Vulnerability Report

WordPress Vulnerability Report: July 30 – August 6, 2026

288 WordPress vulnerabilities disclosed between July 30 – August 6, 2026. 25 critical, 81 high severity. 4 patched, 284 unpatched.

WPSentryAugust 6, 202660 min read

During the reporting period (July 30 – August 6, 2026), 288 WordPress security vulnerabilities were disclosed across plugins, themes, and core. This report aggregates data from the NIST National Vulnerability Database, Wordfence Intelligence, and our own scanning database.

Summary

288
Total
25
Critical
81
High
162
Medium
20
Low
4
Patched
Table of Contents 293 plugins & components

WordPress Plugin Vulnerabilities (287)

Ninja Tables Pro

critical
Vulnerability
Fluent Forms Pro 6.2.7 & Ninja Tables Pro 5.2.13 - Remote Code Execution via Backdoor
Severity
critical Critical risk
Affected Versions
<=5.2.11
CVE Reference
N/A
Patch Status
5.2.13
Source
Wordfence
Plugin Page

Fluent Forms Pro Add On Pack

critical
Vulnerability
Fluent Forms Pro 6.2.7 & Ninja Tables Pro 5.2.13 - Remote Code Execution via Backdoor
Severity
critical Critical risk
Affected Versions
<=6.2.7
CVE Reference
N/A
Patch Status
6.2.8
Source
Wordfence
Plugin Page

Realtyna Organic IDX plugin + WPL Real Estate

critical
Vulnerability
Realtyna Organic IDX plugin + WPL Real Estate — Arbitrary File Upload
Severity
critical Critical risk
Affected Versions
<=5.2.0
CVE Reference
Patch Status
No patch
Source
NVD
Plugin Page

ShopMonitor.io

critical
Vulnerability
ShopMonitor.io — Properly restrict its email-rerouting test mode
Severity
critical Critical risk
Affected Versions
<=1.2.0
CVE Reference
Patch Status
No patch
Source
NVD

FormGent

critical
Vulnerability
FormGent — Unauthorized arbitrary file deletion
Severity
critical Critical risk
Affected Versions
<=1.9.2
CVE Reference
Patch Status
No patch
Source
NVD
Plugin Page

Participants Database

critical
Vulnerability
Participants Database — Properly sanitize and escape a user-supplied parameter before using it in a SQL query
Severity
critical Critical risk
Affected Versions
<=2.7.8.4
CVE Reference
Patch Status
No patch
Source
NVD

Single Sign On For TNG

critical
Vulnerability
Single Sign On For TNG — Authentication Bypass
Severity
critical Critical risk
Affected Versions
<=2.0.0
CVE Reference
Patch Status
No patch
Source
NVD
Plugin Page

WooCommerce - Social Login

critical
Vulnerability
WooCommerce - Social Login — Authentication Bypass
Severity
critical Critical risk
Affected Versions
<=2.8.7
CVE Reference
Patch Status
No patch
Source
NVD

POUCO Import Users

critical
Vulnerability
POUCO Import Users — Perform any capability or nonce checks on AJAX actions available to unauthenticated users that creat
Severity
critical Critical risk
Affected Versions
<=1.0.0
CVE Reference
Patch Status
No patch
Source
NVD

Webinfos

critical
Vulnerability
Webinfos — Validate the type or name of uploaded files
Severity
critical Critical risk
Affected Versions
<=1.2
CVE Reference
Patch Status
No patch
Source
NVD

Super Store Finder

critical
Vulnerability
Super Store Finder — Sanitize a parameter of an unauthenticated AJAX action before using it in a SQL query
Severity
critical Critical risk
Affected Versions
<=7.8
CVE Reference
Patch Status
No patch
Source
NVD

SoftMarket — Digital Marketplace

critical
Vulnerability
SoftMarket — Digital Marketplace — Properly validate an authentication token in one branch of its email-verification flow
Severity
critical Critical risk
Affected Versions
<=1.0.0
CVE Reference
Patch Status
No patch
Source
NVD

Simple Membership

critical
Vulnerability
Simple Membership — Verify whether user creation failed during registration before using the returned value as a user ID
Severity
critical Critical risk
Affected Versions
<=4.7.8
CVE Reference
Patch Status
No patch
Source
NVD

Insert or Embed Articulate Content into

critical
Vulnerability
Insert or Embed Articulate Content into — Correctly validate the contents of an uploaded archive
Severity
critical Critical risk
Affected Versions
<=4.3000000027
CVE Reference
Patch Status
No patch
Source
NVD

Personal QR Message

critical
Vulnerability
Personal QR Message — Restrict the file types that can be uploaded through an unauthenticated handler
Severity
critical Critical risk
Affected Versions
<=1.0
CVE Reference
Patch Status
No patch
Source
NVD

ChamaWP

critical
Vulnerability
ChamaWP — Properly validate a password reset request
Severity
critical Critical risk
Affected Versions
<=1.0.13
CVE Reference
Patch Status
No patch
Source
NVD

Link Library

critical
Vulnerability
Link Library — Properly sanitise and escape a user-supplied value before using it in a SQL query
Severity
critical Critical risk
Affected Versions
<=7.9.3
CVE Reference
Patch Status
No patch
Source
NVD

Import and export users and customers

critical
Vulnerability
Import and export users and customers — Enforce WordPress's role-assignment and per-user edit permissions during CSV import
Severity
critical Critical risk
Affected Versions
<=2.4.2
CVE Reference
Patch Status
No patch
Source
NVD

Easy Integration for Dropbox

critical
Vulnerability
Easy Integration for Dropbox — Perform authorization checks on several of its file-management AJAX actions that it also registers f
Severity
critical Critical risk
Affected Versions
<=2.2.0
CVE Reference
Patch Status
No patch
Source
NVD

Improve SEO

critical
Vulnerability
Improve SEO — Properly validate uploaded files
Severity
critical Critical risk
Affected Versions
<=2.0.11
CVE Reference
Patch Status
No patch
Source
NVD

Membership Plugin – Kadence Memberships

critical
Vulnerability
Membership Plugin – Kadence Memberships — Password reset link poisoning leading to account takeover
Severity
critical Critical risk
Affected Versions
<=4.0.0
CVE Reference
Patch Status
No patch
Source
NVD
Plugin Page

OTP Login With Phone Number, OTP Verification

critical
Vulnerability
OTP Login With Phone Number, OTP Verification — Limit the number of OTP verification attempts or invalidate a one-time login code after a wrong gues
Severity
critical Critical risk
Affected Versions
<=1.8.71
CVE Reference
Patch Status
No patch
Source
NVD

Ajax Load More

critical
Vulnerability
Ajax Load More — Properly sanitise and escape a parameter before using it in a SQL query
Severity
critical Critical risk
Affected Versions
<=8.0.1
CVE Reference
Patch Status
No patch
Source
NVD

Easy Post Submission

critical
Vulnerability
Easy Post Submission — Unauthorized modification of data
Severity
critical Critical risk
Affected Versions
<=2.3.0
CVE Reference
Patch Status
No patch
Source
NVD
Plugin Page

Multi Uploader for Gravity Forms

critical
Vulnerability
Multi Uploader for Gravity Forms — Unauthorized arbitrary media deletion
Severity
critical Critical risk
Affected Versions
<=1.1.8
CVE Reference
Patch Status
No patch
Source
NVD
Plugin Page

ShopLentor – All-in-One WooCommerce Growth & Store Enhancement Plugin

high
Vulnerability
ShopLentor <= 3.3.7 - Authenticated (Administrator+) Arbitrary Function Execution via 'callback' Parameter via REST API
Severity
high High risk
Affected Versions
<=3.3.7
CVE Reference
Patch Status
3.3.8
Source
Wordfence
Plugin Page

Contact Form Extender for Divi – Submissions DB & Extra Fields

high
Vulnerability
Contact Form Extender for Divi Builder <= 1.0.6 - Unauthenticated Arbitrary File Deletion via Path Traversal
Severity
high High risk
Affected Versions
<=1.0.6
CVE Reference
N/A
Patch Status
1.0.7
Source
Wordfence
Plugin Page

Subscriptions for WooCommerce

high
Vulnerability
Subscriptions for WooCommerce — Missing Authorization
Severity
high High risk
Affected Versions
<=2.0.0
CVE Reference
Patch Status
No patch
Source
NVD
Plugin Page

