Live Feed

RecentVulnerabilities.

WordPress plugin and theme CVEs published in the last 30 days, sorted by severity. Updated continuously from the Wordfence Intelligence feed.

Time Window:

100 vulnerabilities found

CVE-2026-12997highImproper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

Gravity Forms <= 2.10.4 - Unauthenticated Arbitrary File Read via 'gform_uploaded_files' Parameter

WordPress · CVSS 7.5 · Jul 15, 2026

CVE-2026-13001criticalImproper Input Validation

Podlove Podcast Publisher <= 4.5.1 - Unauthenticated Arbitrary File Upload via podlove_image_cache_url Parameter

Podlove Podcast Publisher · CVSS 9.8 · Jul 14, 2026

CVE-2026-7640mediumImproper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

WP Customer Area <= 8.3.5 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'type' Shortcode Attribute

WP Customer Area · CVSS 6.4 · Jul 13, 2026

CVE-2026-11802mediumMissing Authorization

FoodBook Lite <= 1.5.6 - Missing Authorization to Unauthenticated User Registration via 'registration_action' AJAX Action

FoodBook Lite – Online Food Ordering System · CVSS 5.3 · Jul 13, 2026

CVE-2026-11390mediumImproper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

News Kit Addons For Elementor <= 1.4.6 - Authenticated (Contributor+) Stored Cross-Site Scripting via Site Logo Title and Single Author Box Widgets

News Kit Addons For Elementor · CVSS 6.4 · Jul 13, 2026

CVE-2026-12536mediumImproper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Avada Builder <= 3.15.5 - Authenticated (Contributor+) Stored Cross-Site Scripting via Module Title

WordPress · CVSS 6.4 · Jul 13, 2026

CVE-2026-12385mediumExposure of Sensitive Information to an Unauthorized Actor

Smart Slider 3 <= 3.5.1.37 - Missing Authorization to Authenticated (Contributor+) Sensitive Information Exposure via WP_Query Parameter Injection via 'keyword' Parameter

Smart Slider 3 · CVSS 4.3 · Jul 13, 2026

WF-53cc91fa-51fd-4d16-b740-a48f8d446b5d-aimogen-procriticalImproper Privilege Management

Aimogen Pro - All-in-One AI Content Writer, Editor, ChatBot & Automation Toolkit <= 2.8.4 - Unauthenticated Privilege Escalation via 'aiomatic_call_google_ai_function'

WordPress · CVSS 9.8 · Jul 13, 2026

CVE-2026-9341mediumAuthorization Bypass Through User-Controlled Key

Academy LMS <= 3.8.0 - Authenticated (Subscriber+) Insecure Direct Object Reference via 'user_id' Parameter

Academy LMS – WordPress LMS Plugin for Complete eLearning Solution · CVSS 4.3 · Jul 13, 2026

CVE-2026-61955mediumImproper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

sync-basalam <= 3.0.2 - Authenticated (Administrator+) SQL Injection

گرویتی فرم فارسی · CVSS 4.9 · Jul 12, 2026

CVE-2026-61956mediumCross-Site Request Forgery (CSRF)

sync-basalam <= 1.9.1 - Cross-Site Request Forgery

ووسلام – همگام سازی ووکامرس و باسلام · CVSS 4.3 · Jul 12, 2026

CVE-2026-61952mediumMissing Authorization

Bulk Edit Products for WooCommerce – WP Sheet Editor <= 1.8.21 - Missing Authorization

Bulk Edit Products for WooCommerce – WP Sheet Editor · CVSS 4.3 · Jul 12, 2026

CVE-2026-1359highIncorrect Authorization

Genolve – AI image AI video generation <= 5.0.5 - Authenticated (Contributor+) Incorrect Authorization to Privilege Escalation via theopt

Genolve – AI image AI video generation · CVSS 8.8 · Jul 10, 2026

CVE-2026-9282highImproper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

W3 Total Cache <= 2.9.4 - Unauthenticated Arbitrary File Read via 'f_array[]' Parameter

