Skip to main content
Skip to footer
Home
CVE Analysis
How it Works
Resources
Pricing
Log in
Create Account
Home
CVE Analysis
How it Works
Resources
Pricing
Log in
Create Account
Severity:
critical
CVE-2026-22460: FormGent – Next-Gen AI Form Builder for WordPress with Multi-Step, Quizzes, Payments & More <= 1.4.2 Unauthenticated Arbitrary File Deletion PoC, Patch Analysis & Rule
March 18, 2026
CVE-2026-22460 affects the Formgent plugin (v1.4.2 and below) with a critical CVSS score of 9.1. Unauthenticated attackers can delete arbitrary…
CVE-2026-2628: All-in-One Microsoft 365 & Entra ID / Azure AD SSO Login <= 2.2.5 Authentication Bypass PoC, Patch Analysis & Rule
March 18, 2026
CVE-2026-2628 affects the Login With Azure plugin (up to version 2.2.5) with a critical CVSS score of 9.8. Unauthenticated attackers…
CVE-2026-1492: User Registration & Membership <= 5.1.2 Unauthenticated Privilege Escalation via Membership Registration PoC, Patch Analysis & Rule
March 18, 2026
CVE-2026-1492 affects the User Registration plugin for WordPress (up to version 5.1.2) with a critical CVSS score of 9.8. Update…
CVE-2026-27983: LMS Elementor Pro <= 1.0.4 Unauthenticated Privilege Escalation PoC, Patch Analysis & Rule
March 18, 2026
CVE-2026-27983 affects the LMS Elementor Pro plugin (up to version 1.0.4) with a critical CVSS score of 9.8, allowing unauthenticated…
CVE-2026-27389: WeDesignTech Ultimate Booking Addon <= 1.0.1 Authentication Bypass PoC, Patch Analysis & Rule
March 18, 2026
CVE-2026-27389 is a critical authentication bypass vulnerability in the WeDesignTech Ultimate Booking Addon for WordPress, with a CVSS score of…
CVE-2026-27384: W3 Total Cache <= 2.9.1 Unauthenticated Arbitrary Code Execution PoC, Patch Analysis & Rule
March 18, 2026
CVE-2026-27384 affects W3 Total Cache plugin (up to 2.9.1) with a critical CVSS score of 9.8. Unauthenticated remote code execution…
CVE-2026-27540: Woocommerce Wholesale Lead Capture <= 2.0.3.1 Unauthenticated Arbitrary File Upload PoC, Patch Analysis & Rule
March 18, 2026
CVE-2026-27540 affects the WooCommerce Wholesale Lead Capture plugin (up to 2.0.3.1) with a critical CVSS score of 9.8. Unauthenticated attackers…
CVE-2026-27542: Woocommerce Wholesale Lead Capture <= 2.0.3.1 Unauthenticated Privilege Escalation PoC, Patch Analysis & Rule
March 18, 2026
CVE-2026-27542 affects the WooCommerce Wholesale Lead Capture plugin (up to version 2.0.3.1) with a critical CVSS score of 9.8. Unauthenticated…
CVE-2026-1994: s2Member <= 260127 Unauthenticated Privilege Escalation via Account Takeover PoC, Patch Analysis & Rule
March 18, 2026
CVE-2026-1994 affects the s2Member plugin for WordPress, allowing unauthenticated attackers to escalate privileges and take over accounts. Update to version…
CVE-2026-1405: Slider Future <= 1.0.5 Unauthenticated Arbitrary File Upload PoC, Patch Analysis & Rule
March 18, 2026
CVE-2026-1405 affects the Slider Future plugin (v1.0.5 and earlier) with a critical CVSS score of 9.8 due to an unauthenticated…
CVE-2025-13563: Lizza LMS Pro <= 1.0.3 Unauthenticated Privilege Escalation PoC, Patch Analysis & Rule
March 18, 2026
CVE-2025-13563 affects the Lizza LMS Pro plugin for WordPress, allowing unauthenticated users to gain admin access. With a CVSS score…
CVE-2026-0926: Prodigy Commerce <= 3.3.0 Unauthenticated Local File Inclusion via parameters[template_name] PoC, Patch Analysis & Rule
March 18, 2026
CVE-2026-0926 affects Prodigy Commerce plugin versions up to 3.3.0, allowing unauthenticated local file inclusion with a CVSS score of 9.8.…
CVE-2025-12882: Clasifico Listing <= 2.0 Unauthenticated Privilege Escalation PoC, Patch Analysis & Rule
March 18, 2026
CVE-2025-12882 affects the Clasifico Listing plugin for WordPress (up to version 2.0) with a critical CVSS score of 9.8. Unauthenticated…
CVE-2026-1937: YayMail <= 4.3.2 Missing Authorization to Authenticated (Shop Manager+) Arbitrary Options Update via 'yaymail_import_state' AJAX Action PoC, Patch Analysis & Rule
March 18, 2026
CVE-2026-1937 affects YayMail plugin versions up to 4.3.2 with a critical CVSS score of 9.8. Authenticated attackers can exploit this…
CVE-2026-1490: Spam protection, Honeypot, Anti-Spam by CleanTalk <= 6.71 Authorization Bypass via Reverse DNS (PTR record) Spoofing to Unauthenticated Arbitrary Plugin Installation PoC, Patch Analysis & Rule
March 18, 2026
CVE-2026-1490 affects the Cleantalk Spam Protect plugin (up to v6.71) with a critical CVSS score of 9.8. This authentication bypass…
CVE-2026-1306: midi-Synth <= 1.1.0 Unauthenticated Arbitrary File Upload via 'export' AJAX Action PoC, Patch Analysis & Rule
March 18, 2026
CVE-2026-1306 affects the Midi Synth plugin for WordPress, with a critical CVSS score of 9.8. Unauthenticated attackers can exploit a…
CVE-2025-8572: Truelysell Core <= 1.8.7 Unauthenticated Privilege Escalation via Registration PoC, Patch Analysis & Rule
March 18, 2026
CVE-2025-8572 affects the Truelysell Core plugin (versions
CVE-2026-1357: Migration, Backup, Staging <= 0.9.123 Unauthenticated Arbitrary File Upload PoC, Patch Analysis & Rule
March 18, 2026
CVE-2026-1357 affects WPvivid Backup & Migration plugin versions up to 0.9.123, allowing unauthenticated file uploads with a CVSS score of…
CVE-2025-69379: Upload Files Anywhere <= 2.8 Unauthenticated Arbitrary File Deletion PoC, Patch Analysis & Rule
March 18, 2026
CVE-2025-69379 reveals a critical file upload vulnerability in the Wp Upload Files Anywhere plugin (up to v2.8) with a CVSS…
CVE-2026-2991: KiviCare – Clinic & Patient Management System (EHR) <= 4.1.2 Unauthenticated Authentication Bypass via Social Login Token PoC, Patch Analysis & Rule
March 18, 2026
CVE-2026-2991 affects Kivicare Clinic Management System (up to 4.1.2) with a critical CVSS score of 9.8. Unauthenticated attackers can bypass…
←
1
…
6
7
8
9
→