Skip to main content
Skip to footer
Home
CVE Analysis
How it Works
Resources
Pricing
Log in
Create Account
Home
CVE Analysis
How it Works
Resources
Pricing
Log in
Create Account
Severity:
high
CVE-2026-14498: Query Wrangler <= 1.5.57 Authenticated (Subscriber+) Remote Code Execution via 'options' Parameter PoC, Patch Analysis & Rule
August 16, 2026
CVE-2026-14498 affects the Query Wrangler plugin for WordPress, with a high severity CVSS score of 8.8. Users should upgrade to…
CVE-2026-17123: Royal Addons for Elementor <= 1.7.1064 Authenticated (Contributor+) Server-Side Request Forgery via Form Builder Widget 'webhook_url' Setting PoC, Patch Analysis & Rule
August 16, 2026
CVE-2026-17123 affects the Royal Elementor Addons plugin (up to v1.7.1064) with a CVSS score of 8.8. Authenticated users can exploit…
CVE-2026-16099: Podlove Podcast Publisher <= 4.5.3 Authenticated (Contributor+) PHP Object Injection to Arbitrary File Deletion via 'unfurl_data' Parameter PoC, Patch Analysis & Rule
August 16, 2026
CVE-2026-16099 affects the Podlove Podcasting Plugin for WordPress (up to v4.5.3) with a CVSS score of 8.8. Authenticated users can…
CVE-2026-15002: Autopay <= 5.0.0 Unauthenticated Stored Cross-Site Scripting via 'bm_woocommerce_css_editor_content' Parameter PoC, Patch Analysis & Rule
August 16, 2026
CVE-2026-15002 affects the Platnosci Online Blue Media plugin for WordPress (up to 5.0.0) with a high severity CVSS score of…
CVE-2026-10734: Infility Global <= 2.15.21 Unauthenticated Stored Cross-Site Scripting via /cf7_record Log Endpoint PoC, Patch Analysis & Rule
August 15, 2026
CVE-2026-10734 affects the Infility Global plugin for WordPress (up to 2.15.21) with a high severity CVSS score of 7.2. Unauthenticated…
CVE-2026-13424: Online Scheduling and Appointment Booking System <= 27.7 Unauthenticated Stored Cross-Site Scripting via bookly_speed_up_update_addons AJAX action PoC, Patch Analysis & Rule
August 15, 2026
CVE-2026-13424 affects the Bookly Responsive Appointment Booking Tool (up to version 27.7) with a high severity CVSS score of 7.2.…
CVE-2026-2497: Gallery by BestWebSoft <= 4.7.9 Authenticated (Editor+) SQL Injection via Gallery Image Order Array Keys PoC, Patch Analysis & Rule
August 15, 2026
CVE-2026-2497 affects the Gallery Plugin for WordPress (up to version 4.7.9) with a CVSS score of 7.2. Authenticated attackers can…
CVE-2026-17581: WCPOS <= 1.9.14 Authenticated (Shop Manager+) Code Injection via 'thermal' Template Engine PoC, Patch Analysis & Rule
August 15, 2026
CVE-2026-17581 affects the Woocommerce Pos plugin (up to 1.9.14) with a CVSS score of 7.2. Authenticated attackers can exploit this…
CVE-2026-17087: WP Travel Engine <= 6.8.4 Missing Authorization to Unauthenticated Sensitive Information Disclosure via 'booking_id' Parameter PoC, Patch Analysis & Rule
August 15, 2026
CVE-2026-17087 affects WP Travel Engine versions up to 6.8.4, allowing unauthorized access to sensitive booking details. Upgrade to 6.8.5 to…
CVE-2026-15142: Real Estate Manager Pro <= 12.8.6 Authenticated (Subscriber+) Privilege Escalation via 'user_has_cap' Filter ID Collision PoC, Patch Analysis & Rule
August 14, 2026
CVE-2026-15142 affects the Real Estate Manager Pro plugin (up to v12.8.6) with a CVSS score of 7.5. Authenticated users can…
CVE-2026-14279: Wholesale Market <= 2.2.2 Authenticated (Subscriber+) Privilege Escalation via 'role_required' Parameter PoC, Patch Analysis & Rule
August 14, 2026
CVE-2026-14279 affects the Wholesale Market plugin for WordPress (up to 2.2.2) with a high severity CVSS score of 8.8. Authenticated…
CVE-2026-16145: Invisible Anti-Spam & CAPTCHA <= 5.1 Unauthenticated Stored Cross-Site Scripting via 'action' Parameter PoC, Patch Analysis & Rule
August 14, 2026
CVE-2026-16145 affects the Gdpr Compliant Recaptcha For All Forms plugin (up to 5.1) with a high severity CVSS score of…
CVE-2026-15312: Propovoice: All-in-One Client Management System <= 1.7.8 Authenticated (ndpv_manager+) Privilege Escalation via 'role' Parameter PoC, Patch Analysis & Rule
August 14, 2026
CVE-2026-15312 affects the Propovoice plugin (up to version 1.7.8) with a CVSS score of 8.8. Authenticated users can escalate privileges…
CVE-2026-15965: MaxUpload <= 1.4.0 Unauthenticated Arbitrary File Upload via 'resumableFilename' Parameter PoC, Patch Analysis & Rule
August 14, 2026
CVE-2026-15965 affects the Maxupload Upload Larger Files Easily plugin (v1.4.0 and earlier) with a high severity CVSS score of 8.8.…
CVE-2026-15162: Object Sync for Salesforce <= 2.2.13 Unauthenticated SQL Injection PoC, Patch Analysis & Rule
August 14, 2026
CVE-2026-15162 affects the Object Sync For Salesforce plugin (v2.2.13) with a CVSS score of 7.5. This high-severity SQL injection allows…
CVE-2026-14433: Online Booking & Scheduling Calendar for WordPress by vcita <= 4.6.0 Unauthenticated Stored Cross-Site Scripting via REST API 'business_id' Parameter PoC, Patch Analysis & Rule
August 14, 2026
CVE-2026-14433 affects Meeting Scheduler By Vcita plugin versions up to 4.6.0, with a CVSS score of 7.2. Unauthenticated attackers can…
CVE-2026-18109: W3 Total Cache <= 2.10.3 Unauthenticated Stored Cross-Site Scripting via Comment Author Name PoC, Patch Analysis & Rule
August 13, 2026
CVE-2026-18109 affects W3 Total Cache plugin versions up to 2.10.3 with a CVSS score of 7.2. This high-severity stored XSS…
CVE-2026-27537: Smart Popup by Supsystic <= 1.11.2 Unauthenticated Stored Cross-Site Scripting PoC, Patch Analysis & Rule
August 13, 2026
CVE-2026-27537 affects the Popup By Supsystic plugin (v1.11.2 and below) with a high severity score of 7.2 due to stored…
CVE-2026-65493: Dokan Pro <= 5.0.2 Authenticated (Subscriber+) PHP Object Injection PoC, Patch Analysis & Rule
August 12, 2026
CVE-2026-65493 affects Dokan Pro versions up to 5.0.2, allowing authenticated attackers to exploit a PHP Object Injection vulnerability. With a…
CVE-2026-18146: Fluent Forms <= 6.2.11 Unauthenticated Stored Cross-Site Scripting via Notification Smartcode Values PoC, Patch Analysis & Rule
August 12, 2026
CVE-2026-18146 affects Fluent Forms versions up to 6.2.11 with a CVSS score of 7.2. This high-severity XSS vulnerability allows attackers…
1
2
3
…
35
→