WordPress Vulnerabilities
A searchable, scoreable changelog of WordPress core, plugin, and theme vulnerabilities, including affected ranges and safe-version guidance where the CVE record supports it.
36,749 published entries · feed refreshed 2026-08-19
This week's summary
- 36,749
- Tracked total
- 75
- Critical this week
- 16,044
- Plugins covered
- 47
- Core CVEs, all time
Unauthenticated & critical — past year, prioritized by observed prevalence
- Elementor Pro permits unauthenticated dangerous-file upload CVE-2026-32475 · 9.0 CVE/CNA
- W3 Total Cache request paths permit unauthenticated arbitrary file overwrite CVE-2026-18051 · 10.0 CVE/CNA
- Avada (Fusion) Builder: Code execution CVE-2026-6279 · 9.8 CVE/CNA
- Avada (Fusion) Builder: Code execution CVE-2026-8713 · 9.1 CVE/CNA
- Broken Link Checker plain-permalink variables permit unauthenticated code execution CVE-2026-18937 · 9.0 CVE/CNA
- WooCommerce Subscriptions HPOS input permits unauthenticated object injection CVE-2026-18391 · 9.8 CVE/CNA
- Ninja Forms: Cross-site scripting CVE-2026-65048 · 9.3 CVE/CNA
- Ninja Forms: Code execution CVE-2025-9083 · 9.8 CVE/CNA
36,749 results
| Aug 19, 2026 |
CVE-2026-18315
TrueBooker permits unauthenticated administrator account takeover
TrueBooker through 1.2.6 exposes the admin_user_create_cus AJAX handler without an authentication or capability check. The handler passes the attacker-controlled truebooker_wp_user_id parameter directly to wp_update_user(), allowing an unauthenticated attacker to replace the email address of any WordPress user, including an administrator. The attacker can then use WordPress's standard lost-password flow to reset the password and take over the targeted account.
|
TrueBooker – Appointment Booking and Scheduler System | truebooker-appointment-booking |
9.8 | Pending |
| Aug 19, 2026 |
CVE-2026-32475
Elementor Pro permits unauthenticated dangerous-file upload
Elementor Pro through 4.2.1 permits an unauthenticated attacker to upload a file of a dangerous type under an undisclosed high-complexity condition. Successful exploitation can place malicious executable content on the WordPress server and may lead to remote code execution and full site compromise. The Patchstack CNA record does not disclose the endpoint or action, upload parameter, handler function, destination path, permitted file types, or prerequisite responsible for the high attack complexity.
|
elementor-pro | elementor-pro |
9.0 | Pending |
| Aug 19, 2026 |
CVE-2026-73394
Stitch Express: Broken access control
Stitch Express is affected by broken access control. The vulnerable path is reachable without authentication. A successful request can reach data or an operation that should be restricted to another user or a more privileged role. The published affected range is n/a through 1.9.0. The public source does not disclose the vulnerable endpoint, action, parameter or function, so the precise input path remains unknown.
|
Stitch Express | stitch-express |
7.5 | Pending |
| Aug 19, 2026 |
CVE-2026-73391
Total Donations: SQL injection
Total Donations is affected by SQL injection. The vulnerable path is reachable without authentication. A successful request can alter database queries and expose or modify WordPress data. The published affected range is n/a through 2.0.5. The public source does not disclose the vulnerable endpoint, action, parameter or function, so the precise input path remains unknown.
|
Total Donations | totaldonations |
9.3 | Pending |
| Aug 19, 2026 |
CVE-2026-73390
Total Donations: Privilege escalation or authentication bypass
Total Donations is affected by privilege escalation or authentication bypass. The vulnerable path is reachable without authentication. A successful request can grant permissions or access that the caller should not possess. The published affected range is n/a through 2.0.5. The public source does not disclose the vulnerable endpoint, action, parameter or function, so the precise input path remains unknown.
|
Total Donations | totaldonations |
9.8 | Pending |
| Aug 19, 2026 |
CVE-2026-73389
Kalles Addons: Code execution
Kalles Addons is affected by code execution. The vulnerable path is reachable without authentication. Successful exploitation can run attacker-controlled code in the WordPress hosting account. The published affected range is n/a through 1.0.6. The public source does not disclose the vulnerable endpoint, action, parameter or function, so the precise input path remains unknown.
|
Kalles Addons | kalles-addons |
9.8 | Pending |
| Aug 19, 2026 |
CVE-2026-73388
Nikstore Core: SQL injection
Nikstore Core is affected by SQL injection. The vulnerable path is reachable without authentication. A successful request can alter database queries and expose or modify WordPress data. The published affected range is n/a through 1.5. The public source does not disclose the vulnerable endpoint, action, parameter or function, so the precise input path remains unknown.
|
Nikstore Core | nikstore-core |
9.3 | Pending |
| Aug 19, 2026 |
CVE-2026-73387
Resido: Filesystem traversal
Resido is affected by filesystem traversal. The vulnerable path is reachable without authentication. A crafted path can escape the intended directory and reach files or directories elsewhere on the server. The published affected range is n/a through 1.5. The public source does not disclose the vulnerable endpoint, action, parameter or function, so the precise input path remains unknown.
|
Resido | resido |
8.1 | Pending |
| Aug 19, 2026 |
CVE-2026-73386
Track Geolocation Of Users Using Contact Form 7: Sensitive information exposure
Track Geolocation Of Users Using Contact Form 7 is affected by sensitive information exposure. The vulnerable path is reachable without authentication. Successful exploitation can disclose data that should not be available to the caller. The published affected range is n/a through 3.0.2. The public source does not disclose the vulnerable endpoint, action, parameter or function, so the precise input path remains unknown.
|
Track Geolocation Of Users Using Contact Form 7 | track-geolocation-of-users-using-contact-form-7 |
7.5 | Pending |
| Aug 19, 2026 |
CVE-2026-73385
Outranking Plugin Options: Broken access control
Outranking Plugin Options is affected by broken access control. The vulnerable path is reachable without authentication. A successful request can reach data or an operation that should be restricted to another user or a more privileged role. The published affected range is n/a through 1.1.3. The public source does not disclose the vulnerable endpoint, action, parameter or function, so the precise input path remains unknown.
|
Outranking Plugin Options | outranking |
7.5 | Pending |
| Aug 19, 2026 |
CVE-2026-73384
Pay with Contact Form 7: Sensitive information exposure
Pay with Contact Form 7 is affected by sensitive information exposure. The vulnerable path is reachable without authentication. Successful exploitation can disclose data that should not be available to the caller. The published affected range is n/a through 1.0.4. The public source does not disclose the vulnerable endpoint, action, parameter or function, so the precise input path remains unknown.
