WordPress Vulnerabilities

A searchable, scoreable changelog of WordPress core, plugin, and theme vulnerabilities, including affected ranges and safe-version guidance where the CVE record supports it.

35,514 published entries · feed refreshed 2026-07-23
35,514Tracked total
26Critical this week
15,812Plugins covered
45Core CVEs, all time
35,514 results
Jul 23, 2026 CVE-2026-65550
Tabs: Cross-site scripting
Tabs is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed. The published affected range is n/a through 2.5.
Tabs tabs-responsive 5.9 Pending
Jul 23, 2026 CVE-2026-65540
Popup for CF7 with Sweet Alert: Cross-site request forgery
Popup for CF7 with Sweet Alert is affected by cross-site request forgery. The vulnerable path is reachable without authentication. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request. The published affected range is n/a through 1.6.5.
Popup for CF7 with Sweet Alert cf7-sweet-alert-popup 7.1 Pending
Jul 23, 2026 CVE-2026-65539
Kwayy HTML Sitemap: Cross-site request forgery
Kwayy HTML Sitemap is affected by cross-site request forgery. The vulnerable path is reachable without authentication. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request. The published affected range is n/a through 4.0.
Kwayy HTML Sitemap kwayy-html-sitemap 7.1 Pending
Jul 23, 2026 CVE-2026-65538
Machete: Cross-site scripting
Machete is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed. The published affected range is n/a through 5.2.
Machete machete 5.9 Pending
Jul 23, 2026 CVE-2026-65537
Cyr to Lat reloaded – transliteration of links and file names: A security weakness
Cyr to Lat reloaded – transliteration of links and file names is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation. The published affected range is n/a through 1.3.3.
Cyr to Lat reloaded – transliteration of links and file names cyr-and-lat 4.3 Pending
Jul 23, 2026 CVE-2026-65536
افزونه حمل و نقل ووکامرس (پست پیشتاز و سفارشی، پیک موتوری): Cross-site request forgery
افزونه حمل و نقل ووکامرس (پست پیشتاز و سفارشی، پیک موتوری) is affected by cross-site request forgery. The vulnerable path is reachable without authentication. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request. The published affected range is n/a through 4.4.5.
افزونه حمل و نقل ووکامرس (پست پیشتاز و سفارشی، پیک موتوری) persian-woocommerce-shipping 6.5 Pending
Jul 23, 2026 CVE-2026-65535
TinyMCE Templates: A security weakness
TinyMCE Templates is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation. The published affected range is n/a through 4.8.1.
TinyMCE Templates tinymce-templates 4.3 Pending
Jul 23, 2026 CVE-2026-65534
Custom links in Elementor Image Carousel: Cross-site scripting
Custom links in Elementor Image Carousel is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed. The published affected range is n/a through 1.1.1.
Custom links in Elementor Image Carousel custom-links-in-elementor-image-carousel 5.9 Pending
Jul 23, 2026 CVE-2026-65533
Smart SEO Tool: Cross-site scripting
Smart SEO Tool is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed. The published affected range is n/a through 4.1.2.
Smart SEO Tool smart-seo-tool 6.5 Pending
Jul 23, 2026 CVE-2026-65532
Persian Woocommerce SMS: SQL injection
Persian Woocommerce SMS is affected by SQL injection. Exposure depends on how the affected operation is made reachable by the site. A successful request can alter database queries and expose or modify WordPress data. The published affected range is n/a through 7.2.2.
Persian Woocommerce SMS persian-woocommerce-sms 7.6 Pending
Jul 23, 2026 CVE-2026-65531
Qubely: A security weakness
Qubely is affected by a security weakness. The vulnerable path is reachable without authentication. The resulting impact depends on how the affected component exposes the vulnerable operation. The published affected range is n/a through 1.8.14.
Qubely qubely 4.8 Pending
Jul 23, 2026 CVE-2026-65530
TemplateSpare: A security weakness
TemplateSpare is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation. The published affected range is n/a through 4.2.2.
