Skip to main content
Skip to footer
Home
CVE Analysis
How it Works
Resources
Pricing
Log in
Create Account
Home
CVE Analysis
How it Works
Resources
Pricing
Log in
Create Account
Severity:
medium
CVE-2026-1883: Wicked Folders <= 4.1.0 Insecure Direct Object Reference to Authenticated (Contributor+) Arbitrary Folder Deletion PoC, Patch Analysis & Rule
March 18, 2026
CVE-2026-1883 affects the Wicked Folders plugin (up to version 4.1.0) with a medium severity (CVSS 4.3) vulnerability allowing authenticated users…
CVE-2026-2358: WP ULike <= 5.0.1 Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode Attribute PoC, Patch Analysis & Rule
March 18, 2026
CVE-2026-2358 affects WP ULike plugin versions up to 5.0.1, with a medium severity (CVSS 6.4) due to stored XSS. Update…
CVE-2026-2918: Happy Addons for Elementor <= 3.21.0 Insecure Direct Object Reference to Authenticated (Contributor+) Stored Cross-Site Scripting via Template Conditions PoC, Patch Analysis & Rule
March 18, 2026
CVE-2026-2918 affects Happy Elementor Addons plugin versions up to 3.21.0, with a CVSS score of 6.4. Authenticated attackers can exploit…
CVE-2026-2917: Happy Addons for Elementor <= 3.21.0 Insecure Direct Object Reference to Authenticated (Contributor+) Post Duplication via 'post_id' Parameter PoC, Patch Analysis & Rule
March 18, 2026
CVE-2026-2917 affects the Happy Elementor Addons plugin (up to v3.21.0) with a medium severity (CVSS 5.4) vulnerability. Update to v3.21.1…
CVE-2026-3226: LearnPress <= 4.3.2.8 Missing Authorization to Authenticated (Subscriber+) Arbitrary Email Notification Triggering PoC, Patch Analysis & Rule
March 18, 2026
CVE-2026-3226 affects the LearnPress plugin (up to v4.3.2.8) with a medium severity (CVSS 4.3). It allows authenticated users to trigger…
CVE-2026-2324: LatePoint – Calendar Booking Plugin for Appointments and Events <= 5.2.7 Cross-Site Request Forgery in Booking Form Settings Update to Stored Cross-Site Scripting PoC, Patch Analysis & Rule
March 18, 2026
CVE-2026-2324 affects the LatePoint plugin (v5.2.7) with a medium severity (CVSS 6.1) cross-site scripting vulnerability. Upgrade to v5.2.8 to mitigate…
CVE-2026-2707: weForms <= 1.6.27 Authenticated (Subscriber+) Stored Cross-Site Scripting via Hidden Field Value via REST API PoC, Patch Analysis & Rule
March 18, 2026
CVE-2026-2707 affects the Weforms plugin for WordPress (up to version 1.6.27) with a medium severity (CVSS 6.4) stored XSS vulnerability.…
CVE-2026-1781: MC4WP: Mailchimp for WordPress <= 4.11.1 Missing Authorization to Unauthenticated Arbitrary Subscription Deletion PoC, Patch Analysis & Rule
March 18, 2026
CVE-2026-1781 affects the Mailchimp For WP plugin (up to v4.11.1) with a CVSS score of 6.5, allowing remote code execution.…
CVE-2025-12473: RTMKit <= 1.6.8 Reflected Cross-Site Scripting via 'themebuilder' Parameter PoC, Patch Analysis & Rule
March 18, 2026
CVE-2025-12473 affects Rometheme For Elementor plugin versions up to 1.6.8, with a CVSS score of 6.1. Ensure you upgrade to…
CVE-2026-1086: Font Pairing Preview For Landing Pages <= 1.3 Cross-Site Request Forgery to Settings Update PoC, Patch Analysis & Rule