Ultimate Member

high
Vulnerability
Ultimate Member — Filter administrator-level capabilities from the roles it makes selectable on its registration forms
Severity
high High risk
Affected Versions
<=2.12.1
CVE Reference
Patch Status
No patch
Source
NVD

miniOrange 2FA

high
Vulnerability
miniOrange 2FA — Validate the submitted one-time password against the targeted user's stored secret
Severity
high High risk
Affected Versions
<=6.2.6
CVE Reference
Patch Status
No patch
Source
NVD

Kirki

high
Vulnerability
Kirki — Restrict which classes may be instantiated when it deserialises data that unauthenticated users can
Severity
high High risk
Affected Versions
<=6.0.13
CVE Reference
Patch Status
No patch
Source
NVD

Kirki

high
Vulnerability
Kirki — Properly sanitise and escape a value taken from the request before using it in a SQL statement
Severity
high High risk
Affected Versions
<=6.0.13
CVE Reference
Patch Status
No patch
Source
NVD

ElementsKit Elementor Addons

high
Vulnerability
ElementsKit Elementor Addons — Prevent a custom-widget definition saved by a user with administrative capabilities from being writt
Severity
high High risk
Affected Versions
<=3.10.01
CVE Reference
Patch Status
No patch
Source
NVD

Frontend Admin by DynamiApps

high
Vulnerability
Frontend Admin by DynamiApps — CVE-2026-13609
Severity
high High risk
Affected Versions
<=3.29.9
CVE Reference
Patch Status
No patch
Source
NVD

GiveWP

high
Vulnerability
GiveWP — Properly restrict access to a REST API endpoint that returns recurring-donation records
Severity
high High risk
Affected Versions
<=4.16.3
CVE Reference
Patch Status
No patch
Source
NVD

Demi

high
Vulnerability
Demi — CVE-2026-14333
Severity
high High risk
Affected Versions
<=0.0.7
CVE Reference
Patch Status
No patch
Source
NVD

FlxWoo

high
Vulnerability
FlxWoo — Verify with the payment processor that a checkout session was actually paid before marking the assoc
Severity
high High risk
Affected Versions
<=3.1.1
CVE Reference
Patch Status
No patch
Source
NVD

JS Help Desk

high
Vulnerability
JS Help Desk — Perform any authorization
Severity
high High risk
Affected Versions
<=3.1.4
CVE Reference
Patch Status
No patch
Source
NVD

Geeky Bot

high
Vulnerability
Geeky Bot — Perform an authorization check on one of its AJAX actions
Severity
high High risk
Affected Versions
<=1.2.8
CVE Reference
Patch Status
No patch
Source
NVD

Product Feed Manager For WooCommerce

high
Vulnerability
Product Feed Manager For WooCommerce — Properly sanitise and escape product-feed custom filter rules before using them in a SQL query
Severity
high High risk
Affected Versions
<=7.6.1
CVE Reference
Patch Status
No patch
Source
NVD

Realtyna Organic IDX

high
Vulnerability
Realtyna Organic IDX — Arbitrary File Upload
Severity
high High risk
Affected Versions
<=5.3.0
CVE Reference
Patch Status
No patch
Source
NVD
Plugin Page

Bit integrations – Form Integration, Webhook, Spreadsheets, CRM, LMS & Email Automation

high
Vulnerability
Bit integrations – Form Integration, Webhook, Spreadsheets, CRM, LMS & Email Automation — Directory Traversal
Severity
high High risk
Affected Versions
<=2.9.0
CVE Reference
Patch Status
No patch
Source
NVD
Plugin Page

Subscriptions for WooCommerce

high
Vulnerability
Subscriptions for WooCommerce — Privilege Escalation
Severity
high High risk
Affected Versions
<=2.0.0
CVE Reference
Patch Status
No patch
Source
NVD
Plugin Page

Demo Import

high
Vulnerability
Demo Import — Validate the type of files uploaded during demo-content import (the WordPress file-type test is disa
Severity
high High risk
Affected Versions
<=1.1.3
CVE Reference
Patch Status
No patch
Source
NVD

Everest Toolkit

high
Vulnerability
Everest Toolkit — Validate the type of files uploaded during demo-content import (the WordPress file-type test is disa
Severity
high High risk
Affected Versions
<=1.2.3
CVE Reference
Patch Status
No patch
Source
NVD

Dynamic Pricing With Discount Rules for WooCommerce

high
Vulnerability
Dynamic Pricing With Discount Rules for WooCommerce — Validate a nonce or user capabilities on one of its AJAX actions and reflects unsanitised user input
Severity
high High risk
Affected Versions
<=5.0.0
CVE Reference
Patch Status
No patch
Source
NVD

Chat On Desk Order Notifications

high
Vulnerability
Chat On Desk Order Notifications — Verify that the one-time password has been validated before processing a password-reset request
Severity
high High risk
Affected Versions
<=1.0.9
CVE Reference
Patch Status
No patch
Source
NVD

DynamicKit for Elementor

high
Vulnerability
DynamicKit for Elementor — Validate the host of a user-supplied URL used as the base of the password-reset link it emails
Severity
high High risk
Affected Versions
<=1.0.3
CVE Reference
Patch Status
No patch
Source
NVD

Login & Register Forms

high
Vulnerability
Login & Register Forms — Properly enforce the rate limit on its password-reset verification-code flow
Severity
high High risk
Affected Versions
<=3.2.5
CVE Reference
Patch Status
No patch
Source
NVD

Mapster WP Maps

high
Vulnerability
Mapster WP Maps — Perform any authorization or post-status check on a public REST endpoint
Severity
high High risk
Affected Versions
<=1.24.0
CVE Reference
Patch Status
No patch
Source
NVD

HUSKY

high
Vulnerability
HUSKY — Sanitize a stored setting value against directory traversal before concatenating it into a file incl
Severity
high High risk
Affected Versions
<=1.4.1
CVE Reference
Patch Status
No patch
Source
NVD

User Profile Builder

high
Vulnerability
User Profile Builder — Correctly bind the automatic login performed after user registration to the newly created account
Severity
high High risk
Affected Versions
<=3.16.4
CVE Reference
Patch Status
No patch
Source
NVD

AI Engine – The Chatbot, AI Framework & MCP for WordPress

high
Vulnerability
AI Engine – The Chatbot, AI Framework & MCP for WordPress — Cross-Site Request Forgery
Severity
high High risk
Affected Versions
<=3.6.5
CVE Reference
Patch Status
No patch
Source
NVD
Plugin Page

MailChimp Subscribe Form, Optin Builder, PopUp Builder, Form Builder

high
Vulnerability
MailChimp Subscribe Form, Optin Builder, PopUp Builder, Form Builder — Stored Cross-Site Scripting
Severity
high High risk
Affected Versions
<=4.3.3
CVE Reference
Patch Status
No patch
Source
NVD
Plugin Page

Nex Forms – Ultimate Form Builder – Lite

high
Vulnerability
Nex Forms – Ultimate Form Builder – Lite — Arbitrary file deletion
Severity
high High risk
Affected Versions
<=9.2.3
CVE Reference
Patch Status
No patch
Source
NVD
Plugin Page

Kali Forms — Contact Form & Drag-and-Drop Builder

high
Vulnerability
Kali Forms — Contact Form & Drag-and-Drop Builder — Remote Code Execution
Severity
high High risk
Affected Versions
<=2.4.20
CVE Reference
Patch Status
No patch
Source
NVD
Plugin Page

Pronamic Pay

high
Vulnerability
Pronamic Pay — Privilege Escalation
Severity
high High risk
Affected Versions
<=10.1.0
CVE Reference
Patch Status
No patch
Source
NVD
Plugin Page

CubeWP Framework

high
Vulnerability
CubeWP Framework — Directory Traversal
Severity
high High risk
Affected Versions
<=1.1.30
CVE Reference
Patch Status
No patch
Source
NVD
Plugin Page

User Access Manager

high
Vulnerability
User Access Manager — Directory Traversal
Severity
high High risk
Affected Versions
<=2.3.15
CVE Reference
Patch Status
No patch
Source
NVD
Plugin Page

Five Star Restaurant Reservations

high
Vulnerability
Five Star Restaurant Reservations — Perform a capability check on one of its AJAX actions
Severity
high High risk
Affected Versions
<=2.7.23
CVE Reference
Patch Status
No patch
Source
NVD

