CVE Datenbank
Durchsuchbare Datenbank mit Sicherheitslücken. Filtere nach Hersteller, Schweregrad oder Zeitraum.
CVE-2026-89235 - The Testimonials by BestWebSoft WordPress plugin through 1.0.8 does not sanitise and escape a parame
CVE-2026-87846 - The Shipping for Nova Poshta WordPress plugin through 1.19.8 does not perform any authorisation, non
CVE-2026-86851 - The Livees Checkout WordPress plugin through 7.0.2 does not perform any capability, nonce or order-k
CVE-2026-85348 - The GDPR Data Request Form WordPress plugin through 1.7.1 does not have CSRF protection when updatin
CVE-2026-103329 - The Super Payments WordPress plugin before 1.43.1 does not properly verify the authenticity of incom
CVE-2026-84224 - The Kirki WordPress plugin before 6.3.2 does not validate the host of a URL it is given before fetch
CVE-2026-84220 - The Kirki WordPress plugin before 6.3.2 does not prevent shortcodes held in comments from being exec
CVE-2025-14123 - The Redux Framework plugin for WordPress is vulnerable to privilege escalation in all versions up to
CVE-2026-74932 - The WP Fastest Cache WordPress plugin before 1.5.1 does not validate the Host header before using it
CVE-2026-77824 - The Media Sweep – WordPress Media Cleaner plugin for WordPress is vulnerable to generic SQL Injectio
CVE-2026-75971 - The ShopEngine Elementor WooCommerce Builder Addon – All in One WooCommerce Solution plugin for Word
CVE-2026-75908 - The Newsletters plugin for WordPress is vulnerable to authorization bypass in all versions up to, an
CVE-2026-19949 - The All-in-One WP Migration and Backup plugin for WordPress is vulnerable to SQL Injection via archi
CVE-2026-18547 - The Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Mem
CVE-2026-17587 - The My Agile Privacy® – CMP, Cookie Consent & Privacy Tools plugin for WordPress is vulnerable to au
CVE-2026-76128 - The eCommerce Product Catalog plugin for WordPress is vulnerable to Stored Cross-Site Scripting via
CVE-2026-18512 - The TranslatePress – Translate Multilingual sites with AI Translation plugin for WordPress is vulner
CVE-2026-18328 - The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is vuln
CVE-2026-18323 - The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is vuln
CVE-2026-18100 - The MetForm – Contact Form, Survey, Quiz, & Custom Form Builder for Elementor plugin for WordPress i
CVE-2026-16601 - The CM Map Locations – Visualize and share your locations in a few clicks plugin for WordPress is vu
CVE-2026-78478 - The Mane theme for WordPress is vulnerable to Local File Inclusion in all versions up to, and includ
CVE-2026-78470 - The WP Project Manager Pro plugin for WordPress is vulnerable to SQL Injection in all versions up to
CVE-2026-12561 - The tagDiv Composer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the vc_raw
CVE-2026-76063 - The FundEngine – Donation and Crowdfunding Platform plugin for WordPress is vulnerable to Stored Cro
CVE-2026-75930 - The FundEngine – Donation and Crowdfunding Platform plugin for WordPress is vulnerable to authorizat
CVE-2026-19943 - The Gutenverse – WordPress Blocks, Page Builder & Site Editor plugin for WordPress is vulnerable to
CVE-2026-19892 - The InfusedWoo Pro plugin for WordPress is vulnerable to Privilege Escalation via Account Takeover i
CVE-2026-17089 - The Events Manager – Calendar, Bookings, Tickets, and more! plugin for WordPress is vulnerable to Re
CVE-2026-14280 - The Events Manager – Calendar, Bookings, Tickets, and more! plugin for WordPress is vulnerable to Lo
CVE-2026-75982 - The LearnPress plugin for WordPress is vulnerable to unauthorized modification of arbitrary WordPres
CVE-2026-75019 - The Cozy Blocks – Page Builder for Gutenberg Editor & FSE with 700+ Patterns, 58 Blocks & Templates