|
Pay with Contact Form 7 | pay-with-contact-form-7 |
7.5 | Pending |
| Aug 19, 2026 |
CVE-2026-73364
Flexible Subscriptions: Code execution
Flexible Subscriptions is affected by code execution. Exploitation requires an authenticated customer account. Successful exploitation can run attacker-controlled code in the WordPress hosting account. The published affected range is n/a through 1.8.1. The public source does not disclose the vulnerable endpoint, action, parameter or function, so the precise input path remains unknown.
|
Flexible Subscriptions | flexible-subscriptions |
9.8 | Pending |
| Aug 19, 2026 |
CVE-2026-73363
Taxi Booking Manager for WooCommerce: Broken access control
Taxi Booking Manager for WooCommerce is affected by broken access control. The vulnerable path is reachable without authentication. A successful request can reach data or an operation that should be restricted to another user or a more privileged role. The published affected range is n/a to < 2.0.8. The public source does not disclose the vulnerable endpoint, action, parameter or function, so the precise input path remains unknown.
|
Taxi Booking Manager for WooCommerce | ecab-taxi-booking-manager |
6.5 | Pending |
| Aug 19, 2026 |
CVE-2026-73354
SimplyRETS Real Estate IDX: Cross-site scripting
SimplyRETS Real Estate IDX is affected by cross-site scripting. The vulnerable path is reachable without authentication. Injected script can execute in the affected site's origin when the vulnerable output is viewed. The published affected range is n/a through 3.2.8. The public source does not disclose the vulnerable endpoint, action, parameter or function, so the precise input path remains unknown.
|
SimplyRETS Real Estate IDX | simply-rets |
7.1 | Pending |
| Aug 19, 2026 |
CVE-2026-73347
TrueBooker: Privilege escalation or authentication bypass
TrueBooker is affected by privilege escalation or authentication bypass. The vulnerable path is reachable without authentication. A successful request can grant permissions or access that the caller should not possess. The published affected range is n/a through 1.2.6. The public source does not disclose the vulnerable endpoint, action, parameter or function, so the precise input path remains unknown.
|
TrueBooker | truebooker-appointment-booking |
9.8 | Pending |
| Aug 19, 2026 |
CVE-2026-73185
NGG Smart Image Search: SQL injection
NGG Smart Image Search is affected by SQL injection. The vulnerable path is reachable without authentication. A successful request can alter database queries and expose or modify WordPress data. The published affected range is n/a to < 4.0.0. The public source does not disclose the vulnerable endpoint, action, parameter or function, so the precise input path remains unknown.
|
NGG Smart Image Search | ngg-smart-image-search |
9.3 | Pending |
| Aug 19, 2026 |
CVE-2026-73184
Global Gallery: Cross-site scripting
Global Gallery is affected by cross-site scripting. The vulnerable path is reachable without authentication. Injected script can execute in the affected site's origin when the vulnerable output is viewed. The published affected range is n/a through 11.1.2. The public source does not disclose the vulnerable endpoint, action, parameter or function, so the precise input path remains unknown.
|
Global Gallery | global-gallery |
7.1 | Pending |
| Aug 19, 2026 |
CVE-2026-73183
Maps Marker Pro: SQL injection
Maps Marker Pro is affected by SQL injection. The vulnerable path is reachable without authentication. A successful request can alter database queries and expose or modify WordPress data. The published affected range is n/a through 4.32. The public source does not disclose the vulnerable endpoint, action, parameter or function, so the precise input path remains unknown.
|
Maps Marker Pro | maps-marker-pro |
9.3 | Pending |
| Aug 19, 2026 |
CVE-2026-73182
BBQ Pro: Cross-site scripting
BBQ Pro is affected by cross-site scripting. The vulnerable path is reachable without authentication. Injected script can execute in the affected site's origin when the vulnerable output is viewed. The published affected range is n/a through 3.9. The public source does not disclose the vulnerable endpoint, action, parameter or function, so the precise input path remains unknown.
|
BBQ Pro | bbq-pro |
7.1 | Pending |
| Aug 19, 2026 |
CVE-2026-66668
Community by PeepSo: SQL injection
Community by PeepSo is affected by SQL injection. Exploitation requires an authenticated subscriber account. A successful request can alter database queries and expose or modify WordPress data. The published affected range is n/a through 9.0.5.2. The public source does not disclose the vulnerable endpoint, action, parameter or function, so the precise input path remains unknown.
|
Community by PeepSo | peepso-core |
8.5 | Pending |
| Aug 19, 2026 |
CVE-2026-66613
JetEngine: Code execution
JetEngine is affected by code execution. The vulnerable path is reachable without authentication. Successful exploitation can run attacker-controlled code in the WordPress hosting account. The published affected range is n/a through 3.8.14. The public source does not disclose the vulnerable endpoint, action, parameter or function, so the precise input path remains unknown.
|
JetEngine | jet-engine |
9.8 | Pending |
| Aug 19, 2026 |
CVE-2026-66596
Newsletter: Cross-site scripting
Newsletter is affected by cross-site scripting. The vulnerable path is reachable without authentication. Injected script can execute in the affected site's origin when the vulnerable output is viewed. The published affected range is n/a through 9.3.3. The public source does not disclose the vulnerable endpoint, action, parameter or function, so the precise input path remains unknown.
|
Newsletter | newsletter |
7.1 | Pending |
| Aug 19, 2026 |
CVE-2026-61986
Contest Gallery: Cross-site scripting
Contest Gallery is affected by cross-site scripting. The vulnerable path is reachable without authentication. Injected script can execute in the affected site's origin when the vulnerable output is viewed. The published affected range is n/a through 30.0.5. The public source does not disclose the vulnerable endpoint, action, parameter or function, so the precise input path remains unknown.
|
Contest Gallery | contest-gallery |
7.1 | Pending |
| Aug 19, 2026 |
CVE-2026-32552
YITH WooCommerce Membership Premium: SQL injection
YITH WooCommerce Membership Premium is affected by SQL injection. Exploitation requires an authenticated subscriber account. A successful request can alter database queries and expose or modify WordPress data. The published affected range is n/a through 2.33.0. The public source does not disclose the vulnerable endpoint, action, parameter or function, so the precise input path remains unknown.