W3 Total Cache · CVSS 7.5 · Jul 10, 2026

CVE-2026-9017mediumMissing Authorization

NEX-Forms <= 9.2.2 - Missing Authorization to Unauthenticated Arbitrary Form Entry Modification via nf_send_nf_email AJAX Action

NEX-Forms – Ultimate Forms Plugin for WordPress · CVSS 5.3 · Jul 10, 2026

CVE-2026-15010mediumImproper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

bbp style pack <= 6.4.5 - Authenticated (Subscriber+) Stored Cross-Site Scripting via Topic Form Additional Fields

bbp style pack · CVSS 6.4 · Jul 10, 2026

CVE-2026-10865mediumExposure of Sensitive Information to an Unauthorized Actor

Cost Calculator Builder <= 4.0.11 - Unauthenticated Sensitive Information Exposure of Payment Gateway Secret Keys

Cost Calculator Builder · CVSS 5.3 · Jul 10, 2026

CVE-2026-12103mediumMissing Authorization

Wallet for WooCommerce <= 1.6.4 - Missing Authorization to Authenticated (Subscriber+) User/Email Enumeration via terawallet_export_user_search AJAX Action

Wallet for WooCommerce · CVSS 4.3 · Jul 10, 2026

CVE-2026-1382mediumImproper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Unpatched

fresh Podcaster <= 1.0.7 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'freshpodcaster' Shortcode Attributes

fresh Podcaster · CVSS 6.4 · Jul 10, 2026

CVE-2025-5017mediumImproper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Unpatched

Catalyst Connect Zoho CRM Client Portal <= 2.2.0 - Authenticated (Administrator+) SQL Injection via uid Parameter

Catalyst Connect Zoho CRM Client Portal · CVSS 4.9 · Jul 10, 2026

CVE-2026-6801mediumExposure of Sensitive Information to an Unauthorized Actor

Context Blog <= 1.3.5 - Unauthenticated Sensitive Information Exposure via 'postID' Parameter

Context Blog · CVSS 5.3 · Jul 10, 2026

CVE-2026-4661highImproper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

WP CTA <= 2.2.2 - Unauthenticated Time-Based Blind SQL Injection via 'fildname' Parameter

WP CTA – Call Now Button, Sticky Button & Call to Action Builder · CVSS 7.5 · Jul 10, 2026

CVE-2026-12994mediumMissing Authorization

WCFM – Frontend Manager for WooCommerce <= 6.7.27 - Missing Authorization to Unauthenticated Arbitrary Inquiry Reply Injection via wcfm-my-account-enquiry-manage Controller

WCFM – Frontend Manager for WooCommerce · CVSS 5.3 · Jul 10, 2026

CVE-2026-11901mediumInsufficient Verification of Data Authenticity

WP Hotel Booking <= 2.3.1 - Unauthenticated Insufficient Verification of Data Authenticity to Payment Bypass via PayPal IPN Handler

WP Hotel Booking · CVSS 5.3 · Jul 10, 2026

CVE-2026-12738mediumMissing Authorization

WP Easy Pay <= 4.5.0 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Post Status Modification via wpep_draft_confirm AJAX Action

WP Easy Pay – Payment and Donation form Builder for Square · CVSS 4.3 · Jul 10, 2026

CVE-2026-11591mediumImproper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Widgets for Google Reviews <= 13.3 - Authenticated (Editor+) Stored Cross-Site Scripting via 'fomo-title' and 'fomo-text' Parameters

Widgets for Google Reviews · CVSS 4.4 · Jul 10, 2026

CVE-2026-15155highWeak Password Recovery Mechanism for Forgotten Password

Essential Addons for Elementor <= 6.6.10 - Authenticated (Contributor+) Account Takeover via Email Header Injection

Essential Addons for Elementor – Popular Elementor Templates & Widgets · CVSS 8.8 · Jul 10, 2026

CVE-2026-11898mediumImproper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

White Label CMS <= 2.7.12 - Authenticated (Administrator+) Stored Cross-Site Scripting via Import Settings

White Label CMS · CVSS 4.4 · Jul 10, 2026

CVE-2026-6939highImproper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

CorvusPay WooCommerce Payment Gateway <= 2.7.4 - Unauthenticated Stored Cross-Site Scripting via 'approval_code' Parameter

