|
1051
|
6.4 |
MEDIUM
Network
|
-
|
-
|
The MIR blocks and shortcodes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'title' attribute (and other attributes such as 'ready_animation_text') of the 'msc_stats' shor…
New
|
CWE-79
Cross-site Scripting
|
CVE-2026-8896
|
2026-06-25 22:26 |
2026-06-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1052
|
6.1 |
MEDIUM
Network
|
-
|
-
|
The Osiris Signature Banner plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 0.5. This is due to missing or incorrect nonce validation on a funct…
New
|
CWE-352
Origin Validation Error
|
CVE-2026-8905
|
2026-06-25 22:26 |
2026-06-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1053
|
6.1 |
MEDIUM
Network
|
-
|
-
|
The EntreDroppers plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via PHP_SELF Parameter in all versions up to, and including, 1.1.2 due to insufficient input sanitization and ou…
New
|
CWE-79
Cross-site Scripting
|
CVE-2026-8628
|
2026-06-25 22:26 |
2026-06-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1054
|
7.5 |
HIGH
Network
|
-
|
-
|
The ClearSale Total plugin for WordPress is vulnerable to SQL Injection via the `pagseguro[metodo]` POST parameter of the `clearsale_total_push` AJAX action in all versions up to, and including, 3.4.…
New
|
CWE-89
SQL Injection
|
CVE-2026-8705
|
2026-06-25 22:26 |
2026-06-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1055
|
5.3 |
MEDIUM
Network
|
-
|
-
|
The Devs Accounting – Simple Accounting and Invoicing Solution plugin for WordPress is vulnerable to unauthorized modification/deletion of data due to a missing capability check on the delete_single_…
New
|
CWE-862
Missing Authorization
|
CVE-2026-9172
|
2026-06-25 22:26 |
2026-06-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1056
|
5.3 |
MEDIUM
Network
|
-
|
-
|
The Devs Accounting – Simple Accounting and Invoicing Solution plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 1.2.0. This is due to the get_single_a…
New
|
CWE-862
Missing Authorization
|
CVE-2026-9175
|
2026-06-25 22:26 |
2026-06-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1057
|
7.5 |
HIGH
Network
|
-
|
-
|
The WP Forms Connector plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 1.8. The plugin registers the REST route wp/v3/user/list/<id> (callback userDet…
New
|
CWE-862
Missing Authorization
|
CVE-2026-9178
|
2026-06-25 22:26 |
2026-06-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1058
|
4.3 |
MEDIUM
Network
|
-
|
-
|
The Generate Security.txt plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.0.12. This is due to the plugin not properly verifying that a user is auth…
New
|
CWE-862
Missing Authorization
|
CVE-2026-9616
|
2026-06-25 22:26 |
2026-06-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1059
|
4.3 |
MEDIUM
Network
|
-
|
-
|
The Reviews and Rating – Docplanner plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.1.4. This is due to the plugin not properly verifying that a use…
New
|
CWE-862
Missing Authorization
|
CVE-2026-9619
|
2026-06-25 22:26 |
2026-06-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1060
|
4.3 |
MEDIUM
Network
|
-
|
-
|
The 24liveblog - live blog tool plugin for WordPress is vulnerable to Exposure of Sensitive Information in versions up to, and including, 2.2. This is due to the lb24_block_enqueue_scripts() function…
New
|
CWE-200
Information Exposure
|
CVE-2026-9183
|
2026-06-25 22:26 |
2026-06-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|