SMS Alert

high
Vulnerability
SMS Alert — Bind its "mobile verified" session flag to the phone number that was actually verified: after an att
Severity
high High risk
Affected Versions
<=3.9.8
CVE Reference
Patch Status
No patch
Source
NVD

Gallery for Google Photos

high
Vulnerability
Gallery for Google Photos — Properly restrict access to the stored third-party OAuth credentials of the connected account
Severity
high High risk
Affected Versions
<=1.2.1
CVE Reference
Patch Status
No patch
Source
NVD

AI ChatBot for WooCommerce

high
Vulnerability
AI ChatBot for WooCommerce — Perform any authorization or nonce check on one of its AJAX actions
Severity
high High risk
Affected Versions
<=4.8.4
CVE Reference
Patch Status
No patch
Source
NVD

login-social

high
Vulnerability
login-social — Validate password-reset requests against a reset key or the requester's identity
Severity
high High risk
Affected Versions
<=1.0.4
CVE Reference
Patch Status
No patch
Source
NVD

Product Attachment for WooCommerce

high
Vulnerability
Product Attachment for WooCommerce — Perform any authorization check before streaming media library files
Severity
high High risk
Affected Versions
<=2.3.3
CVE Reference
Patch Status
No patch
Source
NVD

Simply Schedule Appointments

high
Vulnerability
Simply Schedule Appointments — Correctly restrict a bulk appointment operation to the requester's own records
Severity
high High risk
Affected Versions
<=1.6.12.6
CVE Reference
Patch Status
No patch
Source
NVD

ChamaWP

high
Vulnerability
ChamaWP — Properly validate user input before passing it to a PHP deserialization function
Severity
high High risk
Affected Versions
<=1.0.13
CVE Reference
Patch Status
No patch
Source
NVD

sm page duplicator

high
Vulnerability
sm page duplicator — Sanitise and escape a stored value before using it in a SQL statement when duplicating a page
Severity
high High risk
Affected Versions
<=1.0.0
CVE Reference
Patch Status
No patch
Source
NVD

LogMyTrip

high
Vulnerability
LogMyTrip — Sanitize and escape a value taken from a cookie before using it in a SQL query
Severity
high High risk
Affected Versions
<=1.9
CVE Reference
Patch Status
No patch
Source
NVD

Create Block

high
Vulnerability
Create Block — Correctly escape user-supplied text before writing it into a generated PHP pattern file
Severity
high High risk
Affected Versions
<=2.10.0
CVE Reference
Patch Status
No patch
Source
NVD

VikAppointments Service Booking Calendar

high
Vulnerability
VikAppointments Service Booking Calendar — Unauthenticated SQL injection
Severity
high High risk
Affected Versions
all
CVE Reference
Patch Status
No patch
Source
NVD
Plugin Page

VikRentItems – Flexible Rental Management System

high
Vulnerability
VikRentItems – Flexible Rental Management System — Stored Cross-Site Scripting
Severity
high High risk
Affected Versions
<=1.2.1
CVE Reference
Patch Status
No patch
Source
NVD
Plugin Page

Smart Popup by Supsystic

high
Vulnerability
Smart Popup by Supsystic — Privilege Escalation
Severity
high High risk
Affected Versions
<=1.12.0
CVE Reference
Patch Status
No patch
Source
NVD
Plugin Page

Dokan

high
Vulnerability
Dokan — Privilege Escalation
Severity
high High risk
Affected Versions
<=5.0.1
CVE Reference
Patch Status
No patch
Source
NVD
Plugin Page

zportals

high
Vulnerability
zportals — Properly validate uploaded files
Severity
high High risk
Affected Versions
<=6.3.4
CVE Reference
Patch Status
No patch
Source
NVD

YayPricing

high
Vulnerability
YayPricing — Perform capability checks on several of its REST API routes
Severity
high High risk
Affected Versions
<=3.5.7
CVE Reference
Patch Status
No patch
Source
NVD

WP 2FA

high
Vulnerability
WP 2FA — Validate the second authentication factor when one of its supported methods is selected at login
Severity
high High risk
Affected Versions
<=4.1.0
CVE Reference
Patch Status
No patch
Source
NVD

miniOrange 2FA

high
Vulnerability
miniOrange 2FA — Bind the second factor being configured during the pre-login two-factor challenge to the target acco
Severity
high High risk
Affected Versions
<=6.2.7
CVE Reference
Patch Status
No patch
Source
NVD

Contest Gallery

high
Vulnerability
Contest Gallery — Route its front-end login through the standard WordPress authentication flow
Severity
high High risk
Affected Versions
<=30.0.7
CVE Reference
Patch Status
No patch
Source
NVD

Sunshine Photo Cart

high
Vulnerability
Sunshine Photo Cart — Perform access control checks in one of its AJAX actions
Severity
high High risk
Affected Versions
<=3.6.12
CVE Reference
Patch Status
No patch
Source
NVD

Bit Form

high
Vulnerability
Bit Form — Sanitize an uploaded signature image before storing it
Severity
high High risk
Affected Versions
<=3.2.0
CVE Reference
Patch Status
No patch
Source
NVD

Passster

high
Vulnerability
Passster — Perform a post-status check before returning post content from an unauthenticated REST endpoint
Severity
high High risk
Affected Versions
<=4.3.6
CVE Reference
Patch Status
No patch
Source
NVD

Passster

high
Vulnerability
Passster — Enforce its category-based content protection on the WordPress REST API
Severity
high High risk
Affected Versions
<=4.3.6
CVE Reference
Patch Status
No patch
Source
NVD

Passster

high
Vulnerability
Passster — CVE-2026-16604
Severity
high High risk
Affected Versions
<=4.3.6
CVE Reference
Patch Status
No patch
Source
NVD

MultiVendorX

high
Vulnerability
MultiVendorX — Verify that the store targeted through its REST API belongs to the requesting vendor
Severity
high High risk
Affected Versions
<=5.0.11
CVE Reference
Patch Status
No patch
Source
NVD

User Registration & Membership

high
Vulnerability
User Registration & Membership — Enforce the site's registration-disabled setting when processing registration-form submissions
Severity
high High risk
Affected Versions
<=5.2.6
CVE Reference
Patch Status
No patch
Source
NVD

Page and Post Restriction

high
Vulnerability
Page and Post Restriction — Sensitive Information Exposure
Severity
high High risk
Affected Versions
<=1.4.0
CVE Reference
Patch Status
No patch
Source
NVD
Plugin Page

TableOn – WordPress Posts Table Filterable

high
Vulnerability
TableOn – WordPress Posts Table Filterable — Blind SQL Injection
Severity
high High risk
Affected Versions
<=1.0.5.1
CVE Reference
Patch Status
No patch
Source
NVD
Plugin Page

ShopLentor

high
Vulnerability
ShopLentor — Arbitrary function execution
Severity
high High risk
Affected Versions
<=3.3.7
CVE Reference
Patch Status
No patch
Source
NVD
Plugin Page

Material Dashboard

high
Vulnerability
Material Dashboard — Unauthorized access and modification of data
Severity
high High risk
Affected Versions
<=1.4.10
CVE Reference
Patch Status
No patch
Source
NVD
Plugin Page

LightSync Pro

high
Vulnerability
LightSync Pro — Arbitrary file uploads
Severity
high High risk
Affected Versions
<=2.1.6
CVE Reference
Patch Status
No patch
Source
NVD
Plugin Page

WPFormify – Stripe Payments with Form and Checkout

high
Vulnerability
WPFormify – Stripe Payments with Form and Checkout — Unauthorized modification and deletion of Stripe payment credentials
Severity
high High risk
Affected Versions
<=1.1.1
CVE Reference
Patch Status
No patch
Source
NVD
Plugin Page

AI Chatbot & Workflow Automation by AIWU

high
Vulnerability
AI Chatbot & Workflow Automation by AIWU — Sensitive Information Exposure
Severity
high High risk
Affected Versions
<=1.4.6
CVE Reference
Patch Status
No patch
Source
NVD
Plugin Page

Search Analytics for WP

high
Vulnerability
Search Analytics for WP — Cross-Site Request Forgery
Severity
high High risk
Affected Versions
<=1.4.16
CVE Reference
Patch Status
No patch
Source
NVD
Plugin Page

