Skip to main content
Skip to footer
Home
CVE Analysis
How it Works
Resources
Pricing
Log in
Create Account
Home
CVE Analysis
How it Works
Resources
Pricing
Log in
Create Account
Severity:
medium
CVE-2026-57643: WP Post Author – Author Box, Multiple Authors, Guest Authors & Custom Avatars <= 3.9.1 Authenticated (Contributor+) SQL Injection PoC, Patch Analysis & Rule
June 29, 2026
CVE-2026-57643 affects the WP Post Author plugin (up to version 3.9.1) with a medium severity score of 6.5. Authenticated attackers…
CVE-2026-54818: SlimStat Analytics <= 5.4.11 Authenticated (Subscriber+) SQL Injection PoC, Patch Analysis & Rule
June 28, 2026
CVE-2026-54818 affects the SlimStat Analytics plugin for WordPress (up to 5.4.11) with a medium severity CVSS score of 6.5. Authenticated…
CVE-2026-54817: MStore API – Create Native Android & iOS Apps On The Cloud <= 4.18.4 Missing Authorization PoC, Patch Analysis & Rule
June 28, 2026
CVE-2026-54817 affects the Mstore Api plugin for WordPress (up to version 4.18.4) with a medium severity CVSS score of 5.3.…
CVE-2026-54821: Visual Link Preview <= 2.3.1 Authenticated (Subscriber+) Sensitive Information Exposure PoC, Patch Analysis & Rule
June 28, 2026
CVE-2026-54821 affects the Visual Link Preview plugin (up to version 2.3.1) with a CVSS score of 4.3. Authenticated attackers can…
CVE-2026-54826: SupportCandy – Helpdesk & Customer Support Ticket System <= 3.4.6 Authenticated (Subscriber+) Insecure Direct Object Reference PoC, Patch Analysis & Rule
June 28, 2026
CVE-2026-54826 affects the SupportCandy plugin (up to v3.4.6) with a CVSS score of 4.3. Authenticated users can exploit this IDOR…
CVE-2026-54824: Quads Ads Manager for Google AdSense <= 3.0.3 Unauthenticated Information Exposure PoC, Patch Analysis & Rule
June 28, 2026
CVE-2026-54824 affects Quick Adsense Reloaded plugin versions up to 3.0.3 with a medium severity (CVSS 5.3). Patch to version 3.0.4…
CVE-2026-54830: Five Star Restaurant Reservations – WordPress Booking Plugin <= 2.7.19 Missing Authorization PoC, Patch Analysis & Rule
June 28, 2026
CVE-2026-54830 affects the Restaurant Reservations plugin (up to v2.7.19) with a CVSS score of 5.3. Unauthenticated attackers can exploit this…
CVE-2026-54813: SureDash – Community, Courses & Member Dashboard <= 1.8.0 Authenticated (Subscriber+) SQL Injection PoC, Patch Analysis & Rule
June 28, 2026
CVE-2026-54813 affects the SureDash plugin for WordPress (up to v1.8.0) with a medium severity (CVSS 6.5) SQL injection vulnerability. Users…
CVE-2026-54822: SALESmanago & Leadoo <= 3.11.2 Authenticated (Subscriber+) SQL Injection PoC, Patch Analysis & Rule
June 28, 2026
CVE-2026-54822 affects the SALESmanago plugin (up to version 3.11.2) with a medium severity (CVSS 6.5) SQL injection vulnerability. Users should…
CVE-2026-54828: Motors – Car Dealership & Classified Listings Plugin <= 1.4.109 Missing Authorization PoC, Patch Analysis & Rule
June 28, 2026
CVE-2026-54828 affects the Motors Car Dealership Classified Listings plugin (up to v1.4.109) with a medium severity (CVSS 5.3) vulnerability. Patch…
CVE-2026-54834: Object Cache 4 everyone <= 2.3.2 Information Exposure PoC, Patch Analysis & Rule
June 28, 2026
CVE-2026-54834 affects Object Cache 4 Everyone plugin versions up to 2.3.2, exposing sensitive data to unauthenticated attackers. Upgrade to 2.3.3…
CVE-2026-56024: WP Easy Pay – Payment and Donation form Builder for Square <= 4.5.0 Cross-Site Request Forgery PoC, Patch Analysis & Rule
June 27, 2026
CVE-2026-56024 affects WP Easy Pay plugin versions up to 4.5.0, with a CVSS score of 4.3. This medium-severity CSRF vulnerability…
CVE-2026-56012: Media Library Assistant <= 3.35 Authenticated (Contributor+) SQL Injection PoC, Patch Analysis & Rule
June 27, 2026
CVE-2026-56012 affects the Media Library Assistant plugin for WordPress (up to version 3.35) with a medium severity (CVSS 6.5) SQL…
CVE-2026-54846: Syncee Premium Dropshipping & Wholesale <= 1.0.27 Missing Authorization PoC, Patch Analysis & Rule
June 27, 2026
CVE-2026-54846 affects the Syncee Global Dropshipping plugin (up to v1.0.27) with a CVSS score of 5.3. Unauthenticated attackers can exploit…
CVE-2026-54848: WC Shop Sync – Square Payment Gateway and Product Synchronization for WooCommerce <= 4.7.3 Unauthenticated Information Exposure PoC, Patch Analysis & Rule
June 27, 2026
CVE-2026-54848 affects the Woosquare plugin (up to v4.7.3) with a CVSS score of 5.3, allowing unauthenticated access to sensitive data.…
CVE-2026-54842: Royal MCP – Secure AI Connector for Claude, ChatGPT & Gemini <= 1.4.25 Missing Authorization PoC, Patch Analysis & Rule
June 27, 2026
CVE-2026-54842 affects the Royal MCP plugin for WordPress (up to version 1.4.25) with a medium severity (CVSS 4.3) vulnerability allowing…
CVE-2026-54847: Stylish Cost Calculator – Quote Generator, Lead Gen & Price Estimator <= 8.3.9 Missing Authorization PoC, Patch Analysis & Rule
June 27, 2026
CVE-2026-54847 affects the Stylish Cost Calculator plugin for WordPress (up to v8.3.9) due to a missing capability check, allowing unauthorized…
CVE-2026-54841: Vitepos – Point of Sale (POS) for WooCommerce <= 3.4.2 Unauthenticated Information Exposure PoC, Patch Analysis & Rule
June 27, 2026
CVE-2026-54841 affects the Vitepos Lite plugin for WordPress (up to version 3.4.2) with a CVSS score of 5.3. Unauthenticated attackers…
CVE-2026-56006: Interactive Content – H5P <= 1.17.6 Reflected Cross-Site Scripting PoC, Patch Analysis & Rule
June 27, 2026
CVE-2026-56006 affects the H5P plugin for WordPress (up to version 1.17.6) with a medium severity (CVSS 6.1) XSS vulnerability. Upgrade…
CVE-2026-54839: Trinity Backup – Backup, Migrate, Restore, Clone & Schedule Backups <= 2.0.9 Unauthenticated Information Exposure PoC, Patch Analysis & Rule
June 27, 2026
CVE-2026-54839 affects the Trinity Backup plugin (up to v2.0.9) with a CVSS score of 5.3, exposing sensitive data to unauthenticated…
←
1
…
7
8
9
10
11
…
111
→