|
761
|
6.4 |
MEDIUM
Network
|
-
|
-
|
The Listen Shortcode plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'listen' shortcode in versions up to, and including, 1.0. This is due to insufficient input sanitization…
New
|
CWE-79
Cross-site Scripting
|
CVE-2026-8887
|
2026-05-27 23:50 |
2026-05-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
762
|
6.4 |
MEDIUM
Network
|
-
|
-
|
The BitForm plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'bitform' shortcode in versions up to, and including, 1.1.0. This is due to insufficient input sanitizat…
New
|
CWE-79
Cross-site Scripting
|
CVE-2026-8891
|
2026-05-27 23:50 |
2026-05-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
763
|
6.4 |
MEDIUM
Network
|
-
|
-
|
The iWR Tooltip plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's `iwrtooltip` shortcode in versions up to, and including, 1.0. This is due to insufficient input sani…
New
|
CWE-79
Cross-site Scripting
|
CVE-2026-8894
|
2026-05-27 23:50 |
2026-05-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
764
|
6.4 |
MEDIUM
Network
|
-
|
-
|
The Shortcode Buddy plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Shortcode Attributes in all versions up to, and including, 0.1.9.5 due to insufficient input sanitization and…
New
|
CWE-79
Cross-site Scripting
|
CVE-2026-8897
|
2026-05-27 23:50 |
2026-05-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
765
|
6.4 |
MEDIUM
Network
|
-
|
-
|
The Auto Thumbnail plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'thumbnails' shortcode in all versions up to, and including, 1.0. This is due to insufficient input saniti…
New
|
CWE-79
Cross-site Scripting
|
CVE-2026-8899
|
2026-05-27 23:50 |
2026-05-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
766
|
4.3 |
MEDIUM
Network
|
-
|
-
|
The Search Simple Fields plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 0.2. This is due to missing or incorrect nonce validation on the search_sim…
New
|
CWE-352
Origin Validation Error
|
CVE-2026-8939
|
2026-05-27 23:50 |
2026-05-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
767
|
4.3 |
MEDIUM
Network
|
-
|
-
|
The CDN Linker lite plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.3.1. This is due to missing or incorrect nonce validation on the ossdl_off_opt…
New
|
CWE-352
Origin Validation Error
|
CVE-2026-8941
|
2026-05-27 23:50 |
2026-05-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
768
|
6.4 |
MEDIUM
Network
|
-
|
-
|
The Events In City plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'org-events' shortcode in versions up to, and including, 3.0. This is due to insufficient input sanitizati…
New
|
CWE-79
Cross-site Scripting
|
CVE-2026-8898
|
2026-05-27 23:50 |
2026-05-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
769
|
4.3 |
MEDIUM
Network
|
-
|
-
|
The Two-factor authentication (formerly IP Vault) plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.1. This is due to missing or incorrect nonce…
New
|
CWE-352
Origin Validation Error
|
CVE-2026-8903
|
2026-05-27 23:50 |
2026-05-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
770
|
6.1 |
MEDIUM
Network
|
-
|
-
|
The WP AutoBuzz plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.1.1. This is due to missing or incorrect nonce validation on a function. This …
New
|
CWE-352
Origin Validation Error
|
CVE-2026-8911
|
2026-05-27 23:50 |
2026-05-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|