🔔 Premium Features
🔍 Filter Threats
| Title | Severity | PoC | Actively Exploited | Source | Date |
|---|---|---|---|---|---|
| CVE-2026-1255 The YS LeadGen plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.1.4 due to the 'yslea... | HIGH | ????? | ????? | NVD | 9 hours ago |
| CVE-2026-8354 The Gum Addon for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'pop_tag' parameter in all versions up... | MEDIUM | ????? | ????? | NVD | 9 hours ago |
| CVE-2026-18346 The TikTok plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.4.1. This is due to the plugin not prope... | MEDIUM | ????? | ????? | NVD | 9 hours ago |
| CVE-2026-5410 The Redux Framework plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the spinner field in versions up to, and including, 4.5.13 T... | MEDIUM | ????? | ????? | NVD | 9 hours ago |
| CVE-2026-15098 The Real3D Flipbook Lite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'lightboxtext' shortcode attribute (and o... | MEDIUM | ????? | ????? | NVD | 10 hours ago |
| CVE-2026-9855 The Custom Field Template plugin for WordPress is vulnerable to generic SQL Injection via the 'post_ID' parameter in all versions up to, and... | MEDIUM | ????? | ????? | NVD | 10 hours ago |
| CVE-2026-87917 The MC4WP: Mailchimp for WordPress plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via 'data' Dynamic Content Tag in al... | MEDIUM | ????? | ????? | NVD | 10 hours ago |
| CVE-2026-1984 The Ibtana – Ecommerce Product Addons plugin for WordPress is vulnerable to unauthorized post meta modification due to a missing capability check on... | MEDIUM | ????? | ????? | NVD | 10 hours ago |
| CVE-2026-85658 The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress plugin for WordPress i... | HIGH | ????? | ????? | NVD | 10 hours ago |
| CVE-2026-7527 The WP Ghost (Hide My WP Ghost) – Security & Firewall plugin for WordPress is vulnerable to Open Redirect in all versions up to, and including, ... | MEDIUM | ????? | ????? | NVD | 10 hours ago |
| CVE-2026-5400 The Redux Framework plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Media field filter values in versions up to, and includi... | MEDIUM | ????? | ????? | NVD | 10 hours ago |
| CVE-2026-75959 The GoPay for WooCommerce plugin for WordPress is vulnerable to generic SQL Injection via the 'log_table_filter' parameter in all versions u... | MEDIUM | ????? | ????? | NVD | 10 hours ago |
| CVE-2026-13200 The Create plugin for WordPress is vulnerable to generic SQL Injection via the 'order' parameter in all versions up to, and including, 2.5.3... | MEDIUM | ????? | ????? | NVD | 10 hours ago |
| CVE-2026-12402 The OTP Login & Register Woocommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'fb-config' Setting in all ve... | MEDIUM | ????? | ????? | NVD | 10 hours ago |
| CVE-2026-4327 The The Welcomizer plugin for WordPress is vulnerable to Remote Code Execution in all versions up to and including 2.8.1. This is due to missing autho... | HIGH | ????? | ????? | NVD | 10 hours ago |
| CVE-2026-2422 The WP Composer – The Easiest Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'pbwp_raw_shortcode' ... | MEDIUM | ????? | ????? | NVD | 10 hours ago |
| CVE-2026-1641 The Wow Elements Addons for Elementor plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 1.11.2. ... | MEDIUM | ????? | ????? | NVD | 10 hours ago |
| CVE-2026-9232 The Easy Appointments plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.12.27 via the handl... | MEDIUM | ????? | ????? | NVD | 10 hours ago |
| CVE-2026-15463 The SSL Zen — SSL Certificate Installer & HTTPS Redirects plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'hos... | MEDIUM | ????? | ????? | NVD | 10 hours ago |
| CVE-2026-6295 The WP Optimizer plugin for WordPress is vulnerable to SQL Injection via the 's' parameter in all versions up to and including 2.5.0. This i... | MEDIUM | ????? | ????? | NVD | 10 hours ago |
Showing 21 to 40 of 4378 results