Skip to main content
Skip to footer
Home
CVE Analysis
How it Works
Resources
Pricing
Log in
Free Protection
Home
CVE Analysis
How it Works
Resources
Pricing
Log in
Free Protection
Severity:
medium
CVE-2026-3604: WP SEO Structured Data Schema <= 2.8.1 – Authenticated (Contributor+) Stored Cross-Site Scripting via '_kcseo_ative_tab' Parameter (wp-seo-structured-data-schema)
May 11, 2026
CVE-2026-3604 affects the WP SEO Structured Data Schema plugin (up to v2.8.1) with a CVSS score of 4.9. Authenticated attackers…
CVE-2026-6800: FastBots <= 1.0.12 – Authenticated (Administrator+) Stored Cross-Site Scripting via Plugin Settings (fastbots-ai-chatbots)
May 11, 2026
CVE-2026-6800 affects the Fastbots Ai Chatbots plugin (up to 1.0.12) with a medium severity score of 4.4. Authenticated attackers can…
CVE-2026-6932: Woo Commerce Minimum Weight <= 3.0.1 – Cross-Site Request Forgery via Settings Update Form (woo-commerce-min-weight)
May 11, 2026
CVE-2026-6932 affects the Woo Commerce Min Weight plugin (up to v3.0.1) with a medium severity (CVSS 4.3) CSRF vulnerability. Ensure…
CVE-2026-4859: SP Blog Designer <= 1.0.0 – Authenticated (Contributor+) Stored Cross-Site Scripting via 'design' Attribute (sp-blog-designer)
May 11, 2026
CVE-2026-4859 affects the SP Blog Designer plugin for WordPress (up to 1.0.0) with a medium severity CVSS score of 6.4.…
CVE-2026-4920: Next Date <= 1.0 – Authenticated (Contributor+) Stored Cross-Site Scripting via 'default' Shortcode Attribute (nextdate)
May 11, 2026
CVE-2026-4920 affects the Next Date plugin for WordPress (up to version 1.0) with a CVSS score of 6.4. Authenticated attackers…
CVE-2026-2300: BJ Lazy Load <= 1.0.9 – Authenticated (Contributor+) Stored Cross-Site Scripting via Custom HTML Block (bj-lazy-load)
May 11, 2026
CVE-2026-2300 affects the BJ Lazy Load plugin for WordPress (up to version 1.0.9) with a medium severity (CVSS 6.4) Stored…
CVE-2026-4301: Rate Star Review Vote <= 1.6.4 – Missing Authorization to Authenticated (Subscriber+) Arbitrary Post Modification via 'rating_id' Parameter (rate-star-review)
May 11, 2026
CVE-2026-4301 affects the Rate Star Review plugin (v1.6.4 and earlier) with a medium severity (CVSS 4.3) authentication bypass. Authenticated attackers…
CVE-2026-4663: iPOSpays Gateways WC <= 1.3.7 – Unauthenticated Missing Authorization to Settings Update via REST API Endpoint (ipospays-gateways-wc)
May 11, 2026
CVE-2026-4663 affects the Ipospays Gateways WC plugin (up to version 1.3.7) with a CVSS score of 5.3. Unauthenticated attackers can…
CVE-2026-6663: GWD Connect <= 2.9 – Unauthenticated Limited Code Execution via update_agent (graphic-web-design-inc)
May 11, 2026
CVE-2026-6663 affects the Graphic Web Design Inc plugin (version 2.9) with a medium severity (CVSS 4.8) vulnerability allowing unauthenticated remote…
CVE-2026-7464: WP Google Maps Integration <= 1.2 – Reflected Cross-Site Scripting via 'page' Parameter (wp-google-maps-integration)
May 11, 2026
CVE-2026-7464 affects the WP Google Maps Integration plugin (up to v1.2) with a medium severity CVSS score of 6.1. Unauthenticated…
CVE-2026-7437: AzonPost <= 1.3 – Reflected Cross-Site Scripting (azonpost)
May 11, 2026
CVE-2026-7437 affects the AzonPost plugin for WordPress (up to version 1.3) with a medium severity CVSS score of 6.1. Unauthenticated…
CVE-2026-6808: Pricing Tables for WP <= 1.1.0 – Reflected Cross-Site Scripting via 'page' Parameter (awesome-pricing-tables-lite-by-optimalplugins)
May 11, 2026
CVE-2026-6808 affects Awesome Pricing Tables Lite (v1.1.0 and earlier) with a CVSS score of 6.1. This medium severity reflected XSS…
CVE-2026-7626: Slek Gateway for WooCommerce <= 1.0 – Unauthenticated Insufficiently Protected Credentials via Payment Redirect Form Hidden Fields (slek-gateway-for-woocommerce)
May 11, 2026
CVE-2026-7626 affects the Slek Gateway for WooCommerce plugin (v1.0) with a CVSS score of 5.3. This medium severity vulnerability exposes…
CVE-2026-7616: Zawgyi Embed <= 2.1.1 – Cross-Site Request Forgery via 'zawgyi_forceCSS' Parameter (zawgyi-embed)
May 11, 2026
CVE-2026-7616 affects the Zawgyi Embed plugin for WordPress (up to version 2.1.1) with a medium severity (CVSS 4.3) CSRF vulnerability.…
CVE-2026-7050: Forms Rb <= 1.1.9 – Missing Authorization to Authenticated (Contributor+) Arbitrary Modification via 'form_id' Parameter (forms-rb)
May 11, 2026
CVE-2026-7050 affects the Forms Rb plugin for WordPress (up to version 1.1.9) with a CVSS score of 4.3. Authenticated attackers…
CVE-2026-7561: Tm – WordPress Redirection <= 1.2 – Cross-Site Request Forgery to Stored Cross-Site Scripting (tm-wordpress-redirection)
May 11, 2026
CVE-2026-7561 affects the Tm WordPress Redirection plugin (up to version 1.2) with a CVSS score of 6.1. This medium severity…
CVE-2026-7562: WP-Redirection <= 1.0.3 – Cross-Site Request Forgery to Settings Update (wp-redirection)
May 11, 2026
CVE-2026-7562 affects the WP-Redirection plugin (up to version 1.0.3) with a medium severity CVSS score of 4.3. Unauthenticated attackers can…
CVE-2024-13362: Freemius <= 2.10.1 – Reflected DOM-Based Cross-Site Scripting via url Parameter (product-layouts)
May 10, 2026
CVE-2024-13362 affects the Product Layouts plugin (v1.3.1) with a medium severity CVSS score of 6.1. Users should upgrade to v1.3.5…
CVE-2024-13362: Freemius <= 2.10.1 – Reflected DOM-Based Cross-Site Scripting via url Parameter (smart-phone-field-for-gravity-forms)
May 10, 2026
CVE-2024-13362 affects the Smart Phone Field For Gravity Forms plugin (v2.1.6) with a medium severity CVSS of 6.1. Users should…
CVE-2024-13362: Freemius <= 2.10.1 – Reflected DOM-Based Cross-Site Scripting via url Parameter (wc-cashapp)
May 10, 2026
CVE-2024-13362 affects the Wc Cashapp plugin (v6.0.2) with a medium severity (CVSS 6.1) reflected XSS vulnerability. Update to v6.0.3.1 to…
←
1
…
11
12
13
14
15
…
98
→