|
YITH WooCommerce Membership Premium | yith-woocommerce-membership-premium |
8.5 | Pending |
| Aug 19, 2026 |
CVE-2026-75981
TranslatePress gettext markers permit unauthenticated stored XSS
TranslatePress through 3.2.5 unconditionally converts the plain-text gettext markers #!trpst# and #!trpen# into < and > in translate_page(). An unauthenticated attacker can place those markers around an image element in a comment; the marker text survives wp_kses, then becomes a real HTML tag when the post is rendered in a secondary language. Because remove_tags_from_output() removes script and style elements but not an image event handler, the resulting payload executes in each visitor's browser.
|
TranslatePress – Translate Multilingual sites with AI Translation | translatepress-multilingual |
7.2 | Pending |
| Aug 19, 2026 |
CVE-2026-15780
WP Statistics hit tracking permits unauthenticated stored XSS
WP Statistics through 14.16.8 exposes the public /wp-statistics/v2/hit REST endpoint with a request signature available from the public homepage. An unauthenticated attacker can submit a base64-encoded page_uri whose utm_campaign value overrides the previously sanitized REQUEST_URI and is stored in the database. The malicious campaign value is later rendered without adequate escaping, executing arbitrary script when a user opens an affected statistics view or page.
|
WP Statistics – Simple, privacy-friendly Google Analytics alternative | wp-statistics |
7.2 | Pending |
| Aug 19, 2026 |
CVE-2026-15446
EWWW lazy-load data-script attributes permit Contributor stored XSS
EWWW Image Optimizer through 8.7.3 allows a Contributor to save a crafted image element with class=lazyload and an attacker-controlled data-script URL in post content. When a visitor opens the post, the bundled lazysizes ls.unveilhooks add-on reads that attribute and dynamically creates a script element for the supplied URL, executing attacker-controlled JavaScript in the site's origin.
|
EWWW Image Optimizer | ewww-image-optimizer |
6.4 | Pending |
| Aug 19, 2026 |
CVE-2026-19842
SAML Single Sign On can trust an attacker certificate and permit administrator impersonation
SAML Single Sign On before 5.4.7 stores a certificate carried in a SAML response before verifying that response's signature. An unauthenticated attacker can place an attacker-controlled certificate in that pending state; if an administrator uses the plugin's one-click control to promote it to the trusted signing certificate, the attacker can then authenticate as any user, including an administrator. The record does not disclose the SAML endpoint, response field, storage key or promotion-control action.
|
SAML Single Sign On | saml-single-sign-on |
8.8 | Pending |
| Aug 19, 2026 |
CVE-2026-19782
WPS Bidouille exposes every registered user's email address to Subscribers
WPS Bidouille before 1.33.5 lacks an authorization check on an authenticated AJAX action. Any logged-in user, including a Subscriber, can invoke it and retrieve the email addresses of all registered users. The authoritative record does not disclose the AJAX action name, request parameters, handler function or response format.
|
WPS Bidouille | wps-bidouille |
5.4 | Pending |
| Aug 19, 2026 |
CVE-2026-19709
Membership For WooCommerce accepts an empty API secret and exposes membership records
Membership For WooCommerce before 3.1.2 compares a request secret without first confirming that the site generated an API consumer secret. On a site where the API is enabled but no keys were created, an unauthenticated request can pass that check, reach the plugin's REST routes and disclose any user's membership-plan details. The record does not disclose the REST route names, secret parameter, comparison function or returned fields.
|
Membership For WooCommerce | membership-for-woocommerce |
5.3 | Pending |
| Aug 19, 2026 |
CVE-2026-19417
KiviCare patients can download other patients' medical files
KiviCare before 4.5.4 does not verify that a patient-level user is entitled to the requested media file. An authenticated patient can select any WordPress media item and download it, including medical reports uploaded by other patients. The authoritative record does not disclose the route or action, media identifier, entitlement function, response mechanism or affected file types.
|
KiviCare | kivicare-clinic-management-system |
6.5 | Pending |
| Aug 19, 2026 |
CVE-2026-19416
KiviCare patients can cancel or reschedule other patients' appointments
KiviCare before 4.5.4 does not verify that the requesting patient owns the appointment being modified. An authenticated KiviCare patient can select another patient's appointment and cancel or reschedule it. The authoritative record does not disclose the route or action, appointment-ID parameter, ownership function or request schema.
|
KiviCare | kivicare-clinic-management-system |
4.3 | Pending |
| Aug 19, 2026 |
CVE-2026-19406
Easy Appointments Contributors can read every booking
Easy Appointments before 4.0.1 does not restrict an appointment-listing REST endpoint to records belonging to the requesting user. A Contributor can retrieve every booking on the site, including customer names, schedules and appointment statuses. The authoritative record does not disclose the REST route, HTTP method, query parameters, permission callback or complete returned fields.
|
Easy Appointments | easy-appointments |
2.7 | Pending |
| Aug 19, 2026 |
CVE-2026-19056
ProSolution WP Client admin-page attributes permit reflected XSS
ProSolution WP Client before 2.0.11 reflects an attacker-controlled parameter into an HTML attribute on an administrative page without adequate sanitization or escaping. An unauthenticated attacker can induce a logged-in administrator to submit a crafted request, causing script to execute in that administrator's browser under the site origin. The record does not disclose the admin page, parameter, request method or rendering function.
|
ProSolution WP Client | prosolution-wp-client |
7.1 | Pending |
| Aug 19, 2026 |
CVE-2026-19055
ProSolution WP Client public-page attributes permit reflected XSS
ProSolution WP Client before 2.0.11 reflects several attacker-controlled parameters into HTML attributes on public pages without adequate sanitization or escaping. An unauthenticated attacker can direct any visitor, including an authenticated administrator, to a crafted request that executes script under the site's origin. The record does not disclose the public pages, parameters, request method or rendering functions.
|
ProSolution WP Client | prosolution-wp-client |
7.1 | Pending |
| Aug 19, 2026 |
CVE-2026-18937
Broken Link Checker plain-permalink variables permit unauthenticated code execution
Broken Link Checker before 2.4.12 does not constrain query variables accepted from unauthenticated requests on sites using plain permalinks. An attacker can overwrite arbitrary PHP global variables; when a classic, non-block theme is active, the resulting state can execute arbitrary server-side code. The authoritative record does not disclose the vulnerable request parameter names, overwritten globals, affected theme path or final execution function.
