Skip to main content
Skip to footer
Home
CVE Analysis
How it Works
Resources
Pricing
Log in
Create Account
Home
CVE Analysis
How it Works
Resources
Pricing
Log in
Create Account
Severity:
medium
CVE-2026-13015: WP Google Review Slider <= 18.1 Reflected Cross-Site Scripting via 'place' Parameter PoC, Patch Analysis & Rule
July 3, 2026
Medium CVE-2026-13015 in Wp Google Places Review Slider (CVSS 6.1): WP Google Review Slider. Atomic Edge summarizes impact, exploitability, and…
CVE-2026-13443: Tutor LMS <= 3.9.13 Authenticated (Author+) Stored Cross-Site Scripting via Lesson Attachment Title PoC, Patch Analysis & Rule
July 3, 2026
Medium CVE-2026-13443 in Tutor (CVSS 6.4): Tutor LMS. Atomic Edge summarizes impact, exploitability, and patch details, with WAF rule coverage.…
CVE-2026-9107: Kali Forms <= 2.4.13 Authenticated (Contributor+) Stored Cross-Site Scripting via 'kaliforms_field_components' Parameter PoC, Patch Analysis & Rule
July 3, 2026
Medium CVE-2026-9107 in Kali Forms (CVSS 6.4): Kali Forms. Atomic Edge summarizes impact, exploitability, and patch details, with WAF rule…
CVE-2026-11398: LatePoint <= 5.6.1 Missing Authorization to Unauthenticated Arbitrary Customer Data Modification via process_step_customer() Booking Form Customer Step PoC, Patch Analysis & Rule
July 2, 2026
Medium CVE-2026-11398 in Latepoint (CVSS 5.3): LatePoint. Atomic Edge summarizes impact, exploitability, and patch details. Update to 5.6.2.
CVE-2026-9230: Quiz and Survey Master (QSM) <= 11.1.4 Missing Authorization to Authenticated (Contributor+) Arbitrary Quiz Modification and Email Reroute via Leaked Nonce from /quiz/structure PoC, Patch Analysis & Rule
July 2, 2026
Medium CVE-2026-9230 in Quiz Master Next (CVSS 4.3): Quiz and Survey Master (QSM). Atomic Edge summarizes impact, exploitability, and patch…
CVE-2026-11900: Ad Inserter <= 2.8.16 Insecure Direct Object Reference to Authenticated (Contributor+) Arbitrary Post Content Disclosure via 'data' Shortcode Attribute PoC, Patch Analysis & Rule
July 2, 2026
Medium CVE-2026-11900 in Ad Inserter (CVSS 4.3): Ad Inserter. Atomic Edge summarizes impact, exploitability, and patch details, with WAF rule…
CVE-2026-5137: RTMKit <= 2.0.7 Authenticated (Contributor+) Limited Local File Inclusion via 'template' Parameter PoC, Patch Analysis & Rule
July 2, 2026
Medium CVE-2026-5137 in Rometheme For Elementor (CVSS 4.3): RTMKit. Atomic Edge summarizes impact, exploitability, and patch details, with WAF rule…
CVE-2026-11397: WP Import Export Lite <= 3.9.30 Authenticated (Administrator+) Server-Side Request Forgery via 'file_url' Parameter PoC, Patch Analysis & Rule
July 2, 2026
Medium CVE-2026-11397 in Wp Import Export Lite (CVSS 5.5): WP Import Export Lite. Atomic Edge summarizes impact, exploitability, and patch…
CVE-2026-12557: Ninja Forms File Uploads <= 3.3.29 Missing Authorization to Unauthenticated Log Disclosure and Deletion via debug-log/delete-all and debug-log/get-all REST Endpoints PoC, Patch Analysis & Rule
July 2, 2026
Medium CVE-2026-12557 in Ninja Forms Uploads (CVSS 5.3): Ninja Forms - File Uploads. Atomic Edge summarizes impact, exploitability, and patch…
CVE-2026-8892: CM Business Directory <= 1.5.7 Authenticated (Contributor+) Stored Cross-Site Scripting via Business Address Meta Fields PoC, Patch Analysis & Rule
July 2, 2026
Medium CVE-2026-8892 in Cm Business Directory (CVSS 6.4): CM Business Directory. Atomic Edge summarizes impact, exploitability, and patch details. Update…
CVE-2026-8351: RTMKit <= 2.0.7 Authenticated (Contributor+) Stored Cross-Site Scripting via Advanced Heading Widget 'Background Text' Parameter PoC, Patch Analysis & Rule
July 2, 2026
Medium CVE-2026-8351 in Rometheme For Elementor (CVSS 6.4): RTMKit. Atomic Edge summarizes impact, exploitability, and patch details. Update to 2.0.8.