CorvusPay WooCommerce Payment Gateway · CVSS 7.2 · Jul 10, 2026

CVE-2025-6784highImproper Neutralization of Special Elements used in a Command ('Command Injection')

Code Engine <= 0.3.5 - Authenticated (Contributor+) Remote Code Execution

Code Engine · CVSS 8.8 · Jul 10, 2026

CVE-2026-10041mediumAuthorization Bypass Through User-Controlled Key

WCFM – Frontend Manager for WooCommerce <= 6.7.27 - Authenticated (Subscriber+) Missing Authorization to Arbitrary Vendor Data Manipulation via Multiple AJAX Handlers

WCFM – Frontend Manager for WooCommerce · CVSS 4.3 · Jul 10, 2026

CVE-2026-12126mediumImproper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

WCFM Marketplace <= 3.7.3 - Authenticated (Vendor+) Stored Cross-Site Scripting via Attachment 'post_title'

WCFM Marketplace – Multivendor Marketplace for WooCommerce · CVSS 6.4 · Jul 10, 2026

CVE-2026-13378highImproper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Form Vibes <= 1.5.2 - Unauthenticated Stored Cross-Site Scripting via Contact Form 7 Form Field

Form Vibes – Database Manager for Forms · CVSS 7.2 · Jul 10, 2026

CVE-2026-7655highWeak Password Recovery Mechanism for Forgotten Password

SureCart <= 4.2.3 - Unauthenticated Linked WordPress Account Takeover via Forged customer.updated Webhook

SureCart – Ecommerce Made Easy For Selling Physical Products, Digital Downloads, Subscriptions, Donations, & Payments · CVSS 8.1 · Jul 10, 2026

CVE-2026-1832mediumMissing Authorization

ThriveDesk <= 2.1.7 - Missing Authorization to Authenticated (Subscriber+) Cache Deletion

Agentic Help Desk Plugin for WordPress – Live Chat, AI Chatbot & Ticketing – ThriveDesk · CVSS 4.3 · Jul 10, 2026

CVE-2026-15096mediumImproper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Themify Builder <= 7.7.6 - Authenticated (Contributor+) Stored Cross-Site Scripting via Map Module 'b_width_map' Field

Themify Builder · CVSS 6.4 · Jul 10, 2026

CVE-2026-15097mediumImproper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Themify Builder <= 7.7.6 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'height_slider' Slider Module Field

Themify Builder · CVSS 6.4 · Jul 10, 2026

CVE-2026-3552mediumMissing Authorization

SurfLink < 2.6.0 - Missing Authorization to Authenticated (Subscriber+) 410 Gone URL Import via 'surfl_import_410' AJAX Action

SurfLink – Link Manager & Backup Restore · CVSS 4.3 · Jul 10, 2026

CVE-2026-2354highUnrestricted Upload of File with Dangerous Type Unpatched

Swiss Toolkit For WP <= 1.4.6 - Authenticated (Author+) Arbitrary File Upload via upload_extension_files()

Swiss Toolkit For WP · CVSS 8.8 · Jul 10, 2026

CVE-2025-13968mediumImproper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Starboard Suite Reservation Calendars <= 3.1.4 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode Attributes

Starboard Suite Reservation Calendars · CVSS 6.4 · Jul 10, 2026

CVE-2026-6804mediumMissing Authorization

AI Chatbot & Workflow Automation by AIWU <= 1.4.12 - Missing Authorization to Unauthenticated Arbitrary Modification via 'publishTasks' and 'unpublishTasks' AJAX Actions

AI Chatbot & Workflow Automation by AIWU · CVSS 5.3 · Jul 10, 2026

CVE-2026-6803mediumMissing Authorization

AI Chatbot & Workflow Automation by AIWU <= 1.4.12 - Missing Authorization to Unauthenticated Arbitrary Data Deletion via AJAX Actions 'removeGroup' and 'clear'

AI Chatbot & Workflow Automation by AIWU · CVSS 5.3 · Jul 10, 2026

CVE-2026-7559mediumMissing Authorization

Affilia <= 3.3.3 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Status Modification

