Skip to main content
Skip to footer
Home
CVE Analysis
How it Works
Resources
Pricing
Log in
Free Protection
Home
CVE Analysis
How it Works
Resources
Pricing
Log in
Free Protection
Severity:
medium
CVE-2026-11603: Product Filter Widget for Elementor <= 1.0.6 Reflected Cross-Site Scripting via 'args[filterFormArray]' Parameter PoC, Patch Analysis & Rule
June 9, 2026
CVE-2026-11603 affects the Product Filter Widget for Elementor plugin (up to v1.0.6) with a CVSS score of 6.1. Unauthenticated attackers…
CVE-2026-8599: MailerPress <= 2.0.4 Authenticated (Author+) Stored Cross-Site Scripting via Campaign HTML Content Field PoC, Patch Analysis & Rule
June 9, 2026
CVE-2026-8599 affects the MailerPress plugin (up to v2.0.4) with a medium severity CVSS score of 6.4. Authenticated users can exploit…
CVE-2025-8444: Animation Addons for Elementor – GSAP Powered Elementor Addons & Website Templates <= 2.6.7 Authenticated (Contributor+) DOM-Based Stored Cross-Site Scripting via Multiple Parameters PoC, Patch Analysis & Rule
June 9, 2026
CVE-2025-8444 affects the Animation Addons for Elementor plugin (up to v2.6.7) with a medium severity (CVSS 6.4) XSS vulnerability. Authenticated…
CVE-2026-4058: User Frontend: AI Powered Frontend Posting, User Directory, Profile, Membership & User Registration <= 4.3.2 Missing Authorization to Authenticated (Subscriber+) Subscription Pack Cancellation PoC, Patch Analysis & Rule
June 9, 2026
CVE-2026-4058 affects the Wp User Frontend plugin (up to v4.3.2) with a medium severity (CVSS 4.3). Authenticated users can cancel…
CVE-2026-10738: jQuery Hover Footnotes <= 1.4 Authenticated (Author+) Stored Cross-Site Scripting via Footnote Qualifier ('{{…}}' Syntax) PoC, Patch Analysis & Rule
June 9, 2026
CVE-2026-10738 affects the jQuery Hover Footnotes plugin (v1.4 and earlier) with a CVSS score of 6.4. Authenticated attackers can exploit…
CVE-2026-8883: Global Body Mass Index Calculator <= 1.2 Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode Attributes PoC, Patch Analysis & Rule
June 9, 2026
CVE-2026-8883 affects the Global Body Mass Index Calculator plugin (up to v1.2) with a CVSS score of 6.4. Authenticated attackers…
CVE-2026-8882: WP ApplicantStack Jobs Display <= 1.1.1 Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode Attributes PoC, Patch Analysis & Rule
June 9, 2026
CVE-2026-8882 affects the WP ApplicantStack Jobs Display plugin (up to v1.1.1) with a medium severity (CVSS 6.4) stored XSS vulnerability.…
CVE-2026-10553: jQuery Hover Footnotes <= 1.4 Cross-Site Request Forgery to Plugin Settings Update PoC, Patch Analysis & Rule
June 9, 2026
CVE-2026-10553 affects the jQuery Hover Footnotes plugin (up to v1.4) with a medium severity (CVSS 4.3) CSRF vulnerability. Ensure to…
CVE-2026-8895: kk blog card <= 1.3 Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode Attributes PoC, Patch Analysis & Rule
June 9, 2026
CVE-2026-8895 affects the Kk Blog Card plugin for WordPress (up to v1.3) with a CVSS score of 6.4. Authenticated users…
CVE-2026-7542: Slider Revolution <= 7.0.10 Authenticated (Subscriber+) Sensitive Information Disclosure PoC, Patch Analysis & Rule
June 9, 2026
CVE-2026-7542 affects the Revslider plugin (up to version 7.0.10) with a CVSS score of 6.5. Authenticated users can exploit design…
CVE-2026-8880: RomanCart Ecommerce <= 2.0.8 Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode Attributes PoC, Patch Analysis & Rule
June 9, 2026
CVE-2026-8880 affects the RomanCart Ecommerce plugin for WordPress (up to version 2.0.8) with a CVSS score of 6.4. Authenticated attackers…
CVE-2026-10024: TinyMCE shortcode Addon <= 1.0.0 Authenticated (Contributor+) Stored Cross-Site Scripting via 'btnrel' Shortcode Attribute PoC, Patch Analysis & Rule
June 9, 2026
CVE-2026-10024 affects the 360crest Themeone Tinymce Shortcodes plugin (up to v1.0.0) with a medium severity (CVSS 6.4) Stored XSS vulnerability.…
CVE-2026-10100: Simple Custom Login Page <= 1.0.3 Authenticated (Admin+) Stored Cross-Site Scripting PoC, Patch Analysis & Rule
June 8, 2026
CVE-2026-10100 affects the Simple Custom Login Page plugin for WordPress (up to 1.0.3) with a medium severity (CVSS 4.4) stored…
CVE-2026-9022: Splide Carousel Block <= 1.7.1 Authenticated (Contributor+) Stored Cross-Site Scripting via 'url' Block Attribute PoC, Patch Analysis & Rule
June 4, 2026
CVE-2026-9022 affects the Splide Carousel plugin (up to v1.7.1) with a medium severity (CVSS 6.4) stored XSS vulnerability. Update to…
CVE-2026-2128: Breeze Cache <= 2.5.2 Unauthenticated Exposure of Sensitive Information to an Unauthorized Actor via Crafted Login Cookie PoC, Patch Analysis & Rule
June 4, 2026
CVE-2026-2128 affects the Breeze plugin for WordPress (up to 2.5.2) with a CVSS score of 5.3. It allows unauthorized access…
CVE-2026-7421: Passeum Ticketing <= 1.0 Authenticated (Administrator+) Stored Cross-Site Scripting via 'shop_name' Setting PoC, Patch Analysis & Rule
June 2, 2026
CVE-2026-7421 affects the Passeum Ticketing plugin for WordPress (up to version 1.0) with a medium severity (CVSS 4.4) stored XSS…
CVE-2026-9732: EmergencyWP <= 1.4.2 Cross-Site Request Forgery to Plugin Settings Update PoC, Patch Analysis & Rule
June 2, 2026
CVE-2026-9732 affects EmergencyWP plugin versions up to 1.4.2, exposing a CSRF vulnerability (CVSS 4.3). Unauthenticated attackers can alter critical settings.…
CVE-2026-2382: FPW Category Thumbnails <= 1.9.5 Authenticated (Subscriber+) Stored Cross-Site Scripting via 'id' Parameter PoC, Patch Analysis & Rule
June 2, 2026
CVE-2026-2382 affects the FPW Category Thumbnails plugin for WordPress (up to 1.9.5) with a CVSS score of 6.4. It allows…
CVE-2026-4071: BirdSeed <= 2.2.0 Cross-Site Request Forgery via BirdSeed Token Change PoC, Patch Analysis & Rule
June 2, 2026
CVE-2026-4071 affects the Birdseed plugin for WordPress (up to v2.2.0) with a medium severity (CVSS 4.3) CSRF vulnerability. Ensure to…
CVE-2026-5191: Tiled Gallery Carousel Without JetPack <= 3.1 Authenticated (Contributor+) Stored Cross-Site Scripting via 'data-image-title' PoC, Patch Analysis & Rule
June 2, 2026
CVE-2026-5191 affects the Tiled Gallery Carousel Without Jetpack plugin for WordPress, with a CVSS score of 5.4. Authenticated users can…
←
1
2
3
4
5
6
…
98
→