CVE Datenbank

Durchsuchbare Datenbank mit Sicherheitslücken. Filtere nach Hersteller, Schweregrad oder Zeitraum.

Zurücksetzen
175 CVEs gefunden (Seite 1/1)

CVE-2026-14229 - The ECS WordPress plugin before 4.3.8 does not check the post status or any capability when renderi

🏢 Wordpress 📅 15.8.2026 📊 CVSS: 0.0
0.0

CVE-2026-18387 - The Groundhogg — CRM, Newsletters, and Marketing Automation plugin for WordPress is vulnerable to ge

🏢 Wordpress 📅 15.8.2026 📊 CVSS: 6.5
6.5

CVE-2026-17090 - The Beaver Builder Page Builder – Drag and Drop Website Builder plugin for WordPress is vulnerable t

🏢 Wordpress 📅 15.8.2026 📊 CVSS: 6.4
6.4

CVE-2026-16586 - The Contest Gallery – Upload & Vote Photos, Media, Sell with PayPal & Stripe plugin for WordPress is

🏢 Wordpress 📅 15.8.2026 📊 CVSS: 6.5
6.5

CVE-2026-16146 - The Invisible Anti-Spam & CAPTCHA — reCAPTCHA Alternative for All Forms plugin for WordPress is vuln

🏢 Wordpress 📅 15.8.2026 📊 CVSS: 4.9
4.9

CVE-2026-16145 - The Invisible Anti-Spam & CAPTCHA — reCAPTCHA Alternative for All Forms plugin for WordPress is vuln

🏢 Wordpress 📅 15.8.2026 📊 CVSS: 7.2
7.2

CVE-2026-16094 - The Invisible Anti-Spam & CAPTCHA — reCAPTCHA Alternative for All Forms plugin for WordPress is vuln

🏢 Wordpress 📅 15.8.2026 📊 CVSS: 4.9
4.9

CVE-2026-15993 - The Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder plugin for WordPress is v

🏢 Wordpress 📅 15.8.2026 📊 CVSS: 5.3
5.3

CVE-2026-15948 - The Hydra Booking — Appointment Scheduling & Booking Calendar plugin for WordPress is vulnerable to

🏢 Wordpress 📅 15.8.2026 📊 CVSS: 6.4
6.4

CVE-2026-15453 - The KiviCare – Clinic & Patient Management System (EHR) plugin for WordPress is vulnerable to generi

🏢 Wordpress 📅 15.8.2026 📊 CVSS: 6.5
6.5

CVE-2026-8840 - The Booking calendar, Appointment Booking System plugin for WordPress is vulnerable to authorization

🏢 Wordpress 📅 15.8.2026 📊 CVSS: 5.3
5.3

CVE-2026-16080 - The Image Uploader for Welcart plugin for WordPress is vulnerable to generic SQL Injection via the '

🏢 Wordpress 📅 15.8.2026 📊 CVSS: 6.5
6.5

CVE-2026-15965 - The MaxUpload – Big File Uploads – Increase Maximum File Upload Size plugin for WordPress is vulnera

🏢 Wordpress 📅 15.8.2026 📊 CVSS: 8.8
8.8

CVE-2026-15341 - The User Session Synchronizer plugin for WordPress is vulnerable to Authentication Bypass leading to

🏢 Wordpress 📅 15.8.2026 📊 CVSS: 9.8
9.8

CVE-2026-15312 - The Propovoice: All-in-One Client Management System plugin for WordPress is vulnerable to Privilege

🏢 Wordpress 📅 15.8.2026 📊 CVSS: 8.8
8.8

CVE-2026-15303 - The 6Storage Rentals plugin for WordPress is vulnerable to authentication bypass in versions up to,

🏢 Wordpress 📅 15.8.2026 📊 CVSS: 9.8
9.8

CVE-2026-15162 - The Object Sync for Salesforce plugin is vulnerable to unauthenticated SQL Injection via the wordpre

🏢 Wordpress 📅 15.8.2026 📊 CVSS: 7.5
7.5

CVE-2026-15001 - The bLoyal: Loyalty & Promotions by bLoyal plugin for WordPress is vulnerable to Privilege Escalatio

🏢 Wordpress 📅 15.8.2026 📊 CVSS: 8.8
8.8

CVE-2026-14484 - The RapiSafe – Secure Multi File Upload for Contact Form 7 plugin for WordPress is vulnerable to arb

🏢 Wordpress 📅 15.8.2026 📊 CVSS: 9.1
9.1

CVE-2026-14433 - The Online Booking & Scheduling Calendar for WordPress by vcita plugin for WordPress is vulnerable t

