Skip to main content
Skip to footer
Home
CVE Analysis
How it Works
Resources
Pricing
Log in
Free Protection
Home
CVE Analysis
How it Works
Resources
Pricing
Log in
Free Protection
Severity:
high
CVE-2026-42386: Order Delivery Date for WooCommerce <= 4.5.1 – Unauthenticated SQL Injection (order-delivery-date-for-woocommerce)
May 18, 2026
CVE-2026-42386 affects the Order Delivery Date For WooCommerce plugin (up to v4.5.1) with a CVSS score of 7.5. Patch to…
CVE-2026-42649: Favicon Rotator <= 1.2.11 – Unauthenticated Stored Cross-Site Scripting (favicon-rotator)
May 18, 2026
CVE-2026-42649 affects the Favicon Rotator plugin for WordPress (up to version 1.2.11) with a CVSS score of 7.2. Unauthenticated attackers…
CVE-2026-42381: FunnelKit – Funnel Builder for WooCommerce Checkout <= 3.15.0.1 – Unauthenticated SQL Injection (funnel-builder)
May 18, 2026
CVE-2026-42381 affects the Funnel Builder plugin for WordPress (up to 3.15.0.1) with a high severity SQL injection vulnerability (CVSS 7.5).…
CVE-2026-42653: Affiliate Program Suite — SliceWP Affiliates <= 1.2.6 – Unauthenticated Stored Cross-Site Scripting (slicewp)
May 17, 2026
CVE-2026-42653 affects the SliceWP Affiliates plugin (up to v1.2.6) with a CVSS score of 7.2, exposing users to stored XSS…
CVE-2026-3772: WP Editor <= 1.2.9.2 – Cross-Site Request Forgery to Remote Code Execution via Plugin and Theme File Editor (wp-editor)
May 17, 2026
CVE-2026-3772 affects WP Editor plugin versions up to 1.2.9.2 with a CVSS score of 8.8. It allows unauthenticated attackers to…
CVE-2026-42774: JetEngine <= 3.8.8.1 – Unauthenticated SQL Injection (jet-engine)
May 17, 2026
CVE-2026-42774 affects the Jet Engine plugin for WordPress (up to version 3.8.8.1) with a CVSS score of 7.5. Unauthenticated SQL…
CVE-2026-42650: AutomatorWP – Automator plugin for no-code automations, webhooks & custom integrations in WordPress <= 5.6.7 – Unauthenticated Stored Cross-Site Scripting (automatorwp)
May 17, 2026
CVE-2026-42650 affects AutomatorWP plugin versions up to 5.6.7, with a CVSS score of 7.2. This high-severity XSS vulnerability allows unauthenticated…
CVE-2026-42658: Classified Listing – AI-Powered Classified ads & Business Directory Plugin <= 5.3.8 – Unauthenticated Stored Cross-Site Scripting (classified-listing)
May 17, 2026
CVE-2026-42658 affects the Classified Listing plugin for WordPress (up to version 5.3.8) with a CVSS score of 7.2. Users should…
CVE-2026-4935: OttoKit: All-in-One Automation Platform < 1.1.23 – Unauthenticated SQL Injection (suretriggers)
May 16, 2026
CVE-2026-4935 affects the Suretriggers plugin for WordPress, with a CVSS score of 7.5. This high-severity SQL injection vulnerability allows unauthenticated…
CVE-2026-42665: WP Data Access – App Builder for Tables, Forms, Charts, Maps & Dashboards <= 5.5.70 – Unauthenticated SQL Injection (wp-data-access)
May 16, 2026
CVE-2026-42665 affects the WP Data Access plugin (up to version 5.5.70) with a CVSS score of 7.5. This high-severity SQL…
CVE-2026-8719: AI Engine 3.4.9 – Authenticated (Subscriber+) Privilege Escalation via Missing Authorization in MCP OAuth Bearer Token (ai-engine)
May 16, 2026
CVE-2026-8719 affects the Ai Engine plugin for WordPress (up to version 3.4.9) with a CVSS score of 8.8. This high-severity…
CVE-2026-40798: wpForo Forum <= 3.0.4 – Unauthenticated SQL Injection (wpforo)
May 16, 2026
CVE-2026-40798 affects the wpForo plugin for WordPress (up to v3.0.4) with a CVSS score of 7.5. This high-severity SQL injection…
CVE-2026-42773: eMagicOne Store Manager for WooCommerce <= 1.3.2 – Unauthenticated SQL Injection (store-manager-connector)
May 16, 2026
CVE-2026-42773 affects the Store Manager Connector plugin for WordPress (up to version 1.3.2) with a CVSS score of 7.5. Unauthenticated…
CVE-2026-4029: Database Backup for WordPress <= 2.5.2 – Missing Authorization to Unauthenticated Database Export (wp-db-backup)
May 15, 2026
CVE-2026-4029 affects the Wp Db Backup plugin (up to version 2.5.2) with a high severity CVSS of 7.5, allowing unauthorized…
CVE-2026-6177: Custom Twitter Feeds <= 2.5.4 – Unauthenticated Stored Cross-Site Scripting via Cached Tweet Text (custom-twitter-feeds)
May 15, 2026
CVE-2026-6177 affects the Custom Twitter Feeds plugin for WordPress (up to version 2.5.4) with a CVSS score of 7.2. This…
CVE-2026-4609: ProfileGrid <= 5.9.8.4 – Missing Authorization to Authenticated (Subscriber+) Arbitrary Group Joining (profilegrid-user-profiles-groups-and-communities)
May 15, 2026
CVE-2026-4609 affects the ProfileGrid User Profiles plugin (up to 5.9.8.4) with a CVSS score of 7.1. Authenticated attackers can join…
CVE-2026-7635: coreActivity: Activity Logging for WordPress <= 3.0 – Unauthenticated PHP Object Injection via 'user_agent' Log Meta Field (coreactivity)
May 15, 2026
CVE-2026-7635 affects the Coreactivity plugin for WordPress (versions up to 3.0) with a CVSS score of 8.1. Unauthenticated attackers can…
CVE-2026-6690: LifePress <= 2.2.2 – Unauthenticated Stored Cross-Site Scripting via 'n' Parameter via lp_update_mds AJAX Action (lifepress)
May 15, 2026
CVE-2026-6690 affects the LifePress plugin for WordPress (up to version 2.2.2) with a CVSS score of 7.2. This high-severity stored…
CVE-2026-6228: Frontend Admin by DynamiApps <= 3.28.36 – Unauthenticated Privilege Escalation via Edit User Form (acf-frontend-form-element)
May 14, 2026
CVE-2026-6228 affects the ACF Frontend Form Element plugin for WordPress (up to version 3.28.36) with a CVSS score of 8.8.…
CVE-2026-6403: Quick Playground <= 1.3.3 – Unauthenticated Path Traversal to Arbitrary File Read via 'stylesheet' Parameter (quick-playground)
May 14, 2026
CVE-2026-6403 affects the Quick Playground plugin for WordPress (up to version 1.3.3) with a high severity CVSS score of 7.5.…
←
1
2
3
4
5
6
…
26
→