Skip to main content
Skip to footer
Home
CVE Analysis
How it Works
Resources
Pricing
Log in
Free Protection
Home
CVE Analysis
How it Works
Resources
Pricing
Log in
Free Protection
Severity:
medium
CVE-2026-42676: Points Management System For Gamification, Ranks, Badges, and Loyalty Rewards Program – myCred <= 3.0.4 – Authenticated (Subscriber+) Stored Cross-Site Scripting (mycred)
May 22, 2026
CVE-2026-42676 affects the myCred plugin for WordPress (up to version 3.0.4) with a medium severity CVSS score of 6.4. Users…
CVE-2026-42677: WP Document Revisions <= 3.8.1 – Missing Authorization (wp-document-revisions)
May 22, 2026
CVE-2026-42677 affects the WP Document Revisions plugin (up to version 3.8.1) with a medium severity CVSS score of 5.3. Unauthenticated…
CVE-2026-42674: Advanced Access Manager – Access Governance for WordPress <= 7.1.0 – Missing Authorization (advanced-access-manager)
May 22, 2026
CVE-2026-42674 affects the Advanced Access Manager plugin (up to v7.1.0) with a CVSS score of 5.3. Unauthenticated attackers can exploit…
CVE-2026-8684: MotoPress Hotel Booking <= 6.0.1 – Missing Authorization to Unauthenticated Arbitrary Booking Notes Modification via mphb_update_booking_notes AJAX Action (motopress-hotel-booking-lite)
May 21, 2026
CVE-2026-8684 affects the Motopress Hotel Booking Lite plugin (up to version 6.0.1) with a CVSS score of 5.3. Unauthenticated users…
CVE-2026-8692: Vedrixa Forms <= 1.1.1 – Missing Authorization to Authenticated (Subscriber+) Arbitrary Form Structure Modification via wefb_save_form_structure AJAX Action (vedrixa-forms-registration-builder)
May 21, 2026
CVE-2026-8692 affects Vedrixa Forms Registration Builder plugin versions up to 1.1.1, allowing authenticated users to modify forms. Update to version…
CVE-2026-7615: Widget Context <= 1.3.3 – Cross-Site Request Forgery to Settings Update via 'wl' Parameter (widget-context)
May 21, 2026
CVE-2026-7615 affects the Widget Context plugin for WordPress (up to v1.3.3) with a medium severity (CVSS 4.3) CSRF vulnerability. Update…
CVE-2026-4070: Alfie <= 1.2.1 – Cross-Site Request Forgery to Feed Deletion via 'delete' Parameter (alfie-the-productfeedtool-wp-plugin)
May 21, 2026
CVE-2026-4070 affects the Alfie The Productfeedtool WP Plugin (up to version 1.2.1) with a medium severity CVSS score of 4.3.…
CVE-2026-3481: WP Blockade <= 0.9.14 – Reflected Cross-Site Scripting via 'shortcode' Parameter (wp-blockade)
May 21, 2026
CVE-2026-3481 affects the WP Blockade plugin (up to v0.9.14) with a CVSS score of 6.1. This medium severity XSS vulnerability…
CVE-2026-7636: Slider by Soliloquy <= 2.8.1 – Authenticated (Subscriber+) Information Disclosure via REST API Endpoint (soliloquy-lite)
May 21, 2026
CVE-2026-7636 affects the Soliloquy Lite plugin (up to v2.8.1) with a CVSS score of 4.3. Authenticated users can access sensitive…
CVE-2026-7249: Location Weather <= 3.0.2 – Missing Authorization to Authenticated (Contributor+) Block Settings Modification and Cache Purging (location-weather)
May 21, 2026
CVE-2026-7249 affects the Location Weather plugin for WordPress (versions
CVE-2026-7509: KIA Subtitle <= 4.0.1 – [Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')] (kia-subtitle)
May 21, 2026
CVE-2026-7509 affects the KIA Subtitle plugin (up to 4.0.1) with a medium severity (CVSS 6.4) Stored XSS vulnerability. Users should…
CVE-2026-7798: FluentCRM <= 2.9.87 – Unauthenticated Blind Server-Side Request Forgery via 'SubscribeURL' Parameter (fluent-crm)
May 21, 2026
CVE-2026-7798 affects the Fluent Crm plugin (up to version 2.9.87) with a medium severity (CVSS 5.4) Blind SSRF vulnerability. Update…
CVE-2026-9104: Draft List <= 2.6.3 – Authenticated (Author+) Stored Cross-Site Scripting via Draft Post Title (simple-draft-list)
May 21, 2026
CVE-2026-9104 affects the Simple Draft List plugin for WordPress (up to version 2.6.3) with a medium severity (CVSS 6.4) stored…
CVE-2026-4843: GSheet For Woo Importer <= 2.3.1 – Missing Authorization to Authenticated (Subscriber+) Plugin Settings Reset (import-products-from-gsheet-for-woo-importer)
May 21, 2026
CVE-2026-4843 affects the GSheet For Woo Importer plugin for WordPress (up to v2.3.1) with a CVSS score of 4.3. Patch…
CVE-2026-6864: CBX 5 Star Rating & Review <= 1.0.7 – Reflected Cross-Site Scripting via 'page' Parameter (cbxscratingreview)
May 21, 2026
CVE-2026-6864 affects the CBX 5 Star Rating & Review plugin for WordPress (up to v1.0.7) with a medium severity (CVSS…
CVE-2026-6391: Sentence To SEO (keywords, description and tags) <= 1.0 – Cross-Site Request Forgery to Stored Cross-Site Scripting via Settings Page Parameters (sentence-to-seo)
May 21, 2026
CVE-2026-6391 affects the Sentence To SEO plugin for WordPress (version 1.0 and earlier) with a CVSS score of 6.1. Ensure…
CVE-2026-6394: Nexa Blocks <= 1.1.1 – Unauthenticated Blind Server-Side Request Forgery via 'demo_json_file' Parameter (nexa-blocks)
May 21, 2026
CVE-2026-6394 affects the Nexa Blocks plugin for WordPress (up to v1.1.1), allowing unauthenticated SSRF attacks. Users should patch to mitigate…
CVE-2026-1881: Broadstreet <= 1.52.2 – Authenticated (Subscriber+) Private Post Meta Disclosure via get_sponsored_meta (broadstreet)
May 20, 2026
CVE-2026-1881 affects the Broadstreet plugin for WordPress (up to version 1.52.2) with a medium severity CVSS score of 4.3. Authenticated…
CVE-2026-1543: Avada (Fusion) Builder <= 3.15.2 – Authenticated (Subscriber+) Stored Cross-Site Scripting via Multiple Shortcodes (fusion-builder)
May 20, 2026
CVE-2026-1543 affects the Fusion Builder plugin for WordPress (up to v3.15.2) with a CVSS score of 6.4. Authenticated users can…
CVE-2026-8418: Games Catalog <= 1.2.0 – Cross-Site Request Forgery to Arbitrary Game/Post Deletion (game-catalog)
May 20, 2026
CVE-2026-8418 affects the Game Catalog plugin for WordPress (up to v1.2.0) with a medium severity (CVSS 4.3) CSRF vulnerability. Unauthenticated…
←
1
…
4
5
6
7
8
…
98
→