🏢 Wordpress 📅 15.8.2026 📊 CVSS: 7.2
7.2

CVE-2026-12128 - The Pinpoint Booking System – Version 2 plugin for WordPress is vulnerable to Price Manipulation via

🏢 Wordpress 📅 15.8.2026 📊 CVSS: 5.3
5.3

CVE-2026-42726 - Missing Authorization vulnerability in Strategy11 Team AWP Classifieds another-wordpress-classifieds

🏢 Wordpress 📅 27.5.2026 📊 CVSS: 6.5
6.5

CVE-2026-3349 - The MinhNhut Link Gateway plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via t

🏢 Wordpress 📅 27.5.2026 📊 CVSS: 6.1
6.1

CVE-2026-3348 - The MinhNhut Link Gateway plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the

🏢 Wordpress 📅 27.5.2026 📊 CVSS: 4.4
4.4

CVE-2026-2288 - The myLinksDump plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'link_titl

🏢 Wordpress 📅 27.5.2026 📊 CVSS: 4.8
4.8

CVE-2026-2280 - The rexCrawler plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings

🏢 Wordpress 📅 27.5.2026 📊 CVSS: 4.8
4.8

CVE-2025-0898 - The Xpro Elementor Addons - Pro plugin for WordPress is vulnerable to Arbitrary File Reading in all

🏢 Wordpress 📅 27.5.2026 📊 CVSS: 6.5
6.5

CVE-2026-8942 - The MetaMagic SEO Plugin plugin for WordPress is vulnerable to Cross-Site Request Forgery in all ver

🏢 Wordpress 📅 27.5.2026 📊 CVSS: 4.3
4.3

CVE-2026-8906 - The WP Promoter plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up

🏢 Wordpress 📅 27.5.2026 📊 CVSS: 6.1
6.1

CVE-2026-8832 - The WPCode - Insert Headers and Footers + Custom Code Snippets - WordPress Code Manager plugin for W

🏢 Wordpress 📅 27.5.2026 📊 CVSS: 8.8
8.8

CVE-2026-8143 - The HBook plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'hb_country_iso'

🏢 Wordpress 📅 27.5.2026 📊 CVSS: 7.2
7.2

CVE-2026-8042 - The Github Shortcode plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'repo

🏢 Wordpress 📅 27.5.2026 📊 CVSS: 6.4
6.4

CVE-2026-7618 - The EnvíaloSimple: Email Marketing y Newsletters plugin for WordPress is vulnerable to time-based bl

🏢 Wordpress 📅 27.5.2026 📊 CVSS: 4.9
4.9

CVE-2026-6169 - The affiliate-toolkit plugin for WordPress is vulnerable to remote code execution in all versions up

🏢 Wordpress 📅 27.5.2026 📊 CVSS: 7.2
7.2

CVE-2026-3897 - The Livemesh Addons for Beaver Builder plugin for WordPress is vulnerable to Stored Cross-Site Scrip

🏢 Wordpress 📅 27.5.2026 📊 CVSS: 6.4
6.4

CVE-2026-3896 - The Livemesh SiteOrigin Widgets plugin for WordPress is vulnerable to Stored Cross-Site Scripting vi

🏢 Wordpress 📅 27.5.2026 📊 CVSS: 6.4
6.4

CVE-2026-3895 - The WPBakery Page Builder Addons by Livemesh plugin for WordPress is vulnerable to Stored Cross-Site

🏢 Wordpress 📅 27.5.2026 📊 CVSS: 6.4
6.4

CVE-2026-3375 - The LiteSpeed Cache plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the /wp-js

🏢 Wordpress 📅 27.5.2026 📊 CVSS: 7.2
7.2

CVE-2026-3279 - The Enable jQuery Migrate Helper plugin for WordPress is vulnerable to unauthorized modification of

🏢 Wordpress 📅 27.5.2026 📊 CVSS: 6.5
6.5

CVE-2026-3001 - The Gutenverse plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 's' para

🏢 Wordpress 📅 27.5.2026 📊 CVSS: 6.1
6.1

CVE-2026-2030 - The WPBakery Page Builder Addons by Livemesh plugin for WordPress is vulnerable to Stored Cross-Site

🏢 Wordpress 📅 27.5.2026 📊 CVSS: 6.4
6.4

CVE-2026-9200 - The Query Shortcode plugin for WordPress is vulnerable to Local File Inclusion in all versions up to

