WordPress security by component
WPPizza
Plugin description
WPPizza is a WordPress component with 7 published CVE records in this archive. The latest tracked vulnerability was published Jun 15, 2026; the highest CVE/CNA score is 7.1.
Plugin slug:
wppizzaLatest vulnerability
CVE-2026-40796: WPPizza: A security weakness
WPPizza is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation. The published affected range is n/a through 3.19.9.
| Safe version |
|
||
|---|---|---|---|
| Jun 15, 2026 |
CVE-2026-40796
WPPizza: A security weakness
WPPizza is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation. The published affected range is n/a through 3.19.9.
|
3.20 |
CVE6.5
NVDPending
|
| Aug 22, 2025 |
CVE-2025-57894
WPPizza: A security weakness
WPPizza is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE4.3
NVDPending
|
| Feb 25, 2025 |
CVE-2025-26991
WPPizza: Cross-site scripting
WPPizza is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE7.1
NVDPending
|
| Jun 21, 2024 |
CVE-2024-35766
WPPizza: Cross-site scripting
WPPizza is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE7.1
NVD6.1
|
| May 06, 2024 |
CVE-2024-33576
WPPizza: A security weakness
WPPizza is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE6.5
NVDPending
|
| Oct 31, 2023 |
CVE-2023-46622
Wppizza: Cross-site scripting
Wppizza is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE7.1
NVD6.1
|
| Aug 18, 2023 |
CVE-2023-32105
Wppizza: Cross-site scripting
Wppizza is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE7.1
NVD6.1
|