WordPress Vulnerabilities
A searchable, scoreable changelog of WordPress core, plugin, and theme vulnerabilities, including affected ranges and safe-version guidance where the CVE record supports it.
35,514 published entries · feed refreshed 2026-07-23
35,514Tracked total
26Critical this week
15,812Plugins covered
45Core CVEs, all time
Unauthenticated & critical — no login required to exploit
Participants Database: Arbitrary file deletion
CVE-2026-59555 · 10.0
Blocksy Companion Pro: Code execution
CVE-2026-57624 · 10.0
WordPress & WooCommerce Scraper Plugin, Import Data from Any Site: Dangerous file upload
CVE-2025-69129 · 10.0
Easy Invoice: Code execution
CVE-2026-48836 · 10.0
GeekyBot: Dangerous file upload
CVE-2026-40772 · 10.0
35,514 results
| Jul 23, 2026 |
CVE-2026-65550
Tabs: Cross-site scripting
Tabs is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed. The published affected range is n/a through 2.5.
|
Tabs | tabs-responsive |
5.9 | Pending |
| Jul 23, 2026 |
CVE-2026-65540
Popup for CF7 with Sweet Alert: Cross-site request forgery
Popup for CF7 with Sweet Alert is affected by cross-site request forgery. The vulnerable path is reachable without authentication. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request. The published affected range is n/a through 1.6.5.
|
Popup for CF7 with Sweet Alert | cf7-sweet-alert-popup |
7.1 | Pending |
| Jul 23, 2026 |
CVE-2026-65539
Kwayy HTML Sitemap: Cross-site request forgery
Kwayy HTML Sitemap is affected by cross-site request forgery. The vulnerable path is reachable without authentication. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request. The published affected range is n/a through 4.0.
|
Kwayy HTML Sitemap | kwayy-html-sitemap |
7.1 | Pending |
| Jul 23, 2026 |
CVE-2026-65538
Machete: Cross-site scripting
Machete is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed. The published affected range is n/a through 5.2.
|
Machete | machete |
5.9 | Pending |
| Jul 23, 2026 |
CVE-2026-65537
Cyr to Lat reloaded – transliteration of links and file names: A security weakness
Cyr to Lat reloaded – transliteration of links and file names is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation. The published affected range is n/a through 1.3.3.
|
Cyr to Lat reloaded – transliteration of links and file names | cyr-and-lat |
4.3 | Pending |
| Jul 23, 2026 |
CVE-2026-65536
افزونه حمل و نقل ووکامرس (پست پیشتاز و سفارشی، پیک موتوری): Cross-site request forgery
افزونه حمل و نقل ووکامرس (پست پیشتاز و سفارشی، پیک موتوری) is affected by cross-site request forgery. The vulnerable path is reachable without authentication. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request. The published affected range is n/a through 4.4.5.
|
افزونه حمل و نقل ووکامرس (پست پیشتاز و سفارشی، پیک موتوری) | persian-woocommerce-shipping |
6.5 | Pending |
| Jul 23, 2026 |
CVE-2026-65535
TinyMCE Templates: A security weakness
TinyMCE Templates is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation. The published affected range is n/a through 4.8.1.
|
TinyMCE Templates | tinymce-templates |
4.3 | Pending |
| Jul 23, 2026 |
CVE-2026-65534
Custom links in Elementor Image Carousel: Cross-site scripting
Custom links in Elementor Image Carousel is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed. The published affected range is n/a through 1.1.1.
|
Custom links in Elementor Image Carousel | custom-links-in-elementor-image-carousel |
5.9 | Pending |
| Jul 23, 2026 |
CVE-2026-65533
Smart SEO Tool: Cross-site scripting
Smart SEO Tool is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed. The published affected range is n/a through 4.1.2.
|
Smart SEO Tool | smart-seo-tool |
6.5 | Pending |
| Jul 23, 2026 |
CVE-2026-65532
Persian Woocommerce SMS: SQL injection
Persian Woocommerce SMS is affected by SQL injection. Exposure depends on how the affected operation is made reachable by the site. A successful request can alter database queries and expose or modify WordPress data. The published affected range is n/a through 7.2.2.
|
Persian Woocommerce SMS | persian-woocommerce-sms |
7.6 | Pending |
| Jul 23, 2026 |
CVE-2026-65531
Qubely: A security weakness
Qubely is affected by a security weakness. The vulnerable path is reachable without authentication. The resulting impact depends on how the affected component exposes the vulnerable operation. The published affected range is n/a through 1.8.14.