🏢 Wordpress 📅 27.5.2026 📊 CVSS: 7.5
7.5

CVE-2026-9014 - The WP Promoter plugin for WordPress is vulnerable to unauthorized modification of data due to a mis

🏢 Wordpress 📅 27.5.2026 📊 CVSS: 5.3
5.3

CVE-2026-8994 - The Login with NEAR plugin for WordPress is vulnerable to Authentication Bypass in all versions up t

🏢 Wordpress 📅 27.5.2026 📊 CVSS: 8.1
8.1

CVE-2026-8943 - The GoStats for WordPress plugin for WordPress is vulnerable to Cross-Site Request Forgery in all ve

🏢 Wordpress 📅 27.5.2026 📊 CVSS: 4.3
4.3

CVE-2026-8941 - The CDN Linker lite plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up

🏢 Wordpress 📅 27.5.2026 📊 CVSS: 4.3
4.3

CVE-2026-8939 - The Search Simple Fields plugin for WordPress is vulnerable to Cross-Site Request Forgery in version

🏢 Wordpress 📅 27.5.2026 📊 CVSS: 4.3
4.3

CVE-2026-8938 - The auto making JSON-LD plugin for WordPress is vulnerable to Cross-Site Request Forgery in all vers

🏢 Wordpress 📅 27.5.2026 📊 CVSS: 4.3
4.3

CVE-2026-8911 - The WP AutoBuzz plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up

🏢 Wordpress 📅 27.5.2026 📊 CVSS: 6.1
6.1

CVE-2026-8903 - The Two-factor authentication (formerly IP Vault) plugin for WordPress is vulnerable to Cross-Site R

🏢 Wordpress 📅 27.5.2026 📊 CVSS: 4.3
4.3

CVE-2026-8899 - The Auto Thumbnail plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'thumbn

🏢 Wordpress 📅 27.5.2026 📊 CVSS: 6.4
6.4

CVE-2026-8898 - The Events In City plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'org-ev

🏢 Wordpress 📅 27.5.2026 📊 CVSS: 6.4
6.4

CVE-2026-8897 - The Shortcode Buddy plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Shortcode

🏢 Wordpress 📅 27.5.2026 📊 CVSS: 6.4
6.4

CVE-2026-8894 - The iWR Tooltip plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's `

🏢 Wordpress 📅 27.5.2026 📊 CVSS: 6.4
6.4

CVE-2026-8891 - The BitForm plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'bitf

🏢 Wordpress 📅 27.5.2026 📊 CVSS: 6.4
6.4

CVE-2026-8887 - The Listen Shortcode plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'list

🏢 Wordpress 📅 27.5.2026 📊 CVSS: 6.4
6.4

CVE-2026-8886 - The hk_shortcode plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'title-pl

🏢 Wordpress 📅 27.5.2026 📊 CVSS: 6.4
6.4

CVE-2026-8884 - The Instant-Quote.co Quotation Page plugin for WordPress is vulnerable to Stored Cross-Site Scriptin

🏢 Wordpress 📅 27.5.2026 📊 CVSS: 6.4
6.4

CVE-2026-8877 - The Responsive Video Embedder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via

🏢 Wordpress 📅 27.5.2026 📊 CVSS: 6.4
6.4

CVE-2026-8875 - The Easy Prism Syntax Highlighter plugin for WordPress is vulnerable to Stored Cross-Site Scripting

🏢 Wordpress 📅 27.5.2026 📊 CVSS: 6.4
6.4

CVE-2026-8873 - The Content Slideshow plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Shortcod

🏢 Wordpress 📅 27.5.2026 📊 CVSS: 6.4
6.4

CVE-2026-8872 - The Animate Your Content plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the p

🏢 Wordpress 📅 27.5.2026 📊 CVSS: 6.4
6.4

CVE-2026-8871 - The Formidable Kinetic plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'ki

🏢 Wordpress 📅 27.5.2026 📊 CVSS: 6.4
6.4

CVE-2026-8870 - The Team Master – A Modern WordPress Team Showcase plugin for WordPress is vulnerable to Stored Cros

🏢 Wordpress 📅 27.5.2026 📊 CVSS: 6.4
6.4

CVE-2026-8869 - The Mutual Funds Data plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'tit

🏢 Wordpress 📅 27.5.2026 📊 CVSS: 6.4
6.4

CVE-2026-8868 - The Single Mailchimp plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'sing

🏢 Wordpress 📅 27.5.2026 📊 CVSS: 6.4
6.4

CVE-2026-8867 - The Post Category Gallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the

