Skip to main content
Skip to footer
Home
CVE Analysis
How it Works
Resources
Pricing
Log in
Free Protection
Home
CVE Analysis
How it Works
Resources
Pricing
Log in
Free Protection
Severity:
medium
CVE-2026-8423: JaviBola Custom Theme Test <= 2.0.5 – Cross-Site Request Forgery (javibola-custom-theme)
May 20, 2026
CVE-2026-8423 affects the JaviBola Custom Theme plugin for WordPress (up to v2.0.5) with a medium severity (CVSS 4.3) CSRF vulnerability.…
CVE-2026-4811: WPB Floating Menu or Categories – Sticky Floating Side Menu & Categories with Icons <= 1.0.8 – Authenticated (Editor+) Stored Cross-Site Scripting via 'Icon CSS Class' Category Field (wpb-floating-menu-or-categories)
May 20, 2026
CVE-2026-4811 affects the WPB Floating Menu or Categories plugin (up to v1.0.8) with a medium severity (CVSS 4.9) XSS vulnerability.…
CVE-2026-8685: Infility Global <= 2.15.16 – Authenticated (Subscriber+) SQL Injection via 'orderby' Parameter (infility-global)
May 20, 2026
CVE-2026-8685 affects the Infility Global plugin for WordPress (up to v2.15.16) with a medium severity (CVSS 6.5) SQL injection vulnerability.…
CVE-2026-8418: Games Catalog <= 1.2.0 – Cross-Site Request Forgery to Arbitrary Game/Post Deletion (game-catalog)
May 20, 2026
CVE-2026-8418 affects the Game Catalog plugin for WordPress (up to v1.2.0) with a medium severity (CVSS 4.3) CSRF vulnerability. Unauthenticated…
CVE-2026-8419: Amazon Scraper <= 1.1 – Cross-Site Request Forgery to Stored Cross-Site Scripting via Settings Update (amazon-scraper)
May 20, 2026
CVE-2026-8419 affects the Amazon Scraper plugin for WordPress, version 1.1 and earlier. This medium severity CSRF vulnerability allows attackers to…
CVE-2026-7462: VatanSMS WP SMS <= 1.01 – Reflected Cross-Site Scripting via 'page' Parameter (wp-sms-vatansms-com)
May 20, 2026
CVE-2026-7462 affects the VatanSMS WP SMS plugin (up to version 1.01) with a CVSS score of 6.1. This medium severity…
CVE-2026-6400: Child Height Predictor by Ostheimer <= 1.3 – Cross-Site Request Forgery to Settings Update via Plugin Settings Form (child-height-predictor)
May 20, 2026
CVE-2026-6400 affects the Child Height Predictor plugin for WordPress (up to version 1.3) with a CVSS score of 4.3. Ensure…
CVE-2026-6401: Bottom Bar <= 0.1.7 – Cross-Site Request Forgery to Settings Update (bottom-bar)
May 20, 2026
CVE-2026-6401 affects the Bottom Bar plugin for WordPress (up to version 0.1.7) with a CVSS score of 4.3. This medium-severity…
CVE-2026-8420: BLOGCHAT Chat System <= 1.3.6.3 – Cross-Site Request Forgery to Stored Cross-Site Scripting via Settings Update (blogchat-chat-system)
May 20, 2026
CVE-2026-8420 affects the Blogchat Chat System plugin for WordPress (up to v1.3.6.3) with a medium severity CVSS score of 6.1.…
CVE-2026-6452: Bigfishgames Syndicate <= 1.2 – Cross-Site Request Forgery to Settings Reset and Update (bigfishgames-syndicate)
May 20, 2026
CVE-2026-6452 affects the Bigfishgames Syndicate plugin (up to version 1.2) with a medium severity CVSS score of 4.3. Proper nonce…
CVE-2026-6397: Sticky <= 2.5.6 – Authenticated (Contributor+) Stored Cross-Site Scripting via 'readmoretext' Shortcode Attribute (sticky)
May 20, 2026
CVE-2026-6397 affects the Sticky plugin for WordPress (up to version 2.5.6) with a CVSS score of 6.4. Authenticated attackers can…
CVE-2026-6395: Word 2 Cash <= 0.9.2 – Cross-Site Request Forgeryto Stored Cross-Site Scripting via Settings Page (word-2-cash)
May 20, 2026
CVE-2026-6395 affects the Word 2 Cash plugin (up to version 0.9.2) with a medium severity (CVSS 6.1) vulnerability. Unauthenticated attackers…
CVE-2026-6399: General Options <= 1.1.0 – Authenticated (Administrator+) Stored Cross-Site Scripting via 'ad_contact_number' Parameter (general-options)
May 20, 2026
CVE-2026-6399 affects the General Options plugin for WordPress (up to 1.1.0) with a CVSS score of 4.4. Authenticated admins can…
CVE-2026-6404: Anomify AI <= 0.3.6 – Authenticated (Administrator+) Stored Cross-Site Scripting via 'anomify_api_key' Parameter (anomify)
May 20, 2026
CVE-2026-6404 affects the Anomify plugin (up to version 0.3.6) with a medium severity score of 4.4. Authenticated admins can exploit…
CVE-2025-15369: Xpro Addons — 140+ Widgets for Elementor <= 1.5.0 – Missing Authorization to Unauthenticated Xpro Template Creation (xpro-elementor-addons)
May 19, 2026
CVE-2025-15369 affects the Xpro Elementor Addons plugin (v1.5.0) with a medium severity (CVSS 5.3). Unauthenticated attackers can create published templates.…
CVE-2026-2955: AI Chatbot & Workflow Automation by AIWU <= 1.4.14 – Unauthenticated Stored Cross-Site Scripting via 'X-Forwarded-For' Header (ai-copilot-content-generator)
May 19, 2026
CVE-2026-2955 affects the Ai Copilot Content Generator plugin for WordPress (up to v1.4.14) with a medium severity CVSS of 6.4.…
CVE-2026-5075: All in One SEO <= 4.9.7 – Authenticated (Contributor+) Sensitive Information Exposure via 'internalOptions' Localized Script Data (all-in-one-seo-pack)
May 19, 2026
CVE-2026-5075 affects All in One SEO Pack versions up to 4.9.7, allowing authenticated users to access sensitive data like API…
CVE-2026-6566: Photo Gallery, Sliders, Proofing and Themes <= 4.2.0 – Insecure Direct Object Reference to Authenticated (Subscriber+) Image Deletion via REST API (nextgen-gallery)
May 19, 2026
CVE-2026-6566 affects the NextGEN Gallery plugin for WordPress (up to 4.2.0) with a medium severity CVSS score of 4.3. Authenticated…
CVE-2026-6405: Anomify AI <= 0.3.6 – Cross-Site Request Forgery (anomify)
May 19, 2026
CVE-2026-6405 affects the Anomify plugin for WordPress (up to 0.3.6) with a medium severity (CVSS 4.3) XSS vulnerability. Ensure to…
CVE-2026-8610: TypeSquare Webfonts for ConoHa <= 2.0.4 – Missing Authorization to Authenticated (Subscriber+) Plugin Settings Modification via 'fontThemeUseType' Parameter (ts-webfonts-for-conoha)
May 19, 2026
CVE-2026-8610 affects the Ts Webfonts For Conoha plugin for WordPress versions up to 2.0.4, allowing authenticated users to modify settings…
←
1
…
5
6
7
8
9
…
98
→