|
731
|
4.3 |
MEDIUM
Network
|
-
|
-
|
The CM Ad Changer – A simple tool to control and optimize your site's banners plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.0.7. This is due…
New
|
CWE-352
Origin Validation Error
|
CVE-2026-9236
|
2026-05-27 23:50 |
2026-05-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
732
|
4.3 |
MEDIUM
Network
|
-
|
-
|
The Old Posts Highlighter plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0.3. This is due to missing or incorrect nonce validation on the OPH…
New
|
CWE-352
Origin Validation Error
|
CVE-2026-7614
|
2026-05-27 23:50 |
2026-05-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
733
|
6.4 |
MEDIUM
Network
|
-
|
-
|
The faq shortocde plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'color' shortcode attribute in the 'faq' shortcode in all versions up to, and including, 1.0 due to insuffi…
New
|
CWE-79
Cross-site Scripting
|
CVE-2026-8040
|
2026-05-27 23:50 |
2026-05-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
734
|
6.4 |
MEDIUM
Network
|
-
|
-
|
The My Email Shortcode plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'subject' shortcode attribute in the 'my-email' shortcode in all versions up to, and including, 0.91 d…
New
|
CWE-79
Cross-site Scripting
|
CVE-2026-8048
|
2026-05-27 23:50 |
2026-05-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
735
|
6.4 |
MEDIUM
Network
|
-
|
-
|
The GBI To Print plugin for WordPress is vulnerable to Stored Cross-Site Scripting in version 1.0 via the 'div' attribute of the 'gbitoprint' shortcode. This is due to insufficient output escaping in…
New
|
CWE-79
Cross-site Scripting
|
CVE-2026-8702
|
2026-05-27 23:50 |
2026-05-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
736
|
6.4 |
MEDIUM
Network
|
-
|
-
|
The Endless Scroll plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Shortcode Attributes in all versions up to, and including, 1.0.0 due to insufficient input sanitization and ou…
New
|
CWE-79
Cross-site Scripting
|
CVE-2026-8703
|
2026-05-27 23:50 |
2026-05-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
737
|
6.1 |
MEDIUM
Network
|
-
|
-
|
The NS Product icon badge plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via PHP_SELF in all versions up to, and including, 1.2.4 due to insufficient input sanitization and outp…
New
|
CWE-79
Cross-site Scripting
|
CVE-2026-8707
|
2026-05-27 23:50 |
2026-05-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
738
|
4.3 |
MEDIUM
Network
|
-
|
-
|
The Genzel breadcrumbs plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.2. This is due to missing or incorrect nonce validation on the _options…
New
|
CWE-352
Origin Validation Error
|
CVE-2026-8708
|
2026-05-27 23:50 |
2026-05-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
739
|
6.4 |
MEDIUM
Network
|
-
|
-
|
The Cryptocurrency Prijsvergelijking Widget plugin for WordPress is vulnerable to Stored Cross-Site Scripting in version 1.0. This is due to insufficient output escaping in the as_get_coin_shortcode(…
New
|
CWE-79
Cross-site Scripting
|
CVE-2026-8698
|
2026-05-27 23:50 |
2026-05-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
740
|
6.4 |
MEDIUM
Network
|
-
|
-
|
The GNTT Post Title Ticker plugin for WordPress is vulnerable to Stored Cross-Site Scripting in version 1.0 via the `title-ticker-slide`, `title-ticker-fade`, and `title-ticker-typing` shortcodes. Th…
New
|
CWE-79
Cross-site Scripting
|
CVE-2026-8701
|
2026-05-27 23:50 |
2026-05-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|