Skip to main content
Skip to footer
Home
CVE Analysis
How it Works
Resources
Pricing
Log in
Create Account
Home
CVE Analysis
How it Works
Resources
Pricing
Log in
Create Account
Severity:
high
CVE-2026-54823: Widget Options – Advanced Conditional Visibility for Gutenberg Blocks & Classic Widgets <= 4.2.3 Authenticated (Contributor+) Remote Code Execution PoC, Patch Analysis & Rule
June 28, 2026
CVE-2026-54823 affects the Widget Options plugin (up to v4.2.3) with a CVSS score of 8.8. It allows remote code execution…
CVE-2026-56008: Avada (Fusion) Builder <= 3.15.4 Authenticated (Contributor+) Privilege Escalation PoC, Patch Analysis & Rule
June 27, 2026
CVE-2026-56008 affects the Fusion Builder plugin for WordPress (up to v3.15.4) with a high severity CVSS score of 8.8. Authenticated…
CVE-2026-8095: Frontend File Manager Plugin <= 23.6 Authenticated (Subscriber+) Arbitrary File Deletion PoC, Patch Analysis & Rule
June 27, 2026
CVE-2026-8095 affects the Nmedia User File Uploader plugin (up to version 23.6) with a CVSS score of 8.1. Authenticated attackers…
CVE-2026-54843: MDTF – Meta Data and Taxonomies Filter <= 1.3.7 Unauthenticated SQL Injection PoC, Patch Analysis & Rule
June 27, 2026
CVE-2026-54843 affects the Wp Meta Data Filter And Taxonomy Filter plugin (v1.3.7 and earlier) with a high severity CVSS score…
CVE-2026-54845: MDTF – Meta Data and Taxonomies Filter <= 1.3.8 Unauthenticated Local File Inclusion PoC, Patch Analysis & Rule
June 27, 2026
CVE-2026-54845 affects the Wp Meta Data Filter And Taxonomy Filter plugin (up to 1.3.8) with a CVSS of 8.1. This…
CVE-2026-54836: YMC Filter <= 3.11.5 Unauthenticated SQL Injection PoC, Patch Analysis & Rule
June 27, 2026
CVE-2026-54836 affects the YMC Smart Filter plugin for WordPress (up to version 3.11.5) with a CVSS score of 7.5. Unauthenticated…
CVE-2026-54849: Premmerce Wishlist for WooCommerce <= 1.1.11 Unauthenticated SQL Injection PoC, Patch Analysis & Rule
June 27, 2026
CVE-2026-54849 affects the Premmerce WooCommerce Wishlist plugin (up to 1.1.11) with a high severity SQL injection vulnerability (CVSS 7.5). Users…
CVE-2026-54188: JetEngine <= 3.8.10 Unauthenticated Stored Cross-Site Scripting PoC, Patch Analysis & Rule
June 26, 2026
CVE-2026-54188 affects the Jet Engine plugin for WordPress (up to version 3.8.10) with a high severity CVSS score of 7.2.…
CVE-2026-3652: ARForms <= 7.1.3 Unauthenticated Stored Cross-Site Scripting via 'value' Parameter PoC, Patch Analysis & Rule
June 25, 2026
CVE-2026-3652 affects the ARForms plugin for WordPress (up to version 7.1.3) with a high severity CVSS score of 7.2. Unauthenticated…
CVE-2026-7761: Ultimate Member <= 2.11.4 Authenticated (Contributor+) Account Takeover via Password Reset Link Disclosure PoC, Patch Analysis & Rule
June 25, 2026
CVE-2026-7761 affects the Ultimate Member plugin (versions
CVE-2026-12242: AdRotate Banner Manager <= 5.17.7 Authenticated (Contributor+) PHP Code Injection via 'banner' Shortcode Attribute PoC, Patch Analysis & Rule
June 25, 2026
CVE-2026-12242 affects the AdRotate plugin (up to v5.17.7) with a CVSS score of 8.8. This high-severity PHP code injection vulnerability…
CVE-2026-10091: Email JavaScript Cloak <= 1.03 Unauthenticated Stored Cross-Site Scripting PoC, Patch Analysis & Rule
June 25, 2026
CVE-2026-10091 affects the Email Javascript Cloaker plugin (v1.03) with a CVSS score of 7.2. It allows stored XSS via unsanitized…
CVE-2026-56014: Master Slider – Responsive Touch Slider <= 3.11.2 Unauthenticated Stored Cross-Site Scripting PoC, Patch Analysis & Rule
June 25, 2026
CVE-2026-56014 affects the Master Slider plugin for WordPress (up to version 3.11.2) with a CVSS score of 7.2. Unauthenticated attackers…
CVE-2026-56011: MapPress Maps for WordPress <= 2.97.3 Unauthenticated Stored Cross-Site Scripting PoC, Patch Analysis & Rule
June 25, 2026
CVE-2026-56011 affects MapPress Google Maps for WordPress versions up to 2.97.3, with a CVSS score of 7.2. Users should upgrade…
CVE-2026-6858: Transbank Webpay < 1.14.0 Unauthenticated Stored Cross-Site Scripting PoC, Patch Analysis & Rule
June 25, 2026
CVE-2026-6858 affects the Transbank Webpay Plus Rest plugin (up to version 1.14.0) with a CVSS score of 7.2. This high-severity…
CVE-2026-56010: Abandoned Cart Pro for WooCommerce <= 10.4.0 Authenticated (Subscriber+) Privilege Escalation PoC, Patch Analysis & Rule
June 25, 2026
CVE-2026-56010 affects the WooCommerce Abandon Cart Pro plugin (up to version 10.4.0) with a CVSS score of 8.8. Authenticated users…
CVE-2026-12077: Dokan Pro <= 5.0.4 Unauthenticated SQL Injection via 'latitude' and 'longitude' Parameters PoC, Patch Analysis & Rule
June 24, 2026
CVE-2026-12077 affects the Dokan Pro plugin for WordPress (up to v5.0.4) with a CVSS score of 7.5. This high-severity SQL…
CVE-2026-9179: WP Forms Connector <= 1.8 Unauthenticated SQL Injection via 'order' Parameter PoC, Patch Analysis & Rule
June 24, 2026
CVE-2026-9179 affects the WP Forms Connector plugin (up to version 1.8) with a high severity CVSS score of 7.5. Unauthenticated…
CVE-2026-9178: WP Forms Connector <= 1.8 Missing Authorization to Unauthenticated Information Exposure via 'user/list' REST Endpoint PoC, Patch Analysis & Rule
June 24, 2026
CVE-2026-9178 affects the WP Forms Connector plugin (up to v1.8) with a CVSS score of 7.5. Unauthenticated attackers can access…
CVE-2026-12937: Tourfic <= 2.22.7 Unauthenticated SQL Injection via 'post_id' Parameter PoC, Patch Analysis & Rule
June 24, 2026
CVE-2026-12937 affects the Tourfic plugin for WordPress (up to version 2.22.7), allowing unauthenticated SQL injection with a CVSS score of…
←
1
…
3
4
5
6
7
…
32
→