Skip to main content
Skip to footer
Home
CVE Analysis
How it Works
Resources
Pricing
Log in
Free Protection
Home
CVE Analysis
How it Works
Resources
Pricing
Log in
Free Protection
Severity:
medium
CVE-2026-4071: BirdSeed <= 2.2.0 Cross-Site Request Forgery via BirdSeed Token Change PoC, Patch Analysis & Rule
June 2, 2026
CVE-2026-4071 affects the Birdseed plugin for WordPress (up to v2.2.0) with a medium severity (CVSS 4.3) CSRF vulnerability. Ensure to…
CVE-2026-5191: Tiled Gallery Carousel Without JetPack <= 3.1 Authenticated (Contributor+) Stored Cross-Site Scripting via 'data-image-title' PoC, Patch Analysis & Rule
June 2, 2026
CVE-2026-5191 affects the Tiled Gallery Carousel Without Jetpack plugin for WordPress, with a CVSS score of 5.4. Authenticated users can…
CVE-2026-5074: ARMember Premium <= 7.3.1 Authenticated (Subscriber+) SQL Injection via 'sSortDir_0' Parameter PoC, Patch Analysis & Rule
June 2, 2026
CVE-2026-5074 affects the ARMember Premium plugin (up to 7.3.1) with a CVSS score of 6.5. This medium severity SQL injection…
CVE-2026-2425: hiWeb Migration Simple <= 2.0.0.1 Reflected Cross-Site Scripting via 'new_domain' Parameter PoC, Patch Analysis & Rule
June 2, 2026
CVE-2026-2425 affects the Hiweb Migration Simple plugin for WordPress (up to 2.0.0.1) with a medium severity CVSS score of 6.1.…
CVE-2026-4080: Easy Cart <= 1.8 Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode Attributes PoC, Patch Analysis & Rule
June 2, 2026
CVE-2026-4080 affects the Easy Cart plugin for WordPress (up to version 1.8) with a medium severity CVSS score of 6.4.…
CVE-2026-9730: Remove NoFollow Commenter URL <= 1.0 Cross-Site Request Forgery to Settings Update PoC, Patch Analysis & Rule
June 2, 2026
CVE-2026-9730 affects the Remove Nofollow Commenter Link plugin for WordPress, version 1.0, with a medium severity CVSS score of 4.3.…
CVE-2026-4081: ZeM STL <= 1.0 Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode Attributes PoC, Patch Analysis & Rule
June 2, 2026
CVE-2026-4081 affects the ZeM STL Viewer plugin for WordPress (version 1.0 and earlier) with a CVSS score of 6.4. Authenticated…
CVE-2026-1450: rognone <= 0.6.2 Reflected Cross-Site Scripting via 'mode' Parameter PoC, Patch Analysis & Rule
June 2, 2026
CVE-2026-1450 affects the Rognone plugin for WordPress (up to v0.6.2) with a medium severity (CVSS 6.1) reflected XSS vulnerability. Ensure…
CVE-2026-8885: DeMomentSomTres Shortcodes <= 1.1.1 Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode Attributes PoC, Patch Analysis & Rule
June 2, 2026
CVE-2026-8885 affects the DeMomentSomTres Shortcodes plugin (up to v1.1.1) with a medium severity CVSS score of 6.4. Authenticated attackers can…
CVE-2026-9723: Google Plus One Bottom <= 0.0.2 Cross-Site Request Forgery to Plugin Settings Update via Settings Page PoC, Patch Analysis & Rule
June 2, 2026
CVE-2026-9723 affects the Google Plus One Bottom plugin for WordPress (up to version 0.0.2) with a medium severity (CVSS 4.3)…
CVE-2025-5085: wp-nano-ad <= 1.31 Authenticated (Administrator+) Stored Cross-Site Scripting via blogrole_link Parameter PoC, Patch Analysis & Rule
June 2, 2026
CVE-2025-5085 affects the WP Nano Ad plugin (up to v1.31) with a CVSS score of 5.5. This medium-severity Stored XSS…
CVE-2026-9722: Laiser Tag <= 1.2.5 Cross-Site Request Forgery to Plugin Settings Update via Settings Form PoC, Patch Analysis & Rule
June 2, 2026
CVE-2026-9722 affects the Laiser Tag plugin for WordPress (up to version 1.2.5) with a medium severity CVSS score of 4.3.…
CVE-2026-45442: The Ultimate Video Player For WordPress – by Presto Player <= 4.1.3 – Missing Authorization (presto-player)
May 22, 2026
CVE-2026-45442 affects Presto Player plugin versions up to 4.1.3, allowing unauthorized access to private media. Upgrade to version 4.1.4 to…
CVE-2026-5293: 診断ジェネレータ作成プラグイン <= 1.4.16 – Authenticated (Subscriber+) Stored Cross-Site Scripting via 'js' Parameter (os-diagnosis-generator)
May 22, 2026
CVE-2026-5293 affects the Os Diagnosis Generator plugin for WordPress (up to v1.4.16) with a medium severity CVSS score of 6.4.…
CVE-2026-8038: Faces of Users <= 0.0.3 – Authenticated (Contributor+) Stored Cross-Site Scripting via 'default' Shortcode Attribute (faces-of-users)
May 22, 2026
CVE-2026-8038 affects the Faces of Users WordPress plugin (up to version 0.0.3) with a medium severity CVSS score of 6.4…
CVE-2026-6072: Oliver POS <= 2.4.2.6 – Unauthenticated Authorization Bypass Through User-Controlled Key to 'OliverAuth' Header (oliver-pos)
May 22, 2026
CVE-2026-6072 affects the Oliver POS plugin for WordPress (up to 2.4.2.6) with a medium severity (CVSS 6.5) authentication bypass. Unauthenticated…
CVE-2026-42675: Hydra Booking — Appointment Scheduling & Booking Calendar <= 1.1.41 – Missing Authorization (hydra-booking)
May 22, 2026
CVE-2026-42675 affects the Hydra Booking plugin for WordPress (up to version 1.1.41) with a CVSS score of 5.3. Ensure you…
CVE-2026-45438: Smart Coupons For WooCommerce Coupons < 2.3.0 – Missing Authorization (wt-smart-coupons-for-woocommerce)
May 22, 2026
CVE-2026-45438 affects the Wt Smart Coupons For WooCommerce plugin (up to version 2.3.0) with a CVSS score of 5.3. This…
CVE-2026-42679: Classified Listing – AI-Powered Classified ads & Business Directory Plugin <= 5.3.8 – Authenticated (Subscriber+) Arbitrary File Download (classified-listing)
May 22, 2026
CVE-2026-42679 affects the Classified Listing plugin for WordPress (up to version 5.3.8) with a medium severity (CVSS 4.3). Patch to…
CVE-2026-8096: Kirki <= 6.0.6 – Missing Authorization to Authenticated (Subscriber+) Sensitive Form Submission Data Exposure via 'kirki_wp_admin_get_apis' Action (kirki)
May 22, 2026
CVE-2026-8096 affects the Kirki plugin (up to version 6.0.6) with a medium severity score of 6.5. Authenticated users can bypass…
←
1
…
3
4
5
6
7
…
98
→