MailChimp Forms by MailMunch

high
Vulnerability
MailChimp Forms by MailMunch — Unauthorized modification of data
Severity
high High risk
Affected Versions
<=3.2.7
CVE Reference
Patch Status
No patch
Source
NVD
Plugin Page

Backup Migration

high
Vulnerability
Backup Migration — OS Command Injection
Severity
high High risk
Affected Versions
<=2.1.5.1
CVE Reference
Patch Status
No patch
Source
NVD
Plugin Page

wp-downloadmanager

high
Vulnerability
wp-downloadmanager — An admin-privileged user (current_user_can('manage_downloads')) to upload arbitrary files via downlo
Severity
high High risk
Affected Versions
all
CVE Reference
Patch Status
No patch
Source
NVD
Plugin Page

Content Egg – Affiliate Product Importer & Price Comparison

high
Vulnerability
Content Egg – Affiliate Product Importer & Price Comparison — Arbitrary File Deletion
Severity
high High risk
Affected Versions
<=11.3.0
CVE Reference
Patch Status
No patch
Source
NVD
Plugin Page

Independent Analytics

high
Vulnerability
Independent Analytics — Stored Cross-Site Scripting
Severity
high High risk
Affected Versions
<=2.15.0
CVE Reference
Patch Status
No patch
Source
NVD
Plugin Page

wiseCampaign – WooCommerce Conversions Made Easy

high
Vulnerability
wiseCampaign – WooCommerce Conversions Made Easy — Unauthorized modification and disclosure of data
Severity
high High risk
Affected Versions
<=1.1.16
CVE Reference
Patch Status
No patch
Source
NVD
Plugin Page

File Manager

high
Vulnerability
File Manager — Arbitrary file deletion
Severity
high High risk
Affected Versions
all
CVE Reference
Patch Status
No patch
Source
NVD
Plugin Page

FluentSMTP – WP SMTP Plugin with Amazon SES, SendGrid, MailGun, Postmark, Google and Any SMTP Provider

high
Vulnerability
FluentSMTP – WP SMTP Plugin with Amazon SES, SendGrid, MailGun, Postmark, Google and Any SMTP Provider — Stored Cross-Site Scripting
Severity
high High risk
Affected Versions
<=2.2.95
CVE Reference
Patch Status
No patch
Source
NVD
Plugin Page

Forminator Forms – Contact Form, Payment Form & Custom Form Builder

high
Vulnerability
Forminator Forms – Contact Form, Payment Form & Custom Form Builder — Stored Cross-Site Scripting
Severity
high High risk
Affected Versions
<=1.56.1
CVE Reference
Patch Status
No patch
Source
NVD
Plugin Page

WPMU DEV Dashboard

high
Vulnerability
WPMU DEV Dashboard — Authentication Bypass
Severity
high High risk
Affected Versions
<=5.0.0
CVE Reference
Patch Status
No patch
Source
NVD

TranslatePress – Translate Multilingual sites with AI Translation

high
Vulnerability
TranslatePress – Translate Multilingual sites with AI Translation — Stored Cross-Site Scripting
Severity
high High risk
Affected Versions
<=3.2.6
CVE Reference
Patch Status
No patch
Source
NVD
Plugin Page

FuseWP

medium
Vulnerability
FuseWP — Cross-Site Request Forgery
Severity
medium Medium risk
Affected Versions
<=1.1.24.2
CVE Reference
Patch Status
No patch
Source
NVD
Plugin Page

Academy LMS

medium
Vulnerability
Academy LMS — Restrict access to quiz attempt records to their owner
Severity
medium Medium risk
Affected Versions
<=3.8.2
CVE Reference
Patch Status
No patch
Source
NVD

wpForo Forum

medium
Vulnerability
wpForo Forum — Verify that an AI chat conversation belongs to the requesting user before deleting its messages
Severity
medium Medium risk
Affected Versions
<=3.1.2
CVE Reference
Patch Status
No patch
Source
NVD

GiveWP

medium
Vulnerability
GiveWP — Restrict the set of available payment gateways to those enabled by the administrator
Severity
medium Medium risk
Affected Versions
<=4.16.3
CVE Reference
Patch Status
No patch
Source
NVD

Check & Log Email

medium
Vulnerability
Check & Log Email — Properly sanitize and escape parameters before using them in SQL queries
Severity
medium Medium risk
Affected Versions
<=2.0.15
CVE Reference
Patch Status
No patch
Source
NVD

Lightbox with PhotoSwipe

medium
Vulnerability
Lightbox with PhotoSwipe — Sanitise or escape a link data attribute before rendering it into the image lightbox caption in the
Severity
medium Medium risk
Affected Versions
<=5.9.0
CVE Reference
Patch Status
No patch
Source
NVD

Mailgun for

medium
Vulnerability
Mailgun for — Perform any capability or nonce check on an unauthenticated AJAX action that adds subscribers to the
Severity
medium Medium risk
Affected Versions
<=2.2.1
CVE Reference
Patch Status
No patch
Source
NVD

Events Made Easy

medium
Vulnerability
Events Made Easy — Verify that the requester is authorized to modify the targeted record when handling an unauthenticat
Severity
medium Medium risk
Affected Versions
<=3.1.4
CVE Reference
Patch Status
No patch
Source
NVD

NewStatPress

medium
Vulnerability
NewStatPress — Sanitise and escape data derived from unauthenticated visitor requests before storing it and later o
Severity
medium Medium risk
Affected Versions
<=1.4.5
CVE Reference
Patch Status
No patch
Source
NVD
medium
Vulnerability
Paid Membership Subscriptions — Perform capability or nonce checks on one of its payment-related AJAX actions
Severity
medium Medium risk
Affected Versions
<=3.0.7
CVE Reference
Patch Status
No patch
Source
NVD

Ultimate Addons for WPBakery Page Builder

medium
Vulnerability
Ultimate Addons for WPBakery Page Builder — CVE-2026-14921
Severity
medium Medium risk
Affected Versions
<=3.21.5
CVE Reference
Patch Status
No patch
Source
NVD

JS Help Desk

medium
Vulnerability
JS Help Desk — Perform authorization or ownership checks before returning support-ticket content in a nonce-gated s
Severity
medium Medium risk
Affected Versions
<=3.1.4
CVE Reference
Patch Status
No patch
Source
NVD

JS Help Desk

medium
Vulnerability
JS Help Desk — Verify ownership of the targeted reply before updating it
Severity
medium Medium risk
Affected Versions
<=3.1.4
CVE Reference
Patch Status
No patch
Source
NVD

JS Help Desk

medium
Vulnerability
JS Help Desk — Perform a capability check on a user-listing handler
Severity
medium Medium risk
Affected Versions
<=3.1.4
CVE Reference
Patch Status
No patch
Source
NVD

JS Help Desk

medium
Vulnerability
JS Help Desk — Verify that the requesting user owns the ticket being loaded: a low-privileged authenticated user ca
Severity
medium Medium risk
Affected Versions
<=3.1.5
CVE Reference
Patch Status
No patch
Source
NVD

BuddyPress

medium
Vulnerability
BuddyPress — Properly enforce authorization on its private messaging endpoints
Severity
medium Medium risk
Affected Versions
<=14.5.0
CVE Reference
Patch Status
No patch
Source
NVD

MailPress

medium
Vulnerability
MailPress — Unauthorized access
Severity
medium Medium risk
Affected Versions
<=1.5.0
CVE Reference
Patch Status
No patch
Source
NVD
Plugin Page

MailerPress – Newsletter, email marketing & AI automation

medium
Vulnerability
MailerPress – Newsletter, email marketing & AI automation — Unauthorized access
Severity
medium Medium risk
Affected Versions
<=1.5.0
CVE Reference
Patch Status
No patch
Source
NVD
Plugin Page

Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder

medium
Vulnerability
Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder — Insecure Direct Object Reference
Severity
medium Medium risk
Affected Versions
<=6.2.8
CVE Reference
Patch Status
No patch
Source
NVD
Plugin Page

SendPulse Email Marketing Newsletter

medium
Vulnerability
SendPulse Email Marketing Newsletter — Stored Cross-Site Scripting
Severity
medium Medium risk
Affected Versions
<=2.2.5
CVE Reference
Patch Status
No patch
Source
NVD
Plugin Page

Pinpoint Booking System – Version 2

medium
Vulnerability
Pinpoint Booking System – Version 2 — Blind SQL Injection
Severity
medium Medium risk
Affected Versions
<=2.9.9.6.9
CVE Reference
Patch Status
No patch
Source
NVD
Plugin Page