TemplateSpare templatespare 4.3 Pending
Jul 23, 2026 CVE-2026-65529
Graphina: A security weakness
Graphina is affected by a security weakness. The vulnerable path is reachable without authentication. The resulting impact depends on how the affected component exposes the vulnerable operation. The published affected range is n/a through 3.1.12.
Graphina graphina-elementor-charts-and-graphs 5.3 Pending
Jul 23, 2026 CVE-2026-65528
BSK PDF Manager: Cross-site scripting
BSK PDF Manager is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed. The published affected range is n/a through 3.8.
BSK PDF Manager bsk-pdf-manager 6.5 Pending
Jul 23, 2026 CVE-2026-65527
LIQUID SPEECH BALLOON: Cross-site scripting
LIQUID SPEECH BALLOON is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed. The published affected range is n/a through 1.2.5.
LIQUID SPEECH BALLOON liquid-speech-balloon 6.5 Pending
Jul 23, 2026 CVE-2026-65526
Visualizer: SQL injection
Visualizer is affected by SQL injection. Exposure depends on how the affected operation is made reachable by the site. A successful request can alter database queries and expose or modify WordPress data. The published affected range is n/a through 4.0.6.
Visualizer visualizer 8.5 Pending
Jul 23, 2026 CVE-2026-65525
Civi Framework: A security weakness
Civi Framework is affected by a security weakness. The vulnerable path is reachable without authentication. The resulting impact depends on how the affected component exposes the vulnerable operation. The published affected range is n/a through 2.2.0.
Civi Framework civi-framework 5.3 Pending
Jul 23, 2026 CVE-2026-65524
Avada Custom Branding: A security weakness
Avada Custom Branding is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation. The published affected range is n/a through 1.2.
Avada Custom Branding fusion-white-label-branding 4.3 Pending
Jul 23, 2026 CVE-2026-65522
Manual - Documentation, Knowledge Base & Education WordPress Theme: Cross-site scripting
Manual - Documentation, Knowledge Base & Education WordPress Theme is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed. The published affected range is n/a through 7.5.4.
Manual - Documentation, Knowledge Base & Education WordPress Theme manual 6.5 Pending
Jul 23, 2026 CVE-2026-65521
WP Social Ninja: A security weakness
WP Social Ninja is affected by a security weakness. The vulnerable path is reachable without authentication. The resulting impact depends on how the affected component exposes the vulnerable operation. The published affected range is n/a through 4.3.0.
WP Social Ninja wp-social-reviews 5.3 Pending
Jul 23, 2026 CVE-2026-65519
Photo Gallery: Cross-site scripting
Photo Gallery is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed. The published affected range is n/a through 2.7.7.29.
Photo Gallery gt3-photo-video-gallery 6.5 Pending
Jul 23, 2026 CVE-2026-65518
Accept Donations with PayPal & Stripe: Cross-site scripting
Accept Donations with PayPal & Stripe is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed. The published affected range is n/a through 1.5.5.
Accept Donations with PayPal & Stripe easy-paypal-donation 6.5 Pending
Jul 23, 2026 CVE-2026-65516
PeproDev Ultimate Invoice: Server-side request forgery
PeproDev Ultimate Invoice is affected by server-side request forgery. The vulnerable path is reachable without authentication. The vulnerable server can be induced to make attacker-selected network requests. The published affected range is n/a through 2.2.6.
PeproDev Ultimate Invoice pepro-ultimate-invoice 7.2 Pending
Jul 23, 2026 CVE-2026-65514
Appointment Hour Booking: Cross-site scripting
Appointment Hour Booking is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed. The published affected range is n/a through 1.5.86.
Appointment Hour Booking appointment-hour-booking 6.5 Pending
Jul 23, 2026 CVE-2026-65512
WP Activity Log: Cross-site request forgery
WP Activity Log is affected by cross-site request forgery. The vulnerable path is reachable without authentication. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request. The published affected range is n/a through 5.6.4.