CVE-2026-10627 - The Events Manager – Calendar, Bookings, Tickets, and more! plugin for WordPress is vulnerable to au
CVE-2025-9878 - The PPWP – Password Protect WordPress | #1 Most-Reviewed Password Plugin plugin for WordPress is vul
CVE-2026-19801 - The BetterLinks – Link Shortener, Link Cloaking, Redirects, Affiliate Link Manager & MCP plugin for
CVE-2026-15023 - The Events Manager – Calendar, Bookings, Tickets, and more! plugin for WordPress is vulnerable to ge
CVE-2026-10630 - The WP Courses LMS – Online Courses Builder, eLearning Courses, Courses Solution, Education Courses
CVE-2026-32563 - Subscriber PHP Object Injection in ACPT (Pro) - Custom Post Types Plugin for WordPress <= 2.0.63 ver
CVE-2026-32560 - Subscriber Local File Inclusion in MagicAI for WordPress - AI Text, Image, Chat, Code, and Voice Gen
CVE-2026-32558 - Unauthenticated Privilege Escalation in Affiliate Pro - Affiliate Program for WooCommerce & WordPres
CVE-2026-28153 - Unauthenticated Broken Access Control in Notification Master – Real-Time WordPress Notificatio
CVE-2026-16249 - Rejected reason: This CVE ID is a duplicate of CVE-2026-15303 and was never published. Both IDs were
CVE-2026-77003 - The Content Mask WordPress plugin before 1.8.5.5 does not check the capability required to publish t
CVE-2026-14853 - The WooCommerce Bookings WordPress plugin before 3.9.0 does not perform a capability check on one of
CVE-2026-13598 - The RestrictMate WordPress plugin before 1.3.0 does not restrict the user role supplied during acco
CVE-2026-18027 - The WebToffee WooCommerce PDF Invoices, Packing Slips, Delivery Notes & Shipping Labels plugin for W
CVE-2026-16149 - The Security Hardener plugin for WordPress is vulnerable to Missing Authorization in all versions up
CVE-2026-0551 - The PPWP – Password Protect Pages plugin for WordPress is vulnerable to PHP Object Injection in all
CVE-2026-4703 - The WS Form LITE – Drag & Drop Contact Form Builder plugin for WordPress is vulnerable to PHP Object
CVE-2026-5093 - The GreenShift – Animation and Page Builder Blocks plugin for WordPress is vulnerable to unauthorize
CVE-2026-4561 - The MC4WP: Mailchimp for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting
CVE-2026-4559 - The Image Photo Gallery Final Tiles Grid plugin for WordPress is vulnerable to Stored Cross-Site Scr
CVE-2026-2996 - The Advanced Product Fields (Product Addons) for WooCommerce plugin for WordPress is vulnerable to I
CVE-2026-4244 - The Post Duplicator plugin for WordPress is vulnerable to unauthorized modification of data due to a
CVE-2026-4245 - The Post Duplicator plugin for WordPress is vulnerable to authorization bypass in all versions up to
CVE-2026-3424 - The The kk Star Ratings – Rate Post & Collect User Feedbacks plugin for WordPress is vulnerable to a
CVE-2026-78003 - The Mailgun for WordPress plugin for WordPress is vulnerable to Server-Side Request Forgery (SSRF) v
CVE-2026-77002 - The SmilePass Selfie Login WordPress plugin through 1.0.2 does not perform any server-side verificat
CVE-2026-77001 - The Social Login & Sharing buttons with Analytics By SoClever WordPress plugin through 1.2.0 does no
CVE-2026-77000 - The WP Social Media Login WordPress plugin through 1.0.6 does not verify that a social login was act
CVE-2026-76793 - The Firebase Authentication WordPress plugin before 1.7.1 does not require the email address in an a
CVE-2026-76789 - The Slider Hero with Video Background, Animation WordPress plugin before 9.1.3 does not have authori
CVE-2026-19222 - The Forminator Forms WordPress plugin before 1.57.0.7 does not consistently enforce the role restri
CVE-2026-19221 - The Forminator Forms WordPress plugin before 1.57.0.5 does not restrict a network-wide setting to n
CVE-2026-19093 - The Tutor LMS WordPress plugin before 4.0.6 does not validate a stored file path before using it to