SureForms – Contact Form, Payment Form & Other Custom Form Builder

medium
Vulnerability
SureForms – Contact Form, Payment Form & Other Custom Form Builder — Stored Cross-Site Scripting
Severity
medium Medium risk
Affected Versions
<=2.8.1
CVE Reference
Patch Status
No patch
Source
NVD
Plugin Page

Bit Form

medium
Vulnerability
Bit Form — Sanitise one of its conversational-form display settings before rendering it on the public-facing fo
Severity
medium Medium risk
Affected Versions
<=3.1.4
CVE Reference
Patch Status
No patch
Source
NVD

wpForo Forum

medium
Vulnerability
wpForo Forum — Sanitize and escape a user profile field before outputting it inside an HTML attribute on the public
Severity
medium Medium risk
Affected Versions
<=3.1.2
CVE Reference
Patch Status
No patch
Source
NVD

Direct Payments for WooCommerce

medium
Vulnerability
Direct Payments for WooCommerce — Verify that the requester owns the targeted WooCommerce order in several unauthenticated AJAX handle
Severity
medium Medium risk
Affected Versions
<=2.5.3
CVE Reference
Patch Status
No patch
Source
NVD

Buckaroo Woocommerce Payments Plugin

medium
Vulnerability
Buckaroo Woocommerce Payments Plugin — Perform any capability check or nonce validation on an AJAX action that processes payment capture re
Severity
medium Medium risk
Affected Versions
<=4.9.0
CVE Reference
Patch Status
No patch
Source
NVD

Pixelavo

medium
Vulnerability
Pixelavo — An unauthenticated visitor to inject arbitrary conversion events into the administrator's Facebook a
Severity
medium Medium risk
Affected Versions
<=1.5.4
CVE Reference
Patch Status
No patch
Source
NVD

Podlove Podcast Publisher

medium
Vulnerability
Podlove Podcast Publisher — Perform nonce validation on some of its administrative create and delete actions
Severity
medium Medium risk
Affected Versions
<=4.5.3
CVE Reference
Patch Status
No patch
Source
NVD

Download Manager

medium
Vulnerability
Download Manager — Properly escape a package's title before outputting it in the front-end package templates
Severity
medium Medium risk
Affected Versions
<=3.3.66
CVE Reference
Patch Status
No patch
Source
NVD

Pixel Tag Manager for WooCommerce

medium
Vulnerability
Pixel Tag Manager for WooCommerce — Perform an authorization check on one of its AJAX actions
Severity
medium Medium risk
Affected Versions
<=2.2.1
CVE Reference
Patch Status
No patch
Source
NVD

Authora : Easy login with mobile number

medium
Vulnerability
Authora : Easy login with mobile number — Keep its one-time login code confidential
Severity
medium Medium risk
Affected Versions
<=1.7.7
CVE Reference
Patch Status
No patch
Source
NVD

Event Tickets and Registration

medium
Vulnerability
Event Tickets and Registration — Perform any authorization check on one of its order-management REST endpoints
Severity
medium Medium risk
Affected Versions
<=5.29.0.1
CVE Reference
Patch Status
No patch
Source
NVD

YOP Poll

medium
Vulnerability
YOP Poll — Validate the connection's origin IP address and instead trusts client-controlled forwarding headers
Severity
medium Medium risk
Affected Versions
<=7.0.6
CVE Reference
Patch Status
No patch
Source
NVD

Codeless Page Builder

medium
Vulnerability
Codeless Page Builder — Sanitize or validate a shortcode attribute before using it as an HTML tag name when rendering conten
Severity
medium Medium risk
Affected Versions
<=1.1.4
CVE Reference
Patch Status
No patch
Source
NVD

Admin Columns for ACF Fields

medium
Vulnerability
Admin Columns for ACF Fields — Escape Advanced Custom Fields values before outputting them in the WordPress admin list-table column
Severity
medium Medium risk
Affected Versions
<=0.3.2
CVE Reference
Patch Status
No patch
Source
NVD

Support Genix

medium
Vulnerability
Support Genix — Prevent directory traversal in its ticket-attachment download route
Severity
medium Medium risk
Affected Versions
<=1.4.48
CVE Reference
Patch Status
No patch
Source
NVD

Theme Editor

medium
Vulnerability
Theme Editor — Cross-Site Request Forgery
Severity
medium Medium risk
Affected Versions
<=3.1
CVE Reference
Patch Status
No patch
Source
NVD
Plugin Page

Jeg Kit for Elementor

medium
Vulnerability
Jeg Kit for Elementor — Sensitive Information Exposure
Severity
medium Medium risk
Affected Versions
<=3.1.1
CVE Reference
Patch Status
No patch
Source
NVD
Plugin Page

WooCommerce PayPal Payments

medium
Vulnerability
WooCommerce PayPal Payments — Sensitive Information Disclosure
Severity
medium Medium risk
Affected Versions
<=3.3.2
CVE Reference
Patch Status
No patch
Source
NVD
Plugin Page

RealHomes Memberships

medium
Vulnerability
RealHomes Memberships — Authorization bypass
Severity
medium Medium risk
Affected Versions
<=3.0.9
CVE Reference
Patch Status
No patch
Source
NVD
Plugin Page

Gutena Forms – Contact Form, Survey Form, Feedback Form, Booking Form, and Custom Form Builder

medium
Vulnerability
Gutena Forms – Contact Form, Survey Form, Feedback Form, Booking Form, and Custom Form Builder — Authorization bypass
Severity
medium Medium risk
Affected Versions
<=1.9.0
CVE Reference
Patch Status
No patch
Source
NVD
Plugin Page

GenerateBlocks

medium
Vulnerability
GenerateBlocks — Stored Cross-Site Scripting
Severity
medium Medium risk
Affected Versions
<=2.3.0
CVE Reference
Patch Status
No patch
Source
NVD
Plugin Page

Database Collation Fix

medium
Vulnerability
Database Collation Fix — Time-based SQL Injection
Severity
medium Medium risk
Affected Versions
<=1.2.10
CVE Reference
Patch Status
No patch
Source
NVD
Plugin Page

Kirki – Freeform Page Builder, Website Builder & Customizer

medium
Vulnerability
Kirki – Freeform Page Builder, Website Builder & Customizer — Path Traversal (Zip Slip)
Severity
medium Medium risk
Affected Versions
<=6.0.13
CVE Reference
Patch Status
No patch
Source
NVD
Plugin Page

Powerkit – Supercharge your WordPress Site

medium
Vulnerability
Powerkit – Supercharge your WordPress Site — Stored Cross-Site Scripting
Severity
medium Medium risk
Affected Versions
<=3.1.0
CVE Reference
Patch Status
No patch
Source
NVD
Plugin Page

Powerkit – Supercharge your WordPress Site

medium
Vulnerability
Powerkit – Supercharge your WordPress Site — Stored Cross-Site Scripting
Severity
medium Medium risk
Affected Versions
<=3.1.0
CVE Reference
Patch Status
No patch
Source
NVD
Plugin Page

Powerkit – Supercharge your WordPress Site

medium
Vulnerability
Powerkit – Supercharge your WordPress Site — Stored Cross-Site Scripting
Severity
medium Medium risk
Affected Versions
<=3.1.0
CVE Reference
Patch Status
No patch
Source
NVD
Plugin Page

Advanced Woo Labels – Product Labels & Badges for WooCommerce

medium
Vulnerability
Advanced Woo Labels – Product Labels & Badges for WooCommerce — Stored Cross-Site Scripting
Severity
medium Medium risk
Affected Versions
<=2.48
CVE Reference
Patch Status
No patch
Source
NVD
Plugin Page

Cozy Blocks – Page Builder for Gutenberg Editor & FSE with 600+ Patterns, 58 Blocks & Templates

medium
Vulnerability
Cozy Blocks – Page Builder for Gutenberg Editor & FSE with 600+ Patterns, 58 Blocks & Templates — Stored Cross-Site Scripting
Severity
medium Medium risk
Affected Versions
<=2.2.11
CVE Reference
Patch Status
No patch
Source
NVD
Plugin Page

Icegram Mailer

medium
Vulnerability
Icegram Mailer — SQL Injection
Severity
medium Medium risk
Affected Versions
<=1.0.12
CVE Reference
Patch Status
No patch
Source
NVD
Plugin Page