Affilia – Affiliate Program & Referral Tracking for WordPress · CVSS 4.3 · Jul 10, 2026

CVE-2026-13250mediumMissing Authorization

Solace Extra <= 1.5.3 - Missing Authorization to Unauthenticated Arbitrary Content Deletion via delete_previously_imported AJAX Action

Solace Extra · CVSS 5.3 · Jul 10, 2026

CVE-2026-14262highImproper Privilege Management

Simple JWT Login <= 3.6.6 - Authenticated (Subscriber+) Authentication Bypass to Privilege Escalation via 'payload' Parameter

Simple JWT Login – Allows you to use JWT on REST endpoints. · CVSS 8.8 · Jul 10, 2026

CVE-2026-12141mediumImproper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Premium Addons for Elementor <= 4.11.84 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'premium_tooltip_text' Parameter

Premium Addons for Elementor – Powerful Elementor Templates & Widgets · CVSS 4.9 · Jul 10, 2026

CVE-2026-9738mediumImproper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Print, PDF, Email by PrintFriendly <= 5.5.10 - Authenticated (Administrator+) Stored Cross-Site Scripting via 'content_position_css' Parameter

Print, PDF, Email by PrintFriendly · CVSS 4.4 · Jul 10, 2026

CVE-2026-3576highImproper Input Validation

Planyo online reservation system <= 3.0 - Unauthenticated Server-Side Request Forgery via 'ulap_url' Parameter

Planyo online reservation system · CVSS 7.2 · Jul 10, 2026

CVE-2026-13116mediumAuthorization Bypass Through User-Controlled Key

PDF Invoices & Packing Slips for WooCommerce <= 5.14.0 - Insecure Direct Object Reference to Authenticated (Contributor+) Sensitive Information Disclosure via 'order_id' Shortcode Attribute

PDF Invoices & Packing Slips for WooCommerce · CVSS 4.3 · Jul 10, 2026

CVE-2026-7620mediumMissing Authorization

Notification for Telegram <= 3.5.1 - Missing Authorization to Authenticated (Subscriber+) Cron Modification via nftb_cron_action_set AJAX Action

Notification for Telegram · CVSS 4.3 · Jul 10, 2026

CVE-2026-13262mediumImproper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

Majestic Support <= 1.1.9 - Authenticated (Subscriber+) SQL Injection via 'val' Parameter

Majestic Support – The Leading-Edge Help Desk & Customer Support Plugin · CVSS 6.5 · Jul 10, 2026

CVE-2026-8678mediumMissing Authorization

MyParcel <= 4.25.1 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Order Shipment Data Disclosure and Modification via wcmp_get_shipment_options and wcmp_save_shipment_options AJAX Actions

MyParcel · CVSS 4.3 · Jul 10, 2026

CVE-2026-7544mediumExposure of Sensitive Information to an Unauthorized Actor

Mux Video Uploader <= 1.1.4 - Authenticated (Subscriber+) Information Exposure

Mux Video Uploader · CVSS 4.3 · Jul 10, 2026

CVE-2026-15338highImproper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion')

LA-Studio Element Kit for Elementor <= 1.6.1 - Authenticated (Contributor+) Local File Inclusion via 'progress_type' Widget Setting

LA-Studio Element Kit for Elementor · CVSS 7.5 · Jul 10, 2026

CVE-2026-13114highImproper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Motors <= 1.4.112 - Unauthenticated Stored Cross-Site Scripting via Comment Content and User Biographical Info

Motors – Car Dealership & Classified Listings Plugin · CVSS 7.2 · Jul 10, 2026

CVE-2026-5743mediumImproper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Mixed Media Gallery Blocks <= 3.3.3.1 - Authenticated (Author+) Stored Cross-Site Scripting via sliderMaxHeight Block Attribute

Mixed Media Gallery Blocks · CVSS 6.4 · Jul 10, 2026

CVE-2026-12426mediumExposure of Sensitive Information to an Unauthorized Actor

Members <= 3.2.22 - Unauthenticated Sensitive Information Disclosure via REST API Pagination Side Channel