CVE-2026-18052 - The ManageWP Worker WordPress plugin before 4.9.37 does not bind the account being logged in to the
CVE-2026-16738 - The Conekta Payment Gateway WordPress plugin before 6.2.2 does not verify the authenticity of incomi
CVE-2026-16612 - The FiboSearch WordPress plugin before 1.34.1 does not consistently exclude password-protected prod
CVE-2026-16260 - The Post Grid, Slider & Carousel Ultimate WordPress plugin before 1.8.1 does not sanitise and escap
CVE-2026-14187 - The Tutor LMS WordPress plugin before 4.0.6 does not enforce per-object ownership checks on its cou
CVE-2026-76074 - The AutomatorWP – Automator plugin for no-code automations, webhooks & custom integrations in WordPr
CVE-2026-76057 - The AutomatorWP – Automator plugin for no-code automations, webhooks & custom integrations in WordPr
CVE-2026-75027 - The Themify Builder plugin for WordPress is vulnerable to authorization bypass in all versions up to
CVE-2026-19883 - The WPeMatico RSS Feed Fetcher plugin for WordPress is vulnerable to unauthorized modification of da
CVE-2026-19848 - The ProfilePress WordPress plugin before 4.17.1 does not strip shortcodes from two of its profile fi
CVE-2026-18356 - The Limit Login Attempts Reloaded WordPress plugin before 3.3.5 does not compare logins against its
CVE-2026-17559 - The Passster WordPress plugin before 4.3.9 does not correctly match its own public endpoint paths wh
CVE-2026-16650 - The Charitable WordPress plugin before 1.8.12 does not verify the authenticity of incoming Square pa
CVE-2026-15150 - The myCred WordPress plugin before 3.2.5 does not verify that the receiver of an incoming payment ga
CVE-2026-15046 - The LitExtension WordPress plugin through 1.2.5 does not verify a nonce before an administrative act
CVE-2026-13176 - The Eventin WordPress plugin before 4.1.21 does not validate a user-supplied webhook URL stored on e
CVE-2026-77264 - The Automation Web Platform – Notifications and OTP for WooCommerce, Advanced Country Code plugin fo
CVE-2026-75796 - The AI Engine WordPress plugin before 3.6.1 does not verify that the requesting user is authorized
CVE-2026-19435 - The Duplicate Post WordPress plugin before 1.5.6 does not check the user's capabilities before retur
CVE-2026-19085 - The Duplicate Post WordPress plugin before 1.5.6 does not check that a user may read the content of
CVE-2026-18781 - The Drag and Drop Multiple File Upload for Contact Form 7 WordPress plugin before 1.3.9.9 does not v
CVE-2026-16962 - The Tamara Checkout WordPress plugin through 1.9.9.20 does not verify the order key, a nonce, or any
CVE-2026-16959 - The Media Library Assistant WordPress plugin before 3.40 does not validate a search parameter before
CVE-2026-16577 - The Dokan: AI Powered WooCommerce Multivendor Marketplace Solution WordPress plugin before 5.0.14 d
CVE-2026-16576 - The Dokan: AI Powered WooCommerce Multivendor Marketplace Solution WordPress plugin before 5.0.14 d
CVE-2026-16575 - The Dokan: AI Powered WooCommerce Multivendor Marketplace Solution WordPress plugin before 5.0.14 d
CVE-2026-14601 - The Link Whisper Free WordPress plugin before 0.9.7 does not properly sanitize and escape a paramete
CVE-2026-14325 - The Drag and Drop Multiple File Upload for Contact Form 7 WordPress plugin before 1.3.9.9 does not e
CVE-2026-13736 - The NewPath WildApricotPress Add-on WordPress plugin through 1.0.0 does not enforce its members-onl
CVE-2025-15671 - The Welcart e-Commerce WordPress plugin before 2.12.1 does not regenerate the session identifier on
CVE-2026-18409 - The WPForms Pro plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Single Line Te
CVE-2026-66594 - Subscriber SQL Injection in WordPress Persistent Login <= 3.1.0 versions.