🏢 Wordpress 📅 27.5.2026 📊 CVSS: 6.4
6.4

CVE-2026-8847 - The Dideo plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'dideo'

🏢 Wordpress 📅 27.5.2026 📊 CVSS: 6.4
6.4

CVE-2026-8846 - The Tuxquote plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'TUXQUOTE' sh

🏢 Wordpress 📅 27.5.2026 📊 CVSS: 6.4
6.4

CVE-2026-8845 - The Islamic Database plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'isla

🏢 Wordpress 📅 27.5.2026 📊 CVSS: 6.4
6.4

CVE-2026-8844 - The Responsive Check plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'rspc

🏢 Wordpress 📅 27.5.2026 📊 CVSS: 6.4
6.4

CVE-2026-8837 - The WP Iframe Geo Style for Amazon affiliates plugin for WordPress is vulnerable to Stored Cross-Sit

🏢 Wordpress 📅 27.5.2026 📊 CVSS: 6.4
6.4

CVE-2026-8787 - The Firebase Support & Chat Management plugin for WordPress is vulnerable to privilege escalation in

🏢 Wordpress 📅 27.5.2026 📊 CVSS: 8.8
8.8

CVE-2026-8760 - The Login with OTP plugin for WordPress is vulnerable to authentication bypass in all versions up to

🏢 Wordpress 📅 27.5.2026 📊 CVSS: 9.8
9.8

CVE-2026-8708 - The Genzel breadcrumbs plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versi

🏢 Wordpress 📅 27.5.2026 📊 CVSS: 4.3
4.3

CVE-2026-8707 - The NS Product icon badge plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via P

🏢 Wordpress 📅 27.5.2026 📊 CVSS: 6.1
6.1

CVE-2026-8703 - The Endless Scroll plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Shortcode A

🏢 Wordpress 📅 27.5.2026 📊 CVSS: 6.4
6.4

CVE-2026-8702 - The GBI To Print plugin for WordPress is vulnerable to Stored Cross-Site Scripting in version 1.0 vi

🏢 Wordpress 📅 27.5.2026 📊 CVSS: 6.4
6.4

CVE-2026-8701 - The GNTT Post Title Ticker plugin for WordPress is vulnerable to Stored Cross-Site Scripting in vers

🏢 Wordpress 📅 27.5.2026 📊 CVSS: 6.4
6.4

CVE-2026-8698 - The Cryptocurrency Prijsvergelijking Widget plugin for WordPress is vulnerable to Stored Cross-Site

🏢 Wordpress 📅 27.5.2026 📊 CVSS: 6.4
6.4

CVE-2026-8048 - The My Email Shortcode plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'su

🏢 Wordpress 📅 27.5.2026 📊 CVSS: 6.4
6.4

CVE-2026-8040 - The faq shortocde plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'color'

🏢 Wordpress 📅 27.5.2026 📊 CVSS: 6.4
6.4

CVE-2026-7614 - The Old Posts Highlighter plugin for WordPress is vulnerable to Cross-Site Request Forgery in all ve

🏢 Wordpress 📅 27.5.2026 📊 CVSS: 4.3
4.3

CVE-2026-6268 - The EventPress WordPress theme before 22.2 does not sanitize or escape the 'id' parameter in the eve

🏢 Wordpress 📅 27.5.2026 📊 CVSS: 7.1
7.1

CVE-2026-9236 - The CM Ad Changer – A simple tool to control and optimize your site's banners plugin for WordPress i

🏢 Wordpress 📅 27.5.2026 📊 CVSS: 4.3
4.3

CVE-2026-6287 - The ShopLentor - WooCommerce Builder for Elementor & Gutenberg plugin for WordPress is vulnerable to

🏢 Wordpress 📅 27.5.2026 📊 CVSS: 5.4
5.4

CVE-2025-14481 - The Yoast SEO plugin for WordPress is vulnerable to Insecure Direct Object References in all version

🏢 Wordpress 📅 27.5.2026 📊 CVSS: 4.3
4.3

CVE-2026-9022 - The Splide Carousel Block plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'url

🏢 Wordpress 📅 27.5.2026 📊 CVSS: 6.4
6.4

CVE-2026-7493 - The Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin plugin for WordPress

🏢 Wordpress 📅 27.5.2026 📊 CVSS: 5.3
5.3

CVE-2026-6565 - The Style Kits – Advanced Theme Styles for Elementor, Elementor Kits & Elementor Patterns plugin for