CVE-2026-9626: JSON API User <= 4.1.0 Authenticated (Subscriber+) Stored Cross-Site Scripting via 'content' Parameter PoC, Patch Analysis & Rule
July 2, 2026
CVE-2026-9626 affects the Json Api User plugin for WordPress (up to version 4.1.0) with a medium severity (CVSS 6.4) cross-site…
CVE-2026-8489: Ultimate Member <= 2.11.4 Authenticated (Subscriber+) Stored Cross-Site Scripting via Non-HTML Custom Textarea Profile Field PoC, Patch Analysis & Rule
July 2, 2026
Medium CVE-2026-8489 in Ultimate Member (CVSS 6.4): Ultimate Member. Atomic Edge summarizes impact, exploitability, and patch details, with WAF rule…
CVE-2026-12729: weDocs: AI Powered Knowledge Base, Docs, Documentation, Wiki & AI Chatbot <= 2.3.0 Missing Authorization to Authenticated (Subscriber+) Data Migration via wedocs_migrate_betterdocs_to_wedocs AJAX Action PoC, Patch Analysis & Rule
July 2, 2026
CVE-2026-12729 affects the weDocs plugin for WordPress (up to v2.3.0) with a medium severity (CVSS 4.3) vulnerability. Authenticated users can…
CVE-2026-12734: weDocs: AI Powered Knowledge Base, Docs, Documentation, Wiki & AI Chatbot <= 2.3.0 Authenticated (Contributor+) Stored Cross-Site Scripting via 'connectorWidth' Block Attribute PoC, Patch Analysis & Rule
July 2, 2026
CVE-2026-12734 affects the weDocs plugin for WordPress (up to 2.3.0) with a medium severity (CVSS 6.4) stored XSS vulnerability. Users…
CVE-2026-12920: Cookie Banner for GDPR / CCPA <= 4.3.5 Authenticated (Administrator+) SQL Injection via 's' Parameter PoC, Patch Analysis & Rule
July 2, 2026
CVE-2026-12920 affects the Gdpr Cookie Consent plugin (up to version 4.3.5) with a medium severity SQL injection vulnerability. Update to…
CVE-2026-12154: Reviews Widgets for Google, Yelp & TripAdvisor <= 2.7.3 Authenticated (Contributor+) Stored Cross-Site Scripting via 'page_id' Shortcode Attribute PoC, Patch Analysis & Rule
July 2, 2026
CVE-2026-12154 affects the Fb Reviews Widget plugin (up to version 2.7.3) with a medium severity CVSS score of 6.4. Authenticated…
CVE-2026-12731: weDocs: AI Powered Knowledge Base, Docs, Documentation, Wiki & AI Chatbot <= 2.3.0 Authenticated (Contributor+) Stored Cross-Site Scripting via 'sectionTitleTag' and 'articleTitleTag' Block Attributes PoC, Patch Analysis & Rule
July 2, 2026
CVE-2026-12731 affects the weDocs plugin for WordPress (up to version 2.3.0) with a medium severity CVSS score of 6.4. Update…
CVE-2026-13252: RSS Aggregator by Feedzy <= 5.2.1 Authenticated (Contributor+) Stored Cross-Site Scripting via 'aspectRatio' Attribute PoC, Patch Analysis & Rule
July 1, 2026
CVE-2026-13252 affects the Feedzy Rss Feeds plugin (up to v5.2.1) with a CVSS score of 6.4. This medium-severity Stored XSS…
CVE-2026-9145: Database for Contact Form 7, WPforms, Elementor forms <= 1.5.1 Unauthenticated Arbitrary File Copy/Upload via Elementor Pro Form Upload Field 'raw_value' PoC, Patch Analysis & Rule
July 1, 2026
CVE-2026-9145 affects the Contact Form Entries plugin (up to v1.5.1) with a medium severity (CVSS 6.5) file upload vulnerability. Upgrade…
←
1
…
4
5
6
7
8
…
111
→