CVE-2026-66592 - Unauthenticated SQL Injection in rtMedia for WordPress, BuddyPress and bbPress <= 4.7.11 versions.
CVE-2026-75963 - The Events Made Easy plugin for WordPress is vulnerable to Local File Inclusion in all versions up t
CVE-2026-75860 - The JSON Options WordPress plugin through 0.0.4 does not have any capability check or nonce verifica
CVE-2026-74992 - The Kirki WordPress plugin before 6.2.3 does not properly validate the files contained in archives
CVE-2026-19699 - The GutenKit WordPress plugin before 2.5.0 does not have a sufficient capability check on some of i
CVE-2026-19697 - The GutenKit WordPress plugin before 2.5.0 does not sanitise uploaded SVG files on all of the uploa
CVE-2026-19615 - The Admin and Site Enhancements (ASE) WordPress plugin before 9.0.1 does not sanitise uploaded SVG f
CVE-2026-17153 - The AI Agent by SiteGround plugin for WordPress is vulnerable to authorization bypass in all version
CVE-2026-15049 - The Depicter — Popup & Slider Builder WordPress plugin before 4.8.0 does not validate the type of a
CVE-2026-13405 - The Royal Addons for Elementor WordPress plugin before 1.7.1066 does not correctly sanitise custom
CVE-2026-18315 - The TrueBooker – Appointment Booking and Scheduler System plugin for WordPress is vulnerable to Auth
CVE-2026-64851 - Grav Shortcode Core Plugin allows for the development shortcode plugins that utilize the common form
CVE-2026-75981 - The TranslatePress – Translate Multilingual sites with AI Translation plugin for WordPress is vulner
CVE-2026-15446 - The EWWW Image Optimizer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'data
CVE-2026-19842 - The SAML Single Sign On WordPress plugin before 5.4.7 does not verify the signature of a SAML respo
CVE-2026-19782 - The WPS Bidouille WordPress plugin before 1.33.5 does not have proper authorisation checks in an AJA
CVE-2026-19709 - The Membership For WooCommerce WordPress plugin before 3.1.2 does not check that an API consumer sec
CVE-2026-19417 - The KiviCare WordPress plugin before 4.5.4 does not verify that the requesting user is entitled to
CVE-2026-19416 - The KiviCare WordPress plugin before 4.5.4 does not verify that the requesting user owns the appoin
CVE-2026-19406 - The Easy Appointments WordPress plugin before 4.0.1 does not restrict one of its appointment-listing
CVE-2026-19056 - The ProSolution WP Client WordPress plugin before 2.0.11 does not sanitise and escape a parameter be
CVE-2026-19055 - The ProSolution WP Client WordPress plugin before 2.0.11 does not sanitise and escape several parame
CVE-2026-18937 - The Broken Link Checker WordPress plugin before 2.4.12 does not limit which query variables it accep
CVE-2026-18779 - The TrueBooker WordPress plugin before 1.2.7 does not have proper authorisation checks in one of it
CVE-2026-18778 - The TrueBooker WordPress plugin before 1.2.7 does not have proper authorisation checks in some of i
CVE-2026-18777 - The TrueBooker WordPress plugin before 1.2.7 does not have proper authorisation checks in one of it
CVE-2026-18776 - The TrueBooker WordPress plugin before 1.2.7 does not have proper authorisation checks in some of i
CVE-2026-18466 - The WP Maps WordPress plugin before 4.9.8 does not perform a capability check, nor validate a nonce