WP Activity Log wp-security-audit-log 5.4 Pending
Jul 23, 2026 CVE-2026-65511
Manual - Documentation, Knowledge Base & Education WordPress Theme: Cross-site scripting
Manual - Documentation, Knowledge Base & Education WordPress Theme is affected by cross-site scripting. The vulnerable path is reachable without authentication. Injected script can execute in the affected site's origin when the vulnerable output is viewed. The published affected range is n/a through 7.5.4.
Manual - Documentation, Knowledge Base & Education WordPress Theme manual 7.1 Pending
Jul 23, 2026 CVE-2026-65510
PeproDev Ultimate Invoice: Cross-site scripting
PeproDev Ultimate Invoice is affected by cross-site scripting. The vulnerable path is reachable without authentication. Injected script can execute in the affected site's origin when the vulnerable output is viewed. The published affected range is n/a through 2.2.6.
PeproDev Ultimate Invoice pepro-ultimate-invoice 7.1 Pending
Jul 23, 2026 CVE-2026-65506
MP3 Audio Player for Music, Radio & Podcast by Sonaar: A security weakness
MP3 Audio Player for Music, Radio & Podcast by Sonaar is affected by a security weakness. The vulnerable path is reachable without authentication. The resulting impact depends on how the affected component exposes the vulnerable operation. The published affected range is n/a through 5.12.
MP3 Audio Player for Music, Radio & Podcast by Sonaar mp3-music-player-by-sonaar 5.3 Pending
Jul 23, 2026 CVE-2026-65505
Ultimate Store Kit Elementor Addons: A security weakness
Ultimate Store Kit Elementor Addons is affected by a security weakness. The vulnerable path is reachable without authentication. The resulting impact depends on how the affected component exposes the vulnerable operation. The published affected range is n/a through 3.0.5.
Ultimate Store Kit Elementor Addons ultimate-store-kit 5.3 Pending
Jul 23, 2026 CVE-2026-65503
Ultimate Store Kit Elementor Addons: Cross-site scripting
Ultimate Store Kit Elementor Addons is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed. The published affected range is n/a through 3.0.5.
Ultimate Store Kit Elementor Addons ultimate-store-kit 6.5 Pending
Jul 23, 2026 CVE-2026-65501
Shiptastic for WooCommerce: A security weakness
Shiptastic for WooCommerce is affected by a security weakness. The vulnerable path is reachable without authentication. The resulting impact depends on how the affected component exposes the vulnerable operation. The published affected range is n/a through 5.1.0.
Shiptastic for WooCommerce shiptastic-for-woocommerce 5.3 Pending
Jul 23, 2026 CVE-2026-65500
Manual - Documentation, Knowledge Base & Education WordPress Theme: A security weakness
Manual - Documentation, Knowledge Base & Education WordPress Theme is affected by a security weakness. The vulnerable path is reachable without authentication. The resulting impact depends on how the affected component exposes the vulnerable operation. The published affected range is n/a through 7.5.4.
Manual - Documentation, Knowledge Base & Education WordPress Theme manual 7.5 Pending
Jul 23, 2026 CVE-2026-65499
PeproDev Ultimate Invoice: A security weakness
PeproDev Ultimate Invoice is affected by a security weakness. The vulnerable path is reachable without authentication. The resulting impact depends on how the affected component exposes the vulnerable operation. The published affected range is n/a through 2.2.6.
PeproDev Ultimate Invoice pepro-ultimate-invoice 6.5 Pending
Jul 23, 2026 CVE-2026-65498
Complianz: A security weakness
Complianz is affected by a security weakness. The vulnerable path is reachable without authentication. The resulting impact depends on how the affected component exposes the vulnerable operation. The published affected range is n/a through 7.5.0.
Complianz complianz-gdpr 5.3 Pending
Jul 23, 2026 CVE-2026-65497
Complianz: Code execution
Complianz is affected by code execution. Exposure depends on how the affected operation is made reachable by the site. Successful exploitation can run attacker-controlled code in the WordPress hosting account. The published affected range is n/a through 7.5.0.
Complianz complianz-gdpr 7.2 Pending
Jul 23, 2026 CVE-2026-65496
Complianz: Server-side request forgery
Complianz is affected by server-side request forgery. Exposure depends on how the affected operation is made reachable by the site. The vulnerable server can be induced to make attacker-selected network requests. The published affected range is n/a through 7.5.0.