|
Qubely | qubely |
4.8 | Pending |
| Jul 23, 2026 |
CVE-2026-65530
TemplateSpare: A security weakness
TemplateSpare is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation. The published affected range is n/a through 4.2.2.
|
TemplateSpare | templatespare |
4.3 | Pending |
| Jul 23, 2026 |
CVE-2026-65529
Graphina: A security weakness
Graphina is affected by a security weakness. The vulnerable path is reachable without authentication. The resulting impact depends on how the affected component exposes the vulnerable operation. The published affected range is n/a through 3.1.12.
|
Graphina | graphina-elementor-charts-and-graphs |
5.3 | Pending |
| Jul 23, 2026 |
CVE-2026-65528
BSK PDF Manager: Cross-site scripting
BSK PDF Manager is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed. The published affected range is n/a through 3.8.
|
BSK PDF Manager | bsk-pdf-manager |
6.5 | Pending |
| Jul 23, 2026 |
CVE-2026-65527
LIQUID SPEECH BALLOON: Cross-site scripting
LIQUID SPEECH BALLOON is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed. The published affected range is n/a through 1.2.5.
|
LIQUID SPEECH BALLOON | liquid-speech-balloon |
6.5 | Pending |
| Jul 23, 2026 |
CVE-2026-65526
Visualizer: SQL injection
Visualizer is affected by SQL injection. Exposure depends on how the affected operation is made reachable by the site. A successful request can alter database queries and expose or modify WordPress data. The published affected range is n/a through 4.0.6.
|
Visualizer | visualizer |
8.5 | Pending |
| Jul 23, 2026 |
CVE-2026-65525
Civi Framework: A security weakness
Civi Framework is affected by a security weakness. The vulnerable path is reachable without authentication. The resulting impact depends on how the affected component exposes the vulnerable operation. The published affected range is n/a through 2.2.0.
|
Civi Framework | civi-framework |
5.3 | Pending |
| Jul 23, 2026 |
CVE-2026-65524
Avada Custom Branding: A security weakness
Avada Custom Branding is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation. The published affected range is n/a through 1.2.
|
Avada Custom Branding | fusion-white-label-branding |
4.3 | Pending |
| Jul 23, 2026 |
CVE-2026-65522
Manual - Documentation, Knowledge Base & Education WordPress Theme: Cross-site scripting
Manual - Documentation, Knowledge Base & Education WordPress Theme is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed. The published affected range is n/a through 7.5.4.
|
Manual - Documentation, Knowledge Base & Education WordPress Theme | manual |
6.5 | Pending |
| Jul 23, 2026 |
CVE-2026-65521
WP Social Ninja: A security weakness
WP Social Ninja is affected by a security weakness. The vulnerable path is reachable without authentication. The resulting impact depends on how the affected component exposes the vulnerable operation. The published affected range is n/a through 4.3.0.
|
WP Social Ninja | wp-social-reviews |
5.3 | Pending |
| Jul 23, 2026 |
CVE-2026-65519
Photo Gallery: Cross-site scripting
Photo Gallery is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed. The published affected range is n/a through 2.7.7.29.
|
Photo Gallery | gt3-photo-video-gallery |
6.5 | Pending |
| Jul 23, 2026 |
CVE-2026-65518
Accept Donations with PayPal & Stripe: Cross-site scripting
Accept Donations with PayPal & Stripe is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed. The published affected range is n/a through 1.5.5.
|
Accept Donations with PayPal & Stripe | easy-paypal-donation |
6.5 | Pending |
| Jul 23, 2026 |
CVE-2026-65516
PeproDev Ultimate Invoice: Server-side request forgery
PeproDev Ultimate Invoice is affected by server-side request forgery. The vulnerable path is reachable without authentication. The vulnerable server can be induced to make attacker-selected network requests. The published affected range is n/a through 2.2.6.
|
PeproDev Ultimate Invoice | pepro-ultimate-invoice |
7.2 | Pending |
| Jul 23, 2026 |
CVE-2026-65514
Appointment Hour Booking: Cross-site scripting
Appointment Hour Booking is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed. The published affected range is n/a through 1.5.86.
|
Appointment Hour Booking | appointment-hour-booking |
6.5 | Pending |
| Jul 23, 2026 |
CVE-2026-65512
WP Activity Log: Cross-site request forgery
WP Activity Log is affected by cross-site request forgery. The vulnerable path is reachable without authentication. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request. The published affected range is n/a through 5.6.4.