Members – Membership & User Role Editor Plugin · CVSS 5.3 · Jul 10, 2026

CVE-2026-3367mediumImproper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Lockme OAuth2 calendars integration <= 2.11.0 - Authenticated (Administrator+) Stored Cross-Site Scripting via 'App ID' Setting

Lockme calendars integration · CVSS 4.4 · Jul 10, 2026

CVE-2026-15072mediumImproper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

KiviCare <= 4.5.0 - Authenticated (Doctor+) SQL Injection via 'orderby' Parameter in KCQueryBuilder

KiviCare – Clinic & Patient Management System (EHR) · CVSS 6.5 · Jul 10, 2026

CVE-2026-15073mediumImproper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

KiviCare <= 4.5.0 - Authenticated (Doctor+) SQL Injection via 'orderby' Parameter in DoctorSessionController

KiviCare – Clinic & Patient Management System (EHR) · CVSS 6.5 · Jul 10, 2026

CVE-2026-10628mediumMissing Authorization

Points and Rewards for WooCommerce <= 2.10.1 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Modification via Multiple AJAX Actions

Points and Rewards for WooCommerce · CVSS 4.3 · Jul 10, 2026

CVE-2026-13353highImproper Control of Generation of Code ('Code Injection')

WP Ultimate CSV Importer <= 8.0.1 - Missing Authorization to Authenticated (Subscriber+) Remote Code Execution via 'MappedFields' Parameter

WP Ultimate CSV Importer – Import CSV, XML & Excel into WordPress · CVSS 8.8 · Jul 10, 2026

CVE-2026-11426mediumImproper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

UnderConstructionPage PRO <= 5.76 - Authenticated (Subscriber+) Arbitrary File Read via template_thumbnail Parameter

Under Construction · CVSS 6.5 · Jul 10, 2026

CVE-2026-13756highImproper Privilege Management

WP Grid Builder <= 2.3.3 - Authenticated (Subscriber+) Privilege Escalation via 'key' Parameter

WordPress · CVSS 8.8 · Jul 10, 2026

CVE-2026-12761criticalImproper Authentication

miniOrange Social Login and Register (Discord, Google, Twitter, LinkedIn) <= 7.7.0 - Unauthenticated Authentication Bypass to Administrator Account Takeover via Profile Completion OTP Flow

miniOrange Social Login and Register (Discord, Google, Twitter, LinkedIn) · CVSS 9.8 · Jul 10, 2026

CVE-2026-1667highMissing Authorization

SEO Plugin by Squirrly SEO <= 14.0.0 - Unauthenticated Arbitrary Post Creation and Stored Cross-Site Scripting via savePost()

SEO Plugin by Squirrly SEO · CVSS 7.2 · Jul 10, 2026

CVE-2026-15335highImproper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

Booking Package <= 1.7.20 - Unauthenticated SQL Injection via 'email' Form Parameter

Booking Package · CVSS 7.5 · Jul 10, 2026

CVE-2026-57712highImproper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

WPZOOM Portfolio Lite – Filterable Portfolio Plugin <= 1.4.29 - Unauthenticated Stored Cross-Site Scripting

WPZOOM Portfolio Lite – Filterable Portfolio Plugin · CVSS 7.2 · Jul 10, 2026

CVE-2026-59516highImproper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

ICS Calendar <= 12.1.1 - Unauthenticated Stored Cross-Site Scripting

ICS Calendar · CVSS 7.2 · Jul 10, 2026

CVE-2026-57816highImproper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

FunnelKit – Funnel Builder for WooCommerce Checkout <= 3.15.0.8 - Unauthenticated Stored Cross-Site Scripting

FunnelKit – Funnel Builder for WooCommerce Checkout · CVSS 7.2 · Jul 10, 2026

CVE-2026-57706highImproper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Dokan: AI Powered WooCommerce Multivendor Marketplace Solution – Build Your Own Amazon, eBay, Etsy <= 5.0.6 - Unauthenticated Stored Cross-Site Scripting

Dokan: AI Powered WooCommerce Multivendor Marketplace Solution – Build Your Own Amazon, eBay, Etsy · CVSS 7.2 · Jul 10, 2026