CVE-2026-18231 - The WP Directory Kit WordPress plugin before 1.5.7 does not perform any authorization check on one o
CVE-2026-18202 - The JetEngine WordPress plugin before 3.8.14 adds SVG to the site-wide list of allowed upload types
CVE-2026-18031 - The TabaPay Gateway WordPress plugin through 1.4.0 does not validate the payment callback before est
CVE-2026-17565 - The Animation Addons for Elementor WordPress plugin before 2.7.2 does not validate a user-supplied
CVE-2026-16979 - The SmartCrawl SEO checker, analyzer & optimizer WordPress plugin before 3.16.3 does not perform cap
CVE-2026-16950 - The Product Shortlist WordPress plugin through 1.0.4 does not properly sanitise and escape a paramet
CVE-2026-16617 - The Simple File List WordPress plugin through 6.3.11 does not properly sanitise and escape a file's
CVE-2026-16616 - The Simple File List WordPress plugin through 6.3.11 does not validate the source path of a file-mov
CVE-2026-16570 - The NextScripts: Social Networks Auto-Poster WordPress plugin before 4.4.8 does not escape some of t
CVE-2026-16058 - The YayCurrency WordPress plugin before 3.3.5 does not perform any capability or ownership check on
CVE-2026-15253 - The Easy Media Replace WordPress plugin through 0.2.0 does not sanitise and escape an attachment tit
CVE-2026-14861 - The User Verification by PickPlugins WordPress plugin through 2.0.47 does not verify that a request
CVE-2026-14826 - The Quiz and Survey Master (QSM) WordPress plugin before 11.2.4 does not perform a per-object owner
CVE-2026-14825 - The Quiz and Survey Master (QSM) WordPress plugin before 11.2.4 does not perform a per-object owner
CVE-2026-14334 - The Booking calendar, Appointment Booking System WordPress plugin through 3.2.36 does not properly s
CVE-2026-14287 - The 10Web Booster WordPress plugin before 2.33.5 does not correctly validate an access token on an
CVE-2026-14196 - The WCFM Marketplace WordPress plugin before 3.8.1 does not verify that a marketplace vendor owns a
CVE-2026-13175 - The Eventin WordPress plugin before 4.1.21 does not verify ownership before allowing schedule recor
CVE-2026-13174 - The Eventin WordPress plugin before 4.1.21 does not verify ownership or capability before deleting
CVE-2026-13173 - The Eventin WordPress plugin before 4.1.21 does not verify the current user's permission to edit ot
CVE-2026-13169 - The Eventin WordPress plugin before 4.1.21 does not properly verify ownership of events before allo
CVE-2026-12983 - The Dinatur WordPress plugin through 1.18 does not sanitize and escape user input before using it in
CVE-2026-11565 - The Advanced File Manager WordPress plugin before 5.4.13 does not perform capability checks in seve
CVE-2026-19942 - The Atarim – AI Agency for WordPress: Edit Pages, Fix Code, Update Plugins, SEO & Client Feedback pl
CVE-2026-15421 - The Speed Optimizer – The All-In-One Performance-Boosting Plugin plugin for WordPress is vulnerable
CVE-2025-11729 - The PPWP: Password Protect Pages, Posts & Full or Partial Content plugin for WordPress is vulnerable
CVE-2026-66602 - Cross-Site Request Forgery (CSRF) vulnerability in DevItems HashBar – WordPress Notification Bar all
CVE-2026-73351 - Unauthenticated Cross Site Scripting (XSS) in WordPress Social Login and Register <= 7.8.1 versions.