|
WP Activity Log | wp-security-audit-log |
5.4 | Pending |
| Jul 23, 2026 |
CVE-2026-65511
Manual - Documentation, Knowledge Base & Education WordPress Theme: Cross-site scripting
Manual - Documentation, Knowledge Base & Education WordPress Theme is affected by cross-site scripting. The vulnerable path is reachable without authentication. Injected script can execute in the affected site's origin when the vulnerable output is viewed. The published affected range is n/a through 7.5.4.
|
Manual - Documentation, Knowledge Base & Education WordPress Theme | manual |
7.1 | Pending |
| Jul 23, 2026 |
CVE-2026-65510
PeproDev Ultimate Invoice: Cross-site scripting
PeproDev Ultimate Invoice is affected by cross-site scripting. The vulnerable path is reachable without authentication. Injected script can execute in the affected site's origin when the vulnerable output is viewed. The published affected range is n/a through 2.2.6.
|
PeproDev Ultimate Invoice | pepro-ultimate-invoice |
7.1 | Pending |
| Jul 23, 2026 |
CVE-2026-65506
MP3 Audio Player for Music, Radio & Podcast by Sonaar: A security weakness
MP3 Audio Player for Music, Radio & Podcast by Sonaar is affected by a security weakness. The vulnerable path is reachable without authentication. The resulting impact depends on how the affected component exposes the vulnerable operation. The published affected range is n/a through 5.12.
|
MP3 Audio Player for Music, Radio & Podcast by Sonaar | mp3-music-player-by-sonaar |
5.3 | Pending |
| Jul 23, 2026 |
CVE-2026-65505
Ultimate Store Kit Elementor Addons: A security weakness
Ultimate Store Kit Elementor Addons is affected by a security weakness. The vulnerable path is reachable without authentication. The resulting impact depends on how the affected component exposes the vulnerable operation. The published affected range is n/a through 3.0.5.
|
Ultimate Store Kit Elementor Addons | ultimate-store-kit |
5.3 | Pending |
| Jul 23, 2026 |
CVE-2026-65503
Ultimate Store Kit Elementor Addons: Cross-site scripting
Ultimate Store Kit Elementor Addons is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed. The published affected range is n/a through 3.0.5.
|
Ultimate Store Kit Elementor Addons | ultimate-store-kit |
6.5 | Pending |
| Jul 23, 2026 |
CVE-2026-65501
Shiptastic for WooCommerce: A security weakness
Shiptastic for WooCommerce is affected by a security weakness. The vulnerable path is reachable without authentication. The resulting impact depends on how the affected component exposes the vulnerable operation. The published affected range is n/a through 5.1.0.
|
Shiptastic for WooCommerce | shiptastic-for-woocommerce |
5.3 | Pending |
| Jul 23, 2026 |
CVE-2026-65500
Manual - Documentation, Knowledge Base & Education WordPress Theme: A security weakness
Manual - Documentation, Knowledge Base & Education WordPress Theme is affected by a security weakness. The vulnerable path is reachable without authentication. The resulting impact depends on how the affected component exposes the vulnerable operation. The published affected range is n/a through 7.5.4.
|
Manual - Documentation, Knowledge Base & Education WordPress Theme | manual |
7.5 | Pending |
| Jul 23, 2026 |
CVE-2026-65499
PeproDev Ultimate Invoice: A security weakness
PeproDev Ultimate Invoice is affected by a security weakness. The vulnerable path is reachable without authentication. The resulting impact depends on how the affected component exposes the vulnerable operation. The published affected range is n/a through 2.2.6.
|
PeproDev Ultimate Invoice | pepro-ultimate-invoice |
6.5 | Pending |
| Jul 23, 2026 |
CVE-2026-65498
Complianz: A security weakness
Complianz is affected by a security weakness. The vulnerable path is reachable without authentication. The resulting impact depends on how the affected component exposes the vulnerable operation. The published affected range is n/a through 7.5.0.
|
Complianz | complianz-gdpr |
5.3 | Pending |
| Jul 23, 2026 |
CVE-2026-65497
Complianz: Code execution
Complianz is affected by code execution. Exposure depends on how the affected operation is made reachable by the site. Successful exploitation can run attacker-controlled code in the WordPress hosting account. The published affected range is n/a through 7.5.0.