|
Broken Link Checker | broken-link-checker |
9.0 | Pending |
| Aug 19, 2026 |
CVE-2026-18779
TrueBooker permits unauthenticated deletion of appointments and payment records
TrueBooker before 1.2.7 lacks authorization checks on an AJAX action that deletes appointment records. An unauthenticated caller can target arbitrary appointments and remove the associated booking items and payment records. The authoritative record does not disclose the AJAX action, appointment identifier, handler function or deletion sequence.
|
TrueBooker – Appointment Booking and Scheduler System | truebooker-appointment-booking |
5.3 | Pending |
| Aug 19, 2026 |
CVE-2026-18778
TrueBooker exposes booking-customer personal information without authentication
TrueBooker before 1.2.7 lacks authorization checks on AJAX actions that return appointment-customer records. An unauthenticated caller can retrieve names, email addresses, phone numbers and postal addresses belonging to customers who booked appointments. The record does not disclose the action names, record identifier, handler functions or response format.
|
TrueBooker – Appointment Booking and Scheduler System | truebooker-appointment-booking |
5.3 | Pending |
| Aug 19, 2026 |
CVE-2026-18777
TrueBooker permits unauthenticated appointment-status changes and notification email
TrueBooker before 1.2.7 lacks authorization checks on an AJAX action that changes appointment status. An unauthenticated caller can target arbitrary appointments, alter their status and trigger notification email to affected customers. The record does not disclose the AJAX action, appointment and status parameters, handler function or valid status values.
|
TrueBooker – Appointment Booking and Scheduler System | truebooker-appointment-booking |
5.3 | Pending |
| Aug 19, 2026 |
CVE-2026-18776
TrueBooker permits unauthenticated administrator email changes and account takeover
TrueBooker before 1.2.7 lacks authorization checks on AJAX actions that change user email addresses. An unauthenticated caller can replace the email address of an arbitrary user, including an administrator, then use WordPress password reset to take over that account. The record does not disclose the AJAX actions, user and email parameters, handler functions or nonce behavior.
|
TrueBooker – Appointment Booking and Scheduler System | truebooker-appointment-booking |
9.8 | Pending |
| Aug 19, 2026 |
CVE-2026-18466
WP Maps Subscribers can create unlimited autoloaded database options
WP Maps before 4.9.8 exposes an AJAX action without a capability check or nonce validation. A Subscriber can invoke it repeatedly to create an unlimited number of database options that autoload on every page request, consuming database and PHP resources and degrading site availability. The record does not disclose the AJAX action, option-name and value parameters or handler function.
|
WP Maps | wp-maps |
5.4 | Pending |
| Aug 19, 2026 |
CVE-2026-18231
WP Directory Kit public AJAX exposes role-holder usernames and email addresses
WP Directory Kit before 1.5.7 performs no authorization check on a public AJAX action and returns unfiltered database rows. An unauthenticated caller can use it to retrieve usernames and email addresses belonging to users who hold the plugin's own roles. The record does not disclose the AJAX action, request parameters, query function, returned columns or role names.
|
WP Directory Kit | wpdirectorykit |
5.3 | Pending |
| Aug 19, 2026 |
CVE-2026-18202
JetEngine permits Author SVG uploads containing stored JavaScript
JetEngine before 3.8.14 adds SVG to the site-wide upload allowlist without sanitizing file contents. A user with upload_files, such as an Author, can upload an SVG containing JavaScript that executes when any user opens it; on multisite the same behavior overrides a network administrator's upload-type restriction. The record does not disclose the upload endpoint, field, sanitization function, file URL or exact multisite setting path.
|
JetEngine | jet-engine |
6.8 | Pending |
| Aug 19, 2026 |
CVE-2026-18051
W3 Total Cache request paths permit unauthenticated arbitrary file overwrite
W3 Total Cache before 2.10.5 does not validate the request path used to construct cache-file names. An unauthenticated attacker can write into any existing server directory and overwrite the target name; on Apache the flaw can overwrite .htaccess, break the site and remove hardening rules. The record does not disclose the public request form, path parameter, cache-writing function, required filesystem permissions or exact filename constraints.
|
W3 Total Cache | w3-total-cache |
10.0 | Pending |
| Aug 19, 2026 |
CVE-2026-18031
TabaPay Gateway callbacks permit unauthenticated arbitrary-user login
TabaPay Gateway through 1.4.0 does not validate its payment callback before establishing a session for the account associated with the referenced order. An unauthenticated attacker can target an order belonging to any registered user, including an administrator, and receive that user's authenticated session. The record does not disclose the callback URL, order identifier, validation function, session function or order-discovery method.
|
TabaPay Gateway | tabapay-gateway |
9.8 | Pending |
| Aug 19, 2026 |
CVE-2026-17565
Animation Addons for Elementor exposes unauthenticated SSRF responses
Animation Addons for Elementor before 2.7.2 uses an unauthenticated user-supplied value to build the host of a server-side HTTP request without adequate validation. An attacker can make the WordPress server request internal hosts and read the responses back. The record does not disclose the endpoint or action, host parameter, request function, permitted schemes and ports, redirect behavior or response format.
|
Animation Addons for Elementor | animation-addons-for-elementor |
7.2 | Pending |
| Aug 19, 2026 |
CVE-2026-16979
SmartCrawl Subscribers can enumerate private titles and post-meta keys
SmartCrawl before 3.16.3 omits capability checks from two AJAX actions. A Subscriber can select post IDs to read titles belonging to private and draft posts and enumerate stored post-meta key names. The record does not disclose the AJAX action names, request parameters, handler functions, response format or whether post content is exposed.
|
SmartCrawl SEO checker, analyzer & optimizer | smartcrawl-seo-checker-analyzer-optimizer |
4.3 | Pending |
| Aug 19, 2026 |
CVE-2026-16950
Product Shortlist permits unauthenticated SQL injection
Product Shortlist through 1.0.4 places an unauthenticated request parameter into an SQL statement without adequate sanitization and escaping. An attacker can alter the resulting database query and potentially disclose or modify WordPress data. The record does not disclose the endpoint or action, parameter, query, database function or extraction method.
|
Product Shortlist | product-shortlist |
8.6 | Pending |
| Aug 19, 2026 |
CVE-2026-16617
Simple File List public descriptions permit unauthenticated stored XSS
Simple File List through 6.3.11 fails to sanitize and escape a file description before rendering it in the public file list. When front-end file management is enabled, an unauthenticated user can store script in a description that executes for every visitor who views the list. The record does not disclose the upload or edit action, description parameter, storage function or rendering sink.
