Skip to main content
Skip to footer
Home
CVE Analysis
How it Works
Resources
Pricing
Log in
Create Account
Home
CVE Analysis
How it Works
Resources
Pricing
Log in
Create Account
Severity:
medium
CVE-2025-68534: PDF for WPForms <= 6.3.0 Missing Authorization PoC, Patch Analysis & Rule
March 18, 2026
CVE-2025-68534 affects the PDF for WPForms plugin (up to v6.3.0) with a medium severity CVSS score of 4.3. Authenticated attackers…
CVE-2025-69063: New User Approve <= 3.2.0 Missing Authorization PoC, Patch Analysis & Rule
March 18, 2026
CVE-2025-69063 affects the New User Approve plugin for WordPress, versions up to 3.2.0, with a medium severity CVSS score of…
CVE-2026-1826: OpenPOS Lite <= 3.0 Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode Attributes PoC, Patch Analysis & Rule
March 18, 2026
CVE-2026-1826 affects OpenPOS Lite Version 3.0, allowing authenticated attackers to exploit a stored XSS vulnerability with a CVSS score of…
CVE-2026-1809: HTML Shortcodes <= 1.1 Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode Attributes PoC, Patch Analysis & Rule
March 18, 2026
CVE-2026-1809 affects the Html Shortcodes plugin for WordPress, with a CVSS score of 6.4. Users should update to the patched…
CVE-2026-1885: Slideshow Wp <= 1.1 Authenticated (Contributor+) Stored Cross-Site Scripting via 'sswp-slide' Shortcode 'sswpid' Attribute PoC, Patch Analysis & Rule
March 18, 2026
CVE-2026-1885 affects the Slideshow Wp plugin (up to version 1.1) with a medium severity CVSS score of 6.4. Authenticated attackers…
CVE-2026-0724: WPlyr Media Block <= 1.3.0 Authenticated (Administrator+) Stored Cross-Site Scripting via '_wplyr_accent_color' Parameter PoC, Patch Analysis & Rule
March 18, 2026
CVE-2026-0724 affects the WPlyr Media Block plugin (up to v1.3.0) with a CVSS score of 4.4. Authenticated attackers can exploit…
CVE-2026-1215: MMA Call Tracking <= 2.3.15 Cross-Site Request Forgery to Plugin Settings Update PoC, Patch Analysis & Rule
March 18, 2026
CVE-2026-1215 affects the MMA Call Tracking plugin for WordPress (up to version 2.3.15) with a medium severity CVSS score of…
CVE-2026-1827: IDE Micro code-editor <= 1.0.0 Authenticated (Contributor+) Stored Cross-Site Scripting via 'title' Shortcode Attribute PoC, Patch Analysis & Rule
March 18, 2026
CVE-2026-1827 affects the Flask Micro plugin for WordPress (up to version 1.0.0) with a CVSS score of 6.4. Authenticated users…
CVE-2026-1804: WDES Responsive Popup <= 1.3.6 Authenticated (Contributor+) Stored Cross-Site Scripting via 'attr' Shortcode Attribute PoC, Patch Analysis & Rule
March 18, 2026
CVE-2026-1804 affects the Wdes Responsive Popup plugin (up to v1.3.6) with a medium severity (CVSS 6.4) stored XSS vulnerability. Authenticated…
CVE-2026-1748: Invoct – PDF Invoices & Billing for WooCommerce <= 1.6 Missing Authorization to Authenticated (Subscriber+) Information Exposure PoC, Patch Analysis & Rule
March 18, 2026
CVE-2026-1748 affects the Kirilkirkov Pdf Invoice Manager plugin (up to v1.6) with a CVSS score of 4.3. Authenticated users can…
CVE-2026-1853: BuddyHolis ListSearch <= 1.1 Authenticated (Contributor+) Stored Cross-Site Scripting via 'placeholder' Shortcode Attribute PoC, Patch Analysis & Rule
March 18, 2026
CVE-2026-1853 affects the Listsearch plugin for WordPress (up to v1.1) with a CVSS score of 6.4. This medium-severity XSS vulnerability…
CVE-2026-28126: RH Frontend Publishing Pro <= 4.3.2 Reflected Cross-Site Scripting PoC, Patch Analysis & Rule
March 18, 2026
CVE-2026-28126 affects the RH Frontend Publishing Pro plugin (up to version 4.3.2) with a medium severity CVSS score of 6.1.…
CVE-2026-1893: Orbisius Random Name Generator <= 1.0.2 Authenticated (Contributor+) Stored Cross-Site Scripting via 'btn_label' Shortcode Attribute PoC, Patch Analysis & Rule
March 18, 2026
CVE-2026-1893 affects the Orbisius Random Name Generator plugin (up to 1.0.2) with a medium severity CVSS score of 6.4. Authenticated…
CVE-2026-1231: Beaver Builder Page Builder – Drag and Drop Website Builder <= 2.10.0.5 Authenticated (Custom+) Missing Authorization to Stored Cross-Site Scripting via Global Settings PoC, Patch Analysis & Rule
March 18, 2026
CVE-2026-1231 affects Beaver Builder Lite up to version 2.10.0.5 with a CVSS score of 6.4. This medium-severity XSS vulnerability allows…
CVE-2025-13431: SlimStat Analytics <= 5.3.1 Authenticated (Subscriber+) SQL Injection via `args` Parameter PoC, Patch Analysis & Rule
March 18, 2026
CVE-2025-13431 affects the SlimStat Analytics plugin for WordPress, versions 5.3.1 and earlier, with a medium severity CVSS score of 6.5.…
CVE-2025-15524: Gallery by FooGallery <= 3.1.9 Missing Authorization to Authenticated (Subscriber+) Arbitrary Gallery Metadata Exposure PoC, Patch Analysis & Rule
March 18, 2026
CVE-2025-15524 affects the FooGallery plugin (up to version 3.1.9) with a medium severity (CVSS 4.3) vulnerability. Authenticated users can access…
CVE-2026-1821: Microtango <= 0.9.29 Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode Attributes PoC, Patch Analysis & Rule
March 18, 2026
CVE-2026-1821 affects the Microtango plugin (up to v0.9.29) with a medium severity (CVSS 6.4) XSS vulnerability. Update to v0.9.30 to…
CVE-2026-0815: Category Image <= 2.0 Authenticated (Editor+) Stored Cross-Site Scripting via 'tag-image' Parameter PoC, Patch Analysis & Rule
March 18, 2026
CVE-2026-0815 affects the Category Image plugin for WordPress (up to v2.0) with a medium severity CVSS of 4.4. Authenticated attackers…
CVE-2026-1786: Twitter posts to Blog <= 1.11.25 Missing Authorization to Unauthenticated Plugin Settings Update PoC, Patch Analysis & Rule
March 18, 2026
CVE-2026-1786 affects the Twitter Posts To Blog plugin (up to version 1.11.25) with a medium severity (CVSS 6.5) vulnerability allowing…
CVE-2026-1833: WaMate Confirm <= 2.0.1 Missing Authorization to Authenticated (Subscriber+) Arbitrary Phone Number Blocking/Unblocking PoC, Patch Analysis & Rule
March 18, 2026
CVE-2026-1833 affects the WaMate Confirm plugin for WordPress (up to 2.0.1) with a medium severity (CVSS 5.3). Authenticated users can…
←
1
…
113
114
115
116
117
…
120
→