|
Complianz | complianz-gdpr |
7.2 | Pending |
| Jul 23, 2026 |
CVE-2026-65496
Complianz: Server-side request forgery
Complianz is affected by server-side request forgery. Exposure depends on how the affected operation is made reachable by the site. The vulnerable server can be induced to make attacker-selected network requests. The published affected range is n/a through 7.5.0.
|
Complianz | complianz-gdpr |
4.4 | Pending |
| Jul 23, 2026 |
CVE-2026-65495
Dokan Pro: A security weakness
Dokan Pro is affected by a security weakness. The vulnerable path is reachable without authentication. The resulting impact depends on how the affected component exposes the vulnerable operation. The published affected range is n/a through 5.0.3.
|
Dokan Pro | dokan-pro |
7.5 | Pending |
| Jul 23, 2026 |
CVE-2026-65494
Dokan Pro: SQL injection
Dokan Pro is affected by SQL injection. Exposure depends on how the affected operation is made reachable by the site. A successful request can alter database queries and expose or modify WordPress data. The published affected range is n/a through 5.0.2.
|
Dokan Pro | dokan-pro |
7.1 | Pending |
| Jul 23, 2026 |
CVE-2026-65493
Dokan Pro: Code execution
Dokan Pro is affected by code execution. Exposure depends on how the affected operation is made reachable by the site. Successful exploitation can run attacker-controlled code in the WordPress hosting account. The published affected range is n/a through 5.0.2.
|
Dokan Pro | dokan-pro |
7.5 | Pending |
| Jul 23, 2026 |
CVE-2026-65492
Dokan Pro: Cross-site scripting
Dokan Pro is affected by cross-site scripting. The vulnerable path is reachable without authentication. Injected script can execute in the affected site's origin when the vulnerable output is viewed. The published affected range is n/a through 5.0.0.
|
Dokan Pro | dokan-pro |
7.1 | Pending |
| Jul 23, 2026 |
CVE-2026-65491
Query Wrangler: A security weakness
Query Wrangler is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation. The published affected range is n/a through 1.5.57.
|
Query Wrangler | query-wrangler |
4.3 | Pending |
| Jul 23, 2026 |
CVE-2026-65490
Create by Mediavine: A security weakness
Create by Mediavine is affected by a security weakness. The vulnerable path is reachable without authentication. The resulting impact depends on how the affected component exposes the vulnerable operation. The published affected range is n/a through 2.5.3.
|
Create by Mediavine | mediavine-create |
5.3 | Pending |
| Jul 23, 2026 |
CVE-2026-65489
LA-Studio Element Kit for Elementor: A security weakness
LA-Studio Element Kit for Elementor is affected by a security weakness. The vulnerable path is reachable without authentication. The resulting impact depends on how the affected component exposes the vulnerable operation. The published affected range is n/a through 1.6.2.
|
LA-Studio Element Kit for Elementor | lastudio-element-kit |
5.3 | Pending |
| Jul 23, 2026 |
CVE-2026-65488
LA-Studio Element Kit for Elementor: Cross-site request forgery
LA-Studio Element Kit for Elementor is affected by cross-site request forgery. The vulnerable path is reachable without authentication. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request. The published affected range is n/a through 1.6.2.
|
LA-Studio Element Kit for Elementor | lastudio-element-kit |
7.1 | Pending |
| Jul 23, 2026 |
CVE-2026-65487
Photography: A security weakness
Photography is affected by a security weakness. The vulnerable path is reachable without authentication. The resulting impact depends on how the affected component exposes the vulnerable operation. The published affected range is n/a through 7.7.6.
|
Photography | photography |
5.3 | Pending |
| Jul 23, 2026 |
CVE-2026-65486
Event post: A security weakness
Event post is affected by a security weakness. The vulnerable path is reachable without authentication. The resulting impact depends on how the affected component exposes the vulnerable operation. The published affected range is n/a through 6.0.1.
|
Event post | event-post |
5.3 | Pending |
| Jul 23, 2026 |
CVE-2026-65485
Content Control: A security weakness
Content Control is affected by a security weakness. The vulnerable path is reachable without authentication. The resulting impact depends on how the affected component exposes the vulnerable operation. The published affected range is n/a through 2.6.5.
|
Content Control | content-control |
5.3 | Pending |
| Jul 23, 2026 |
CVE-2026-65484
Style Kits: A security weakness
Style Kits is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation. The published affected range is n/a through 2.6.5.
