Skip to main content
Skip to footer
Home
CVE Analysis
How it Works
Resources
Pricing
Log in
Create Account
Home
CVE Analysis
How it Works
Resources
Pricing
Log in
Create Account
Severity:
high
CVE-2025-69383: shop <= 2.6.1 Unauthenticated Local File Inclusion PoC, Patch Analysis & Rule
March 18, 2026
CVE-2025-69383 affects the Wpshop plugin (up to 2.6.1) with a CVSS score of 8.1, allowing unauthenticated attackers to execute arbitrary…
CVE-2025-69382: Themesflat Elementor <= 1.0.1 Unauthenticated PHP Object Injection PoC, Patch Analysis & Rule
March 18, 2026
CVE-2025-69382 affects the Themesflat Elementor plugin (v1.0.1 and earlier) with a CVSS score of 8.1. This high-severity file upload vulnerability…
CVE-2025-69387: Simple Retail Menus <= 4.2.1 Unauthenticated Local File Inclusion PoC, Patch Analysis & Rule
March 18, 2026
CVE-2025-69387 affects the Simple Retail Menus plugin (up to v4.2.1) with a high severity CVSS of 8.1. Unauthenticated attackers can…
CVE-2025-67991: User Extra Fields <= 16.8 Unauthenticated Stored Cross-Site Scripting PoC, Patch Analysis & Rule
March 18, 2026
CVE-2025-67991 affects the Wp User Extra Fields plugin (up to version 16.8) with a high severity CVSS score of 7.2…
CVE-2026-2992: KiviCare <= 4.1.2 Missing Authorization to Unauthenticated Privilege Escalation via Setup Wizard PoC, Patch Analysis & Rule
March 18, 2026
CVE-2026-2992 affects the Kivicare Clinic Management System plugin (up to version 4.1.2) with a high severity CVSS score of 8.2.…
CVE-2026-1463: Photo Gallery, Sliders, Proofing and Themes – NextGEN Gallery <= 4.0.4 Authenticated (Author+) Local File Inclusion PoC, Patch Analysis & Rule
March 18, 2026
CVE-2026-1463 affects NextGEN Gallery plugin (up to v4.0.4) with a high severity CVSS score of 8.8. Authenticated attackers can exploit…
CVE-2026-3090: Post SMTP <= 3.8.0 Unauthenticated Stored Cross-Site Scripting via 'event_type' PoC, Patch Analysis & Rule
March 18, 2026
CVE-2026-3090 affects Post SMTP plugin versions up to 3.8.0 with a CVSS score of 7.2. It allows stored XSS attacks.…
CVE-2026-2890: Formidable Forms <= 6.28 Missing Authorization to Unauthenticated Payment Integrity Bypass via PaymentIntent Reuse PoC, Patch Analysis & Rule
March 18, 2026
CVE-2026-2890 affects the Formidable Forms plugin (up to v6.28) with a high severity (CVSS 7.5) vulnerability allowing payment integrity bypass.…
CVE-2026-1947: NEX-Forms – Ultimate Forms Plugin for WordPress <= 9.1.9 Missing Authorization to Unauthenticated Arbitrary Form Entry Modification via nf_set_entry_update_id PoC, Patch Analysis & Rule
March 18, 2026
CVE-2026-1947 affects the Nex Forms Express WP Form Builder plugin (up to v9.1.9) with a CVSS score of 7.5. Unauthenticated…
CVE-2026-3231: Checkout Field Editor (Checkout Manager) for WooCommerce <= 2.1.7 Unauthenticated Stored Cross-Site Scripting via Block Checkout Custom Radio Field PoC, Patch Analysis & Rule
March 18, 2026
CVE-2026-3231 affects Woo Checkout Field Editor Pro (up to v2.1.7) with a high severity CVSS score of 7.2. Unauthenticated attackers…
CVE-2026-1708: Appointment Booking Calendar <= 1.6.9.27 Unauthenticated SQL Injection via 'append_where_sql' Parameter PoC, Patch Analysis & Rule
March 18, 2026
CVE-2026-1708 affects the Simply Schedule Appointments plugin (versions
CVE-2026-3657: My Sticky Bar <= 2.8.6 Unauthenticated SQL Injection via 'stickymenu_contact_lead_form' Action PoC, Patch Analysis & Rule
March 18, 2026
CVE-2026-3657 affects the My Sticky Menu plugin (up to version 2.8.6) with a high severity SQL injection vulnerability (CVSS 7.5).…
CVE-2026-3045: Appointment Booking Calendar <= 1.6.9.29 Missing Authorization to Unauthenticated Sensitive Information Exposure via Settings REST API Endpoint PoC, Patch Analysis & Rule
March 18, 2026
CVE-2026-3045 affects the Simply Schedule Appointments plugin (up to 1.6.9.29) with a CVSS score of 7.5. Unauthenticated users can access…
CVE-2026-2724: Unlimited Elements For Elementor <= 2.0.5 Unauthenticated Stored Cross-Site Scripting via Form Entry Fields PoC, Patch Analysis & Rule
March 18, 2026
CVE-2026-2724 affects Unlimited Elements For Elementor (up to v2.0.5) with a CVSS score of 7.2. This high-severity XSS vulnerability allows…
CVE-2026-1454: Responsive Contact Form Builder & Lead Generation Plugin <= 2.0.1 Unauthenticated Stored Cross-Site Scripting PoC, Patch Analysis & Rule
March 18, 2026
CVE-2026-1454 affects the Lead Form Builder plugin for WordPress (up to v2.0.1) with a CVSS score of 7.2. Ensure you…
CVE-2026-3178: Name Directory <= 1.32.1 Unauthenticated Stored Cross-Site Scripting via 'name_directory_name' PoC, Patch Analysis & Rule
March 18, 2026
CVE-2026-3178 affects the Name Directory plugin (up to 1.32.1) with a high severity CVSS score of 7.2 due to stored…
CVE-2025-13067: Royal Addons for Elementor <= 1.7.1049 Authenticated (Author+) Arbitrary File Upload via main.php Upload Bypass PoC, Patch Analysis & Rule
March 18, 2026
CVE-2025-13067 affects the Royal Elementor Addons plugin (up to v1.7.1049) with a high severity (CVSS 8.8) file upload vulnerability. Update…
CVE-2026-3453: ProfilePress <= 4.16.11 Insecure Direct Object Reference to Authenticated (Subscriber+) Arbitrary Subscription Cancellation/Expiration PoC, Patch Analysis & Rule
March 18, 2026
CVE-2026-3453 affects the Wp User Avatar plugin (up to version 4.16.11) with a CVSS score of 8.1. Authenticated users can…
CVE-2026-2413: Ally – Web Accessibility & Usability <= 4.0.3 Unauthenticated SQL Injection via URL Path PoC, Patch Analysis & Rule
March 18, 2026
CVE-2026-2413 affects the Pojo Accessibility plugin (up to v4.0.3) with a high severity (CVSS 7.5) SQL injection vulnerability. Update to…
CVE-2026-3222: WP Maps <= 4.9.1 Unauthenticated SQL Injection via 'location_id' Parameter PoC, Patch Analysis & Rule
March 18, 2026
CVE-2026-3222 affects the WP Google Map Plugin (up to v4.9.1) with a high severity CVSS of 7.5 due to SQL…
←
1
…
32
33
34
35
→