Skip to main content
Skip to footer
Home
CVE Analysis
How it Works
Resources
Pricing
Log in
Create Account
Home
CVE Analysis
How it Works
Resources
Pricing
Log in
Create Account
Severity:
high
CVE-2026-59556: Dynamic Pricing With Discount Rules for WooCommerce <= 4.5.11 Unauthenticated Stored Cross-Site Scripting PoC, Patch Analysis & Rule
August 9, 2026
CVE-2026-59556 affects the Aco Woo Dynamic Pricing plugin (up to 4.5.11) with a high severity CVSS score of 7.2. Unauthenticated…
CVE-2026-59553: Product Feed Manager For WooCommerce – Sell on 200+ Online Marketplaces <= 7.6.1 Unauthenticated Stored Cross-Site Scripting PoC, Patch Analysis & Rule
August 9, 2026
CVE-2026-59553 affects the Best Woocommerce Feed plugin (versions 7.6.1 and earlier) with a CVSS score of 7.2. Users should upgrade…
CVE-2026-59527: MapSVG – Vector maps, Image maps, Google Maps <= 8.14.0 Unauthenticated SQL Injection PoC, Patch Analysis & Rule
August 9, 2026
CVE-2026-59527 affects the MapSVG Lite Interactive Vector Maps plugin for WordPress (up to 8.14.0) with a CVSS score of 7.5.…
CVE-2026-65545: AI Engine – The Chatbot, AI Framework & MCP for WordPress <= 3.6.8 Unauthenticated Stored Cross-Site Scripting PoC, Patch Analysis & Rule
August 8, 2026
CVE-2026-65545 affects the Ai Engine plugin (up to v3.6.8) with a high severity CVSS score of 7.2 due to stored…
CVE-2026-65549: Jeg Kit for Elementor – Powerful Addons for Elementor, Widgets & Templates for WordPress <= 3.2.10 Authenticated (Author+) PHP Object Injection PoC, Patch Analysis & Rule
August 8, 2026
CVE-2026-65549 affects the Jeg Elementor Kit plugin (up to version 3.2.10) with a high severity CVSS score of 7.5. Authenticated…
CVE-2026-65517: Easy PayPal & Stripe Buy Now Button <= 2.0.4 Unauthenticated Stored Cross-Site Scripting PoC, Patch Analysis & Rule
August 8, 2026
CVE-2026-65517 affects Wp Ecommerce Paypal plugin versions up to 2.0.4, with a CVSS score of 7.2. This high-severity stored XSS…
CVE-2026-65508: Simply Schedule Appointments <= 1.6.12.10 Unauthenticated SQL Injection PoC, Patch Analysis & Rule
August 8, 2026
CVE-2026-65508 affects the Simply Schedule Appointments plugin (up to 1.6.12.10) with a high severity SQL injection vulnerability (CVSS 7.5). Update…
CVE-2026-65509: wpDataTables (Premium) <= 7.5.1 Unauthenticated Stored Cross-Site Scripting PoC, Patch Analysis & Rule
August 8, 2026
CVE-2026-65509 affects the wpDataTables plugin (up to version 7.5.1) with a high severity CVSS score of 7.2. Unauthenticated attackers can…
CVE-2026-65544: Social Share, Social Login and Social Comments Plugin – Super Socializer <= 7.14.5 Unauthenticated Stored Cross-Site Scripting PoC, Patch Analysis & Rule
August 8, 2026
CVE-2026-65544 affects the Super Socializer plugin (up to version 7.14.5) with a CVSS score of 7.2. This high-severity XSS vulnerability…
CVE-2026-66707: Meta for WooCommerce <= 3.7.5 Unauthenticated Stored Cross-Site Scripting PoC, Patch Analysis & Rule
August 6, 2026
CVE-2026-66707 affects the Facebook For WooCommerce plugin (up to version 3.7.5) with a CVSS score of 7.2. Unauthenticated XSS vulnerabilities…