|
Style Kits | analogwp-templates |
6.3 | Pending |
| Jul 23, 2026 |
CVE-2026-65483
HashThemes Demo Importer: Cross-site scripting
HashThemes Demo Importer is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed. The published affected range is n/a through 1.4.2.
|
HashThemes Demo Importer | hashthemes-demo-importer |
5.9 | Pending |
| Jul 23, 2026 |
CVE-2026-65482
LA-Studio Element Kit for Elementor: Cross-site scripting
LA-Studio Element Kit for Elementor is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed. The published affected range is n/a through 1.6.2.
|
LA-Studio Element Kit for Elementor | lastudio-element-kit |
6.5 | Pending |
| Jul 23, 2026 |
CVE-2026-65481
Vino: Filesystem traversal
Vino is affected by filesystem traversal. Exposure depends on how the affected operation is made reachable by the site. A crafted path can escape the intended directory and reach files or directories elsewhere on the server. The published affected range is n/a through 1.9.
|
Vino | vino |
7.5 | Pending |
| Jul 23, 2026 |
CVE-2026-65480
TheGem: Cross-site scripting
TheGem is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed. The published affected range is n/a through 5.11.1.
|
TheGem | thegem |
6.5 | Pending |
| Jul 23, 2026 |
CVE-2026-65479
Reviewer: A security weakness
Reviewer is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation. The published affected range is n/a through 3.14.2.
|
Reviewer | reviewer |
5.4 | Pending |
| Jul 23, 2026 |
CVE-2026-65478
ListingPro: A security weakness
ListingPro is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation. The published affected range is n/a through 2.9.10.
|
ListingPro | listingpro-plugin |
5.4 | Pending |
| Jul 23, 2026 |
CVE-2026-65477
Tonda Core: Filesystem traversal
Tonda Core is affected by filesystem traversal. Exposure depends on how the affected operation is made reachable by the site. A crafted path can escape the intended directory and reach files or directories elsewhere on the server. The published affected range is n/a through 2.1.2.
|
Tonda Core | tonda-core |
7.5 | Pending |
| Jul 23, 2026 |
CVE-2026-65476
Civi: A security weakness
Civi is affected by a security weakness. The vulnerable path is reachable without authentication. The resulting impact depends on how the affected component exposes the vulnerable operation. The published affected range is n/a through 2.2.4.
|
Civi | civi |
5.3 | Pending |
| Jul 23, 2026 |
CVE-2026-65475
Modula Image Gallery: Cross-site scripting
Modula Image Gallery is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed. The published affected range is 2.14.25 through 2.14.30.
|
Modula Image Gallery | modula-best-grid-gallery |
6.5 | Pending |
| Jul 23, 2026 |
CVE-2026-65474
Ninja Tables: A security weakness
Ninja Tables is affected by a security weakness. The vulnerable path is reachable without authentication. The resulting impact depends on how the affected component exposes the vulnerable operation. The published affected range is n/a through 5.2.10.
|
Ninja Tables | ninja-tables |
5.3 | Pending |
| Jul 23, 2026 |
CVE-2026-65473
Virtue/Ascend/Pinnacle Toolkit: Cross-site scripting
Virtue/Ascend/Pinnacle Toolkit is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed. The published affected range is n/a through 4.9.12.
|
Virtue/Ascend/Pinnacle Toolkit | virtue-toolkit |
6.5 | Pending |
| Jul 23, 2026 |
CVE-2026-65472
Kit (formerly ConvertKit): A security weakness
Kit (formerly ConvertKit) is affected by a security weakness. The vulnerable path is reachable without authentication. The resulting impact depends on how the affected component exposes the vulnerable operation. The published affected range is n/a through 3.3.5.
|
Kit (formerly ConvertKit) | convertkit |
5.3 | Pending |
| Jul 23, 2026 |
CVE-2026-65471
Avada Core: Cross-site request forgery
Avada Core is affected by cross-site request forgery. The vulnerable path is reachable without authentication. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request. The published affected range is n/a through 5.15.6.
|
Avada Core | fusion-core |
9.6 | Pending |
| Jul 23, 2026 |
CVE-2026-65470
Fluent Support: Cross-site scripting
Fluent Support is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed. The published affected range is n/a through 2.3.0.
