Skip to main content
Skip to footer
Home
CVE Analysis
How it Works
Resources
Pricing
Log in
Free Protection
Home
CVE Analysis
How it Works
Resources
Pricing
Log in
Free Protection
Severity:
medium
CVE-2025-68049: bunny.net – WordPress CDN Plugin <= 2.3.6 – Missing Authorization (bunnycdn)
May 16, 2026
CVE-2025-68049 affects the Bunnycdn WordPress plugin (up to version 2.3.6) with a medium severity (CVSS 4.3) vulnerability allowing unauthorized access.…
CVE-2026-27416: PDF Poster – Display PDF Files with Custom Viewer <= 2.4.1 – Missing Authorization (pdf-poster)
May 16, 2026
CVE-2026-27416 affects the PDF Poster plugin for WordPress (versions ≤ 2.4.1) with a CVSS score of 5.3. Update to version…
CVE-2025-68604: WPGraphQL <= 2.5.3 – Cross-Site Request Forgery (wp-graphql)
May 16, 2026
CVE-2025-68604 affects the WP GraphQL plugin (up to 2.5.3) with a medium severity (CVSS 4.3) due to cross-site request forgery.…
CVE-2026-27415: BEAR – Bulk Editor and Products Manager Professional for WooCommerce by Pluginus.Net <= 1.1.5 – Cross-Site Request Forgery (woo-bulk-editor)
May 16, 2026
CVE-2026-27415 affects the Woo Bulk Editor plugin for WordPress (up to version 1.1.5) with a medium severity (CVSS 4.3) CSRF…
CVE-2025-62127: WEN Logo Slider <= 3.4.0 – Authenticated (Author+) Stored Cross-Site Scripting (wen-logo-slider)
May 16, 2026
CVE-2025-62127 affects the WEN Logo Slider plugin (up to v3.4.0) with a CVSS score of 6.4. This medium-severity XSS vulnerability…
CVE-2025-66105: Bus Ticket Booking with Seat Reservation < 5.6.8 – Missing Authorization (bus-ticket-booking-with-seat-reservation)
May 16, 2026
CVE-2025-66105 affects the Bus Ticket Booking with Seat Reservation plugin for WordPress (up to v5.6.8). This medium severity vulnerability allows…
CVE-2025-4202: Multicollab: Content Team Collaboration and Editorial Workflow <= 5.2 – Missing Authorization to Authenticated (Subscriber+) Collaboration Comment (commenting-feature)
May 15, 2026
CVE-2025-4202 affects the Multicollab plugin for WordPress (up to version 5.2) with a CVSS score of 4.3. Authenticated users can…
CVE-2026-6708: HEL Online Classroom: AI-powered Online Classrooms <= 1.0.3 – Missing Authorization to Unauthenticated Arbitrary Classroom Deletion via 'id' Parameter (hel-online-classroom)
May 15, 2026
CVE-2026-6708 affects the HEL Online Classroom plugin (up to v1.0.3) with a CVSS score of 5.3. Unauthenticated attackers can delete…
CVE-2025-14767: WPC Badge Management for WooCommerce <= 3.1.6 – Authenticated (Shop Manager+) Stored Cross-Site Scripting via 'text' Attribute (wpc-badge-management)
May 15, 2026
CVE-2025-14767 affects the WPC Badge Management plugin (up to 3.1.6) with a CVSS score of 5.5. Authenticated attackers can exploit…
CVE-2026-6913: Shortcodely <= 1.0.1 – Authenticated (Contributor+) Stored Cross-Site Scripting via 'widget_area' Shortcode Attribute (shortcodely)
May 15, 2026
CVE-2026-6913 affects the Shortcodely plugin for WordPress (up to version 1.0.1) with a CVSS score of 6.4. It allows authenticated…
CVE-2026-8681: Essential Chat Support <= 1.0.1 – Missing Authorization to Unauthenticated Settings Reset via 'ecs_reset_settings' Parameter (essential-chat-support)
May 15, 2026
CVE-2026-8681 affects the Essential Chat Support plugin (up to version 1.0.1) with a medium severity CVSS score of 5.3. Unauthenticated…
CVE-2026-6709: Coinbase Commerce for Contact Form 7 <= 1.1.2 – Missing Authorization to Authenticated (Subscriber+) API Key Modification via 'cccf7_api_key' Parameter (coinbase-commerce-for-contact-form-7)
May 15, 2026
CVE-2026-6709 affects the Coinbase Commerce for Contact Form 7 plugin (v1.1.2 and lower), allowing authenticated attackers to overwrite API keys…
CVE-2026-6710: Skysa Text Ticker App <= 1.4 – Cross-Site Request Forgery to Settings Modification via 'Save Settings' Form (skysa-text-ticker-app)
May 15, 2026
CVE-2026-6710 affects the Skysa Text Ticker App plugin for WordPress (up to version 1.4) with a CVSS score of 4.3.…
CVE-2026-7661: Bootstrap Shortcode <= 1.0 – Authenticated (Contributor+) Stored Cross-Site Scripting via 'box' Shortcode (bootstrap-shortcode)
May 15, 2026
CVE-2026-7661 affects the Bootstrap Shortcode plugin for WordPress (up to version 1.0) with a CVSS score of 6.4. Authenticated attackers…
CVE-2026-5693: Smart Appointment & Booking <= 1.0.8 – Missing Authorization to Unauthenticated Arbitrary Booking Cancellation (smart-appointment-booking)
May 15, 2026
CVE-2026-5693 affects the Smart Appointment Booking plugin (versions
CVE-2026-5340: Fancy Image Show <= 9.1 – Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode Attributes (fancy-image-show)
May 15, 2026
CVE-2026-5340 affects the Fancy Image Show plugin for WordPress (up to v9.1), allowing authenticated users to inject stored XSS. Patch…
CVE-2026-5715: Voyage Plus <= 1.0.6 – Authenticated (Contributor+) Stored Cross-Site Scripting via 'post-content' Shortcode (voyage-plus)
May 15, 2026
CVE-2026-5715 affects the Voyage Plus plugin for WordPress (up to version 1.0.6) with a medium severity CVSS score of 6.4.…
CVE-2026-6256: Credits Shortcode <= 1.2 – Authenticated (Contributor+) Stored Cross-Site Scripting via 'link' Shortcode Attribute (source-shortcode)
May 15, 2026
CVE-2026-6256 affects the Source Shortcode plugin for WordPress (v1.2 and earlier) with a CVSS score of 6.4. Authenticated users can…
CVE-2026-5028: Eight Day Week Print Workflow <= 1.2.6 – Authenticated (Subscriber+) SQL Injection via 'title' Parameter (eight-day-week-print-workflow)
May 15, 2026
CVE-2026-5028 affects the Eight Day Week Print Workflow plugin for WordPress (up to version 1.2.6) with a medium severity (CVSS…
CVE-2026-7659: Advanced Social Media Icons <= 1.2 – Authenticated (Contributor+) Stored Cross-Site Scripting via 'social' Shortcode (advanced-social-media-icons)
May 15, 2026
CVE-2026-7659 affects the Advanced Social Media Icons plugin (up to v1.2) with a medium severity CVSS score of 6.4. Authenticated…
←
1
…
8
9
10
11
12
…
98
→