CVE-2026-66702: Rank Math SEO – AI SEO Tools to Dominate SEO Rankings <= 1.0.274.1 Unauthenticated Stored Cross-Site Scripting PoC, Patch Analysis & Rule
August 6, 2026
CVE-2026-66702 affects the Rank Math SEO plugin (versions up to 1.0.274.1) with a high severity CVSS score of 7.2 due…
CVE-2026-66705: Meta pixel for WordPress <= 5.2.1 Unauthenticated Stored Cross-Site Scripting PoC, Patch Analysis & Rule
August 6, 2026
CVE-2026-66705 affects the Official Facebook Pixel plugin (up to 5.2.1) with a CVSS score of 7.2. This high-severity XSS vulnerability…
CVE-2026-66690: GiveWP – Donation Plugin and Fundraising Platform <= 4.16.5 Unauthenticated Stored Cross-Site Scripting PoC, Patch Analysis & Rule
August 6, 2026
CVE-2026-66690 affects the GiveWP Donation Plugin (up to version 4.16.5) with a CVSS score of 7.2. This high-severity XSS vulnerability…
CVE-2026-56058: Quform WordPress Form Builder <= 2.23.0 Authenticated (Subscriber+) Arbitrary File Upload PoC, Patch Analysis & Rule
August 6, 2026
CVE-2026-56058 affects the Quform plugin (up to version 2.23.0) with a CVSS score of 8.8. It allows authenticated users to…
CVE-2025-15028: FormGent – Next-Gen AI Form Builder for WordPress with Multi-Step, Quizzes, Payments & More <= 1.9.2 Unauthenticated Stored Cross-Site Scripting PoC, Patch Analysis & Rule
August 5, 2026
CVE-2025-15028 affects the Formgent plugin (up to v1.9.2) with a high severity CVSS of 7.2 due to stored XSS vulnerabilities.…
CVE-2026-18510: TranslatePress <= 3.2.6 Unauthenticated Stored Cross-Site Scripting via Comment Content PoC, Patch Analysis & Rule
August 5, 2026
CVE-2026-18510 affects the TranslatePress Multilingual plugin (up to v3.2.6) with a high severity CVSS score of 7.2. Unauthenticated attackers can…
CVE-2026-15918: VikAppointments – Services Booking Calendar <= 1.2.19 Unauthenticated SQL Injection PoC, Patch Analysis & Rule
August 5, 2026
CVE-2026-15918 affects VikAppointments plugin version 1.2.19 with a CVSS score of 7.5. This high-severity SQL injection vulnerability allows unauthenticated users…
CVE-2026-15459: WPMU DEV Dashboard <= 5.0.0 Authentication Bypass to Arbitrary Plugin Installation (Remote Code Execution) via Forged WDP_AUTH HMAC on ?wpmudev-hub= Endpoint PoC, Patch Analysis & Rule
August 5, 2026
CVE-2026-15459 affects WPMU DEV Dashboard plugin version 5.0.0 and earlier, with a CVSS score of 8.1. Unauthenticated attackers can bypass…
CVE-2026-13395: Online Scheduling and Appointment Booking System – Bookly < 27.8 Unauthenticated SQL Injection PoC, Patch Analysis & Rule
August 5, 2026
CVE-2026-13395 affects the Bookly Responsive Appointment Booking Tool (v27.8 and earlier) with a high severity CVSS score of 7.5. Unauthenticated…
CVE-2026-16636: FluentSMTP <= 2.2.95 Unauthenticated Stored Cross-Site Scripting via Recipient Display Name (to.name) in Email Logs PoC, Patch Analysis & Rule
August 5, 2026
CVE-2026-16636 affects Fluent SMTP plugin versions up to 2.2.95, exposing a high severity cross-site scripting risk (CVSS 7.2). Upgrade to…
←
1
2
3
4
5
…
35
→