|
Fluent Support | fluent-support |
6.5 | Pending |
| Jul 23, 2026 |
CVE-2026-65469
AWP Classifieds: A security weakness
AWP Classifieds is affected by a security weakness. The vulnerable path is reachable without authentication. The resulting impact depends on how the affected component exposes the vulnerable operation. The published affected range is n/a through 4.4.7.
|
AWP Classifieds | another-wordpress-classifieds-plugin |
5.3 | Pending |
| Jul 23, 2026 |
CVE-2026-65468
JetBooking: A security weakness
JetBooking is affected by a security weakness. The vulnerable path is reachable without authentication. The resulting impact depends on how the affected component exposes the vulnerable operation. The published affected range is n/a through 4.1.2.
|
JetBooking | jet-booking |
5.3 | Pending |
| Jul 23, 2026 |
CVE-2026-65467
JetEngine: Server-side request forgery
JetEngine is affected by server-side request forgery. Exposure depends on how the affected operation is made reachable by the site. The vulnerable server can be induced to make attacker-selected network requests. The published affected range is n/a through 3.8.11.
|
JetEngine | jet-engine |
4.9 | Pending |
| Jul 23, 2026 |
CVE-2026-65466
JetBooking: Server-side request forgery
JetBooking is affected by server-side request forgery. Exposure depends on how the affected operation is made reachable by the site. The vulnerable server can be induced to make attacker-selected network requests. The published affected range is n/a through 4.1.2.
|
JetBooking | jet-booking |
4.9 | Pending |
| Jul 23, 2026 |
CVE-2026-65465
JetElements For Elementor: Cross-site scripting
JetElements For Elementor is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed. The published affected range is n/a through 2.9.1.1.
|
JetElements For Elementor | jet-elements |
6.5 | Pending |
| Jul 23, 2026 |
CVE-2026-65464
GiveWP: Cross-site request forgery
GiveWP is affected by cross-site request forgery. The vulnerable path is reachable without authentication. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request. The published affected range is n/a through 4.16.3.
|
GiveWP | give |
5.4 | Pending |
| Jul 23, 2026 |
CVE-2026-65463
Masteriyo - LMS: A security weakness
Masteriyo - LMS is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation. The published affected range is n/a through 2.3.1.
|
Masteriyo - LMS | learning-management-system |
5.4 | Pending |
| Jul 23, 2026 |
CVE-2026-65462
Uncanny Automator: SQL injection
Uncanny Automator is affected by SQL injection. Exposure depends on how the affected operation is made reachable by the site. A successful request can alter database queries and expose or modify WordPress data. The published affected range is n/a through 7.3.2.
|
Uncanny Automator | uncanny-automator |
7.6 | Pending |
| Jul 23, 2026 |
CVE-2026-65461
Really Simple CSV Importer: Dangerous file upload
Really Simple CSV Importer is affected by dangerous file upload. Exposure depends on how the affected operation is made reachable by the site. Successful exploitation can place attacker-controlled executable content on the server and may lead to full site compromise. The published affected range is n/a through 1.3.
|
Really Simple CSV Importer | really-simple-csv-importer |
9.1 | Pending |
| Jul 23, 2026 |
CVE-2026-65460
Zarinpal Gateway: Cross-site request forgery
Zarinpal Gateway is affected by cross-site request forgery. The vulnerable path is reachable without authentication. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request. The published affected range is n/a through 5.1.0.
|
Zarinpal Gateway | zarinpal-woocommerce-payment-gateway |
4.3 | Pending |
| Jul 23, 2026 |
CVE-2026-65458
Polylang: A security weakness
Polylang is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation. The published affected range is n/a through 3.8.5.
|
Polylang | polylang |
4.3 | Pending |
| Jul 23, 2026 |
CVE-2026-65457
ЮKassa для WooCommerce: A security weakness
ЮKassa для WooCommerce is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation. The published affected range is n/a through 2.16.1.
|
ЮKassa для WooCommerce | yookassa |
4.3 | Pending |
| Jul 23, 2026 |
CVE-2026-65456
Product Slider for WooCommerce: A security weakness
Product Slider for WooCommerce is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation. The published affected range is n/a through 1.13.62.
|
Product Slider for WooCommerce | woocommerce-products-slider |
4.3 | Pending |
| Jul 23, 2026 |
CVE-2026-65455
MapSVG: Dangerous file upload
MapSVG is affected by dangerous file upload. Exposure depends on how the affected operation is made reachable by the site. Successful exploitation can place attacker-controlled executable content on the server and may lead to full site compromise. The published affected range is n/a through 8.14.0.