Icegram Engage – Popups, Optins, CTAs & Lead Generation

medium
Vulnerability
Icegram Engage – Popups, Optins, CTAs & Lead Generation — Second-order SQL Injection
Severity
medium Medium risk
Affected Versions
<=3.1.42
CVE Reference
Patch Status
No patch
Source
NVD
Plugin Page

GamiPress – Gamification plugin to reward points, achievements, badges & ranks in WordPress

medium
Vulnerability
GamiPress – Gamification plugin to reward points, achievements, badges & ranks in WordPress — Stored Cross-Site Scripting
Severity
medium Medium risk
Affected Versions
<=7.9.9.1
CVE Reference
Patch Status
No patch
Source
NVD
Plugin Page

GamiPress – Gamification plugin to reward points, achievements, badges & ranks in WordPress

medium
Vulnerability
GamiPress – Gamification plugin to reward points, achievements, badges & ranks in WordPress — Stored Cross-Site Scripting
Severity
medium Medium risk
Affected Versions
<=7.9.9.1
CVE Reference
Patch Status
No patch
Source
NVD
Plugin Page

GSheetConnector – CF7 Google Sheets Connector with Real-Time Sync

medium
Vulnerability
GSheetConnector – CF7 Google Sheets Connector with Real-Time Sync — Generic SQL Injection
Severity
medium Medium risk
Affected Versions
<=5.2.1
CVE Reference
Patch Status
No patch
Source
NVD
Plugin Page

Easy Property Listings

medium
Vulnerability
Easy Property Listings — Stored Cross-Site Scripting
Severity
medium Medium risk
Affected Versions
<=3.5.24
CVE Reference
Patch Status
No patch
Source
NVD
Plugin Page

Download Manager

medium
Vulnerability
Download Manager — Stored Cross-Site Scripting
Severity
medium Medium risk
Affected Versions
<=3.3.66
CVE Reference
Patch Status
No patch
Source
NVD
Plugin Page

WPvivid Backup & Migration

medium
Vulnerability
WPvivid Backup & Migration — SQL Injection
Severity
medium Medium risk
Affected Versions
<=0.9.131
CVE Reference
Patch Status
No patch
Source
NVD
Plugin Page

Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder

medium
Vulnerability
Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder — Reflected Cross-Site Scripting
Severity
medium Medium risk
Affected Versions
<=6.2.8
CVE Reference
Patch Status
No patch
Source
NVD
Plugin Page

Advanced Views – Display Custom Fields (ACF, Pods, MetaBox), Posts, CPT and Woo Products anywhere in Gutenberg, Elementor, Divi, Beaver…

medium
Vulnerability
Advanced Views – Display Custom Fields (ACF, Pods, MetaBox), Posts, CPT and Woo Products anywhere in Gutenberg, Elementor, Divi, Beaver… — Sensitive Information Exposure
Severity
medium Medium risk
Affected Versions
<=3.9.1
CVE Reference
Patch Status
No patch
Source
NVD
Plugin Page

Payment forms, Buy now buttons, and Invoicing System | GetPaid

medium
Vulnerability
Payment forms, Buy now buttons, and Invoicing System | GetPaid — Local File Inclusion
Severity
medium Medium risk
Affected Versions
<=2.8.56
CVE Reference
Patch Status
No patch
Source
NVD
Plugin Page

PixelYourSite – Your smart PIXEL (TAG) & API Manager

medium
Vulnerability
PixelYourSite – Your smart PIXEL (TAG) & API Manager — Sensitive Information Exposure
Severity
medium Medium risk
Affected Versions
<=11.2.1
CVE Reference
Patch Status
No patch
Source
NVD
Plugin Page

Kadence Blocks — Page Builder Toolkit for Gutenberg Editor

medium
Vulnerability
Kadence Blocks — Page Builder Toolkit for Gutenberg Editor — Stored Cross-Site Scripting
Severity
medium Medium risk
Affected Versions
<=3.7.8.1
CVE Reference
Patch Status
No patch
Source
NVD
Plugin Page

Wp Responsive Thumbnail Slider

medium
Vulnerability
Wp Responsive Thumbnail Slider — Reflected Cross-Site Scripting
Severity
medium Medium risk
Affected Versions
all
CVE Reference
Patch Status
No patch
Source
NVD
Plugin Page

Kadence Blocks — Page Builder Toolkit for Gutenberg Editor

medium
Vulnerability
Kadence Blocks — Page Builder Toolkit for Gutenberg Editor — Stored Cross-Site Scripting
Severity
medium Medium risk
Affected Versions
<=3.7.8
CVE Reference
Patch Status
No patch
Source
NVD
Plugin Page

CubeWP Framework

medium
Vulnerability
CubeWP Framework — SQL Injection
Severity
medium Medium risk
Affected Versions
<=1.1.30
CVE Reference
Patch Status
No patch
Source
NVD
Plugin Page

Charitable

medium
Vulnerability
Charitable — Sanitise and escape one of its campaign image text fields before outputting it in an HTML attribute
Severity
medium Medium risk
Affected Versions
<=1.8.5.3
CVE Reference
Patch Status
No patch
Source
NVD

Clever Mega Menu for Visual Composer

medium
Vulnerability
Clever Mega Menu for Visual Composer — Perform a nonce or capability check in an AJAX action that updates navigation menu item metadata
Severity
medium Medium risk
Affected Versions
<=1.0.1
CVE Reference
Patch Status
No patch
Source
NVD

webtoffee-cookie-consent

medium
Vulnerability
webtoffee-cookie-consent — Perform authorization checks on several of its REST API routes
Severity
medium Medium risk
Affected Versions
<=3.5.3
CVE Reference
Patch Status
No patch
Source
NVD

Element Pack Addons for Elementor

medium
Vulnerability
Element Pack Addons for Elementor — Sanitize option values passed through certain data attributes before a bundled front-end library re-
Severity
medium Medium risk
Affected Versions
<=8.7.13
CVE Reference
Patch Status
No patch
Source
NVD

King Addons for Elementor

medium
Vulnerability
King Addons for Elementor — Escape a user-supplied grid setting before reflecting it into an HTML attribute in an unauthenticate
Severity
medium Medium risk
Affected Versions
<=51.1.76
CVE Reference
Patch Status
No patch
Source
NVD

JetEngine

medium
Vulnerability
JetEngine — Escape a post meta value before outputting it through one of its shortcodes
Severity
medium Medium risk
Affected Versions
<=3.8.12
CVE Reference
Patch Status
No patch
Source
NVD

FluentBoards

medium
Vulnerability
FluentBoards — Verify that the items selected for a board import operation belong to a board the requesting user is
Severity
medium Medium risk
Affected Versions
<=1.95.3
CVE Reference
Patch Status
No patch
Source
NVD

Meta Box

medium
Vulnerability
Meta Box — Verify that a user is authorized to delete the supplied attachment before deleting it
Severity
medium Medium risk
Affected Versions
<=5.13.1
CVE Reference
Patch Status
No patch
Source
NVD

RT Mega Menu

medium
Vulnerability
RT Mega Menu — Perform a capability check on the AJAX action that saves mega-menu configuration and per-menu-item s
Severity
medium Medium risk
Affected Versions
<=1.5.2
CVE Reference
Patch Status
No patch
Source
NVD

LWS Optimize

medium
Vulnerability
LWS Optimize — Perform a capability check on its cache-clearing actions
Severity
medium Medium risk
Affected Versions
<=3.4
CVE Reference
Patch Status
No patch
Source
NVD

Event Booking Manager for WooCommerce

medium
Vulnerability
Event Booking Manager for WooCommerce — Prevent the deserialization of user-controlled input in some of its event content fields
Severity
medium Medium risk
Affected Versions
<=5.3.7
CVE Reference
Patch Status
No patch
Source
NVD

Event Booking Manager for WooCommerce

medium
Vulnerability
Event Booking Manager for WooCommerce — Sanitise or escape event timeline content submitted by users with post-editing access before storing
Severity
medium Medium risk
Affected Versions
<=5.3.7
CVE Reference
Patch Status
No patch
Source
NVD

Event Booking Manager for WooCommerce

medium
Vulnerability
Event Booking Manager for WooCommerce — Properly verify authorization on the object being modified when quick-editing events
Severity
medium Medium risk
Affected Versions
<=5.3.7
CVE Reference
Patch Status
No patch
Source
NVD

