Total CVEs

126,184

Critical Severity

2,292

High Severity

7,950

Last 7 Days

1,208
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 2,021 - 2,040 of 22,589 CVEs
CVE-2026-4353 MEDIUM - 6.4

The CI HUB Connector plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'id' attribute of the `cihub_metadata` shortcode in all versions up to, and including, 1.2.106 due to insufficient input sanitization and output escaping. This makes it possible for authenticated...

Published: Apr 22, 2026
Source: NVD
CVE-2026-4280 MEDIUM - 6.5

The Breaking News WP plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1.3. This is due to the brnwp_ajax_form AJAX endpoint lacking both authorization checks and CSRF verification, combined with insufficient path validation when the brnwp_theme option ...

Published: Apr 22, 2026
Source: NVD
CVE-2026-4279 MEDIUM - 6.4

The Bread & Butter plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'breadbutter-customevent-button' shortcode in all versions up to, and including, 8.2.0.25. This is due to insufficient input sanitization and output escaping on the 'event' shortcode ...

Published: Apr 22, 2026
Source: NVD
CVE-2026-4142 MEDIUM - 4.4

The Sentence To SEO (keywords, description and tags) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'Permanent keywords' field in all versions up to and including 1.0. This is due to insufficient input sanitization and output escaping. The plugin reads user input...

Published: Apr 22, 2026
Source: NVD
CVE-2026-4140 MEDIUM - 4.3

The Ni WooCommerce Order Export plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to and including 3.1.6. This is due to missing nonce validation in the ni_order_export_action() AJAX handler function. The handler processes settings updates when the 'page' ...

Published: Apr 22, 2026
Source: NVD
CVE-2026-4139 MEDIUM - 4.3

The mCatFilter plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to and including 0.5.2. This is due to the complete absence of nonce verification and capability checks in the compute_post() function, which processes settings updates. The compute_post() function is ...

Published: Apr 22, 2026
Source: NVD
CVE-2026-4138 MEDIUM - 4.3

The DX Unanswered Comments plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.7. This is due to missing nonce validation on the plugin's settings form in the dxuc-unanswered-comments-admin-page.php file. This makes it possible for unauthenti...

Published: Apr 22, 2026
Source: NVD
CVE-2026-4133 MEDIUM - 4.3

The TextP2P Texting Widget plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to and including 1.7. This is due to missing nonce validation in the imTextP2POptionPage() function which processes settings updates. The form at line 314 does not include a wp_nonce_field(...

Published: Apr 22, 2026
Source: NVD
CVE-2026-4132 HIGH - 7.2

The HTTP Headers plugin for WordPress is vulnerable to External Control of File Name or Path leading to Remote Code Execution in all versions up to and including 1.19.2. This is due to insufficient validation of the file path stored in the 'hh_htpasswd_path' option and lack of sanitization...

Published: Apr 22, 2026
Source: NVD
CVE-2026-4131 MEDIUM - 6.1

The WP Responsive Popup + Optin plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to and including 1.4. This is due to the settings form on the admin page (wpo_admin_page.php) lacking nonce generation (wp_nonce_field) and verification (wp_verify_nonce/check_admin_re...

Published: Apr 22, 2026
Source: NVD
CVE-2026-4128 MEDIUM - 4.3

The TP Restore Categories And Taxonomies plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 1.0.1. The delete_term() function, which handles the 'tpmcattt_delete_term' AJAX action, does not perform any capability check (e.g., current_user_can(...

Published: Apr 22, 2026
Source: NVD
CVE-2026-4126 MEDIUM - 4.3

The Table Manager plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.0.0 via the 'table_manager' shortcode. The shortcode handler `tablemanager_render_table_shortcode()` takes a user-controlled `table` attribute, applies only `sanit...

Published: Apr 22, 2026
Source: NVD
CVE-2026-4125 MEDIUM - 6.4

The WPMK Block plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'class' shortcode attribute in all versions up to and including 1.0.1. This is due to insufficient input sanitization and output escaping on user-supplied shortcode attributes. Specifically, in the wpm...

Published: Apr 22, 2026
Source: NVD
CVE-2026-4121 MEDIUM - 4.3

The Kcaptcha plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to and including 1.0.1. This is due to missing nonce validation in the plugin's settings page handler (admin/setting.php). The settings form does not include a wp_nonce_field() and the form processi...

Published: Apr 22, 2026
Source: NVD
CVE-2026-4119 CRITICAL - 9.1

The Create DB Tables plugin for WordPress is vulnerable to authorization bypass in all versions up to and including 1.2.1. The plugin registers admin_post action hooks for creating tables (admin_post_add_table) and deleting tables (admin_post_delete_db_table) without implementing any capability chec...

Published: Apr 22, 2026
Source: NVD
CVE-2026-4118 MEDIUM - 4.3

The Call To Action Plugin plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.1.3. This is due to missing nonce validation in the cbox_options_page() function which handles saving, creating, and deleting plugin settings. The form rendered on the s...

Published: Apr 22, 2026
Source: NVD
CVE-2026-4117 MEDIUM - 5.3

The CalJ plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 1.5. This is due to a missing capability check in the CalJSettingsPage class constructor, which processes the 'save-obtained-key' operation directly from POST data without verifying t...

Published: Apr 22, 2026
Source: NVD
CVE-2026-4090 MEDIUM - 6.1

The Inquiry Cart plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.4.2. This is due to missing nonce verification in the rd_ic_settings_page function when processing settings form submissions. This makes it possible for unauthenticated attackers...

Published: Apr 22, 2026
Source: NVD
CVE-2026-4089 MEDIUM - 6.4

The Twittee Text Tweet plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'id' shortcode attribute in all versions up to and including 1.0.8. This is due to insufficient input sanitization and output escaping on user-supplied shortcode attributes. The ttt_twittee_twe...

Published: Apr 22, 2026
Source: NVD
CVE-2026-4088 MEDIUM - 6.4

The Switch CTA Box plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'wppw_cta_box' shortcode in all versions up to, and including, 1.1. This is due to insufficient input sanitization and output escaping on user-supplied post meta values including 'cta_box_butt...

Published: Apr 22, 2026
Source: NVD