|
Simple File List | simple-file-list |
8.8 | Pending |
| Aug 19, 2026 |
CVE-2026-16616
Simple File List public move operations permit arbitrary file read and relocation
Simple File List through 6.3.11 does not validate the source path used by a file-move operation reachable without authentication. An attacker can read arbitrary server files and relocate critical files outside the web root, causing sensitive-information disclosure, service disruption and potential site takeover. The record does not disclose the action or route, path parameter, move function, response mechanism or filesystem constraints.
|
Simple File List | simple-file-list |
8.6 | Pending |
| Aug 19, 2026 |
CVE-2026-16570
NextScripts admin query parameters permit reflected XSS
NextScripts: Social Networks Auto-Poster before 4.4.8 reflects query-string parameters on an administrative page without adequate escaping. An unauthenticated attacker can trick a logged-in user, including an administrator, into opening a crafted link that executes script under the site's origin. The record does not disclose the admin page, parameter names or rendering functions.
|
NextScripts: Social Networks Auto-Poster | nextscripts-social-networks-auto-poster |
7.1 | Pending |
| Aug 19, 2026 |
CVE-2026-16058
YayCurrency exposes multi-vendor order and earnings records without authentication
YayCurrency before 3.3.5 omits capability and ownership checks from several unauthenticated multi-vendor integration handlers. An attacker can iterate identifiers to read store order totals and vendor earnings, balance ledgers and withdrawal histories. The record does not disclose the handlers or routes, identifier parameters, vendor integrations, returned fields or enumeration bounds.
|
YayCurrency | yaycurrency |
5.3 | Pending |
| Aug 19, 2026 |
CVE-2026-15253
Easy Media Replace attachment titles permit Author stored XSS in the media library
Easy Media Replace through 0.2.0 outputs an attachment title inside an HTML attribute in the media-library list view without adequate sanitization or escaping. An Author can store script in a title that executes when a higher-privileged user views the media library. The record does not disclose the upload or edit action, title parameter, list-view template or exact attribute context.
|
Easy Media Replace | easy-media-replace |
6.8 | Pending |
| Aug 19, 2026 |
CVE-2026-14861
User Verification permits unauthenticated verification resets and account lockout
User Verification by PickPlugins through 2.0.47 neither verifies that a resend-verification request may act on the supplied user nor binds its protecting token to that user. An unauthenticated attacker can reset any account's email-verification status, including an administrator's, and lock that user out. The record does not disclose the endpoint or action, user parameter, token field, reset function or email behavior.
|
User Verification by PickPlugins | user-verification-by-pickplugins |
7.5 | Pending |
| Aug 19, 2026 |
CVE-2026-14826
QSM Contributors can read other users' quiz notification configuration
Quiz and Survey Master before 11.2.4 omits a per-object ownership check from REST routes that return quiz email-notification and results-page configuration. A Contributor can select a quiz created by another user and read its configuration, including notification-recipient email addresses. The record does not disclose the REST route names, quiz-ID parameter, permission callback or complete configuration schema.
|
Quiz and Survey Master (QSM) | quiz-master-next |
2.7 | Pending |
| Aug 19, 2026 |
CVE-2026-14825
QSM Contributors can modify other users' quiz text settings
Quiz and Survey Master before 11.2.4 omits a per-object ownership check before saving a quiz's front-end text settings. A Contributor can select a quiz created by another user and replace the text shown to visitors. The record does not disclose the route or action, quiz-ID and text parameters, permission callback, writable settings or persistence function.
|
Quiz and Survey Master (QSM) | quiz-master-next |
2.7 | Pending |
| Aug 19, 2026 |
CVE-2026-14334
Booking Calendar permits unauthenticated stored-XSS SVG uploads
Booking calendar, Appointment Booking System 3.2.18 through 3.2.36 does not properly sanitize uploaded SVG files. An unauthenticated booking submitter can upload an SVG that bypasses the plugin's script stripping; its JavaScript executes when the file is opened, including by an administrator reviewing the booking. The record does not disclose the submission route or action, file field, sanitizer, storage path or review interface.
|
Booking calendar, Appointment Booking System | booking-calendar |
8.8 | Pending |
| Aug 19, 2026 |
CVE-2026-14287
10Web Booster token validation permits unauthenticated stored XSS
10Web Booster before 2.33.5 incorrectly validates an access token on an unauthenticated request handler and renders attacker-supplied stylesheet content into the page head without escaping. An attacker can store markup that executes as JavaScript for anonymous visitors to the affected page. The record does not disclose the handler or route, token and stylesheet parameters, storage key or page-head rendering function.
|
10Web Booster | 10web-booster |
4.7 | Pending |
| Aug 19, 2026 |
CVE-2026-14196
WCFM Marketplace vendors can delete reviews belonging to other stores
WCFM Marketplace before 3.8.1 does not verify that the current marketplace vendor owns a selected review before allowing it to be unapproved or permanently deleted. Any vendor can therefore modify or delete reviews belonging to another vendor's store. The record does not disclose the endpoint or action, review-ID parameter, ownership function or nonce behavior.
|
WCFM Marketplace | wcfm-marketplace |
4.3 | Pending |
| Aug 19, 2026 |
CVE-2026-13175
Eventin Contributors can modify or delete other users' schedules
Eventin before 4.1.21 does not verify schedule ownership before allowing a record to be modified or deleted. A Contributor can select schedule entries created by another user and alter or remove them. The record does not disclose the route or action, schedule identifier, ownership function, editable fields or deletion function.
|
Eventin | wp-event-solution |
6.5 | Pending |
| Aug 19, 2026 |
CVE-2026-13174
Eventin Contributors can permanently delete other users' accounts
Eventin before 4.1.21 fails to verify ownership or capability before deleting a user account. A Contributor can select and permanently delete accounts belonging to other users. The record does not disclose the endpoint or action, user-ID parameter, deletion function, protected-role behavior or nonce checks.
|
Eventin | wp-event-solution |
7.2 | Pending |
| Aug 19, 2026 |
CVE-2026-13173
Eventin Contributors can change other users' roles and metadata
Eventin before 4.1.21 does not verify permission to edit another user before assigning roles and updating user metadata during speaker creation. A Contributor can target another account and modify its role and metadata. The record does not disclose the speaker endpoint or action, target-user and role parameters, capability check, assignable roles or metadata keys.