CVE-2026-75091 - The Quill Forms | Conversational Multi Step Forms, Surveys & quizzes plugin for WordPress is vulnera
CVE-2026-15748 - The Forminator Forms plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up
CVE-2026-11801 - The WPAdverts – Classifieds Plugin plugin for WordPress is vulnerable to authorization bypass in all
CVE-2026-65640 - WordPress is vulnerable to a remote code execution vulnerability via malicious Postscript file uploa
CVE-2026-14832 - The ShopSmart Loyalty for WooCommerce WordPress plugin through 1.0.0 does not perform any authorizat
CVE-2026-13700 - The WooMS WordPress plugin through 9.14 does not validate a user-supplied URL before using it in a s
CVE-2024-13784 - The Contact Form, Survey, Quiz & Popup Form Builder – ARForms plugin for WordPress is vulnerable to
CVE-2026-2497 - The Gallery by BestWebSoft plugin for WordPress is vulnerable to SQL Injection via the '_gallery_ord
CVE-2026-2357 - The Bold Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plug
CVE-2026-18347 - The Kirki – Freeform Page Builder, Website Builder & Customizer plugin for WordPress is vulnerable t
CVE-2026-17608 - The WP Compress – Instant Performance & Speed Optimization plugin for WordPress is vulnerable to Cro
CVE-2026-17604 - The Kirki – Freeform Page Builder, Website Builder & Customizer plugin for WordPress is vulnerable t
CVE-2026-17087 - The WP Travel Engine – Tour Booking Plugin – Tour Operator Software plugin for WordPress is vulnerab
CVE-2026-13424 - The Online Scheduling and Appointment Booking System – Bookly plugin for WordPress is vulnerable to
CVE-2026-12998 - The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is vuln
CVE-2026-10734 - The Infility Global plugin for WordPress is vulnerable to Stored Cross-Site Scripting via /cf7_recor
CVE-2026-9767 - The The School Management – Education & Learning ERP plugin for WordPress is vulnerable to generic S
CVE-2026-2283 - The User Login History plugin for WordPress is vulnerable to SQL Injection via the 'blog_id' paramet
CVE-2026-19726 - The Visualizer WordPress plugin before 4.0.7 does not properly authorise access to the configuratio
CVE-2026-19725 - The WPvivid — Backup, Migration & Staging WordPress plugin before 0.9.131 does not sanitise a value
CVE-2026-19717 - The CatFolders Document Gallery & PDF Library WordPress plugin before 2.0.7 does not have authorisat
CVE-2026-19712 - The Masteriyo LMS WordPress plugin before 2.3.3 does not sanitise and escape a quiz field before ou
CVE-2026-19711 - The Premium Packages WordPress plugin before 7.0.7 does not validate a withdrawal request against t
CVE-2026-19613 - The ECS WordPress plugin before 4.3.10 does not perform ownership or post-status checks when one of
CVE-2026-18653 - The WP Directory Kit WordPress plugin before 1.5.7 does not sanitise and escape a parameter before u
CVE-2026-18402 - The SureDash – Community, Courses & Member Dashboard plugin for WordPress is vulnerable to Stored Cr
CVE-2026-18316 - The Solace Extra plugin for WordPress is vulnerable to unauthorized modification and loss of data du
CVE-2026-17582 - The Slider Hero plugin for WordPress is vulnerable to second-order SQL Injection in versions up to,
CVE-2026-17581 - The WCPOS – Point of Sale (POS) plugin for WooCommerce plugin for WordPress is vulnerable to Code In
CVE-2026-17533 - The All-in-One WP Migration and Backup WordPress plugin before 7.108 does not restrict its migration
CVE-2026-16775 - The Smash Balloon Social Post Feed – Simple Social Feeds for WordPress plugin for WordPress is vulne
CVE-2026-16758 - The Snippet Shortcodes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Shortco
CVE-2026-15790 - The Youtube Showcase plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions u