🏢 Wordpress 📅 27.5.2026 📊 CVSS: 6.4
6.4

CVE-2026-8174 - Zohocorp Zoho Mail wordpress plugin is vulnerable to Cross-Site request forgery (CSRF). This issue

🏢 Wordpress 📅 26.5.2026 📊 CVSS: 5.7
5.7

CVE-2018-25352 - WordPress Ultimate Form Builder Lite plugin version 1.3.7 and below contains an SQL injection vulner

🏢 Wordpress 📅 23.5.2026 📊 CVSS: 7.1
7.1

CVE-2018-25347 - WordPress Contact Form Maker Plugin 1.12.20 contains SQL injection vulnerabilities that allow authen

🏢 Wordpress 📅 23.5.2026 📊 CVSS: 7.1
7.1

CVE-2018-25346 - WordPress Form Maker Plugin 1.12.24 and below contains SQL injection vulnerabilities that allow auth

🏢 Wordpress 📅 23.5.2026 📊 CVSS: 7.1
7.1

CVE-2026-9284 - The WooCommerce PayPal Payments plugin for WordPress is vulnerable to unauthorized order manipulatio

🏢 Wordpress 📅 23.5.2026 📊 CVSS: 8.2
8.2

CVE-2026-6898 - The Wishlist Member plugin for WordPress is vulnerable to unauthorized modification of data due to a

🏢 Wordpress 📅 23.5.2026 📊 CVSS: 8.8
8.8

CVE-2026-6897 - The Wishlist Member plugin for WordPress is vulnerable to unauthorized modification of data due to a

🏢 Wordpress 📅 23.5.2026 📊 CVSS: 8.8
8.8

CVE-2026-6895 - The WishList Member plugin for WordPress is vulnerable to Missing Authorization leading to Sensitive

🏢 Wordpress 📅 23.5.2026 📊 CVSS: 8.8
8.8

CVE-2026-6419 - The WishList Member plugin for WordPress is vulnerable to Privilege Escalation via Missing Authoriza

🏢 Wordpress 📅 23.5.2026 📊 CVSS: 8.8
8.8

CVE-2026-9011 - The Ditty – Responsive News Tickers, Sliders, and Lists plugin for WordPress is vulnerable to author

🏢 Wordpress 📅 22.5.2026 📊 CVSS: 7.5
7.5

CVE-2026-8692 - The Vedrixa Forms – User Registration Form, Signup Form & Drag & Drop Form Builder plugin for WordPr

🏢 Wordpress 📅 22.5.2026 📊 CVSS: 4.3
4.3

CVE-2026-8684 - The MotoPress Hotel Booking plugin for WordPress is vulnerable to authorization bypass in all versio

🏢 Wordpress 📅 22.5.2026 📊 CVSS: 5.3
5.3

CVE-2026-8679 - The AudioIgniter plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions

🏢 Wordpress 📅 22.5.2026 📊 CVSS: 7.5
7.5

CVE-2026-7798 - The FluentCRM – Email Newsletter, Automation, Email Marketing, Email Campaigns, Optins, Leads, and C

🏢 Wordpress 📅 22.5.2026 📊 CVSS: 5.4
5.4

CVE-2026-7636 - The Slider by Soliloquy – Responsive Image Slider for WordPress plugin for WordPress is vulnerable t

🏢 Wordpress 📅 22.5.2026 📊 CVSS: 4.3
4.3

CVE-2026-7615 - The Widget Context plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions

🏢 Wordpress 📅 22.5.2026 📊 CVSS: 4.3
4.3

CVE-2026-9104 - The Draft List plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Draft Post Titl

🏢 Wordpress 📅 22.5.2026 📊 CVSS: 6.4
6.4

CVE-2026-9018 - The Easy Elements for Elementor – Addons & Website Templates plugin for WordPress is vulnerable to P

🏢 Wordpress 📅 22.5.2026 📊 CVSS: 8.8
8.8

CVE-2026-7509 - The KIA Subtitle plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's

🏢 Wordpress 📅 22.5.2026 📊 CVSS: 6.4
6.4

CVE-2026-7249 - The Location Weather plugin for WordPress is vulnerable to unauthorized modification of data due to

🏢 Wordpress 📅 22.5.2026 📊 CVSS: 4.3
4.3

CVE-2026-6864 - The CBX 5 Star Rating & Review plugin for WordPress is vulnerable to Reflected Cross-Site Scripting

🏢 Wordpress 📅 22.5.2026 📊 CVSS: 6.1
6.1

CVE-2026-4070 - The Alfie – Feed Plugin plugin for WordPress is vulnerable to Cross-Site Request Forgery in all vers

