Skip to main content
Skip to footer
Home
CVE Analysis
How it Works
Resources
Pricing
Log in
Free Protection
Home
CVE Analysis
How it Works
Resources
Pricing
Log in
Free Protection
Severity:
high
CVE-2026-49104: Integration for Keap/infusionsoft and Contact Form 7, WPForms, Elementor, Formidable, Ninja Forms <= 1.2.1 Unauthenticated PHP Object Injection PoC, Patch Analysis & Rule
June 13, 2026
CVE-2026-49104 affects the Cf7 Infusionsoft plugin (up to version 1.2.1) with a high severity CVSS score of 8.1. Unauthenticated attackers…
CVE-2026-49105: WP Zendesk for Contact Form 7, WPForms, Elementor, Formidable and Ninja Forms <= 1.1.4 Unauthenticated PHP Object Injection PoC, Patch Analysis & Rule
June 13, 2026
CVE-2026-49105 affects the Cf7 Zendesk plugin for WordPress (up to 1.1.4) with a high severity CVSS score of 8.1. Unauthenticated…
CVE-2026-49085: WP Insightly for Contact Form 7, WPForms, Elementor, Formidable and Ninja Forms <= 1.1.4 Unauthenticated PHP Object Injection PoC, Patch Analysis & Rule
June 13, 2026
CVE-2026-49085 affects the Cf7 Insightly plugin for WordPress, with a CVSS score of 8.1. Users should upgrade to version 1.1.5…
CVE-2026-8438: All-In-One Security (AIOS) <= 5.4.7 Unauthenticated Stored Cross-Site Scripting via REST API Request Path PoC, Patch Analysis & Rule
June 12, 2026
CVE-2026-8438 affects the All In One WP Security And Firewall plugin (up to version 5.4.7) with a CVSS score of…
CVE-2026-5415: WP Captcha PRO <= 5.38 Authenticated (Subscriber+) Authentication Bypass via Temporary Login Link PoC, Patch Analysis & Rule
June 12, 2026
CVE-2026-5415 affects the Advanced Google Recaptcha plugin, allowing authenticated attackers to bypass authentication due to a nonce check flaw. Users…
CVE-2026-7537: MDJM Event Management <= 1.7.8.3 Authenticated (Administrator+) Arbitrary File Upload via 'mdjm_email_upload_file' Parameter PoC, Patch Analysis & Rule
June 11, 2026
CVE-2026-7537 affects the Mobile Dj Manager plugin (up to 1.7.8.3) with a CVSS score of 7.2. Authenticated attackers can exploit…
CVE-2026-8901: Integration for Freshsales <= 1.0.15 Unauthenticated Stored Cross-Site Scripting via Form Submission Data PoC, Patch Analysis & Rule
June 11, 2026
CVE-2026-8901 affects the Crm Integration Freshworks Any Form plugin (up to v1.0.15) with a CVSS score of 7.2. It allows…
CVE-2026-10795: UpdraftPlus: WP Backup & Migration Plugin <= 1.26.4 Unauthenticated Authentication Bypass via UpdraftCentral udrpc PoC, Patch Analysis & Rule
June 10, 2026
CVE-2026-10795 affects UpdraftPlus plugin versions up to 1.26.4 with a high severity CVSS score of 8.1. Patch to 1.26.5 to…
CVE-2026-9185: 6Storage Rentals <= 2.22.0 Unauthenticated Insecure Direct Object Reference to Arbitrary User Disclosure and Modification via 'userId' Parameter PoC, Patch Analysis & Rule
June 10, 2026
CVE-2026-9185 affects the 6Storage Rentals plugin for WordPress (up to 2.22.0) with a CVSS score of 7.5. Unauthenticated attackers can…
CVE-2026-7556: FV Flowplayer Video Player <= 7.5.49.7212 Unauthenticated Stored Cross-Site Scripting via Comment Text PoC, Patch Analysis & Rule
June 10, 2026