Complianz complianz-gdpr 4.4 Pending
Jul 23, 2026 CVE-2026-65495
Dokan Pro: A security weakness
Dokan Pro is affected by a security weakness. The vulnerable path is reachable without authentication. The resulting impact depends on how the affected component exposes the vulnerable operation. The published affected range is n/a through 5.0.3.
Dokan Pro dokan-pro 7.5 Pending
Jul 23, 2026 CVE-2026-65494
Dokan Pro: SQL injection
Dokan Pro is affected by SQL injection. Exposure depends on how the affected operation is made reachable by the site. A successful request can alter database queries and expose or modify WordPress data. The published affected range is n/a through 5.0.2.
Dokan Pro dokan-pro 7.1 Pending
Jul 23, 2026 CVE-2026-65493
Dokan Pro: Code execution
Dokan Pro is affected by code execution. Exposure depends on how the affected operation is made reachable by the site. Successful exploitation can run attacker-controlled code in the WordPress hosting account. The published affected range is n/a through 5.0.2.
Dokan Pro dokan-pro 7.5 Pending
Jul 23, 2026 CVE-2026-65492
Dokan Pro: Cross-site scripting
Dokan Pro is affected by cross-site scripting. The vulnerable path is reachable without authentication. Injected script can execute in the affected site's origin when the vulnerable output is viewed. The published affected range is n/a through 5.0.0.
Dokan Pro dokan-pro 7.1 Pending
Jul 23, 2026 CVE-2026-65491
Query Wrangler: A security weakness
Query Wrangler is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation. The published affected range is n/a through 1.5.57.
Query Wrangler query-wrangler 4.3 Pending
Jul 23, 2026 CVE-2026-65490
Create by Mediavine: A security weakness
Create by Mediavine is affected by a security weakness. The vulnerable path is reachable without authentication. The resulting impact depends on how the affected component exposes the vulnerable operation. The published affected range is n/a through 2.5.3.
Create by Mediavine mediavine-create 5.3 Pending
Jul 23, 2026 CVE-2026-65489
LA-Studio Element Kit for Elementor: A security weakness
LA-Studio Element Kit for Elementor is affected by a security weakness. The vulnerable path is reachable without authentication. The resulting impact depends on how the affected component exposes the vulnerable operation. The published affected range is n/a through 1.6.2.
LA-Studio Element Kit for Elementor lastudio-element-kit 5.3 Pending
Jul 23, 2026 CVE-2026-65488
LA-Studio Element Kit for Elementor: Cross-site request forgery
LA-Studio Element Kit for Elementor is affected by cross-site request forgery. The vulnerable path is reachable without authentication. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request. The published affected range is n/a through 1.6.2.
LA-Studio Element Kit for Elementor lastudio-element-kit 7.1 Pending
Jul 23, 2026 CVE-2026-65487
Photography: A security weakness
Photography is affected by a security weakness. The vulnerable path is reachable without authentication. The resulting impact depends on how the affected component exposes the vulnerable operation. The published affected range is n/a through 7.7.6.
Photography photography 5.3 Pending
Jul 23, 2026 CVE-2026-65486
Event post: A security weakness
Event post is affected by a security weakness. The vulnerable path is reachable without authentication. The resulting impact depends on how the affected component exposes the vulnerable operation. The published affected range is n/a through 6.0.1.
Event post event-post 5.3 Pending
Jul 23, 2026 CVE-2026-65485
Content Control: A security weakness
Content Control is affected by a security weakness. The vulnerable path is reachable without authentication. The resulting impact depends on how the affected component exposes the vulnerable operation. The published affected range is n/a through 2.6.5.
Content Control content-control 5.3 Pending
Jul 23, 2026 CVE-2026-65484
Style Kits: A security weakness
Style Kits is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation. The published affected range is n/a through 2.6.5.
Style Kits analogwp-templates 6.3 Pending
Jul 23, 2026 CVE-2026-65483
HashThemes Demo Importer: Cross-site scripting
HashThemes Demo Importer is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed. The published affected range is n/a through 1.4.2.
