|
921
|
6.4 |
MEDIUM
Network
|
-
|
-
|
The WP Travel Engine – Tour Booking Plugin – Tour Operator Software plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'wte_trip_tax' shortcode in all versions up to, …
|
CWE-79
Cross-site Scripting
|
CVE-2026-2437
|
2026-04-25 03:13 |
2026-04-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
922
|
4.3 |
MEDIUM
Network
|
-
|
-
|
The Kadence Blocks — Page Builder Toolkit for Gutenberg Editor plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 3.6.3. This is due to the plugin not pr…
|
CWE-862
Missing Authorization
|
CVE-2026-2826
|
2026-04-25 03:13 |
2026-04-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
923
|
7.1 |
HIGH
Network
|
-
|
-
|
The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress plugin for WordPress is vulnerable to unauthorized membership payment bypass …
|
CWE-862
Missing Authorization
|
CVE-2026-3445
|
2026-04-25 03:13 |
2026-04-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
924
|
7.2 |
HIGH
Network
|
-
|
-
|
The Widgets for Social Photo Feed plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'feed_data' parameter keys in all versions up to, and including, 1.7.9 due to insufficient …
|
CWE-79
Cross-site Scripting
|
CVE-2026-5425
|
2026-04-25 03:13 |
2026-04-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
925
|
5.3 |
MEDIUM
Network
|
-
|
-
|
The Listeo Core plugin for WordPress is vulnerable to unauthenticated arbitrary media upload in all versions up to, and including, 2.0.27 via the "listeo_core_handle_dropped_media" function. This is …
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2025-14938
|
2026-04-25 03:13 |
2026-04-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
926
|
6.4 |
MEDIUM
Network
|
-
|
-
|
The WPFunnels – Easy Funnel Builder To Optimize Buyer Journeys And Get More Leads & Sales plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'wpf_optin_form' shortcode in all v…
|
CWE-79
Cross-site Scripting
|
CVE-2026-0626
|
2026-04-25 03:13 |
2026-04-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
927
|
7.5 |
HIGH
Network
|
-
|
-
|
The Text to Speech for WP (AI Voices by Mementor) plugin for WordPress is vulnerable to sensitive information exposure in all versions up to, and including, 1.9.8. This is due to the plugin containin…
|
CWE-798
Use of Hard-coded Credentials
|
CVE-2026-1233
|
2026-04-25 03:13 |
2026-04-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
928
|
7.2 |
HIGH
Network
|
-
|
-
|
The Visitor Traffic Real Time Statistics plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'page_title' parameter in all versions up to, and including, 8.4 due to insufficient…
|
CWE-79
Cross-site Scripting
|
CVE-2026-2936
|
2026-04-25 03:13 |
2026-04-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
929
|
6.5 |
MEDIUM
Network
|
-
|
-
|
The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress plugin for WordPress is vulnerable to arbitrary shortcode execution in all ve…
|
CWE-94
Code Injection
|
CVE-2026-3309
|
2026-04-25 03:13 |
2026-04-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
930
|
8.8 |
HIGH
Network
|
-
|
-
|
The wpForo Forum plugin for WordPress is vulnerable to arbitrary file deletion in all versions up to, and including, 2.4.16. This is due to a missing file name/path validation against path traversal …
|
CWE-22
Path Traversal
|
CVE-2026-3666
|
2026-04-25 03:13 |
2026-04-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|