CVE-2026-15604 - The Toocheke Companion plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions
CVE-2026-15384 - The Manual Image Crop WordPress plugin before 1.15 does not perform any capability check or nonce ve
CVE-2026-15351 - The WC Vendors – WooCommerce Multivendor, WooCommerce Marketplace, Product Vendors plugin for WordPr
CVE-2026-15345 - The ShortPixel Adaptive Images – WebP, AVIF, CDN, Image Optimization plugin for WordPress is vulnera
CVE-2026-15056 - The StoreEngine — Complete eCommerce Solution with Memberships, Licensing, Affiliates & More plugin
CVE-2026-13712 - The Divi WordPress theme before 5.9.0 does not properly escape some of its Social Media Follow modul
CVE-2026-10035 - The Turnkey bbPress by WeaverTheme plugin for WordPress is vulnerable to PHP Object Injection in all
CVE-2026-18432 - The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to Privilege Escalation in all v
CVE-2026-18385 - The The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restri
CVE-2026-17123 - The Royal Elementor Addons plugin for WordPress is vulnerable to Server-Side Request Forgery in vers
CVE-2026-16779 - The Kubio AI Page Builder plugin for WordPress is vulnerable to authorization bypass in all versions
CVE-2026-16099 - The Podlove Podcast Publisher plugin for WordPress is vulnerable to arbitrary file deletion due to i
CVE-2026-16098 - The ProSolution WP Client plugin for WordPress is vulnerable to Arbitrary File Upload in all version
CVE-2026-16079 - The Fullscreen Galleria plugin for WordPress is vulnerable to generic SQL Injection via 'href' Attri
CVE-2026-15963 - The Quiz and Survey Master (QSM) – Easy Quiz and Survey Maker plugin for WordPress is vulnerable to
CVE-2026-15726 - The Serious Slider plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'theme' Sho
CVE-2026-15602 - The NEX-Forms – Ultimate Forms Plugin for WordPress plugin for WordPress is vulnerable to generic SQ
CVE-2026-15441 - The WC Product Table Lite plugin for WordPress is vulnerable to CSS Injection in versions up to, and
CVE-2026-15066 - The Loco Translate plugin for WordPress is vulnerable to Stored Cross-Site Scripting via PO File Ext
CVE-2026-15009 - The Advanced File Manager – Ultimate File Manager for WordPress And Document Library Solution plugin
CVE-2026-15002 - The Platnosci Online Blue Media (Autopay) plugin for WordPress is vulnerable to Stored Cross-Site Sc
CVE-2026-14524 - The ProSolution WP Client plugin for WordPress is vulnerable to arbitrary file deletion due to insuf
CVE-2026-14498 - The Query Wrangler plugin for WordPress is vulnerable to Remote Code Execution in all versions up to
CVE-2026-13358 - The Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin plugin for WordPress
CVE-2026-13167 - The Everest Forms – Contact Form, Payment Form, Quiz, Survey & Custom Form Builder with AI plugin fo
CVE-2026-12905 - The Bookly plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions up to,
CVE-2026-12477 - The Gravity Booster – Styles & Layouts for Gravity Forms plugin for WordPress is vulnerable to Store
CVE-2026-11780 - The Quiz and Survey Master (QSM) – Easy Quiz and Survey Maker plugin for WordPress is vulnerable to
CVE-2025-10005 - The PPWP – Password Protect WordPress | #1 Most-Reviewed Password Plugin plugin for WordPress is vul
CVE-2026-2487 - The Admin Custom Login plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin s
CVE-2026-18855 - The Link Library plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient f
CVE-2026-19598 - The Pods – Custom Content Types and Fields plugin for WordPress is vulnerable to Privilege Escalatio
CVE-2026-12248 - The WPML Multilingual CMS plugin for WordPress is vulnerable to SQL Injection via the 'sorting' para
CVE-2026-18438 - The Templately – Elementor & Gutenberg Template Library: 6500+ Free & Pro Ready Templates And Cloud!