|
Eventin | wp-event-solution |
2.7 | Pending |
| Aug 19, 2026 |
CVE-2026-13169
Eventin Contributors can alter, delete or take ownership of other users' events
Eventin before 4.1.21 does not properly verify event ownership before modification, deletion or author reassignment. A Contributor can target events created by other users, including administrators, and alter, remove or take ownership of them. The record does not disclose the endpoint or action, event and author parameters, ownership function or writable fields.
|
Eventin | wp-event-solution |
8.1 | Pending |
| Aug 19, 2026 |
CVE-2026-12983
Dinatur permits unauthenticated SQL injection and database-table truncation
Dinatur through 1.18 places unauthenticated user input into an SQL query without adequate sanitization and escaping. The same handler also truncates a plugin database table without any authorization check, allowing an unauthenticated visitor both to inject SQL and wipe the plugin's stored data. The record does not disclose the handler route or action, parameters, SQL statements, table name or database function.
|
Dinatur | dinatur |
8.6 | Pending |
| Aug 19, 2026 |
CVE-2026-11565
Advanced File Manager grants low-role users arbitrary file read and overwrite
Advanced File Manager before 5.4.13 omits capability checks from several file-management AJAX actions. Any role an administrator has granted plugin access, potentially as low as Subscriber, can read arbitrary server files including sensitive configuration and overwrite existing non-PHP files; the record states that this can be leveraged to compromise administrators and the site. The record does not disclose the action names, path and content parameters, handler functions, overwrite constraints or required plugin-access setting.
|
Advanced File Manager | advanced-file-manager |
8.5 | Pending |
| Aug 19, 2026 |
CVE-2026-19942
Atarim Author-level attachment paths permit arbitrary file deletion
Atarim through 5.1.1 lets an Author first invoke the atarim/update-post-field ability to replace an attacker-owned attachment's _wp_attached_file metadata with a directory-traversal path, then invoke atarim/replace-media-file. The AVCF_Abilities_Media::register() replace-media-file callback passes the resolved get_attached_file() path to file deletion without adequate confinement, allowing arbitrary server files such as wp-config.php to be removed and potentially producing remote code execution through the resulting site state.
|
Atarim – AI Agency for WordPress: Edit Pages, Fix Code, Update Plugins, SEO & Client Feedback | atarim-visual-collaboration |
8.1 | Pending |
| Aug 19, 2026 |
CVE-2026-15421
Speed Optimizer lazy-load image attributes permit Contributor stored XSS
Speed Optimizer through 7.8.0 insufficiently sanitizes and escapes image tag attributes when the administrator has enabled Lazy Load Media. A Contributor can place script-capable content in those attributes; the payload is stored in a page and executes whenever a visitor opens the injected page. The authoritative record does not disclose the editor route, request parameter or exact rendering function.
|
Speed Optimizer – The All-In-One Performance-Boosting Plugin | sg-cachepress |
6.4 | Pending |
| Aug 19, 2026 |
CVE-2025-11729
PPWP Contributors can retrieve the master password for protected content
PPWP through 1.9.15 applies an improper capability check in can_access(). A Contributor can retrieve a master password and use it to open any content protected by the plugin. The authoritative record does not disclose the endpoint or action, request parameter, response format or password storage key.
|
PPWP – Password Protect Pages | password-protect-page |
4.3 | Pending |
| Aug 18, 2026 |
CVE-2026-66591
Media Library Assistant permits low-privilege stored cross-site scripting
Media Library Assistant through 3.39 lets a low-privilege authenticated user store attacker-controlled content that later executes as script in a victim's browser under the site's origin. The Patchstack CNA vector requires low privileges and victim interaction, but the record does not disclose the minimum WordPress role, endpoint or action, input field, storage function, rendering sink or affected victim view.
|
Media Library Assistant | media-library-assistant |
6.5 | Pending |
| Aug 18, 2026 |
CVE-2026-66589
B2BKing permits low-privilege access to an undisclosed protected operation
B2BKing through 5.2.30 fails to enforce authorization on an operation reachable by a low-privilege authenticated user. The Patchstack CNA assigns low confidentiality and integrity impact but does not disclose the endpoint or action, parameters, required WordPress role, protected object or resulting read and state change.
|
B2BKing | b2bking-wholesale-for-woocommerce |
5.4 | Pending |
| Aug 18, 2026 |
CVE-2026-27365
PublishPress Series permits privileged stored cross-site scripting
PublishPress Series through 2.17.0 lets a privileged authenticated user store attacker-controlled content that later executes as script in a victim's browser under the site's origin. The Patchstack CNA vector requires high privileges and victim interaction, but the record does not disclose the minimum WordPress role, endpoint or action, input field, storage function, rendering sink or affected victim view.
|
PublishPress Series | organize-series |
5.9 | Pending |
| Aug 18, 2026 |
CVE-2026-66603
Draft List permits low-privilege stored cross-site scripting
Draft List through 2.6.4 lets a low-privilege authenticated user supply attacker-controlled content that the plugin stores and later renders without adequate neutralization. When a victim views the affected output, the stored script executes in the site's origin. The Patchstack CNA record does not disclose the minimum WordPress role, endpoint or action, input field, storage function, rendering sink or affected victim view.
|
Draft List | simple-draft-list |
6.5 | Pending |
| Aug 18, 2026 |
CVE-2026-66602
HashBar permits cross-site request forgery against an undisclosed privileged operation
HashBar – WordPress Notification Bar through 2.0.0 does not adequately verify that an undisclosed state-changing request was intentionally made by the logged-in victim. An unauthenticated attacker can cause a privileged user's browser to submit that request with the victim's session authority. The Patchstack CNA record assigns high confidentiality, integrity and availability impact but does not disclose the endpoint, action, nonce failure, parameters, required victim role or resulting operation.
|
HashBar – WordPress Notification Bar | hashbar-wp-notification-bar |
8.8 | Pending |
| Aug 18, 2026 |
CVE-2026-74015
Readabler: SQL injection
Readabler is affected by SQL injection. The vulnerable path is reachable without authentication. A successful request can alter database queries and expose or modify WordPress data. The published affected range is n/a to < 2.0.18. The public source does not disclose the vulnerable endpoint, action, parameter or function, so the precise input path remains unknown.
|
Readabler | readabler |
9.3 | Pending |
| Aug 18, 2026 |
CVE-2026-74012
TaxoPress: Code execution
TaxoPress is affected by code execution. Exploitation requires an authenticated editor account. Successful exploitation can run attacker-controlled code in the WordPress hosting account. The published affected range is n/a through 3.51.0. The public source does not disclose the vulnerable endpoint, action, parameter or function, so the precise input path remains unknown.