|
MapSVG | mapsvg-lite-interactive-vector-maps |
9.1 | Pending |
| Jul 23, 2026 |
CVE-2026-65454
Quiz And Survey Master: SQL injection
Quiz And Survey Master is affected by SQL injection. Exposure depends on how the affected operation is made reachable by the site. A successful request can alter database queries and expose or modify WordPress data. The published affected range is n/a through 11.2.0.
|
Quiz And Survey Master | quiz-master-next |
8.5 | Pending |
| Jul 23, 2026 |
CVE-2026-65453
Ebook Store: A security weakness
Ebook Store is affected by a security weakness. The vulnerable path is reachable without authentication. The resulting impact depends on how the affected component exposes the vulnerable operation. The published affected range is n/a through 6.19.
|
Ebook Store | ebook-store |
5.3 | Pending |
| Jul 23, 2026 |
CVE-2026-65452
Ebook Store: A security weakness
Ebook Store is affected by a security weakness. The vulnerable path is reachable without authentication. The resulting impact depends on how the affected component exposes the vulnerable operation. The published affected range is n/a through 6.19.
|
Ebook Store | ebook-store |
5.3 | Pending |
| Jul 23, 2026 |
CVE-2026-65451
MapSVG: SQL injection
MapSVG is affected by SQL injection. Exposure depends on how the affected operation is made reachable by the site. A successful request can alter database queries and expose or modify WordPress data. The published affected range is n/a through 8.14.0.
|
MapSVG | mapsvg |
8.5 | Pending |
| Jul 23, 2026 |
CVE-2026-65450
MapSVG: SQL injection
MapSVG is affected by SQL injection. Exposure depends on how the affected operation is made reachable by the site. A successful request can alter database queries and expose or modify WordPress data. The published affected range is n/a through 8.14.0.
|
MapSVG | mapsvg-lite-interactive-vector-maps |
8.5 | Pending |
| Jul 23, 2026 |
CVE-2026-65449
MapSVG: Cross-site scripting
MapSVG is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed. The published affected range is n/a through 8.14.0.
|
MapSVG | mapsvg-lite-interactive-vector-maps |
6.5 | Pending |
| Jul 23, 2026 |
CVE-2026-61981
Simple Link Directory Pro: Cross-site request forgery
Simple Link Directory Pro is affected by cross-site request forgery. The vulnerable path is reachable without authentication. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request. The published affected range is n/a through 15.0.8.
|
Simple Link Directory Pro | simple-link-directory-pro |
5.4 | Pending |
| Jul 23, 2026 |
CVE-2026-61973
ShopLentor Pro: A security weakness
ShopLentor Pro is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation. The published affected range is n/a through 2.8.5.
|
ShopLentor Pro | woolentor-addons-pro |
4.3 | Pending |
| Jul 23, 2026 |
CVE-2026-61972
ShopLentor Pro: A security weakness
ShopLentor Pro is affected by a security weakness. The vulnerable path is reachable without authentication. The resulting impact depends on how the affected component exposes the vulnerable operation. The published affected range is n/a through 2.8.5.
|
ShopLentor Pro | woolentor-addons-pro |
5.3 | Pending |
| Jul 23, 2026 |
CVE-2026-61954
PayU India: A security weakness
PayU India is affected by a security weakness. The vulnerable path is reachable without authentication. The resulting impact depends on how the affected component exposes the vulnerable operation. The published affected range is n/a through 3.8.9.
|
PayU India | payu-india |
7.5 | Pending |
| Jul 23, 2026 |
CVE-2026-61951
TrueBooker: Privilege escalation or authentication bypass
TrueBooker is affected by privilege escalation or authentication bypass. The vulnerable path is reachable without authentication. A successful request can grant permissions or access that the caller should not possess. The published affected range is n/a through 1.2.3.
|
TrueBooker | truebooker-appointment-booking |
9.8 | Pending |
| Jul 23, 2026 |
CVE-2026-61950
TrueBooker: SQL injection
TrueBooker is affected by SQL injection. The vulnerable path is reachable without authentication. A successful request can alter database queries and expose or modify WordPress data. The published affected range is n/a through 1.2.3.
|
TrueBooker | truebooker-appointment-booking |
9.3 | Pending |
| Jul 23, 2026 |
CVE-2026-61949
Bookly: SQL injection
Bookly is affected by SQL injection. The vulnerable path is reachable without authentication. A successful request can alter database queries and expose or modify WordPress data. The published affected range is n/a through 27.7.