HashThemes Demo Importer hashthemes-demo-importer 5.9 Pending
Jul 23, 2026 CVE-2026-65482
LA-Studio Element Kit for Elementor: Cross-site scripting
LA-Studio Element Kit for Elementor is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed. The published affected range is n/a through 1.6.2.
LA-Studio Element Kit for Elementor lastudio-element-kit 6.5 Pending
Jul 23, 2026 CVE-2026-65481
Vino: Filesystem traversal
Vino is affected by filesystem traversal. Exposure depends on how the affected operation is made reachable by the site. A crafted path can escape the intended directory and reach files or directories elsewhere on the server. The published affected range is n/a through 1.9.
Vino vino 7.5 Pending
Jul 23, 2026 CVE-2026-65480
TheGem: Cross-site scripting
TheGem is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed. The published affected range is n/a through 5.11.1.
TheGem thegem 6.5 Pending
Jul 23, 2026 CVE-2026-65479
Reviewer: A security weakness
Reviewer is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation. The published affected range is n/a through 3.14.2.
Reviewer reviewer 5.4 Pending
Jul 23, 2026 CVE-2026-65478
ListingPro: A security weakness
ListingPro is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation. The published affected range is n/a through 2.9.10.
ListingPro listingpro-plugin 5.4 Pending
Jul 23, 2026 CVE-2026-65477
Tonda Core: Filesystem traversal
Tonda Core is affected by filesystem traversal. Exposure depends on how the affected operation is made reachable by the site. A crafted path can escape the intended directory and reach files or directories elsewhere on the server. The published affected range is n/a through 2.1.2.
Tonda Core tonda-core 7.5 Pending
Jul 23, 2026 CVE-2026-65476
Civi: A security weakness
Civi is affected by a security weakness. The vulnerable path is reachable without authentication. The resulting impact depends on how the affected component exposes the vulnerable operation. The published affected range is n/a through 2.2.4.
Civi civi 5.3 Pending
Jul 23, 2026 CVE-2026-65475
Modula Image Gallery: Cross-site scripting
Modula Image Gallery is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed. The published affected range is 2.14.25 through 2.14.30.
Modula Image Gallery modula-best-grid-gallery 6.5 Pending
Jul 23, 2026 CVE-2026-65474
Ninja Tables: A security weakness
Ninja Tables is affected by a security weakness. The vulnerable path is reachable without authentication. The resulting impact depends on how the affected component exposes the vulnerable operation. The published affected range is n/a through 5.2.10.
Ninja Tables ninja-tables 5.3 Pending
Jul 23, 2026 CVE-2026-65473
Virtue/Ascend/Pinnacle Toolkit: Cross-site scripting
Virtue/Ascend/Pinnacle Toolkit is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed. The published affected range is n/a through 4.9.12.
Virtue/Ascend/Pinnacle Toolkit virtue-toolkit 6.5 Pending
Jul 23, 2026 CVE-2026-65472
Kit (formerly ConvertKit): A security weakness
Kit (formerly ConvertKit) is affected by a security weakness. The vulnerable path is reachable without authentication. The resulting impact depends on how the affected component exposes the vulnerable operation. The published affected range is n/a through 3.3.5.
Kit (formerly ConvertKit) convertkit 5.3 Pending
Jul 23, 2026 CVE-2026-65471
Avada Core: Cross-site request forgery
Avada Core is affected by cross-site request forgery. The vulnerable path is reachable without authentication. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request. The published affected range is n/a through 5.15.6.
Avada Core fusion-core 9.6 Pending
Jul 23, 2026 CVE-2026-65470
Fluent Support: Cross-site scripting
Fluent Support is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed. The published affected range is n/a through 2.3.0.
Fluent Support fluent-support 6.5 Pending
Jul 23, 2026 CVE-2026-65469
AWP Classifieds: A security weakness
AWP Classifieds is affected by a security weakness. The vulnerable path is reachable without authentication. The resulting impact depends on how the affected component exposes the vulnerable operation. The published affected range is n/a through 4.4.7.