🏢 Wordpress 📅 22.5.2026 📊 CVSS: 4.3
4.3

CVE-2026-3481 - The WP Blockade plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'shortc

🏢 Wordpress 📅 22.5.2026 📊 CVSS: 6.1
6.1

CVE-2026-2518 - The FastX theme for WordPress is vulnerable to unauthorized limited plugin installation and activati

🏢 Wordpress 📅 22.5.2026 📊 CVSS: 4.3
4.3

CVE-2026-4834 - The WP ERP Pro plugin for WordPress is vulnerable to SQL Injection via the 'search_key' parameter in

🏢 Wordpress 📅 22.5.2026 📊 CVSS: 7.5
7.5

CVE-2026-6960 - The BookingPress Pro plugin for WordPress is vulnerable to arbitrary file uploads due to missing fil

🏢 Wordpress 📅 21.5.2026 📊 CVSS: 9.8
9.8

CVE-2026-5118 - The Divi Form Builder plugin for WordPress is vulnerable to privilege escalation in versions up to,

🏢 Wordpress 📅 21.5.2026 📊 CVSS: 9.8
9.8

CVE-2026-6279 - The Avada Builder (fusion-builder) plugin for WordPress is vulnerable to Unauthenticated Remote Code

🏢 Wordpress 📅 21.5.2026 📊 CVSS: 9.8
9.8

CVE-2026-1543 - The Avada (Fusion) Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via mul

🏢 Wordpress 📅 21.5.2026 📊 CVSS: 6.4
6.4

CVE-2026-4811 - The WPB Floating Menu & Categories for WordPress – Sticky Side Menu with Icons plugin for WordPress

🏢 Wordpress 📅 21.5.2026 📊 CVSS: 4.9
4.9

CVE-2026-1881 - The Broadstreet plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versio

🏢 Wordpress 📅 21.5.2026 📊 CVSS: 4.3
4.3

CVE-2026-7613 - The Cost of Goods by PixelYourSite plugin for WordPress is vulnerable to Stored Cross-Site Scripting

🏢 Wordpress 📅 20.5.2026 📊 CVSS: 7.2
7.2

CVE-2026-6728 - The Slider Revolution plugin for WordPress is vulnerable to Sensitive Information Exposure in versio

🏢 Wordpress 📅 20.5.2026 📊 CVSS: 5.3
5.3

CVE-2026-9065 - SureCart version prior to 4.2.1 are vulnerable to authenticated SQL injection via multiple parameter

🏢 Wordpress 📅 20.5.2026 📊 CVSS: 0.0
0.0

CVE-2026-6405 - The Anomify AI – Anomaly Detection and Alerting plugin for WordPress is vulnerable to Cross-Site Req

🏢 Wordpress 📅 20.5.2026 📊 CVSS: 4.3
4.3

CVE-2026-5200 - The AcyMailing – An Ultimate Newsletter Plugin and Marketing Automation Solution for WordPress plugi

🏢 Wordpress 📅 20.5.2026 📊 CVSS: 8.8
8.8

CVE-2026-7385 - The Decent Comments WordPress plugin before 3.0.2 does not restrict access to comment author email a

🏢 Wordpress 📅 20.5.2026 📊 CVSS: 5.8
5.8

CVE-2026-6566 - The Photo Gallery, Sliders, Proofing and Themes – NextGEN Gallery plugin for WordPress is vulnerable

🏢 Wordpress 📅 20.5.2026 📊 CVSS: 4.3
4.3

CVE-2026-5776 - The Email Encoder WordPress plugin before 2.4.7 does not escape email addresses retrieved via user

🏢 Wordpress 📅 20.5.2026 📊 CVSS: 6.1
6.1

CVE-2026-2955 - The AI Chatbot & Workflow Automation by AIWU plugin for WordPress is vulnerable to Stored Cross-Site

🏢 Wordpress 📅 20.5.2026 📊 CVSS: 6.4
6.4

CVE-2026-7522 - The Advanced Database Cleaner – Premium plugin for WordPress is vulnerable to Local File Inclusion i

🏢 Wordpress 📅 20.5.2026 📊 CVSS: 8.8
8.8

CVE-2026-5075 - The All in One SEO plugin for WordPress is vulnerable to Sensitive Information Exposure via 'interna

🏢 Wordpress 📅 20.5.2026 📊 CVSS: 4.3
4.3

CVE-2026-9010 - The Boost plugin for WordPress is vulnerable to time-based SQL Injection via the 'current_url' and '