|
TaxoPress | simple-tags |
8.8 | Pending |
| Aug 18, 2026 |
CVE-2026-74009
Razorpay for WooCommerce: Broken access control
Razorpay for WooCommerce is affected by broken access control. The vulnerable path is reachable without authentication. A successful request can reach data or an operation that should be restricted to another user or a more privileged role. The published affected range is n/a through 4.8.7. The public source does not disclose the vulnerable endpoint, action, parameter or function, so the precise input path remains unknown.
|
Razorpay for WooCommerce | woo-razorpay |
5.3 | Pending |
| Aug 18, 2026 |
CVE-2026-74008
Shortcodes and extra features for Phlox theme: Sensitive information exposure
Shortcodes and extra features for Phlox theme is affected by sensitive information exposure. The vulnerable path is reachable without authentication. Successful exploitation can disclose data that should not be available to the caller. The published affected range is n/a through 2.17.22. The public source does not disclose the vulnerable endpoint, action, parameter or function, so the precise input path remains unknown.
|
Shortcodes and extra features for Phlox theme | auxin-elements |
5.3 | Pending |
| Aug 18, 2026 |
CVE-2026-74007
3D FlipBook – PDF Flipbook Viewer, Flipbook Image Gallery: Sensitive information exposure
3D FlipBook – PDF Flipbook Viewer, Flipbook Image Gallery is affected by sensitive information exposure. The vulnerable path is reachable without authentication. Successful exploitation can disclose data that should not be available to the caller. The published affected range is n/a through 1.16.20. The public source does not disclose the vulnerable endpoint, action, parameter or function, so the precise input path remains unknown.
|
3D FlipBook – PDF Flipbook Viewer, Flipbook Image Gallery | interactive-3d-flipbook-powered-physics-engine |
5.3 | Pending |
| Aug 18, 2026 |
CVE-2026-74006
WP Table Builder: Broken access control
WP Table Builder is affected by broken access control. Exploitation requires an authenticated contributor account. A successful request can reach data or an operation that should be restricted to another user or a more privileged role. The published affected range is n/a through 2.2.0. The public source does not disclose the vulnerable endpoint, action, parameter or function, so the precise input path remains unknown.
|
WP Table Builder | wp-table-builder |
4.3 | Pending |
| Aug 18, 2026 |
CVE-2026-74004
Gravity Booster – Styles & Layouts for Gravity Forms: Broken access control
Gravity Booster – Styles & Layouts for Gravity Forms is affected by broken access control. Exploitation requires an authenticated subscriber account. A successful request can reach data or an operation that should be restricted to another user or a more privileged role. The published affected range is n/a through 6.0. The public source does not disclose the vulnerable endpoint, action, parameter or function, so the precise input path remains unknown.
|
Gravity Booster – Styles & Layouts for Gravity Forms | styles-and-layouts-for-gravity-forms |
5.4 | Pending |
| Aug 18, 2026 |
CVE-2026-74003
RomethemeForm For Elementor: Broken access control
RomethemeForm For Elementor is affected by broken access control. Exploitation requires an authenticated contributor account. A successful request can reach data or an operation that should be restricted to another user or a more privileged role. The published affected range is n/a through 1.2.6. The public source does not disclose the vulnerable endpoint, action, parameter or function, so the precise input path remains unknown.
|
RomethemeForm For Elementor | romethemeform |
4.3 | Pending |
| Aug 18, 2026 |
CVE-2026-73997
Starter Templates by Kadence WP: Denial of service
Starter Templates by Kadence WP is affected by denial of service. The vulnerable path is reachable without authentication. A successful request can exhaust or disrupt the affected operation and make site functionality unavailable. The published affected range is n/a through 2.3.3. The public source does not disclose the vulnerable endpoint, action, parameter or function, so the precise input path remains unknown.
|
Starter Templates by Kadence WP | kadence-starter-templates |
7.5 | Pending |
| Aug 18, 2026 |
CVE-2026-73996
Masteriyo - LMS: Dangerous file upload
Masteriyo - LMS is affected by dangerous file upload. The vulnerable path is reachable without authentication. Successful exploitation can place attacker-controlled executable content on the server and may lead to full site compromise. The published affected range is n/a through 2.3.2. The public source does not disclose the vulnerable endpoint, action, parameter or function, so the precise input path remains unknown.
|
Masteriyo - LMS | learning-management-system |
9.8 | Pending |
| Aug 18, 2026 |
CVE-2026-73995
User Registration: Privilege escalation or authentication bypass
User Registration is affected by privilege escalation or authentication bypass. Exploitation requires an authenticated subscriber account. A successful request can grant permissions or access that the caller should not possess. The published affected range is n/a through 5.2.6. The public source does not disclose the vulnerable endpoint, action, parameter or function, so the precise input path remains unknown.
|
User Registration | user-registration |
5.4 | Pending |
| Aug 18, 2026 |
CVE-2026-73994
Charitable: Broken access control
Charitable is affected by broken access control. The vulnerable path is reachable without authentication. A successful request can reach data or an operation that should be restricted to another user or a more privileged role. The published affected range is n/a through 1.8.11.3. The public source does not disclose the vulnerable endpoint, action, parameter or function, so the precise input path remains unknown.
|
Charitable | charitable |
7.5 | Pending |
| Aug 18, 2026 |
CVE-2026-73404
MasterStudy LMS: Broken access control
MasterStudy LMS is affected by broken access control. Exploitation requires an authenticated subscriber account. A successful request can reach data or an operation that should be restricted to another user or a more privileged role. The published affected range is n/a through 3.7.41. The public source does not disclose the vulnerable endpoint, action, parameter or function, so the precise input path remains unknown.
|
MasterStudy LMS | masterstudy-lms-learning-management-system |
6.5 | Pending |
| Aug 18, 2026 |
CVE-2026-73400
Restaurant Menu by MotoPress: Filesystem traversal
Restaurant Menu by MotoPress is affected by filesystem traversal. The vulnerable path is reachable without authentication. A crafted path can escape the intended directory and reach files or directories elsewhere on the server. The published affected range is n/a through 2.4.11. The public source does not disclose the vulnerable endpoint, action, parameter or function, so the precise input path remains unknown.