|
Bookly | bookly-responsive-appointment-booking-tool |
9.3 | Pending |
| Jul 23, 2026 |
CVE-2026-61948
WPDM – Premium Packages: SQL injection
WPDM – Premium Packages is affected by SQL injection. The vulnerable path is reachable without authentication. A successful request can alter database queries and expose or modify WordPress data. The published affected range is n/a through 6.2.0.
|
WPDM – Premium Packages | wpdm-premium-packages |
9.3 | Pending |
| Jul 23, 2026 |
CVE-2026-61947
Form Vibes – Database Manager for Forms: Cross-site scripting
Form Vibes – Database Manager for Forms is affected by cross-site scripting. The vulnerable path is reachable without authentication. Injected script can execute in the affected site's origin when the vulnerable output is viewed. The published affected range is n/a through 1.5.2.
|
Form Vibes – Database Manager for Forms | form-vibes |
7.1 | Pending |
| Jul 23, 2026 |
CVE-2026-61946
Easy Appointments: A security weakness
Easy Appointments is affected by a security weakness. The vulnerable path is reachable without authentication. The resulting impact depends on how the affected component exposes the vulnerable operation. The published affected range is n/a through 3.12.27.
|
Easy Appointments | easy-appointments |
6.5 | Pending |
| Jul 23, 2026 |
CVE-2026-61945
WooCommerce Product Stock Alert: A security weakness
WooCommerce Product Stock Alert is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation. The published affected range is n/a through 3.0.6.
|
WooCommerce Product Stock Alert | woocommerce-product-stock-alert |
6.5 | Pending |
| Jul 23, 2026 |
CVE-2026-61944
Bookly: Cross-site scripting
Bookly is affected by cross-site scripting. The vulnerable path is reachable without authentication. Injected script can execute in the affected site's origin when the vulnerable output is viewed. The published affected range is n/a through 27.7.
|
Bookly | bookly-responsive-appointment-booking-tool |
7.1 | Pending |
| Jul 23, 2026 |
CVE-2026-61943
WPDM – Premium Packages: A security weakness
WPDM – Premium Packages is affected by a security weakness. The vulnerable path is reachable without authentication. The resulting impact depends on how the affected component exposes the vulnerable operation. The published affected range is n/a through 6.2.0.
|
WPDM – Premium Packages | wpdm-premium-packages |
7.5 | Pending |
| Jul 23, 2026 |
CVE-2026-59555
Participants Database: Arbitrary file deletion
Participants Database is affected by arbitrary file deletion. The vulnerable path is reachable without authentication. A successful request can remove files outside the intended scope and may make the site unavailable. The published affected range is n/a through 2.7.8.3.
|
Participants Database | participants-database |
10.0 | Pending |
| Jul 23, 2026 |
CVE-2026-59554
Ziina: A security weakness
Ziina is affected by a security weakness. The vulnerable path is reachable without authentication. The resulting impact depends on how the affected component exposes the vulnerable operation. The published affected range is n/a through 1.2.21.
|
Ziina | ziina |
7.5 | Pending |
| Jul 23, 2026 |
CVE-2026-59547
Payment Gateway for PayPal on WooCommerce: A security weakness
Payment Gateway for PayPal on WooCommerce is affected by a security weakness. The vulnerable path is reachable without authentication. The resulting impact depends on how the affected component exposes the vulnerable operation. The published affected range is n/a through 9.1.4.
|
Payment Gateway for PayPal on WooCommerce | woo-paypal-gateway |
7.5 | Pending |
| Jul 23, 2026 |
CVE-2026-59545
miniOrange Discord Integration: A security weakness
miniOrange Discord Integration is affected by a security weakness. The vulnerable path is reachable without authentication. The resulting impact depends on how the affected component exposes the vulnerable operation. The published affected range is n/a through 2.2.4.
|
miniOrange Discord Integration | miniorange-discord-integration |
8.1 | Pending |
| Jul 23, 2026 |
CVE-2026-59544
Thrive Quiz Builder: Code execution
Thrive Quiz Builder is affected by code execution. The vulnerable path is reachable without authentication. Successful exploitation can run attacker-controlled code in the WordPress hosting account. The published affected range is n/a through 10.9.3.0.
|
Thrive Quiz Builder | thrive-quiz-builder |
9.8 | Pending |
No vulnerabilities match those filters.