CVE-2026-7556 affects the FV WordPress Flowplayer plugin with a CVSS score of 7.2. This high-severity XSS vulnerability allows attackers to…
CVE-2026-9851: Booking Package <= 1.7.16 Authenticated (Editor+) Privilege Escalation via Account Takeover to updateUser AJAX Action PoC, Patch Analysis & Rule
June 10, 2026
CVE-2026-9851 affects the Booking Package plugin for WordPress (up to v1.7.16) with a CVSS score of 7.2. Authenticated attackers can…
CVE-2026-3018: Newsletters <= 4.13 Unauthenticated SQL Injection via wpmlsubscriber_id Parameter PoC, Patch Analysis & Rule
June 9, 2026
CVE-2026-3018 affects the Newsletters Lite plugin for WordPress (up to v4.13) with a CVSS score of 7.5. This high-severity SQL…
CVE-2026-11616: Events Calendar for GeoDirectory <= 2.3.28 Authenticated (Subscriber+) Privilege Escalation PoC, Patch Analysis & Rule
June 9, 2026
CVE-2026-11616 affects the Events For Geodirectory plugin (up to version 2.3.28) with a CVSS score of 8.8. Authenticated users can…
CVE-2026-9662: Recover Exit For WooCommerce <= 1.0.3 Unauthenticated Local File Inclusion via 'tpf' Parameter PoC, Patch Analysis & Rule
June 9, 2026
CVE-2026-9662 reveals a high severity Local File Inclusion vulnerability in the Recover Exit For WooCommerce plugin (up to 1.0.3). Unauthenticated…
CVE-2026-5073: ARMember Premium <= 7.3.1 Unauthenticated SQL Injection via 'order' Parameter PoC, Patch Analysis & Rule
June 2, 2026
CVE-2026-5073 reveals a high severity SQL injection vulnerability in the ARMember plugin for WordPress, affecting versions up to 7.3.1. Users…
CVE-2026-1829: Content Visibility for Divi Builder <= 4.02 Authenticated (Contributor+) Remote Code Execution PoC, Patch Analysis & Rule
June 2, 2026
CVE-2026-1829 affects the Content Visibility For Divi Builder plugin (up to version 4.02) with a CVSS score of 8.8. Authenticated…
CVE-2026-6895: Wishlist Member <= 3.30.1 – Missing Authorization to Authenticated (Subscriber+) API Secret Key Disclosure and Privilege Escalation via 'wlm3_export_settings' AJAX Action (wishlist-member-x)
May 22, 2026
CVE-2026-6895 affects the WishList Member plugin (up to version 3.30.1) with a CVSS score of 8.8. It allows privilege escalation…
CVE-2026-6419: Wishlist Member <= 3.30.1 – Missing Authorization to Authenticated (Subscriber+) API Secret Key Disclosure and Privilege Escalation via 'wlm3_get_screen' AJAX action (wishlist-member-x)
May 22, 2026
CVE-2026-6419 affects Wishlist Member X plugin versions up to 3.30.1, allowing privilege escalation for authenticated users. With a CVSS score…
CVE-2026-9284: WooCommerce PayPal Payments <= 4.0.1 – Missing Authorization to Unauthenticated Order Manipulation and Information Disclosure (woocommerce-paypal-payments)
May 22, 2026
CVE-2026-9284 affects the WooCommerce PayPal Payments plugin (up to 4.0.1) with a CVSS of 8.2. It allows unauthorized order manipulation…
CVE-2026-6898: WishList Member <= 3.30.1 – Missing Authorization to Authenticated (Subscriber+) Generate API Secret Key via 'wlm3_generate_api_key' AJAX action (wishlist-member-x)
May 22, 2026
CVE-2026-6898 affects Wishlist Member X plugin versions up to 3.30.1, allowing authenticated attackers to take over sites by modifying the…
←
1
2
3
4
…
26
→