|
Restaurant Menu by MotoPress | mp-restaurant-menu |
8.1 | Pending |
| Aug 18, 2026 |
CVE-2026-73399
Flutterwave WooCommerce: Privilege escalation or authentication bypass
Flutterwave WooCommerce is affected by privilege escalation or authentication bypass. The vulnerable path is reachable without authentication. A successful request can grant permissions or access that the caller should not possess. The published affected range is n/a through 3.3.0. The public source does not disclose the vulnerable endpoint, action, parameter or function, so the precise input path remains unknown.
|
Flutterwave WooCommerce | rave-woocommerce-payment-gateway |
6.5 | Pending |
| Aug 18, 2026 |
CVE-2026-73398
Piraeus Bank WooCommerce Payment Gateway: Privilege escalation or authentication bypass
Piraeus Bank WooCommerce Payment Gateway is affected by privilege escalation or authentication bypass. The vulnerable path is reachable without authentication. A successful request can grant permissions or access that the caller should not possess. The published affected range is 3.2.0. The public source does not disclose the vulnerable endpoint, action, parameter or function, so the precise input path remains unknown.
|
Piraeus Bank WooCommerce Payment Gateway | woo-payment-gateway-for-piraeus-bank |
6.5 | Pending |
| Aug 18, 2026 |
CVE-2026-73397
Youzify: Code execution
Youzify is affected by code execution. The vulnerable path is reachable without authentication. Successful exploitation can run attacker-controlled code in the WordPress hosting account. The published affected range is n/a through 1.3.7. The public source does not disclose the vulnerable endpoint, action, parameter or function, so the precise input path remains unknown.
|
Youzify | youzify |
9.8 | Pending |
| Aug 18, 2026 |
CVE-2026-73396
MWB HubSpot for WooCommerce: Privilege escalation or authentication bypass
MWB HubSpot for WooCommerce is affected by privilege escalation or authentication bypass. Exploitation requires an authenticated subscriber account. A successful request can grant permissions or access that the caller should not possess. The published affected range is n/a through 1.6.7. The public source does not disclose the vulnerable endpoint, action, parameter or function, so the precise input path remains unknown.
|
MWB HubSpot for WooCommerce | makewebbetter-hubspot-for-woocommerce |
7.1 | Pending |
| Aug 18, 2026 |
CVE-2026-73395
Booking calendar, Appointment Booking System: Broken access control
Booking calendar, Appointment Booking System is affected by broken access control. The vulnerable path is reachable without authentication. A successful request can reach data or an operation that should be restricted to another user or a more privileged role. The published affected range is n/a through 3.2.36. The public source does not disclose the vulnerable endpoint, action, parameter or function, so the precise input path remains unknown.
|
Booking calendar, Appointment Booking System | booking-calendar |
6.5 | Pending |
| Aug 18, 2026 |
CVE-2026-73393
Subscribe2: Cross-site scripting
Subscribe2 is affected by cross-site scripting. The vulnerable path is reachable without authentication. Injected script can execute in the affected site's origin when the vulnerable output is viewed. The published affected range is n/a through 10.46. The public source does not disclose the vulnerable endpoint, action, parameter or function, so the precise input path remains unknown.
|
Subscribe2 | subscribe2 |
7.1 | Pending |
| Aug 18, 2026 |
CVE-2026-73392
Super Store Finder: SQL injection
Super Store Finder is affected by SQL injection. The vulnerable path is reachable without authentication. A successful request can alter database queries and expose or modify WordPress data. The published affected range is n/a through 7.8. The public source does not disclose the vulnerable endpoint, action, parameter or function, so the precise input path remains unknown.
|
Super Store Finder | superstorefinder-wp |
9.3 | Pending |
| Aug 18, 2026 |
CVE-2026-73383
CTX Feed: Unauthorized file download
CTX Feed is affected by unauthorized file download. Exploitation requires an authenticated shop manager account. A successful request can download a file that the caller should not be permitted to access. The published affected range is n/a through 6.6.47. The public source does not disclose the vulnerable endpoint, action, parameter or function, so the precise input path remains unknown.
|
CTX Feed | webappick-product-feed-for-woocommerce |
4.9 | Pending |
| Aug 18, 2026 |
CVE-2026-73382
Site Reviews: Cross-site scripting
Site Reviews is affected by cross-site scripting. The vulnerable path is reachable without authentication. Injected script can execute in the affected site's origin when the vulnerable output is viewed. The published affected range is n/a through 8.2.0. The public source does not disclose the vulnerable endpoint, action, parameter or function, so the precise input path remains unknown.
|
Site Reviews | site-reviews |
7.1 | Pending |
| Aug 18, 2026 |
CVE-2026-73381
Popup by Supsystic: Privilege escalation or authentication bypass
Popup by Supsystic is affected by privilege escalation or authentication bypass. The vulnerable path is reachable without authentication. A successful request can grant permissions or access that the caller should not possess. The published affected range is n/a through 1.13.0. The public source does not disclose the vulnerable endpoint, action, parameter or function, so the precise input path remains unknown.
|
Popup by Supsystic | popup-by-supsystic |
9.1 | Pending |
| Aug 18, 2026 |
CVE-2026-73380
Popup by Supsystic: Code execution
Popup by Supsystic is affected by code execution. The vulnerable path is reachable without authentication. Successful exploitation can run attacker-controlled code in the WordPress hosting account. The published affected range is n/a through 1.13.0. The public source does not disclose the vulnerable endpoint, action, parameter or function, so the precise input path remains unknown.
|
Popup by Supsystic | popup-by-supsystic |
9.8 | Pending |
| Aug 18, 2026 |
CVE-2026-73379
Contact Form by Supsystic: Privilege escalation or authentication bypass
Contact Form by Supsystic is affected by privilege escalation or authentication bypass. The vulnerable path is reachable without authentication. A successful request can grant permissions or access that the caller should not possess. The published affected range is n/a to < 1.10.0. The public source does not disclose the vulnerable endpoint, action, parameter or function, so the precise input path remains unknown.
|
Contact Form by Supsystic | contact-form-by-supsystic |
6.5 | Pending |
| Aug 18, 2026 |
CVE-2026-73378
Contact Form by Supsystic: Cross-site scripting
Contact Form by Supsystic is affected by cross-site scripting. The vulnerable path is reachable without authentication. Injected script can execute in the affected site's origin when the vulnerable output is viewed. The published affected range is n/a to < 1.10.0. The public source does not disclose the vulnerable endpoint, action, parameter or function, so the precise input path remains unknown.
|
Contact Form by Supsystic | contact-form-by-supsystic |
7.1 | Pending |
No vulnerabilities match those filters.