Narrative Publisher

medium
Vulnerability
Narrative Publisher — Restrict write access to a REST-exposed post meta field or escape it when rendering
Severity
medium Medium risk
Affected Versions
<=1.0.7
CVE Reference
Patch Status
No patch
Source
NVD

ProfileGrid

medium
Vulnerability
ProfileGrid — Verify that a notification belongs to the requesting user before deleting it
Severity
medium Medium risk
Affected Versions
<=5.9.9.8
CVE Reference
Patch Status
No patch
Source
NVD

Frontend File Manager Plugin

medium
Vulnerability
Frontend File Manager Plugin — Perform nonce validation on one of its file-metadata update actions
Severity
medium Medium risk
Affected Versions
<=23.6
CVE Reference
Patch Status
No patch
Source
NVD

Exclusive Addons for Elementor

medium
Vulnerability
Exclusive Addons for Elementor — Stored Cross-Site Scripting
Severity
medium Medium risk
Affected Versions
<=2.7.9.8
CVE Reference
Patch Status
No patch
Source
NVD
Plugin Page

Import and export users and customers

medium
Vulnerability
Import and export users and customers — Restrict the path of a file it reads and displays during a CSV import
Severity
medium Medium risk
Affected Versions
<=2.4.3
CVE Reference
Patch Status
No patch
Source
NVD

SVG Support

medium
Vulnerability
SVG Support — Apply its SVG sanitisation to uploaded files using the
Severity
medium Medium risk
Affected Versions
<=2.5.17
CVE Reference
Patch Status
No patch
Source
NVD

Simply Schedule Appointments

medium
Vulnerability
Simply Schedule Appointments — Perform a capability check on an administrative appointment-listing shortcode
Severity
medium Medium risk
Affected Versions
<=1.6.12.11
CVE Reference
Patch Status
No patch
Source
NVD

GEO my WP

medium
Vulnerability
GEO my WP — Perform any ownership or capability check on two of its logged-in AJAX actions
Severity
medium Medium risk
Affected Versions
<=4.5.5.3
CVE Reference
Patch Status
No patch
Source
NVD

Blog Floating Button

medium
Vulnerability
Blog Floating Button — Sanitize or escape the visitor User-Agent header
Severity
medium Medium risk
Affected Versions
<=1.4.20
CVE Reference
Patch Status
No patch
Source
NVD

Simple Membership

medium
Vulnerability
Simple Membership — Sanitise a subscriber name value received from an unauthenticated payment approval request
Severity
medium Medium risk
Affected Versions
<=4.7.8
CVE Reference
Patch Status
No patch
Source
NVD

Contest Gallery

medium
Vulnerability
Contest Gallery — Perform per-object capability or nonce checks in one of its post-deletion handlers
Severity
medium Medium risk
Affected Versions
<=30.0.7
CVE Reference
Patch Status
No patch
Source
NVD

ProfileGrid

medium
Vulnerability
ProfileGrid — Perform authorization checks when listing a group's pending membership requests
Severity
medium Medium risk
Affected Versions
<=6.0.0.0
CVE Reference
Patch Status
No patch
Source
NVD

Clearfy Cache

medium
Vulnerability
Clearfy Cache — Restrict the classes allowed when unserializing settings-import data
Severity
medium Medium risk
Affected Versions
<=2.4.3
CVE Reference
Patch Status
No patch
Source
NVD

Academy LMS

medium
Vulnerability
Academy LMS — Verify course enrollment or lesson publication status when returning a single lesson through its RES
Severity
medium Medium risk
Affected Versions
<=3.8.3
CVE Reference
Patch Status
No patch
Source
NVD

Dokan: AI Powered WooCommerce Multivendor Marketplace Solution

medium
Vulnerability
Dokan: AI Powered WooCommerce Multivendor Marketplace Solution — Verify order ownership on a REST endpoint that performs bulk order-status changes
Severity
medium Medium risk
Affected Versions
<=5.0.9
CVE Reference
Patch Status
No patch
Source
NVD

Dokan: AI Powered WooCommerce Multivendor Marketplace Solution

medium
Vulnerability
Dokan: AI Powered WooCommerce Multivendor Marketplace Solution — Verify product ownership on its product-attribute REST write endpoints
Severity
medium Medium risk
Affected Versions
<=5.0.9
CVE Reference
Patch Status
No patch
Source
NVD

EmbedPress

medium
Vulnerability
EmbedPress — Validate user-supplied URLs before making server-side requests through unauthenticated endpoints
Severity
medium Medium risk
Affected Versions
<=4.6.1
CVE Reference
Patch Status
No patch
Source
NVD

wpForo Forum

medium
Vulnerability
wpForo Forum — Restrict which profile fields a member may set when editing their own account
Severity
medium Medium risk
Affected Versions
<=3.1.3
CVE Reference
Patch Status
No patch
Source
NVD

GDPR Framework By Data443

medium
Vulnerability
GDPR Framework By Data443 — Properly verify authorization or the identity of the data subject when recording cookie-consent choi
Severity
medium Medium risk
Affected Versions
<=2.4.0
CVE Reference
Patch Status
No patch
Source
NVD

Quiz and Survey Master (QSM)

medium
Vulnerability
Quiz and Survey Master (QSM) — Properly escape a question setting before outputting it into an unquoted HTML attribute
Severity
medium Medium risk
Affected Versions
<=11.2.2
CVE Reference
Patch Status
No patch
Source
NVD
medium
Vulnerability
Paid Membership Subscriptions — Verify that the subscription being modified through its change-subscription checkout belongs to the
Severity
medium Medium risk
Affected Versions
<=3.0.8
CVE Reference
Patch Status
No patch
Source
NVD

Database for Contact Form 7, WPforms, Elementor forms

medium
Vulnerability
Database for Contact Form 7, WPforms, Elementor forms — Properly sanitise and escape a parameter before using it in a SQL statement
Severity
medium Medium risk
Affected Versions
<=1.5.5
CVE Reference
Patch Status
No patch
Source
NVD

Visualizer

medium
Vulnerability
Visualizer — Restrict a user-supplied URL to safe address ranges before fetching it server-side
Severity
medium Medium risk
Affected Versions
<=4.0.6
CVE Reference
Patch Status
No patch
Source
NVD

Nested Pages

medium
Vulnerability
Nested Pages — Properly escape post titles before outputting them into HTML attributes on an administrative listing
Severity
medium Medium risk
Affected Versions
<=3.2.15
CVE Reference
Patch Status
No patch
Source
NVD

miniOrange 2FA

medium
Vulnerability
miniOrange 2FA — Restrict who can trigger its second-factor configuration OTP send
Severity
medium Medium risk
Affected Versions
<=6.2.7
CVE Reference
Patch Status
No patch
Source
NVD

Contest Gallery

medium
Vulnerability
Contest Gallery — Perform any capability or nonce check in one of its handlers
Severity
medium Medium risk
Affected Versions
<=30.0.7
CVE Reference
Patch Status
No patch
Source
NVD

Brizy

medium
Vulnerability
Brizy — Sanitize or escape featured-image focal-point coordinates submitted through one of its AJAX actions
Severity
medium Medium risk
Affected Versions
<=2.8.19
CVE Reference
Patch Status
No patch
Source
NVD

PowerPress Podcasting plugin by Blubrry

medium
Vulnerability
PowerPress Podcasting plugin by Blubrry — Sanitise and escape some of its Podcast Episode settings
Severity
medium Medium risk
Affected Versions
<=11.16.11
CVE Reference
Patch Status
No patch
Source
NVD

Clearfy Cache

medium
Vulnerability
Clearfy Cache — Perform a capability check in one of its admin-page dispatch paths
Severity
medium Medium risk
Affected Versions
<=2.4.3
CVE Reference
Patch Status
No patch
Source
NVD

Clearfy Cache

medium
Vulnerability
Clearfy Cache — Validate the redirect target in its Cyrlitera old-URL redirect handler
Severity
medium Medium risk
Affected Versions
<=2.4.3
CVE Reference
Patch Status
No patch
Source
NVD

Simple Google Calendar Outlook Events Widget

medium
Vulnerability
Simple Google Calendar Outlook Events Widget — Validate a user-supplied URL before performing a server-side request
Severity
medium Medium risk
Affected Versions
<=3.1.0
CVE Reference
Patch Status
No patch
Source
NVD