CVE-2026-16142 - The TrueBooker plugin for WordPress is vulnerable to Account Takeover in all versions up to, and inc
CVE-2026-15142 - The Real Estate Manager Pro plugin for WordPress is vulnerable to Privilege Escalation in all versio
CVE-2026-15826 - The User Profile Builder plugin for WordPress is vulnerable to Authentication Bypass via Type Confus
CVE-2026-14279 - The Wholesale Market plugin for WordPress is vulnerable to privilege escalation in versions up to, a
CVE-2026-18807 - The ECS WordPress plugin before 4.3.8 does not have capability or ownership checks on its dynamic r
CVE-2026-18216 - The Backup Migration WordPress plugin before 2.1.7 does not properly restrict a post-restore automat
CVE-2026-16611 - The Product Feed PRO for WooCommerce by AdTribes WordPress plugin before 13.5.7 does not perform an
CVE-2026-16541 - The Simply Schedule Appointments WordPress plugin before 1.6.12.17 does not restrict the user record
CVE-2026-14230 - The ECS WordPress plugin before 4.3.8 does not perform capability or object-ownership checks on its
CVE-2026-14229 - The ECS WordPress plugin before 4.3.8 does not check the post status or any capability when renderi
CVE-2026-18387 - The Groundhogg — CRM, Newsletters, and Marketing Automation plugin for WordPress is vulnerable to ge
CVE-2026-17090 - The Beaver Builder Page Builder – Drag and Drop Website Builder plugin for WordPress is vulnerable t
CVE-2026-16586 - The Contest Gallery – Upload & Vote Photos, Media, Sell with PayPal & Stripe plugin for WordPress is
CVE-2026-16146 - The Invisible Anti-Spam & CAPTCHA — reCAPTCHA Alternative for All Forms plugin for WordPress is vuln
CVE-2026-16145 - The Invisible Anti-Spam & CAPTCHA — reCAPTCHA Alternative for All Forms plugin for WordPress is vuln
CVE-2026-16094 - The Invisible Anti-Spam & CAPTCHA — reCAPTCHA Alternative for All Forms plugin for WordPress is vuln
CVE-2026-15993 - The Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder plugin for WordPress is v
CVE-2026-15948 - The Hydra Booking — Appointment Scheduling & Booking Calendar plugin for WordPress is vulnerable to
CVE-2026-15453 - The KiviCare – Clinic & Patient Management System (EHR) plugin for WordPress is vulnerable to generi
CVE-2026-8840 - The Booking calendar, Appointment Booking System plugin for WordPress is vulnerable to authorization
CVE-2026-16080 - The Image Uploader for Welcart plugin for WordPress is vulnerable to generic SQL Injection via the '
CVE-2026-15965 - The MaxUpload – Big File Uploads – Increase Maximum File Upload Size plugin for WordPress is vulnera
CVE-2026-15341 - The User Session Synchronizer plugin for WordPress is vulnerable to Authentication Bypass leading to
CVE-2026-15312 - The Propovoice: All-in-One Client Management System plugin for WordPress is vulnerable to Privilege
CVE-2026-15303 - The 6Storage Rentals plugin for WordPress is vulnerable to authentication bypass in versions up to,
CVE-2026-15162 - The Object Sync for Salesforce plugin is vulnerable to unauthenticated SQL Injection via the wordpre
CVE-2026-15001 - The bLoyal: Loyalty & Promotions by bLoyal plugin for WordPress is vulnerable to Privilege Escalatio
CVE-2026-14484 - The RapiSafe – Secure Multi File Upload for Contact Form 7 plugin for WordPress is vulnerable to arb
CVE-2026-14433 - The Online Booking & Scheduling Calendar for WordPress by vcita plugin for WordPress is vulnerable t
CVE-2026-12128 - The Pinpoint Booking System – Version 2 plugin for WordPress is vulnerable to Price Manipulation via
🏢 CVE nach Hersteller
Empfohlene IT-Security & Netzwerk-Hardware
Von NetzBastion getestete & empfohlene Sicherheits- und Netzwerk-Hardware