🏢 Wordpress 📅 20.5.2026 📊 CVSS: 7.5
7.5

CVE-2026-7637 - The Boost plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and includin

🏢 Wordpress 📅 20.5.2026 📊 CVSS: 9.8
9.8

CVE-2025-15369 - The Xpro Addons — 140+ Widgets for Elementor plugin for WordPress is vulnerable to unauthorized modi

🏢 Wordpress 📅 20.5.2026 📊 CVSS: 5.3
5.3

CVE-2026-8685 - The Infility Global plugin for WordPress is vulnerable to SQL Injection via the 'orderby' and 'order

🏢 Wordpress 📅 20.5.2026 📊 CVSS: 6.5
6.5

CVE-2026-8627 - The Correct Prices plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the $_SE

🏢 Wordpress 📅 20.5.2026 📊 CVSS: 6.1
6.1

CVE-2026-8626 - The SponsorMe plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via PHP_SELF Para

🏢 Wordpress 📅 20.5.2026 📊 CVSS: 6.1
6.1

CVE-2026-8624 - The LJ comments import: reloaded plugin for WordPress is vulnerable to Reflected Cross-Site Scriptin

🏢 Wordpress 📅 20.5.2026 📊 CVSS: 6.1
6.1

CVE-2026-8610 - The TypeSquare Webfonts for ConoHa plugin for WordPress is vulnerable to authorization bypass in all

🏢 Wordpress 📅 20.5.2026 📊 CVSS: 4.3
4.3

CVE-2026-8424 - The Remove Yellow BGBOX plugin for WordPress is vulnerable to Cross-Site Request Forgery in all vers

🏢 Wordpress 📅 20.5.2026 📊 CVSS: 4.3
4.3

CVE-2026-8423 - The JaviBola Custom Theme Test plugin for WordPress is vulnerable to Cross-Site Request Forgery in a

🏢 Wordpress 📅 20.5.2026 📊 CVSS: 4.3
4.3

CVE-2026-8420 - The BLOGCHAT Chat System plugin for WordPress is vulnerable to Cross-Site Request Forgery in all ver

🏢 Wordpress 📅 20.5.2026 📊 CVSS: 6.1
6.1

CVE-2026-8419 - The Amazon Scraper plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions

🏢 Wordpress 📅 20.5.2026 📊 CVSS: 4.3
4.3

CVE-2026-8418 - The Games Catalog plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to

🏢 Wordpress 📅 20.5.2026 📊 CVSS: 4.3
4.3

CVE-2026-8038 - The Faces of Users plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'defaul

🏢 Wordpress 📅 20.5.2026 📊 CVSS: 6.4
6.4

CVE-2026-7472 - The Read More & Accordion plugin for WordPress is vulnerable to time-based blind SQL Injection via t

🏢 Wordpress 📅 20.5.2026 📊 CVSS: 4.9
4.9

CVE-2026-7467 - The Read More & Accordion plugin for WordPress is vulnerable to Privilege Escalation in all versions

🏢 Wordpress 📅 20.5.2026 📊 CVSS: 8.8
8.8

CVE-2026-7462 - The VatanSMS WP SMS plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the `pa

🏢 Wordpress 📅 20.5.2026 📊 CVSS: 6.1
6.1

CVE-2026-7284 - The Easy Elements for Elementor – Addons & Website Templates plugin for WordPress is vulnerable to p

🏢 Wordpress 📅 20.5.2026 📊 CVSS: 9.8
9.8

CVE-2026-6555 - The ProSolution WP Client plugin for WordPress is vulnerable to Arbitrary File Upload in versions up

🏢 Wordpress 📅 20.5.2026 📊 CVSS: 9.8
9.8

CVE-2026-6549 - The Logo Manager For Enamad plugin for WordPress is vulnerable to Stored Cross-Site Scripting via th

🏢 Wordpress 📅 20.5.2026 📊 CVSS: 6.4
6.4

CVE-2026-6456 - The Account Switcher plugin for WordPress is vulnerable to Privilege Escalation in all versions up t

🏢 Wordpress 📅 20.5.2026 📊 CVSS: 8.8
8.8

CVE-2026-6452 - The Bigfishgames Syndicate plugin for WordPress is vulnerable to Cross-Site Request Forgery in all v

🏢 Wordpress 📅 20.5.2026 📊 CVSS: 4.3
4.3

CVE-2026-6404 - The Anomify AI – Anomaly Detection and Alerting plugin for WordPress is vulnerable to Stored Cross-S

🏢 Wordpress 📅 20.5.2026 📊 CVSS: 4.4
4.4

CVE-2026-6401 - The Bottom Bar plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up t

