1w ago

The Search Atlas SEO – Premier SEO Plugin for One-Click WP Publishing & Integrated AI Optimization plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 2.6.23

The Search Atlas SEO – Premier SEO Plugin for One-Click WP Publishing & Integrated AI Optimization plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 2.6.23. This is due to the plugin not pro…

▾ Sunlitshahrukhlinkgraph · Search Atlas SEO – OTTO AI SEO Automation for WordPressEPSS 0.23%via NVD
CVE-2026-15463Medium· 6.1
1w ago

The SSL Zen — SSL Certificate Installer & HTTPS Redirects plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'host' parameter in all versions up to, and including, 4.7.42 due to insufficient input sanitization a…

The SSL Zen — SSL Certificate Installer & HTTPS Redirects plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'host' parameter in all versions up to, and including, 4.7.42 due to insufficient input sanitization a…

▾ Sunlitsslzen · SSL Zen — SSL Certificate Installer & HTTPS RedirectsEPSS 0.14%via NVD
CVE-2026-2422Medium· 6.4
1w ago

The WP Composer – The Easiest Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'pbwp_raw_shortcode' shortcode in all versions up to, and including, 1.0.5

The WP Composer – The Easiest Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'pbwp_raw_shortcode' shortcode in all versions up to, and including, 1.0.5. This is due to the shortcode handler decodin…

▾ Sunlitghozylab · WP Composer – The Easiest Page BuilderEPSS 0.21%via NVD
CVE-2026-1641Medium· 6.5
1w ago

The Wow Elements Addons for Elementor plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 1.11.2

The Wow Elements Addons for Elementor plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 1.11.2. This is due to the plugin passing user-controlled input from the 'Changelog File' setti…

▾ Sunlitwowelements · Wow Elements Addons for ElementorEPSS 0.28%via NVD
CVE-2026-13200Medium· 6.5
1w ago

The Create plugin for WordPress is vulnerable to generic SQL Injection via the 'order' parameter in all versions up to, and including, 2.5.3 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation o…

The Create plugin for WordPress is vulnerable to generic SQL Injection via the 'order' parameter in all versions up to, and including, 2.5.3 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation o…

▾ Sunlitmischiefmarmot · CreateEPSS 0.25%via NVD
CVEs tagged “cve.org” — page 108 · VulnSea