|
431
|
4.4 |
MEDIUM
Network
|
-
|
-
|
The General Options plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to and including 1.1.0. This is due to the use of sanitize_text_field() for output escaping in the…
New
|
CWE-79
Cross-site Scripting
|
CVE-2026-6399
|
2026-05-20 22:54 |
2026-05-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
432
|
4.3 |
MEDIUM
Network
|
-
|
-
|
The Child Height Predictor by Ostheimer plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to and including 1.3. This is due to missing nonce verification in the opti…
New
|
CWE-352
Origin Validation Error
|
CVE-2026-6400
|
2026-05-20 22:54 |
2026-05-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
433
|
9.8 |
CRITICAL
Network
|
-
|
-
|
The ProSolution WP Client plugin for WordPress is vulnerable to Arbitrary File Upload in versions up to, and including, 2.0.0. This is due to an array validation mismatch where only the first file in…
New
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2026-6555
|
2026-05-20 22:54 |
2026-05-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
434
|
9.8 |
CRITICAL
Network
|
-
|
-
|
The Easy Elements for Elementor – Addons & Website Templates plugin for WordPress is vulnerable to privilege escalation via user registration in all versions up to, and including, 1.4.4. This is due …
New
|
CWE-269
Improper Privilege Management
|
CVE-2026-7284
|
2026-05-20 22:54 |
2026-05-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
435
|
6.1 |
MEDIUM
Network
|
-
|
-
|
The VatanSMS WP SMS plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the `page` parameter in all versions up to, and including, 1.01. This is due to insufficient input sanitiz…
New
|
CWE-79
Cross-site Scripting
|
CVE-2026-7462
|
2026-05-20 22:54 |
2026-05-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
436
|
4.3 |
MEDIUM
Network
|
-
|
-
|
The Bottom Bar plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to and including 0.1.7. This is due to missing nonce verification on the plugin's settings update fo…
New
|
CWE-352
Origin Validation Error
|
CVE-2026-6401
|
2026-05-20 22:54 |
2026-05-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
437
|
4.4 |
MEDIUM
Network
|
-
|
-
|
The Anomify AI – Anomaly Detection and Alerting plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'anomify_api_key' parameter in versions up to and including 0.3.6. This is du…
New
|
CWE-79
Cross-site Scripting
|
CVE-2026-6404
|
2026-05-20 22:54 |
2026-05-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
438
|
8.8 |
HIGH
Network
|
-
|
-
|
The Account Switcher plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.0.2. This is due to the `rememberLogin` REST API endpoint using a loose compari…
New
|
CWE-287
Improper Authentication
|
CVE-2026-6456
|
2026-05-20 22:54 |
2026-05-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
439
|
8.8 |
HIGH
Network
|
-
|
-
|
The Read More & Accordion plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 3.5.7. This is due to the 'RadMoreAjax::importData' function not restricting…
New
|
CWE-269
Improper Privilege Management
|
CVE-2026-7467
|
2026-05-20 22:54 |
2026-05-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
440
|
4.9 |
MEDIUM
Network
|
-
|
-
|
The Read More & Accordion plugin for WordPress is vulnerable to time-based blind SQL Injection via the 'orderby' parameter in all versions up to, and including, 3.5.7. This is due to the use of esc_s…
New
|
CWE-89
SQL Injection
|
CVE-2026-7472
|
2026-05-20 22:54 |
2026-05-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|