🔍 Filter Threats
| Title | Severity | PoC | Actively Exploited | Source | Date |
|---|---|---|---|---|---|
| CVE-2026-103519 The The WP Ultimate Review plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 2.4.3. This is du... | MEDIUM | ????? | ????? | NVD | 3 days ago |
| CVE-2026-15795 The Responsive Plus – Elementor Templates & Starter Sites plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Shortcode Attrib... | MEDIUM | ????? | ????? | NVD | 3 days ago |
| CVE-2026-100157 The The WP Ultimate Review plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 2.4.3. This is du... | MEDIUM | ????? | ????? | NVD | 3 days ago |
| CVE-2026-103421 The WPMobile.App – Android and iOS App Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'REQUEST_URI (path seg... | MEDIUM | ????? | ????? | NVD | 3 days ago |
| CVE-2026-97341 The Visitor Traffic Real Time Statistics plugin for WordPress is vulnerable to Stored DOM-Based Cross-Site Scripting via 'X-Real-IP' HTTP He... | HIGH | ????? | ????? | NVD | 3 days ago |
| CVE-2026-97344 The Wp Social Login and Register Social Counter plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Avatar Alt Attribute via Arbitra... | MEDIUM | ????? | ????? | NVD | 3 days ago |
| CVE-2026-96962 The Pie Register WordPress plugin before 3.8.4.14 does not restrict access to an invitation-code report, allowing unauthenticated visitors who know a... | LOW | ????? | ????? | NVD | 3 days ago |
| CVE-2026-97337 The Simple Membership plugin for WordPress is vulnerable to unauthorized modification of data and sensitive information disclosure in versions up to, ... | HIGH | ????? | ????? | NVD | 3 days ago |
| CVE-2026-96650 The Strong Testimonials plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'platform_user_photo' Custom Field in all vers... | HIGH | ????? | ????? | NVD | 3 days ago |
| CVE-2026-94239 The Loco Translate WordPress plugin before 2.8.9 does not sanitise and escape some bundle configuration values before outputting them back in an admin... | MEDIUM | ????? | ????? | NVD | 3 days ago |
| CVE-2026-94238 The Loco Translate WordPress plugin before 2.8.9 does not restrict which file paths its translation file routes will read, allowing users granted the ... | MEDIUM | ????? | ????? | NVD | 3 days ago |
| CVE-2026-96575 The Transliterator – Multilingual and Multi-script Text Conversion plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Comment Con... | HIGH | ????? | ????? | NVD | 3 days ago |
| CVE-2026-96564 The SEOPress – AI SEO Plugin & On-site SEO plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Author Display Name in all vers... | HIGH | ????? | ????? | NVD | 3 days ago |
| CVE-2026-92923 The Unlimited Elements for Elementor WordPress plugin before 2.0.21 does not sanitise and escape a parameter before using it in a SQL statement, allow... | MEDIUM | ????? | ????? | NVD | 3 days ago |
| CVE-2026-92437 The Mailchimp for WooCommerce WordPress plugin before 6.3 does not require authentication, a nonce or an ownership check before it acts on a customer&... | MEDIUM | ????? | ????? | NVD | 3 days ago |
| CVE-2026-93430 The GD Rating System plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'title' and 'url' Render Args in gdrts_... | HIGH | ????? | ????? | NVD | 3 days ago |
| CVE-2026-91078 The TillKit WordPress plugin before 1.0.5 does not require the hard-coded, publicly known PIN of the privileged POS account it creates on activation t... | HIGH | ????? | ????? | NVD | 3 days ago |
| CVE-2026-89236 The SaveTo Wishlist Lite WordPress plugin before 1.1.5 does not sanitise and escape parameters before using them in the ORDER BY clause of a SQL quer... | HIGH | ????? | ????? | NVD | 3 days ago |
| CVE-2026-88783 The Kubio AI Page Builder WordPress plugin before 2.9.3 does not limit its widening of the allowed HTML elements to the editor context, so the wider s... | HIGH | ????? | ????? | NVD | 3 days ago |
| CVE-2026-91108 The Alt Text AI – Automatically generate image alt text for SEO and accessibility plugin for WordPress is vulnerable to authorization bypass in all ... | MEDIUM | ????? | ????? | NVD | 3 days ago |