Skip to main content
Skip to footer
Home
CVE Analysis
How it Works
Resources
Pricing
Log in
Create Account
Home
CVE Analysis
How it Works
Resources
Pricing
Log in
Create Account
Severity:
medium
CVE-2026-22480: WebToffee WooCommerce Product Feeds – Google Shopping, Pinterest, TikTok Ads, & More <= 2.3.3 Authenticated (Shop manager+) PHP Object Injection PoC, Patch Analysis & Rule
March 18, 2026
CVE-2026-22480 affects the Webtoffee Product Feed plugin for WordPress (versions up to 2.3.3) with a medium severity CVSS of 6.6.…
CVE-2026-2830: WP All Import <= 4.0.0 Reflected Cross-Site Scripting via 'filepath' PoC, Patch Analysis & Rule
March 18, 2026
CVE-2026-2830 affects WP All Import plugin versions up to 4.0.0, with a CVSS score of 6.1. It allows reflected XSS…
CVE-2026-2593: Greenshift – animation and page builder blocks <= 12.8.5 Authenticated (Contributor+) Stored Cross-Site Scripting PoC, Patch Analysis & Rule
March 18, 2026
CVE-2026-2593 affects the Greenshift Animation And Page Builder Blocks plugin (up to 12.8.5) with a medium severity (CVSS 6.4) XSS…
CVE-2026-1981: Winston AI <= 0.0.3 Missing Authorization to Authenticated (Subscriber+) Arbitrary Plugin Settings Deletion PoC, Patch Analysis & Rule
March 18, 2026
CVE-2026-1981 affects the Winston Ai Wp plugin up to version 0.0.3, allowing unauthorized data modification by authenticated users. Upgrade to…
CVE-2026-2589: Greenshift – animation and page builder blocks <= 12.8.3 Unauthenticated Sensitive Information Exposure via Settings Backup PoC, Patch Analysis & Rule
March 18, 2026
CVE-2026-2589 affects the Greenshift Animation And Page Builder Blocks plugin (up to version 12.8.3) with a CVSS score of 5.3.…
CVE-2025-68515: WP Booking System – Booking Calendar <= 2.0.19.12 Unauthenticated Information Exposure PoC, Patch Analysis & Rule
March 18, 2026
CVE-2025-68515 affects the WP Booking System plugin (up to version 2.0.19.12) with a CVSS score of 5.3, exposing sensitive data…
CVE-2026-3034: OoohBoi Steroids for Elementor <= 2.1.24 Authenticated (Contributor+) Stored Cross-Site Scripting via Multiple URL Controls PoC, Patch Analysis & Rule
March 18, 2026
CVE-2026-3034 affects the Ooohboi Steroids for Elementor plugin (up to v2.1.24) with a medium severity (CVSS 6.4) stored XSS vulnerability.…
CVE-2026-2899: Fluent Forms Pro Add On Pack <= 6.1.17 Missing Authorization to Unauthenticated Arbitrary Attachment Deletion PoC, Patch Analysis & Rule
March 18, 2026
CVE-2026-2899 affects the Fluent Forms Pro Add On Pack plugin (up to version 6.1.17) with a medium severity (CVSS 6.5)…
CVE-2026-2893: Page and Post Clone <= 6.3 Authenticated (Contributor+) SQL Injection via 'meta_key' Parameter PoC, Patch Analysis & Rule
March 18, 2026
CVE-2026-2893 affects the Page Or Post Clone plugin for WordPress, with a medium severity CVSS score of 6.5. Users should…
CVE-2025-69347: Subscription for WooCommerce – WordPress Recurring Payments Plugin <= 1.8.10 Authenticated (Customer+) Insecure Direct Object Reference PoC, Patch Analysis & Rule
March 18, 2026
CVE-2025-69347 affects the Subscription for WooCommerce plugin (up to v1.8.10) with a medium severity (CVSS 4.3) remote code execution vulnerability.…
CVE-2026-3072: Media Library Assistant <= 3.33 Missing Authorization to Authenticated (Subscriber+) Arbitrary Attachment Taxonomy Modification PoC, Patch Analysis & Rule
March 18, 2026
CVE-2026-3072 affects the Media Library Assistant plugin (up to v3.33) with a medium severity (CVSS 4.3) vulnerability allowing unauthorized data…
←
1
…
118
119
120