CVE-2026-57668highImproper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

NEX-Forms – Ultimate Forms Plugin for WordPress <= 9.2.2 - Unauthenticated Stored Cross-Site Scripting

NEX-Forms – Ultimate Forms Plugin for WordPress · CVSS 7.2 · Jul 10, 2026

CVE-2026-57695highImproper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Document Gallery <= 5.1.0 - Unauthenticated Stored Cross-Site Scripting

Document Gallery · CVSS 7.2 · Jul 10, 2026

CVE-2026-57708highImproper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Database for Contact Form 7, WPforms, Elementor forms <= 1.5.2 - Unauthenticated Stored Cross-Site Scripting

Database for Contact Form 7, WPforms, Elementor forms · CVSS 7.2 · Jul 10, 2026

CVE-2026-57735highImproper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Breakdance <= 2.7.1 - Unauthenticated Stored Cross-Site Scripting

WordPress · CVSS 7.2 · Jul 10, 2026

CVE-2026-57711mediumImproper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

SupportCandy – AI Customer Support Ticket System & Live Chatbot Agent <= 3.4.8 - Authenticated (Customer+) Stored Cross-Site Scripting

SupportCandy – Helpdesk & Customer Support Ticket System · CVSS 6.4 · Jul 10, 2026

CVE-2026-12918mediumImproper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

Mail Mint <= 1.24.1 - Authenticated (Administrator+) SQL Injection via 'recipients' Parameter

Mail Mint – Email Marketing, Newsletter, Email Automation & WooCommerce Emails · CVSS 4.9 · Jul 9, 2026

CVE-2026-13247mediumImproper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Logo Slider <= 5.5 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'lgx_tooltip_position' Parameter

Logo Slider – Logo Carousel, Logo Showcase & Client Logo Slider Plugin · CVSS 6.4 · Jul 9, 2026

CVE-2026-11990mediumMissing Authorization

KiviCare <= 4.4.0 - Missing Authorization to Unauthenticated Payment Bypass and Appointment Status Manipulation via /payment-success REST Endpoint

KiviCare – Clinic & Patient Management System (EHR) · CVSS 5.3 · Jul 9, 2026

CVE-2026-13010mediumImproper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

JoomSport <= 5.7.9 - Authenticated (Contributor+) SQL Injection via 'event' Shortcode Attribute

JoomSport – for Sports: Team & League, Football, Hockey & more · CVSS 6.5 · Jul 9, 2026

CVE-2026-13710mediumImproper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Jeg Kit for Elementor <= 3.2.6 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'sg_body_description' Parameter via 'jkit_image_box' Shortcode/Widget

Jeg Kit for Elementor – Powerful Addons for Elementor, Widgets & Templates for WordPress · CVSS 6.4 · Jul 9, 2026

CVE-2026-9857mediumMissing Authorization

Invoice123 <= 1.7.0 - Missing Authorization to Authenticated (Subscriber+) Setting Modification via s123_submit_api_key & s123_submit_invoice_settings AJAX actions

Invoice123 · CVSS 4.3 · Jul 9, 2026

CVE-2026-15026mediumMissing Authorization

Import and export users and customers <= 2.4.0 - Missing Authorization to Authenticated (Subscriber+) Sensitive Information Exposure via email_template_selected AJAX Action

Import and export users and customers · CVSS 4.3 · Jul 9, 2026

CVE-2026-9838mediumImproper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

ICS Calendar <= 12.0.9 - Reflected Cross-Site Scripting via 'htmltagtitle' Parameter

ICS Calendar · CVSS 6.1 · Jul 9, 2026

CVE-2026-3907mediumImproper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Hostel <= 1.1.7 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'wphostel-book' Shortcode

Hostel · CVSS 6.4 · Jul 9, 2026

CVE-2026-12108mediumImproper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Highlighting Code Block <= 2.2.0 - Authenticated (Administrator+) Stored Cross-Site Scripting via 'font_family' Setting

Highlighting Code Block · CVSS 4.4 · Jul 9, 2026

CVE-2025-11977mediumImproper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion')

