Total CVEs

142,250

Critical Severity

3,947

High Severity

14,209

Last 7 Days

1,911
Quick preset (or use dates below)
Clear Filters
πŸ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years β†’
Showing 11,821 - 11,840 of 14,291 CVEs
CVE-2026-1394 MEDIUM - 4.3

The WP Quick Contact Us plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0. This is due to missing nonce validation on the settings update functionality. This makes it possible for unauthenticated attackers to update the plugin's settings ...

Published: Feb 14, 2026
Source: NVD
CVE-2026-1303 MEDIUM - 5.3

The MailChimp Campaigns plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 3.2.4. This is due to missing capability checks on the `mailchimp_campaigns_manager_disconnect_app` function that is hooked to the AJAX action of the same name. This makes it pos...

Published: Feb 14, 2026
Source: NVD
CVE-2026-1187 MEDIUM - 6.4

The ZoomifyWP Free plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'filename' parameter of the 'zoomify' shortcode in all versions up to, and including, 1.1 due to insufficient input sanitization and output escaping on user supplied attributes. This make...

Published: Feb 14, 2026
Source: NVD
CVE-2026-1096 MEDIUM - 6.4

The Best-wp-google-map plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'latitude' and 'longitudinal' parameters of the 'google_map_view' shortcode in all versions up to, and including, 2.1 due to insufficient input sanitization and output escap...

Published: Feb 14, 2026
Source: NVD
CVE-2026-0751 MEDIUM - 6.4

The Payment Page | Payment Form for Stripe plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'pricing_plan_select_text_font_family' parameter in all versions up to, and including, 1.4.6 due to insufficient input sanitization and output escaping. This makes it possib...

Published: Feb 14, 2026
Source: NVD
CVE-2026-0736 MEDIUM - 6.4

The Chatbot for WordPress by Collect.chat plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the '_inpost_head_script[synth_header_script]' post meta field in all versions up to, and including, 2.4.8 due to insufficient input sanitization and output escaping. This makes ...

Published: Feb 14, 2026
Source: NVD
CVE-2026-0735 MEDIUM - 4.4

The User Language Switch plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'tab_color_picker_language_switch' parameter in all versions up to, and including, 1.6.10 due to insufficient input sanitization and output escaping. This makes it possible for authenticated ...

Published: Feb 14, 2026
Source: NVD
CVE-2026-0727 MEDIUM - 5.4

The Accordion and Accordion Slider plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.4.5. This is due to the plugin not properly verifying that a user is authorized to perform an action in the 'wp_aas_save_attachment_data' and 'wp_aas_g...

Published: Feb 14, 2026
Source: NVD
CVE-2026-0693 MEDIUM - 4.4

The Allow HTML in Category Descriptions plugin for WordPress is vulnerable to Stored Cross-Site Scripting via category descriptions in all versions up to, and including, 1.2.4. This is due to the plugin unconditionally removing the `wp_kses_data` output filter for term_description, link_description,...

Published: Feb 14, 2026
Source: NVD
CVE-2026-0559 MEDIUM - 6.4

The MasterStudy LMS WordPress Plugin – for Online Courses and Education plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'stm_lms_courses_grid_display' shortcode in all versions up to, and including, 3.7.11 due to insufficient input sanitization and o...

Published: Feb 14, 2026
Source: NVD
CVE-2026-0557 MEDIUM - 6.4

The WP Data Access plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'wpda_app' shortcode in all versions up to, and including, 5.5.63 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for au...

Published: Feb 14, 2026
Source: NVD
CVE-2025-6792 MEDIUM - 5.3

The One to one user Chat by WPGuppy plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the /wp-json/guppylite/v2/channel-authorize rest endpoint in all versions up to, and including, 1.1.4. This makes it possible for unauthenticated attackers to in...

Published: Feb 14, 2026
Source: NVD
CVE-2025-15483 MEDIUM - 4.4

The Link Hopper plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the β€˜hop_name’ parameter in all versions up to, and including, 2.5 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level access, to...

Vendor: ajferg
Product: Link Hopper
Published: Feb 14, 2026
Source: NVD
CVE-2025-14873 MEDIUM - 4.3

The LatePoint – Calendar Booking Plugin for Appointments and Events plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 5.2.5. This is due to the 'call_by_route_name' function in the routing layer only validating user capabilities without ...

Vendor: latepoint
Product: LatePoint – Calendar Booking Plugin for Appointments and Events
Published: Feb 14, 2026
Source: NVD
CVE-2025-14852 MEDIUM - 4.3

The MDirector Newsletter plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 4.5.8. This is due to missing nonce verification on the mdirectorNewsletterSave function. This makes it possible for unauthenticated attackers to update the plugin's s...

Vendor: antevenio
Product: MDirector Newsletter
Published: Feb 14, 2026
Source: NVD
CVE-2026-1932 MEDIUM - 5.3

The Appointment Booking Calendar Plugin – Bookr plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the update-appointment REST API endpoint in all versions up to, and including, 1.0.2. This makes it possible for unauthenticated attackers to m...

Published: Feb 14, 2026
Source: NVD
CVE-2026-2027 MEDIUM - 4.4

The AMP Enhancer – Compatibility Layer for Official AMP Plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the AMP Custom CSS setting in all versions up to, and including, 1.0.49 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it ...

Published: Feb 14, 2026
Source: NVD
CVE-2026-1983 MEDIUM - 4.3

The SEATT: Simple Event Attendance plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.5.0. This is due to missing nonce validation on the event deletion functionality. This makes it possible for unauthenticated attackers to delete arbitrary event...

Published: Feb 14, 2026
Source: NVD
CVE-2026-1912 MEDIUM - 6.4

The Citations tools plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'code' parameter in the 'ctdoi' shortcode in all versions up to, and including, 0.3.2 due to insufficient input sanitization and output escaping on user supplied attributes. This makes i...

Published: Feb 14, 2026
Source: NVD
CVE-2026-1904 MEDIUM - 6.4

The Simple Wp colorfull Accordion plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'title' parameter in the 'accordion' shortcode in all versions up to, and including, 1.0 due to insufficient input sanitization and output escaping. This makes it possible ...

Published: Feb 14, 2026
Source: NVD