AWP Classifieds another-wordpress-classifieds-plugin 5.3 Pending
Jul 23, 2026 CVE-2026-65468
JetBooking: A security weakness
JetBooking is affected by a security weakness. The vulnerable path is reachable without authentication. The resulting impact depends on how the affected component exposes the vulnerable operation. The published affected range is n/a through 4.1.2.
JetBooking jet-booking 5.3 Pending
Jul 23, 2026 CVE-2026-65467
JetEngine: Server-side request forgery
JetEngine is affected by server-side request forgery. Exposure depends on how the affected operation is made reachable by the site. The vulnerable server can be induced to make attacker-selected network requests. The published affected range is n/a through 3.8.11.
JetEngine jet-engine 4.9 Pending
Jul 23, 2026 CVE-2026-65466
JetBooking: Server-side request forgery
JetBooking is affected by server-side request forgery. Exposure depends on how the affected operation is made reachable by the site. The vulnerable server can be induced to make attacker-selected network requests. The published affected range is n/a through 4.1.2.
JetBooking jet-booking 4.9 Pending
Jul 23, 2026 CVE-2026-65465
JetElements For Elementor: Cross-site scripting
JetElements For Elementor is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed. The published affected range is n/a through 2.9.1.1.
JetElements For Elementor jet-elements 6.5 Pending
Jul 23, 2026 CVE-2026-65464
GiveWP: Cross-site request forgery
GiveWP is affected by cross-site request forgery. The vulnerable path is reachable without authentication. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request. The published affected range is n/a through 4.16.3.
GiveWP give 5.4 Pending
Jul 23, 2026 CVE-2026-65463
Masteriyo - LMS: A security weakness
Masteriyo - LMS is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation. The published affected range is n/a through 2.3.1.
Masteriyo - LMS learning-management-system 5.4 Pending
Jul 23, 2026 CVE-2026-65462
Uncanny Automator: SQL injection
Uncanny Automator is affected by SQL injection. Exposure depends on how the affected operation is made reachable by the site. A successful request can alter database queries and expose or modify WordPress data. The published affected range is n/a through 7.3.2.
Uncanny Automator uncanny-automator 7.6 Pending
Jul 23, 2026 CVE-2026-65461
Really Simple CSV Importer: Dangerous file upload
Really Simple CSV Importer is affected by dangerous file upload. Exposure depends on how the affected operation is made reachable by the site. Successful exploitation can place attacker-controlled executable content on the server and may lead to full site compromise. The published affected range is n/a through 1.3.
Really Simple CSV Importer really-simple-csv-importer 9.1 Pending
Jul 23, 2026 CVE-2026-65460
Zarinpal Gateway: Cross-site request forgery
Zarinpal Gateway is affected by cross-site request forgery. The vulnerable path is reachable without authentication. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request. The published affected range is n/a through 5.1.0.
Zarinpal Gateway zarinpal-woocommerce-payment-gateway 4.3 Pending
Jul 23, 2026 CVE-2026-65458
Polylang: A security weakness
Polylang is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation. The published affected range is n/a through 3.8.5.
Polylang polylang 4.3 Pending
Jul 23, 2026 CVE-2026-65457
ЮKassa для WooCommerce: A security weakness
ЮKassa для WooCommerce is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation. The published affected range is n/a through 2.16.1.
ЮKassa для WooCommerce yookassa 4.3 Pending
Jul 23, 2026 CVE-2026-65456
Product Slider for WooCommerce: A security weakness
Product Slider for WooCommerce is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation. The published affected range is n/a through 1.13.62.
Product Slider for WooCommerce woocommerce-products-slider 4.3 Pending
Jul 23, 2026 CVE-2026-65455
MapSVG: Dangerous file upload
MapSVG is affected by dangerous file upload. Exposure depends on how the affected operation is made reachable by the site. Successful exploitation can place attacker-controlled executable content on the server and may lead to full site compromise. The published affected range is n/a through 8.14.0.
