Skip to main content
Skip to footer
Home
CVE Analysis
How it Works
Resources
Pricing
Log in
Create Account
Home
CVE Analysis
How it Works
Resources
Pricing
Log in
Create Account
Severity:
medium
CVE-2026-54839: Trinity Backup – Backup, Migrate, Restore, Clone & Schedule Backups <= 2.0.9 Unauthenticated Information Exposure PoC, Patch Analysis & Rule
June 27, 2026
CVE-2026-54839 affects the Trinity Backup plugin (up to v2.0.9) with a CVSS score of 5.3, exposing sensitive data to unauthenticated…
CVE-2026-56007: Ocean Product Sharing <= 2.2.2 Authenticated (Shop manager+) Stored Cross-Site Scripting PoC, Patch Analysis & Rule
June 27, 2026
CVE-2026-56007 affects the Ocean Product Sharing plugin (up to 2.2.2) with a medium severity (CVSS 4.4) Stored XSS vulnerability. Patch…
CVE-2026-56009: Bricksable for Bricks Builder <= 1.6.83 Authenticated (Author+) Stored Cross-Site Scripting PoC, Patch Analysis & Rule
June 27, 2026
CVE-2026-56009 affects the Bricksable plugin for WordPress (up to 1.6.83) with a medium severity (CVSS 6.4) stored XSS vulnerability. Update…
CVE-2026-54837: Intranet & Private Site – All-In-One Intranet <= 1.8.1 Missing Authorization PoC, Patch Analysis & Rule
June 27, 2026
CVE-2026-54837 affects the All In One Intranet plugin for WordPress (up to version 1.8.1) with a medium severity (CVSS 5.3).…
CVE-2026-11597: Surbma | Infusionsoft Shortcode <= 2.0.1 Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode Attributes PoC, Patch Analysis & Rule
June 26, 2026
CVE-2026-11597 affects the Surbma Infusionsoft Shortcode plugin (up to 2.0.1) with a CVSS score of 6.4. Authenticated users can exploit…
CVE-2026-9242: RegistrationMagic <= 6.0.8.6 Authenticated (Subscriber+) Authentication Bypass via Forged PayPal IPN Request PoC, Patch Analysis & Rule
June 26, 2026
CVE-2026-9242 affects the Custom Registration Form Builder plugin (up to version 6.0.8.6) with a CVSS score of 5.3. Unauthenticated attackers…
CVE-2026-9233: Quiz and Survey Master (QSM) <= 11.1.4 Missing Authorization to Authenticated (Contributor+) Arbitrary Modification via qsm_insert_quiz_template AJAX Action PoC, Patch Analysis & Rule
June 26, 2026
CVE-2026-9233 affects the Quiz Master Next plugin (up to version 11.1.4) with a medium severity (CVSS 4.3) authentication bypass. Update…
CVE-2026-11364: Product Specifications for Woocommerce <= 0.8.9 Missing Authorization to Authenticated (Subscriber+) Arbitrary Attribute/Group Creation, Modification, and Deletion via 'dwps_modify_groups' and 'dwps_modify_attributes' AJAX Actions PoC, Patch Analysis & Rule
June 26, 2026
CVE-2026-11364 affects the Product Specifications plugin for WooCommerce (up to v0.8.9) with a CVSS score of 4.3. Patch to v0.8.10…
CVE-2026-12432: Stripe Payment Forms by WP Full Pay <= 8.4.3 Missing Authorization to Unauthenticated Payment Record Manipulation via 'paymentIntentId' Parameter PoC, Patch Analysis & Rule
June 26, 2026
CVE-2026-12432 affects WP Full Stripe Free plugin versions up to 8.4.3, with a medium severity score of 5.3. Unauthenticated attackers…
CVE-2026-13295: Page Builder by SiteOrigin <= 2.34.3 Authenticated (Contributor+) Stored Cross-Site Scripting via panels_data Parameter PoC, Patch Analysis & Rule
June 26, 2026
