Skip to main content
Skip to footer
Home
CVE Analysis
How it Works
Resources
Pricing
Log in
Free Protection
Home
CVE Analysis
How it Works
Resources
Pricing
Log in
Free Protection
Severity:
high
CVE-2026-4094: FOX – Currency Switcher Professional for WooCommerce <= 1.4.5 – Missing Authorization to Authenticated (Contributor+) Configuration Deletion (woocommerce-currency-switcher)
May 14, 2026
CVE-2026-4094 affects the Woocommerce Currency Switcher plugin (up to v1.4.5) with a CVSS score of 8.1. Authenticated attackers can exploit…
CVE-2026-5396: Fluent Forms <= 6.1.21 – Authenticated (Subscriber+) Authorization Bypass via 'form_id' Parameter (fluentform)
May 14, 2026
CVE-2026-5396 affects the Fluent Forms plugin for WordPress (up to 6.1.21) with a high severity (CVSS 8.2) authentication bypass vulnerability.…
CVE-2026-4031: Database Backup for WordPress <= 2.5.2 – Missing Authorization to Unauthenticated Database Backup Interception (wp-db-backup)
May 14, 2026
CVE-2026-4031 affects the Wp Db Backup plugin (up to version 2.5.2) with a CVSS score of 7.5. Unauthenticated attackers can…
CVE-2026-42668: Omnisend for WooCommerce <= 1.18.0 – Unauthenticated Omnisend Account Takeover via Predictable Connect Token (omnisend-connect)
May 14, 2026
CVE-2026-42668 affects the Omnisend Connect plugin (v1.18.0) with a CVSS score of 7.5. Unauthenticated attackers can exploit a remote code…
CVE-2026-4030: Database Backup for WordPress <= 2.5.2 – Missing Authorization to Unauthenticated Arbitrary File Read and Deletion (wp-db-backup)
May 14, 2026
CVE-2026-4030 affects the Wp Db Backup plugin (up to 2.5.2) with a CVSS score of 8.1. Unauthenticated attackers can read…
CVE-2026-6514: InfusedWoo Pro <= 5.1.2 – Unauthenticated Arbitrary File Read via 'url' Parameter (infusedwooPRO)
May 13, 2026
CVE-2026-6514 affects the InfusedWoo Pro plugin for WordPress (up to 5.1.2) with a CVSS score of 7.5. Unauthenticated attackers can…
CVE-2026-5395: Fluent Forms <= 6.2.0 – Authenticated (Subscriber+) Authorization Bypass via 'table' Parameter (fluentform)
May 13, 2026
CVE-2026-5395 affects the Fluentform plugin (up to version 6.2.0) with a CVSS score of 8.2. Authenticated users can bypass access…
CVE-2026-3718: ManageWP Worker <= 4.9.31 – Unauthenticated Stored Cross-Site Scripting via 'MWP-Key-Name' Header (worker)
May 13, 2026
CVE-2026-3718 affects the ManageWP Worker plugin for WordPress (up to version 4.9.31) with a CVSS score of 7.2. Patch to…
CVE-2026-6506: InfusedWoo Pro <= 5.1.2 – Authenticated (Subscriber+) Missing Authorization to Privilege Escalation via Arbitrary User Meta Update (infusedwooPRO)
May 13, 2026
CVE-2026-6506 affects the InfusedWoo Pro plugin for WordPress (up to v5.1.2) with a CVSS score of 8.8. Authenticated users can…
CVE-2026-3892: Motors – Car Dealer, Classifieds & Listing <= 1.4.107 – Authenticated (Subscriber+) Arbitrary File Deletion via 'stm_dealer_logo_path' Parameter (motors-car-dealership-classified-listings)
May 13, 2026
CVE-2026-3892 affects the Motors Car Dealership Classified Listings plugin (up to 1.4.107) with a CVSS score of 8.1. Authenticated users…
CVE-2026-6929: JoomSport <= 5.7.7 – Unauthenticated SQL Injection via 'sortf' Parameter (joomsport-sports-league-results-management)
May 12, 2026
CVE-2026-6929 affects the JoomSport plugin for WordPress (up to version 5.7.7) with a CVSS score of 7.5. This high-severity SQL…
CVE-2026-4798: Avada Builder <= 3.15.1 – Unauthenticated SQL Injection via 'product_order' Parameter (fusion-builder)
May 12, 2026
CVE-2026-4798 affects the Fusion Builder plugin for WordPress (up to 3.15.1) with a CVSS score of 7.5. This high-severity SQL…
CVE-2026-5371: MonsterInsights <= 10.1.2 – Missing Authorization to Authenticated (Subscriber+) Sensitive Information Exposure And Plugin Integration Reset (google-analytics-for-wordpress)
May 12, 2026
CVE-2026-5371 affects the Google Analytics For WordPress plugin (up to version 10.1.2) with a CVSS score of 7.1. Authenticated attackers…
CVE-2026-1250: Court Reservation – Manage Your Court Bookings Online <= 1.10.11 – Unauthenticated SQL Injection (court-reservation)
May 12, 2026
CVE-2026-1250 affects the Court Reservation plugin for WordPress (up to 1.10.11) with a CVSS score of 7.5. Unauthenticated SQL injection…
CVE-2026-3425: RTMKit Addons for Elementor <= 2.0.2 – Authenticated (Author+) Local File Inclusion via 'path' (rometheme-for-elementor)
May 12, 2026
CVE-2026-3425 affects the Rometheme For Elementor plugin (up to v2.0.2) with a CVSS score of 8.8. Authenticated attackers can exploit…
CVE-2026-2993: AI Chatbot & Workflow Automation by AIWU <= 1.4.17 – Unauthenticated SQL Injection in getListForTbl() (ai-copilot-content-generator)
May 11, 2026
CVE-2026-2993 affects the Ai Copilot Content Generator plugin (up to v1.4.17) with a high severity SQL injection vulnerability (CVSS 7.5).…
CVE-2026-1719: Gravity Bookings <= 2.5.9 – Unauthenticated SQL Injection via 'category_id' Parameter (gf-bookings-premium)
May 5, 2026
CVE-2026-1719 affects the Gravity Bookings Premium plugin for WordPress (up to v2.5.9) with a high severity CVSS score of 7.5.…
CVE-2026-7332: LatePoint <= 5.5.0 – Unauthenticated Stored Cross-Site Scripting via 'booking_form_page_url' Parameter (latepoint)
May 5, 2026
CVE-2026-7332 affects the LatePoint plugin (up to version 5.5.0) with a CVSS score of 7.2, enabling unauthenticated stored XSS. Update…
CVE-2026-7448: LatePoint <= 5.5.0 – Unauthenticated Stored Cross-Site Scripting via 'first_name' Parameter (latepoint)
May 5, 2026
CVE-2026-7448 affects the LatePoint plugin (up to v5.5.0) with a CVSS score of 7.2. This high-severity XSS vulnerability allows unauthenticated…
CVE-2026-2892: Otter Blocks <= 3.1.4 – Improper Authorization to Unauthenticated Purchase Verification Bypass via Forged Cookie (otter-blocks)
May 4, 2026
CVE-2026-2892 affects the Otter Blocks plugin for WordPress, allowing unauthenticated attackers to bypass purchase verification. Update to version 3.1.5 to…
←
1
…
3
4
5
6
7
…
26
→