Total CVEs

140,410

Critical Severity

3,747

High Severity

13,544

Last 7 Days

1,645
Quick preset (or use dates below)
Clear Filters
📅 Showing Year: 2026 (January 1 - December 31, 2026) View All Years →
Showing 7,081 - 7,100 of 13,554 CVEs
CVE-2026-39484 MEDIUM - 4.7

URL Redirection to Untrusted Site ('Open Redirect') vulnerability in John Darrel Hide My WP Ghost hide-my-wp allows Phishing.This issue affects Hide My WP Ghost: from n/a through < 7.0.00.

Vendor: John Darrel
Product: Hide My WP Ghost
Published: Apr 08, 2026
Source: NVD
CVE-2026-39483 MEDIUM - 6.5

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Hidekazu Ishikawa VK All in One Expansion Unit vk-all-in-one-expansion-unit allows Stored XSS.This issue affects VK All in One Expansion Unit: from n/a through <= 9.113.3.

Vendor: Hidekazu Ishikawa
Product: VK All in One Expansion Unit
Published: Apr 08, 2026
Source: NVD
CVE-2026-39482 MEDIUM - 6.5

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in PublishPress Post Expirator post-expirator allows DOM-Based XSS.This issue affects Post Expirator: from n/a through <= 4.9.4.

Vendor: PublishPress
Product: Post Expirator
Published: Apr 08, 2026
Source: NVD
CVE-2026-39477 MEDIUM - 4.3

Missing Authorization vulnerability in Brainstorm Force CartFlows cartflows allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects CartFlows: from n/a through <= 2.2.3.

Vendor: Brainstorm Force
Product: CartFlows
Published: Apr 08, 2026
Source: NVD
CVE-2026-39476 MEDIUM - 4.3

Missing Authorization vulnerability in Syed Balkhi User Feedback userfeedback-lite allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects User Feedback: from n/a through <= 1.10.1.

Vendor: Syed Balkhi
Product: User Feedback
Published: Apr 08, 2026
Source: NVD
CVE-2026-39473 MEDIUM - 5.3

Insertion of Sensitive Information Into Sent Data vulnerability in Pär Thernström Simple History simple-history allows Retrieve Embedded Sensitive Data.This issue affects Simple History: from n/a through <= 5.24.0.

Vendor: Pär Thernström
Product: Simple History
Published: Apr 08, 2026
Source: NVD
CVE-2026-39469 MEDIUM - 4.3

Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Softaculous PageLayer pagelayer allows Retrieve Embedded Sensitive Data.This issue affects PageLayer: from n/a through <= 2.0.8.

Vendor: Softaculous
Product: PageLayer
Published: Apr 08, 2026
Source: NVD
CVE-2026-39464 MEDIUM - 5.5

Server-Side Request Forgery (SSRF) vulnerability in SeedProd Coming Soon Page, Under Construction & Maintenance Mode by SeedProd coming-soon allows Server Side Request Forgery.This issue affects Coming Soon Page, Under Construction & Maintenance Mode by SeedProd: from n/a through <= 6.19....

Vendor: SeedProd
Product: Coming Soon Page, Under Construction & Maintenance Mode by SeedProd
Published: Apr 08, 2026
Source: NVD
CVE-2026-1396 MEDIUM - 6.4

The Magic Conversation For Gravity Forms plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'magic-conversation' shortcode in all versions up to, and including, 3.0.97 due to insufficient input sanitization and output escaping on user supplied attributes. This makes ...

Published: Apr 08, 2026
Source: NVD
CVE-2026-4655 MEDIUM - 6.4

The Element Pack Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the SVG Image Widget in versions up to and including 8.4.2. This is due to insufficient input sanitization and output escaping on SVG content fetched from remote URLs in the render_svg() funct...

Published: Apr 08, 2026
Source: NVD
CVE-2026-4654 MEDIUM - 5.3

The Awesome Support – WordPress HelpDesk & Support Plugin plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions up to, and including, 6.3.7. This is due to the wpas_get_ticket_replies_ajax() function failing to verify whether the authenticated user has permission to ...

Published: Apr 08, 2026
Source: NVD
CVE-2026-4330 MEDIUM - 4.3

The Blog2Social: Social Media Auto Post & Scheduler plugin for WordPress is vulnerable to authorization bypass through user-controlled key in all versions up to, and including, 8.8.3. This is due to the plugin's AJAX handlers failing to validate that the user-supplied 'b2s_id' par...

Published: Apr 08, 2026
Source: NVD
CVE-2026-5508 MEDIUM - 6.4

The WowPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's `wowpress` shortcode in all versions up to, and including, 1.0.0. This is due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authentica...

Published: Apr 08, 2026
Source: NVD
CVE-2026-5506 MEDIUM - 6.4

The Wavr plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's `wave` shortcode in all versions up to, and including, 0.2.6. This is due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated atta...

Published: Apr 08, 2026
Source: NVD
CVE-2026-5169 MEDIUM - 4.4

The Inquiry Form to Posts or Pages plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'Form Header' field in versions up to and including 1.0. This is due to insufficient input sanitization when saving via update_option() and lack of output escaping when displaying t...

Published: Apr 08, 2026
Source: NVD
CVE-2026-5167 MEDIUM - 5.3

The Masteriyo LMS – Online Course Builder for eLearning, LMS & Education plugin for WordPress is vulnerable to Authorization Bypass Through User-Controlled Key in versions up to and including 2.1.7. This is due to insufficient webhook signature verification in the handle_webhook() function. The ...

Published: Apr 08, 2026
Source: NVD
CVE-2026-4871 MEDIUM - 6.4

The Sports Club Management plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'before' and 'after' attributes of the `scm_member_data` shortcode in all versions up to, and including, 1.12.9 due to insufficient input sanitization and output escaping. This ma...

Published: Apr 08, 2026
Source: NVD
CVE-2026-4141 MEDIUM - 4.3

The Quran Translations plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.7. This is due to missing nonce validation in the quran_playlist_options() function that handles the plugin's settings page. The function processes POST requests to up...

Published: Apr 08, 2026
Source: NVD
CVE-2026-3781 MEDIUM - 5.4

The Attendance Manager plugin for WordPress is vulnerable to SQL Injection via the 'attmgr_off' parameter in all versions up to, and including, 0.6.2. This is due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This make...

Published: Apr 08, 2026
Source: NVD
CVE-2026-3618 MEDIUM - 6.4

The Columns by BestWebSoft plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'id' shortcode attribute of the [print_clmns] shortcode in all versions up to and including 1.0.3. This is due to insufficient input sanitization and output escaping on the 'id' a...

Published: Apr 08, 2026
Source: NVD