🏢 Wordpress 📅 20.5.2026 📊 CVSS: 4.3
4.3

CVE-2026-6400 - The Child Height Predictor by Ostheimer plugin for WordPress is vulnerable to Cross-Site Request For

🏢 Wordpress 📅 20.5.2026 📊 CVSS: 4.3
4.3

CVE-2026-6399 - The General Options plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up

🏢 Wordpress 📅 20.5.2026 📊 CVSS: 4.4
4.4

CVE-2026-6397 - The Sticky plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `cvmh-sticky` s

🏢 Wordpress 📅 20.5.2026 📊 CVSS: 6.4
6.4

CVE-2026-6395 - The Word 2 Cash plugin for WordPress is vulnerable to Cross-Site Request Forgery leading to Stored C

🏢 Wordpress 📅 20.5.2026 📊 CVSS: 6.1
6.1

CVE-2026-6391 - The Sentence To SEO (keywords, description and tags) plugin for WordPress is vulnerable to Cross-Sit

🏢 Wordpress 📅 20.5.2026 📊 CVSS: 6.1
6.1

CVE-2026-6072 - The Oliver POS – A WooCommerce Point of Sale (POS) plugin for WordPress is vulnerable to Authorizati

🏢 Wordpress 📅 20.5.2026 📊 CVSS: 6.5
6.5

CVE-2026-5293 - The 診断ジェネレータ作成プラグイン (Diagnosis Generator) plugin for WordPress is vulnerable to Stored Cross-Site Sc

🏢 Wordpress 📅 20.5.2026 📊 CVSS: 6.4
6.4

CVE-2026-3985 - The Creative Mail – Easier WordPress & WooCommerce Email Marketing plugin for WordPress is vulnerabl

🏢 Wordpress 📅 20.5.2026 📊 CVSS: 7.5
7.5

CVE-2026-8096 - The Kirki – Freeform Page Builder, Website Builder & Customizer plugin for WordPress is vulnerable t

🏢 Wordpress 📅 19.5.2026 📊 CVSS: 6.5
6.5

CVE-2026-8073 - The Kirki – Freeform Page Builder, Website Builder & Customizer plugin for WordPress is vulnerable t

🏢 Wordpress 📅 19.5.2026 📊 CVSS: 7.5
7.5

CVE-2026-8912 - The Contest Gallery plugin for WordPress is vulnerable to SQL Injection via the 'form_input' paramet

🏢 Wordpress 📅 19.5.2026 📊 CVSS: 7.5
7.5

CVE-2026-4883 - The Piotnet Forms plugin for WordPress is vulnerable to arbitrary file upload due to missing file ty

🏢 Wordpress 📅 19.5.2026 📊 CVSS: 9.8
9.8

CVE-2026-4885 - The Piotnet Addons for Elementor Pro plugin for WordPress is vulnerable to arbitrary file upload due

🏢 Wordpress 📅 19.5.2026 📊 CVSS: 9.8
9.8

CVE-2025-15609 - The Fortis for WooCommerce WordPress plugin before 1.3.1 may leak sensitive API keys to unauthentica

🏢 Wordpress 📅 19.5.2026 📊 CVSS: 7.5
7.5

CVE-2026-6495 - The Ajax Load More WordPress plugin before 7.8.4 does not sanitise and escape a parameter before ou

🏢 Wordpress 📅 18.5.2026 📊 CVSS: 7.1
7.1

CVE-2026-6381 - The WP Maps WordPress plugin before 4.9.3 does not properly sanitize a parameter before using it in

🏢 Wordpress 📅 18.5.2026 📊 CVSS: 7.5
7.5

CVE-2026-6379 - The WP Photo Album Plus WordPress plugin before 9.1.11.001 does not properly sanitize and escape a p

🏢 Wordpress 📅 18.5.2026 📊 CVSS: 8.6
8.6

CVE-2026-3220 - The Autoptimize WordPress plugin before 3.1.15, Clearfy Cache WordPress plugin before 2.4.2, Speed

🏢 Wordpress 📅 18.5.2026 📊 CVSS: 8.8
8.8

CVE-2026-1631 - The Feeds for YouTube (YouTube video, channel, and gallery plugin) WordPress plugin before 2.6.4 is

🏢 Wordpress 📅 18.5.2026 📊 CVSS: 5.4
5.4

🏢 CVE nach Hersteller

Empfohlene Sicherheitstools

Unterstütze uns durch einen Kauf - wir erhalten eine kleine Provision.