HappyForms <= 1.26.12 - Authenticated (Admin+) Local File Inclusion

Happyforms – Form Builder for WordPress: Drag & Drop Contact Forms, Surveys, Payments & Multipurpose Forms · CVSS 6.6 · Jul 9, 2026

CVE-2026-1946mediumMissing Authorization

GW AI Website Builder <= 1.0.1 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Plugin Settings Deletion

GW AI Website Builder · CVSS 4.3 · Jul 9, 2026

CVE-2026-6440mediumCross-Site Request Forgery (CSRF)

GoodMeet <= 1.1.8 - Cross-Site Request Forgery to Google Meet Credential Reset via 'goodmeet_reset_google_meet_credential'

GoodMeet – Google Meet Integration for Webinar, Meeting & Video Conference · CVSS 4.3 · Jul 9, 2026

CVE-2026-12924mediumImproper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Eventin <= 4.1.15 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'etn_faq_content' Parameter

Eventin – Event Calendar, Event Registration, Tickets & Booking (AI Powered) · CVSS 6.4 · Jul 9, 2026

CVE-2026-12400mediumAuthorization Bypass Through User-Controlled Key

FlowForms <= 1.1.1 - Authenticated (Contributor+) Insecure Direct Object Reference to Arbitrary Form Modification via REST API '/flowforms/v1/forms/{id}' Endpoints

FlowForms – Conversational Form Builder for WordPress · CVSS 4.3 · Jul 9, 2026

CVE-2026-13039mediumMissing Authorization

Eventin 4.0.26 - 4.1.15 - Missing Authorization to Unauthenticated Payment Bypass via REST API

Eventin – Event Calendar, Event Registration, Tickets & Booking (AI Powered) · CVSS 5.3 · Jul 9, 2026

CVE-2026-6802mediumAuthorization Bypass Through User-Controlled Key

Easy Upload Files During Checkout <= 3.0.1 - Missing Authorization to Unauthenticated Arbitrary Attachment Deletion via 'eufdc-delete' Parameter

Easy Upload Files During Checkout · CVSS 5.3 · Jul 9, 2026

CVE-2026-11992mediumMissing Authorization

Easy Appointments <= 3.12.27 - Missing Authorization to Authenticated (Author+) Bulk Appointment Manipulation

Easy Appointments · CVSS 4.3 · Jul 9, 2026

CVE-2026-14475mediumImproper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

Cookie Banner for GDPR / CCPA <= 4.3.6 - Authenticated (Administrator+) SQL Injection via 'scan_id' Parameter

Cookie Banner for GDPR / CCPA – WPLP Cookie Consent · CVSS 4.9 · Jul 9, 2026

CVE-2026-12955mediumMissing Authorization

Cookie Banner for GDPR / CCPA <= 4.3.6 - Missing Authorization to Authenticated (Subscriber+) Scan Schedule Modification via gcc_save_schedule_scan AJAX Action

Cookie Banner for GDPR / CCPA – WPLP Cookie Consent · CVSS 4.3 · Jul 9, 2026

CVE-2026-15104mediumImproper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

BetterDocs <= 4.6.0 - Authenticated (Custom+) SQL Injection via 'lang' Parameter

BetterDocs – Knowledge Base Docs & FAQ Solution for Elementor & Block Editor · CVSS 6.5 · Jul 9, 2026

CVE-2026-13347highImproper Limitation of a Pathname to a Restricted Directory ('Path Traversal') Unpatched

Hide My WP Lite <= 1.3 - Unauthenticated Path Traversal to Arbitrary File Read via 'he_wrapper_js' Parameter

Hide My WP Lite · CVSS 7.5 · Jul 9, 2026

CVE-2026-12123mediumServer-Side Request Forgery (SSRF)

All-in-One Video Gallery <= 4.8.5 - Authenticated (Subscriber+) Server-Side Request Forgery via 'vdl' Parameter

All-in-One Video Gallery · CVSS 6.4 · Jul 9, 2026

CVE-2026-15070highCross-Site Request Forgery (CSRF)

Salon Booking System <= 10.30.32 - Cross-Site Request Forgery to Remote Code Execution via 'value' Parameter

Salon Booking System – Free Version · CVSS 8.8 · Jul 9, 2026