CVE-2026-13295 affects the Siteorigin Panels plugin (up to v2.34.3) with a medium severity (CVSS 6.4) Stored XSS vulnerability. Users should…
CVE-2026-12399: Gutenverse <= 3.8.0 Authenticated (Editor+) Stored Cross-Site Scripting via 'fonts[].font.font.value' Parameter PoC, Patch Analysis & Rule
June 26, 2026
CVE-2026-12399 affects Gutenverse plugin versions 3.8.0 and below, with a CVSS score of 4.4. Authenticated users can exploit this cross-site…
CVE-2026-11783: Dokan: AI Powered WooCommerce Multivendor Marketplace Solution <= 5.0.4 Authenticated (Custom+) Stored Cross-Site Scripting via Product SKU PoC, Patch Analysis & Rule
June 26, 2026
CVE-2026-11783 affects Dokan Lite plugin versions up to 5.0.4, allowing stored XSS due to insufficient input sanitization. Update to 5.0.5…
CVE-2026-11987: Dokan: AI Powered WooCommerce Multivendor Marketplace Solution <= 5.0.4 Authenticated (Subscriber+) Insecure Direct Object Reference to Information Disclosure via 'id' Parameter PoC, Patch Analysis & Rule
June 26, 2026
CVE-2026-11987 affects Dokan Lite plugin versions up to 5.0.4, allowing authenticated users to access other vendors' unpublished products. Upgrade to…
CVE-2026-11773: Masteriyo LMS <= 2.2.1 Missing Authorization to Authenticated (Student+) Arbitrary Course Announcement Modification PoC, Patch Analysis & Rule
June 26, 2026
CVE-2026-11773 affects the Masteriyo LMS plugin (up to v2.2.1) with a medium severity CVSS score of 4.3. Authenticated users can…
CVE-2026-13333: Groundhogg <= 4.5.5 Authenticated (Sales Rep+) SQL Injection via 'query[select]' Parameter PoC, Patch Analysis & Rule
June 26, 2026
CVE-2026-13333 affects the Groundhogg plugin for WordPress (up to version 4.5.5) with a medium severity CVSS score of 6.5. Authenticated…
CVE-2026-12404: NEX-Forms <= 9.2.2 Missing Authorization to Unauthenticated Sensitive Information Disclosure via CSVExport Class PoC, Patch Analysis & Rule
June 26, 2026
CVE-2026-12404 affects Nex Forms Express WP Form Builder versions up to 9.2.2, allowing unauthenticated users to access sensitive data. Upgrade…
CVE-2026-13422: HD Quiz 2.2.0 2.2.1 Cross-Site Request Forgery via Multiple AJAX Handlers PoC, Patch Analysis & Rule
June 26, 2026
CVE-2026-13422 affects the HD Quiz plugin for WordPress (versions 2.2.0 to 2.2.1) with a CVSS score of 4.3. Patch to…
CVE-2026-13335: CodePeople Post Map for Google Maps <= 1.2.6 Authenticated (Contributor +) Stored Cross-Site Scripting via 'cpm_point' Post Meta PoC, Patch Analysis & Rule
June 26, 2026
CVE-2026-13335 affects the CodePeople Post Map plugin (up to version 1.2.6) with a CVSS score of 6.4. Authenticated attackers can…
CVE-2026-3462: Frisbii Pay <= 1.8.9 Missing Authorization to Authenticated (Subscriber+) Payment Token Modification PoC, Patch Analysis & Rule
June 26, 2026
CVE-2026-3462 affects the Reepay Checkout Gateway plugin (up to version 1.8.9) with a CVSS score of 6.5. Authenticated attackers can…
CVE-2026-11356: Ivory Search <= 5.5.15 Authenticated (Administrator+) Stored Cross-Site Scripting via 'menu_title' and 'menu_magnifier_color' Settings PoC, Patch Analysis & Rule
June 26, 2026
CVE-2026-11356 affects the Ivory Search plugin for WordPress (up to version 5.5.15) with a medium severity (CVSS 4.4) stored XSS…
←
1
…
8
9
10
11
12
…
111
→