Skip to main content
Skip to footer
Home
CVE Analysis
How it Works
Resources
Pricing
Log in
Create Account
Home
CVE Analysis
How it Works
Resources
Pricing
Log in
Create Account
Severity:
high
CVE-2026-3496: JetBooking <= 4.0.3 Unauthenticated SQL Injection via 'check_in_date' Parameter PoC, Patch Analysis & Rule
March 18, 2026
CVE-2026-3496 affects the Jet Booking plugin (up to version 4.0.3) with a high severity score of 7.5. This SQL injection…
CVE-2026-1992: ExactMetrics 8.6.0 9.0.2 Authenticated (Custom) Insecure Direct Object Reference to Arbitrary Plugin Installation PoC, Patch Analysis & Rule
March 18, 2026
CVE-2026-1992 affects the Google Analytics Dashboard for WP plugin (versions 8.6.0 to 9.0.2) with a CVSS score of 8.8. Patch…
CVE-2026-2466: DukaPress <= 3.2.4 Unauthenticated Stored Cross-Site Scripting PoC, Patch Analysis & Rule
March 18, 2026
CVE-2026-2466 affects the DukaPress plugin (up to version 3.2.4) with a high severity CVSS score of 7.2. Unauthenticated attackers can…
CVE-2026-1993: ExactMetrics 7.1.0 9.0.2 Authenticated (Custom) Improper Privilege Management to Role Privilege Escalation via Settings Update PoC, Patch Analysis & Rule
March 18, 2026
CVE-2026-1993 affects the Google Analytics Dashboard for WP plugin (versions 7.1.0 to 9.0.2) with a CVSS score of 8.8. Update…
CVE-2025-14675: Meta Box <= 5.11.1 Authenticated (Contributor+) Arbitrary File Deletion PoC, Patch Analysis & Rule
March 18, 2026
CVE-2025-14675 affects the Meta Box plugin (up to v5.11.1) with a high severity score of 7.2. Patching to v5.11.2 is…
CVE-2026-3585: The Events Calendar <= 6.15.17 Authenticated (Author+) Arbitrary File Read via ajax_create_import PoC, Patch Analysis & Rule
March 18, 2026
CVE-2026-3585 affects The Events Calendar plugin (up to 6.15.17) with a CVSS score of 7.5. This high-severity file upload vulnerability…
CVE-2026-1261: MetForm Pro <= 3.9.6 Unauthenticated Stored Cross-Site Scripting PoC, Patch Analysis & Rule
March 18, 2026
CVE-2026-1261 affects Metform Pro plugin versions up to 3.9.6, posing a high severity risk (CVSS 7.2) due to stored XSS…
CVE-2026-1074: WP App Bar <= 1.5 Unauthenticated Stored Cross-Site Scripting via 'app-bar-features' Parameter PoC, Patch Analysis & Rule
March 18, 2026
CVE-2026-1074 affects the WP App Bar plugin (up to version 1.5) with a CVSS score of 7.2. This high-severity stored…
CVE-2026-2020: JS Archive List <= 6.1.7 Authenticated (Contributor+) PHP Object Injection via 'included' Shortcode Attribute PoC, Patch Analysis & Rule
March 18, 2026
CVE-2026-2020 affects the Jquery Archive List Widget plugin (up to 6.1.7) with a high severity (CVSS 7.5) PHP Object Injection…
CVE-2025-14353: ZIP Code Based Content Protection <= 1.0.2 Unauthenticated SQL Injection via 'zipcode' Parameter PoC, Patch Analysis & Rule
March 18, 2026
CVE-2025-14353 affects the Zip Code Based Content Protection plugin for WordPress (up to v1.0.2) with a CVSS score of 7.5.…
CVE-2025-8899: Paid Videochat Turnkey Site – HTML5 PPV Live Webcams <= 7.3.20 Authenticated (Author+) Privilege Escalation PoC, Patch Analysis & Rule
March 18, 2026
CVE-2025-8899 affects the Ppv Live Webcams plugin (up to v7.3.20) with a high severity (CVSS 8.8) privilege escalation vulnerability. Authenticated…
CVE-2026-3352: Easy PHP Settings <= 1.0.4 Authenticated (Administrator+) PHP Code Injection via 'wp_memory_limit' Setting PoC, Patch Analysis & Rule
March 18, 2026
CVE-2026-3352 affects Easy Php Settings plugin versions up to 1.0.4, allowing PHP code injection with a CVSS score of 7.2.…
CVE-2026-2365: Fluent Forms Pro <= 6.1.17 Unauthenticated Stored Cross-Site Scripting via Draft Form Submission PoC, Patch Analysis & Rule
March 18, 2026
CVE-2026-2365 affects Fluent Forms Pro (up to 6.1.17) with a CVSS score of 7.2. Unauthenticated attackers can exploit stored XSS…
CVE-2026-22484: Lisfinity Core Lisfinity Core plugin used for pebas® Lisfinity WordPress theme <= 1.5.0 Unauthenticated SQL Injection PoC, Patch Analysis & Rule
March 18, 2026
CVE-2026-22484 affects the Lisfinity Core plugin (v1.5.0) with a CVSS score of 7.5. This high-severity SQL injection vulnerability allows unauthenticated…
CVE-2026-22485: My Album Gallery <= 1.0.4 Authenticated (Subscriber+) Arbitrary File Deletion PoC, Patch Analysis & Rule
March 18, 2026
CVE-2026-22485 affects the My Album Gallery plugin (v1.0.4) with a high severity (CVSS 8.1) file upload vulnerability, allowing authenticated users…
CVE-2026-27095: Bus Ticket Booking with Seat Reservation <= 5.6.2 Unauthenticated PHP Object Injection PoC, Patch Analysis & Rule
March 18, 2026
CVE-2026-27095 affects the Bus Ticket Booking With Seat Reservation plugin (up to 5.6.2) with a CVSS score of 8.1. This…
CVE-2026-3459: Drag and Drop Multiple File Upload for Contact Form 7 <= 1.3.9.5 Unauthenticated Arbitrary File Upload PoC, Patch Analysis & Rule
March 18, 2026
CVE-2026-3459 affects the Drag And Drop Multiple File Upload Contact Form 7 plugin, with a CVSS score of 8.1. Update…
CVE-2026-22471: Secudeal Payments for Ecommerce <= 1.1 Unauthenticated PHP Object Injection PoC, Patch Analysis & Rule
March 18, 2026
CVE-2026-22471 affects the Secudeal Payments for Ecommerce plugin (v1.1) with a high severity CVSS score of 8.1. Unauthenticated attackers can…
CVE-2026-1321: Membership Plugin – Restrict Content <= 3.2.20 Unauthenticated Privilege Escalation via 'rcp_level' PoC, Patch Analysis & Rule
March 18, 2026
CVE-2026-1321 affects the Restrict Content plugin (up to v3.2.20) with a CVSS score of 8.1. Unauthenticated attackers can exploit this…
←
1
…
33
34
35