MapSVG mapsvg-lite-interactive-vector-maps 9.1 Pending
Jul 23, 2026 CVE-2026-65454
Quiz And Survey Master: SQL injection
Quiz And Survey Master is affected by SQL injection. Exposure depends on how the affected operation is made reachable by the site. A successful request can alter database queries and expose or modify WordPress data. The published affected range is n/a through 11.2.0.
Quiz And Survey Master quiz-master-next 8.5 Pending
Jul 23, 2026 CVE-2026-65453
Ebook Store: A security weakness
Ebook Store is affected by a security weakness. The vulnerable path is reachable without authentication. The resulting impact depends on how the affected component exposes the vulnerable operation. The published affected range is n/a through 6.19.
Ebook Store ebook-store 5.3 Pending
Jul 23, 2026 CVE-2026-65452
Ebook Store: A security weakness
Ebook Store is affected by a security weakness. The vulnerable path is reachable without authentication. The resulting impact depends on how the affected component exposes the vulnerable operation. The published affected range is n/a through 6.19.
Ebook Store ebook-store 5.3 Pending
Jul 23, 2026 CVE-2026-65451
MapSVG: SQL injection
MapSVG is affected by SQL injection. Exposure depends on how the affected operation is made reachable by the site. A successful request can alter database queries and expose or modify WordPress data. The published affected range is n/a through 8.14.0.
MapSVG mapsvg 8.5 Pending
Jul 23, 2026 CVE-2026-65450
MapSVG: SQL injection
MapSVG is affected by SQL injection. Exposure depends on how the affected operation is made reachable by the site. A successful request can alter database queries and expose or modify WordPress data. The published affected range is n/a through 8.14.0.
MapSVG mapsvg-lite-interactive-vector-maps 8.5 Pending
Jul 23, 2026 CVE-2026-65449
MapSVG: Cross-site scripting
MapSVG is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed. The published affected range is n/a through 8.14.0.
MapSVG mapsvg-lite-interactive-vector-maps 6.5 Pending
Jul 23, 2026 CVE-2026-61981
Simple Link Directory Pro: Cross-site request forgery
Simple Link Directory Pro is affected by cross-site request forgery. The vulnerable path is reachable without authentication. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request. The published affected range is n/a through 15.0.8.
Simple Link Directory Pro simple-link-directory-pro 5.4 Pending
Jul 23, 2026 CVE-2026-61973
ShopLentor Pro: A security weakness
ShopLentor Pro is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation. The published affected range is n/a through 2.8.5.
ShopLentor Pro woolentor-addons-pro 4.3 Pending
Jul 23, 2026 CVE-2026-61972
ShopLentor Pro: A security weakness
ShopLentor Pro is affected by a security weakness. The vulnerable path is reachable without authentication. The resulting impact depends on how the affected component exposes the vulnerable operation. The published affected range is n/a through 2.8.5.
ShopLentor Pro woolentor-addons-pro 5.3 Pending
Jul 23, 2026 CVE-2026-61954
PayU India: A security weakness
PayU India is affected by a security weakness. The vulnerable path is reachable without authentication. The resulting impact depends on how the affected component exposes the vulnerable operation. The published affected range is n/a through 3.8.9.
PayU India payu-india 7.5 Pending
Jul 23, 2026 CVE-2026-61951
TrueBooker: Privilege escalation or authentication bypass
TrueBooker is affected by privilege escalation or authentication bypass. The vulnerable path is reachable without authentication. A successful request can grant permissions or access that the caller should not possess. The published affected range is n/a through 1.2.3.
TrueBooker truebooker-appointment-booking 9.8 Pending
Jul 23, 2026 CVE-2026-61950
TrueBooker: SQL injection
TrueBooker is affected by SQL injection. The vulnerable path is reachable without authentication. A successful request can alter database queries and expose or modify WordPress data. The published affected range is n/a through 1.2.3.
TrueBooker truebooker-appointment-booking 9.3 Pending
Jul 23, 2026 CVE-2026-61949
Bookly: SQL injection
Bookly is affected by SQL injection. The vulnerable path is reachable without authentication. A successful request can alter database queries and expose or modify WordPress data. The published affected range is n/a through 27.7.