March 18, 2026
CVE-2026-1086 affects the Wp Font Pairing Preview plugin (v1.3) with a medium severity (CVSS 4.3) due to cross-site request forgery.…
CVE-2026-1071: Carta Online <= 2.13.0 Authenticated (Administrator+) Stored Cross-Site Scripting via Plugin Settings PoC, Patch Analysis & Rule
March 18, 2026
CVE-2026-1071 affects the Carta Online plugin for WordPress (up to v2.13.0) with a medium severity (CVSS 4.4) stored XSS vulnerability.…
CVE-2026-2420: LotekMedia Popup Form <= 1.0.6 Authenticated (Administrator+) Stored Cross-Site Scripting via Plugin Settings PoC, Patch Analysis & Rule
March 18, 2026
CVE-2026-2420 affects the LotekMedia Popup Form plugin (v1.0.6) with a medium severity CVSS score of 4.4. Ensure to patch to…
CVE-2026-1085: True Ranker <= 2.2.9 Cross-Site Request Forgery to Unauthorized True Ranker Disconnection PoC, Patch Analysis & Rule
March 18, 2026
CVE-2026-1085 affects the Seo Local Rank plugin (v2.2.9) with a medium severity (CVSS 4.3) CSRF vulnerability. Ensure you update to…
CVE-2026-2433: RSS Aggregator – RSS Import, News Feeds, Feed to Post, and Autoblogging <= 5.0.11 Unauthenticated DOM-Based Reflected Cross-Site Scripting via postMessage PoC, Patch Analysis & Rule
March 18, 2026
CVE-2026-2433 affects the Wp Rss Aggregator plugin (up to 5.0.11) with a medium severity (CVSS 6.1) cross-site scripting vulnerability. Update…
CVE-2026-22520: Handmade Framework <= 3.9 Reflected Cross-Site Scripting PoC, Patch Analysis & Rule
March 18, 2026
CVE-2026-22520 affects the Handmade Framework plugin for WordPress (up to version 3.9) with a medium severity (CVSS 6.1) cross-site scripting…
CVE-2026-1920: Booktics <= 1.0.16 Missing Authorization to Addon Plugin Installation PoC, Patch Analysis & Rule
March 18, 2026
CVE-2026-1920 affects the Booktics plugin (up to v1.0.16) with a CVSS score of 5.3. Unauthenticated attackers can exploit this vulnerability…
CVE-2026-1919: Booktics <= 1.0.16 Missing Authorization to Get Items via REST API endpoints PoC, Patch Analysis & Rule
March 18, 2026
CVE-2026-1919 affects the Booktics plugin (up to version 1.0.16) with a medium severity (CVSS 5.3) vulnerability allowing unauthorized data access.…
CVE-2026-3228: NextScripts: Social Networks Auto-Poster <= 4.4.6 Authenticated (Contributor+) Stored Cross-Site Scripting via 'nxs_fbembed' Shortcode PoC, Patch Analysis & Rule
March 18, 2026
CVE-2026-3228 affects the NextScripts Social Networks Auto-Poster plugin (up to 4.4.6) with a medium severity CVSS of 6.4. Ensure proper…
CVE-2026-2569: Dear Flipbook <= 2.4.20 Authenticated (Auhtor+) Stored Cross-Site Scripting via PDF Page Labels PoC, Patch Analysis & Rule
March 18, 2026
CVE-2026-2569 affects the 3d Flipbook Dflip Lite plugin (up to v2.4.20) with a CVSS score of 6.4. Authenticated attackers can…
CVE-2026-27091: UiPress lite | Effortless custom dashboards, admin themes and pages <= 3.5.09 Missing Authorization PoC, Patch Analysis & Rule
March 18, 2026
CVE-2026-27091 affects the Uipress Lite plugin (v3.5.09) with a medium severity (CVSS 4.3) vulnerability. Authenticated users can exploit this flaw…
←
1
…
116
117
118
119
120
→