Total CVEs

130,823

Critical Severity

2,726

High Severity

9,741

Last 7 Days

870
Quick preset (or use dates below)
Clear Filters
πŸ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years β†’
Showing 481 - 500 of 27,228 CVEs
CVE-2026-8418 MEDIUM - 4.3

The Games Catalog plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.2.0. This is due to missing or incorrect nonce validation on the gc_crud() function which handles the delete action (action=delete) via a GET request without any wp_verify_nonce() /...

Published: May 20, 2026
Source: NVD
CVE-2026-8038 MEDIUM - 6.4

The Faces of Users plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'default' shortcode attribute in the 'facesofusers' shortcode in all versions up to, and including, 0.0.3 due to insufficient input sanitization and output escaping. This makes it possibl...

Published: May 20, 2026
Source: NVD
CVE-2026-7472 MEDIUM - 4.9

The Read More & Accordion plugin for WordPress is vulnerable to time-based blind SQL Injection via the 'orderby' parameter in all versions up to, and including, 3.5.7. This is due to the use of esc_sql() without surrounding the value in quotes in an ORDER BY clause inside the getAllDat...

Published: May 20, 2026
Source: NVD
CVE-2026-7467 HIGH - 8.8

The Read More & Accordion plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 3.5.7. This is due to the 'RadMoreAjax::importData' function not restricting which database tables can be written to during import and not properly validating the ...

Published: May 20, 2026
Source: NVD
CVE-2026-7462 MEDIUM - 6.1

The VatanSMS WP SMS plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the `page` parameter in all versions up to, and including, 1.01. This is due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary w...

Published: May 20, 2026
Source: NVD
CVE-2026-7284 CRITICAL - 9.8

The Easy Elements for Elementor – Addons & Website Templates plugin for WordPress is vulnerable to privilege escalation via user registration in all versions up to, and including, 1.4.4. This is due to the 'easyel_handle_register' function not restricting what user roles a user can reg...

Published: May 20, 2026
Source: NVD
CVE-2026-6555 CRITICAL - 9.8

The ProSolution WP Client plugin for WordPress is vulnerable to Arbitrary File Upload in versions up to, and including, 2.0.0. This is due to an array validation mismatch where only the first file in the upload array undergoes extension and MIME type validation, while all files are processed and upl...

Published: May 20, 2026
Source: NVD
CVE-2026-6549 MEDIUM - 6.4

The Logo Manager For Enamad plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'title' attribute of the `vc_enamad_namad`, `vc_enamad_shamed`, and `vc_enamad_custom` shortcodes in all versions up to, and including, 0.7.4 due to insufficient input sanitization and out...

Published: May 20, 2026
Source: NVD
CVE-2026-6456 HIGH - 8.8

The Account Switcher plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.0.2. This is due to the `rememberLogin` REST API endpoint using a loose comparison (`!=` instead of `!==`) for secret validation at `app/RestAPI.php:111`, combined with no validati...

Published: May 20, 2026
Source: NVD
CVE-2026-6452 MEDIUM - 4.3

The Bigfishgames Syndicate plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.2. This is due to missing or incorrect nonce validation on the bigfishgames_syndicate_submenu() function. This makes it possible for unauthenticated attackers to reset ...

Published: May 20, 2026
Source: NVD
CVE-2026-6404 MEDIUM - 4.4

The Anomify AI – Anomaly Detection and Alerting plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'anomify_api_key' parameter in versions up to and including 0.3.6. This is due to insufficient input sanitization and missing output escaping: the plugin applies saniti...

Published: May 20, 2026
Source: NVD
CVE-2026-6401 MEDIUM - 4.3

The Bottom Bar plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to and including 0.1.7. This is due to missing nonce verification on the plugin's settings update forms handled in bottom-bar-admin.php. None of the three settings forms (main settings, sharing se...

Published: May 20, 2026
Source: NVD
CVE-2026-6400 MEDIUM - 4.3

The Child Height Predictor by Ostheimer plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to and including 1.3. This is due to missing nonce verification in the options() function, which handles plugin settings updates. The form template does not include a wp_nonce_...

Published: May 20, 2026
Source: NVD
CVE-2026-6399 MEDIUM - 4.4

The General Options plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to and including 1.1.0. This is due to the use of sanitize_text_field() for output escaping in the Contact Number (ad_contact_number) field β€” a function that strips HTML tags but does not encode doub...

Published: May 20, 2026
Source: NVD
CVE-2026-6397 MEDIUM - 6.4

The Sticky plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `cvmh-sticky` shortcode `readmoretext` attribute in versions up to and including 2.5.6. This is due to insufficient input sanitization and output escaping in the `cvmh_sticky_front_render()` function β€” the `readmore...

Published: May 20, 2026
Source: NVD
CVE-2026-6395 MEDIUM - 6.1

The Word 2 Cash plugin for WordPress is vulnerable to Cross-Site Request Forgery leading to Stored Cross-Site Scripting in versions up to and including 0.9.2. This is due to the complete absence of nonce verification on the settings save handler in the w2c_admin() function, combined with missing inp...

Published: May 20, 2026
Source: NVD
CVE-2026-6394 MEDIUM - 5.4

The Nexa Blocks – Gutenberg Blocks, Page Builder for Gutenberg Editor & FSE plugin for WordPress is vulnerable to Server-Side Request Forgery (SSRF) in versions up to and including 1.1.1. This is due to the import_demo() function accepting a user-supplied URL in the demo_json_file POST parameter...

Published: May 20, 2026
Source: NVD
CVE-2026-6391 MEDIUM - 6.1

The Sentence To SEO (keywords, description and tags) plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0. This is due to missing or incorrect nonce validation on the create_admin_page() function. This makes it possible for unauthenticated attack...

Published: May 20, 2026
Source: NVD
CVE-2026-6072 MEDIUM - 6.5

The Oliver POS – A WooCommerce Point of Sale (POS) plugin for WordPress is vulnerable to Authorization Bypass Through User-Controlled Key in all versions up to and including 2.4.2.6. The plugin protects its entire /wp-json/pos-bridge/* REST API namespace through the oliver_pos_rest_authentication() ...

Published: May 20, 2026
Source: NVD
CVE-2026-5293 MEDIUM - 6.4

The θ¨Ίζ–­γ‚Έγ‚§γƒγƒ¬γƒΌγ‚Ώδ½œζˆγƒ—γƒ©γ‚°γ‚€γƒ³ (Diagnosis Generator) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'js' parameter in versions up to and including 1.4.16. This is due to missing authorization checks and insufficient input sanitization in the themeFunc() function. The functi...

Published: May 20, 2026
Source: NVD