Bookly bookly-responsive-appointment-booking-tool 9.3 Pending
Jul 23, 2026 CVE-2026-61948
WPDM – Premium Packages: SQL injection
WPDM – Premium Packages is affected by SQL injection. The vulnerable path is reachable without authentication. A successful request can alter database queries and expose or modify WordPress data. The published affected range is n/a through 6.2.0.
WPDM – Premium Packages wpdm-premium-packages 9.3 Pending
Jul 23, 2026 CVE-2026-61947
Form Vibes – Database Manager for Forms: Cross-site scripting
Form Vibes – Database Manager for Forms is affected by cross-site scripting. The vulnerable path is reachable without authentication. Injected script can execute in the affected site's origin when the vulnerable output is viewed. The published affected range is n/a through 1.5.2.
Form Vibes – Database Manager for Forms form-vibes 7.1 Pending
Jul 23, 2026 CVE-2026-61946
Easy Appointments: A security weakness
Easy Appointments is affected by a security weakness. The vulnerable path is reachable without authentication. The resulting impact depends on how the affected component exposes the vulnerable operation. The published affected range is n/a through 3.12.27.
Easy Appointments easy-appointments 6.5 Pending
Jul 23, 2026 CVE-2026-61945
WooCommerce Product Stock Alert: A security weakness
WooCommerce Product Stock Alert is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation. The published affected range is n/a through 3.0.6.
WooCommerce Product Stock Alert woocommerce-product-stock-alert 6.5 Pending
Jul 23, 2026 CVE-2026-61944
Bookly: Cross-site scripting
Bookly is affected by cross-site scripting. The vulnerable path is reachable without authentication. Injected script can execute in the affected site's origin when the vulnerable output is viewed. The published affected range is n/a through 27.7.
Bookly bookly-responsive-appointment-booking-tool 7.1 Pending
Jul 23, 2026 CVE-2026-61943
WPDM – Premium Packages: A security weakness
WPDM – Premium Packages is affected by a security weakness. The vulnerable path is reachable without authentication. The resulting impact depends on how the affected component exposes the vulnerable operation. The published affected range is n/a through 6.2.0.
WPDM – Premium Packages wpdm-premium-packages 7.5 Pending
Jul 23, 2026 CVE-2026-59555
Participants Database: Arbitrary file deletion
Participants Database is affected by arbitrary file deletion. The vulnerable path is reachable without authentication. A successful request can remove files outside the intended scope and may make the site unavailable. The published affected range is n/a through 2.7.8.3.
Participants Database participants-database 10.0 Pending
Jul 23, 2026 CVE-2026-59554
Ziina: A security weakness
Ziina is affected by a security weakness. The vulnerable path is reachable without authentication. The resulting impact depends on how the affected component exposes the vulnerable operation. The published affected range is n/a through 1.2.21.
Ziina ziina 7.5 Pending
Jul 23, 2026 CVE-2026-59547
Payment Gateway for PayPal on WooCommerce: A security weakness
Payment Gateway for PayPal on WooCommerce is affected by a security weakness. The vulnerable path is reachable without authentication. The resulting impact depends on how the affected component exposes the vulnerable operation. The published affected range is n/a through 9.1.4.
Payment Gateway for PayPal on WooCommerce woo-paypal-gateway 7.5 Pending
Jul 23, 2026 CVE-2026-59545
miniOrange Discord Integration: A security weakness
miniOrange Discord Integration is affected by a security weakness. The vulnerable path is reachable without authentication. The resulting impact depends on how the affected component exposes the vulnerable operation. The published affected range is n/a through 2.2.4.
miniOrange Discord Integration miniorange-discord-integration 8.1 Pending
Jul 23, 2026 CVE-2026-59544
Thrive Quiz Builder: Code execution
Thrive Quiz Builder is affected by code execution. The vulnerable path is reachable without authentication. Successful exploitation can run attacker-controlled code in the WordPress hosting account. The published affected range is n/a through 10.9.3.0.
Thrive Quiz Builder thrive-quiz-builder 9.8 Pending