Skip to main content
Skip to footer
Home
CVE Analysis
How it Works
Resources
Pricing
Log in
Create Account
Home
CVE Analysis
How it Works
Resources
Pricing
Log in
Create Account
Severity:
medium
CVE-2026-1786: Twitter posts to Blog <= 1.11.25 Missing Authorization to Unauthenticated Plugin Settings Update PoC, Patch Analysis & Rule
March 18, 2026
CVE-2026-1786 affects the Twitter Posts To Blog plugin (up to version 1.11.25) with a medium severity (CVSS 6.5) vulnerability allowing…
CVE-2026-1833: WaMate Confirm <= 2.0.1 Missing Authorization to Authenticated (Subscriber+) Arbitrary Phone Number Blocking/Unblocking PoC, Patch Analysis & Rule
March 18, 2026
CVE-2026-1833 affects the WaMate Confirm plugin for WordPress (up to 2.0.1) with a medium severity (CVSS 5.3). Authenticated users can…
CVE-2026-2498: WP Social Meta <= 1.0.1 Authenticated (Administrator+) Stored Cross-Site Scripting via Settings PoC, Patch Analysis & Rule
March 18, 2026
CVE-2026-2498 affects WP Social Meta plugin versions up to 1.0.1 with a CVSS score of 4.4. Admin-level users can exploit…
CVE-2026-2029: Livemesh Addons for Beaver Builder <= 3.9.2 Authenticated (Contributor+) Stored Cross-Site Scripting via 'title' and 'value' Shortcode Attributes PoC, Patch Analysis & Rule
March 18, 2026
CVE-2026-2029 affects the Addons For Beaver Builder plugin (up to v3.9.2) with a medium severity CVSS score of 6.4. Authenticated…
CVE-2025-14895: PopupKit <= 2.2.0 Missing Authorization to Sensitive Information Disclosure and Data Deletion PoC, Patch Analysis & Rule
March 18, 2026
CVE-2025-14895 affects Popup Builder Block plugin versions up to 2.2.0, with a medium severity (CVSS 5.4) authentication bypass vulnerability. Update…
CVE-2026-1922: The Events Calendar Shortcode & Block <= 3.1.2 Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode Attributes PoC, Patch Analysis & Rule
March 18, 2026
CVE-2026-1922 affects The Events Calendar Shortcode plugin (up to v3.1.2) with a medium severity (CVSS 6.4) XSS vulnerability. Update to…
CVE-2025-69389: Visitor Maps Extended Referer Field <= 1.2.6 Reflected Cross-Site Scripting PoC, Patch Analysis & Rule
March 18, 2026
CVE-2025-69389 affects the Visitor Maps Extended Referer Field plugin for WordPress, with a medium severity CVSS score of 6.1. Users…
CVE-2025-69390: Business Template Blocks for WPBakery (Visual Composer) Page Builder <= 1.3.2 Reflected Cross-Site Scripting PoC, Patch Analysis & Rule
March 18, 2026
CVE-2025-69390 affects the Templates And Addons For WPBakery Page Builder plugin (v1.3.2) with a medium severity (CVSS 6.1) reflected XSS…
CVE-2026-25423: Real 3D FlipBook <= 4.19.1 Missing Authorization PoC, Patch Analysis & Rule
March 18, 2026
CVE-2026-25423 affects the Real3D Flipbook Lite plugin (up to version 4.19.1) with a medium severity (CVSS 4.3) vulnerability. Ensure you…
CVE-2025-13391: Product Options and Price Calculation Formulas for WooCommerce – Uni CPO (Premium) <= 4.9.60 Missing Authorization to Unauthenticated Arbitrary Attachment and Dropbox File Deletion PoC, Patch Analysis & Rule
March 18, 2026
CVE-2025-13391 affects the Uni Woo Custom Product Options Premium plugin (up to version 4.9.60) with a CVSS score of 5.8.…
CVE-2025-69326: NEX-Forms <= 9.1.7 Reflected Cross-Site Scripting PoC, Patch Analysis & Rule
March 18, 2026
CVE-2025-69326 affects the Nex Forms Express WP Form Builder plugin (up to v9.1.7) with a medium severity CVSS score of…
CVE-2025-15147: WCFM Membership – WooCommerce Memberships for Multivendor Marketplace <= 2.11.8 Insecure Direct Object Reference to Update Membership Payment PoC, Patch Analysis & Rule
March 18, 2026
CVE-2025-15147 affects the Wc Multivendor Membership plugin (up to 2.11.8) with a CVSS score of 4.3. Authenticated attackers can exploit…
CVE-2026-1722: WCFM Marketplace <= 3.7.0 Insecure Direct Object Reference to Unauthenticated Arbitrary Refund Request Creation PoC, Patch Analysis & Rule
March 18, 2026
CVE-2026-1722 affects the Wc Multivendor Marketplace plugin (up to v3.7.0), exposing it to remote code execution. Update to v3.7.1 to…
CVE-2025-69325: Primer MyData for Woocommerce <= 4.2.8 Unauthenticated Path Traversal PoC, Patch Analysis & Rule
March 18, 2026
CVE-2025-69325 affects the Primer MyData plugin for WordPress (versions
CVE-2025-69381: WooCommerce Bulk Product Editor <= 3.0 Missing Authorization PoC, Patch Analysis & Rule
March 18, 2026
CVE-2025-69381 affects the WooCommerce Quick Product Editor plugin (up to v3.0) with a medium severity (CVSS 4.3) remote code execution…
CVE-2026-24955: Whizz Plugins <= 1.9 Reflected Cross-Site Scripting PoC, Patch Analysis & Rule
March 18, 2026
CVE-2026-24955 affects Whizz Plugins for WordPress (v1.9 and below) with a medium severity (CVSS 6.1) reflected XSS vulnerability. Users should…
CVE-2025-67993: Atarim <= 4.2.1 Missing Authorization PoC, Patch Analysis & Rule
March 18, 2026
CVE-2025-67993 affects Atarim Visual Collaboration plugin versions up to 4.2.1, with a CVSS score of 5.3. Patch to version 4.2.2…
CVE-2025-69384: Timeline Event History <= 3.2 Reflected Cross-Site Scripting PoC, Patch Analysis & Rule
March 18, 2026
CVE-2025-69384 affects the Timeline Event History plugin for WordPress (up to version 3.2) with a medium severity CVSS score of…
CVE-2026-24953: Simple File List <= 6.1.15 Authenticated (Subscriber+) Arbitrary File Download PoC, Patch Analysis & Rule
March 18, 2026
CVE-2026-24953 affects the Simple File List plugin (up to 6.1.15) with a medium severity (CVSS 6.5) path traversal vulnerability. Update…
CVE-2026-0996: Fluent Forms <= 6.1.14 Authenticated (Subscriber+) Stored Cross-Site Scripting via AI Form Builder Module PoC, Patch Analysis & Rule
March 18, 2026
CVE-2026-0996 affects the Fluent Forms plugin (up to v6.1.14) with a CVSS score of 6.4. This medium-severity XSS vulnerability allows…
←
1
…
114
115
116
117
118
…
120
→