Wired Impact Volunteer Management

medium
Vulnerability
Wired Impact Volunteer Management — Have authorisation checks in one of its AJAX actions
Severity
medium Medium risk
Affected Versions
<=2.8.2
CVE Reference
Patch Status
No patch
Source
NVD

REST API Log

medium
Vulnerability
REST API Log — Bind the token protecting its log download feature to the log entry being requested
Severity
medium Medium risk
Affected Versions
<=1.7.1
CVE Reference
Patch Status
No patch
Source
NVD

Chat Widget: Floating Customer Support Button for 30+ Channels, Supporting SMS, Calls, and Chat

medium
Vulnerability
Chat Widget: Floating Customer Support Button for 30+ Channels, Supporting SMS, Calls, and Chat — Validate the type
Severity
medium Medium risk
Affected Versions
<=1.8.2
CVE Reference
Patch Status
No patch
Source
NVD

ERP: Complete HR, Accounting & CRM Suite with WooCommerce CRM Support

medium
Vulnerability
ERP: Complete HR, Accounting & CRM Suite with WooCommerce CRM Support — SQL Injection
Severity
medium Medium risk
Affected Versions
<=1.17.4
CVE Reference
Patch Status
No patch
Source
NVD
Plugin Page

PrettyLinks – Affiliate Links, Link Branding, Link Tracking, Marketing and Stripe Payments Plugin

medium
Vulnerability
PrettyLinks – Affiliate Links, Link Branding, Link Tracking, Marketing and Stripe Payments Plugin — SQL Injection
Severity
medium Medium risk
Affected Versions
<=3.6.20
CVE Reference
Patch Status
No patch
Source
NVD
Plugin Page

Cost Calculator Builder

medium
Vulnerability
Cost Calculator Builder — Unauthorized access of sensitive data
Severity
medium Medium risk
Affected Versions
<=3.6.17
CVE Reference
Patch Status
No patch
Source
NVD
Plugin Page

Football Pool

medium
Vulnerability
Football Pool — Reflected Cross-Site Scripting
Severity
medium Medium risk
Affected Versions
<=2.13.4
CVE Reference
Patch Status
No patch
Source
NVD
Plugin Page

Orbit Fox: Duplicate Page, Menu Icons, SVG Support, Cookie Notice, Custom Fonts & More

medium
Vulnerability
Orbit Fox: Duplicate Page, Menu Icons, SVG Support, Cookie Notice, Custom Fonts & More — Sanitize uploaded SVG files when its SVG upload feature is enabled
Severity
medium Medium risk
Affected Versions
<=3.0.8
CVE Reference
Patch Status
No patch
Source
NVD

GDPR Cookie Compliance

medium
Vulnerability
GDPR Cookie Compliance — CVE-2026-16613
Severity
medium Medium risk
Affected Versions
<=5.1.0
CVE Reference
Patch Status
No patch
Source
NVD

MultiVendorX

medium
Vulnerability
MultiVendorX — Verify that the requested store belongs to the current user in one of its REST API endpoints
Severity
medium Medium risk
Affected Versions
<=5.0.11
CVE Reference
Patch Status
No patch
Source
NVD

Custom Fields

medium
Vulnerability
Custom Fields — Validate a user-supplied file path before deletion
Severity
medium Medium risk
Affected Versions
<=1.5.1
CVE Reference
Patch Status
No patch
Source
NVD

WP Custom HTML Page

medium
Vulnerability
WP Custom HTML Page — Sanitise HTML stored through one of its custom page handlers
Severity
medium Medium risk
Affected Versions
<=0.6.2
CVE Reference
Patch Status
No patch
Source
NVD

GeoDirectory

medium
Vulnerability
GeoDirectory — Restrict a user-search handler to users allowed to list users
Severity
medium Medium risk
Affected Versions
<=2.8.168
CVE Reference
Patch Status
No patch
Source
NVD

DHL Shipping Germany for WooCommerce

medium
Vulnerability
DHL Shipping Germany for WooCommerce — Perform any authorization check (no capability
Severity
medium Medium risk
Affected Versions
<=4.0.1
CVE Reference
Patch Status
No patch
Source
NVD

MLSImport: IDX Plugin & MLS Plugin for Real Estate Listings

medium
Vulnerability
MLSImport: IDX Plugin & MLS Plugin for Real Estate Listings — Have authorisation and CSRF checks in one of its AJAX actions
Severity
medium Medium risk
Affected Versions
<=7.0.4
CVE Reference
Patch Status
No patch
Source
NVD

Groundhogg — CRM, Newsletters, and Marketing Automation

medium
Vulnerability
Groundhogg — CRM, Newsletters, and Marketing Automation — Insecure Direct Object Reference
Severity
medium Medium risk
Affected Versions
<=4.5.2
CVE Reference
Patch Status
No patch
Source
NVD
Plugin Page

JoomSport – for Sports: Team & League, Football, Hockey & more

medium
Vulnerability
JoomSport – for Sports: Team & League, Football, Hockey & more — Time-based SQL Injection
Severity
medium Medium risk
Affected Versions
<=5.7.9
CVE Reference
Patch Status
No patch
Source
NVD
Plugin Page

WP TripAdvisor Review Slider

medium
Vulnerability
WP TripAdvisor Review Slider — Generic SQL Injection
Severity
medium Medium risk
Affected Versions
<=14.3
CVE Reference
Patch Status
No patch
Source
NVD
Plugin Page

WP Post Author – Author Box, Multiple Authors, Guest Authors & Custom Avatars

medium
Vulnerability
WP Post Author – Author Box, Multiple Authors, Guest Authors & Custom Avatars — Generic SQL Injection
Severity
medium Medium risk
Affected Versions
<=3.9.1
CVE Reference
Patch Status
No patch
Source
NVD
Plugin Page

User Access Manager

medium
Vulnerability
User Access Manager — Second-Order SQL Injection
Severity
medium Medium risk
Affected Versions
<=2.3.12
CVE Reference
Patch Status
No patch
Source
NVD
Plugin Page

Translate Multilingual sites – TranslatePress

medium
Vulnerability
Translate Multilingual sites – TranslatePress — Reflected Cross-Site Scripting
Severity
medium Medium risk
Affected Versions
<=3.2.5
CVE Reference
Patch Status
No patch
Source
NVD
Plugin Page

Seraphinite Accelerator

medium
Vulnerability
Seraphinite Accelerator — Reflected Cross-Site Scripting
Severity
medium Medium risk
Affected Versions
<=2.29.15
CVE Reference
Patch Status
No patch
Source
NVD
Plugin Page

Super Progressive Web Apps

medium
Vulnerability
Super Progressive Web Apps — Stored Cross-Site Scripting
Severity
medium Medium risk
Affected Versions
<=2.2.43
CVE Reference
Patch Status
No patch
Source
NVD
Plugin Page

Contact Form 7 – Dynamic Text Extension

medium
Vulnerability
Contact Form 7 – Dynamic Text Extension — Stored Cross-Site Scripting
Severity
medium Medium risk
Affected Versions
<=5.0.5
CVE Reference
Patch Status
No patch
Source
NVD
Plugin Page

Askeet

medium
Vulnerability
Askeet — SQL Injection
Severity
medium Medium risk
Affected Versions
<=3.0
CVE Reference
Patch Status
No patch
Source
NVD
Plugin Page

SKT Skill Bar

medium
Vulnerability
SKT Skill Bar — Stored Cross-Site Scripting
Severity
medium Medium risk
Affected Versions
<=2.6
CVE Reference
Patch Status
No patch
Source
NVD
Plugin Page

Xpro Addons

medium
Vulnerability
Xpro Addons — Unauthorized creation of data
Severity
medium Medium risk
Affected Versions
<=1.5.1
CVE Reference
Patch Status
No patch
Source
NVD
Plugin Page

Simple Yearly Archive

medium
Vulnerability
Simple Yearly Archive — Stored Cross-Site Scripting
Severity
medium Medium risk
Affected Versions
<=2.2.4
CVE Reference
Patch Status
No patch
Source
NVD
Plugin Page

Layouts for WPBakery

medium
Vulnerability
Layouts for WPBakery — Unauthorized actions
Severity
medium Medium risk
Affected Versions
<=1.1.3
CVE Reference
Patch Status
No patch
Source
NVD
Plugin Page

Smash Balloon Social Photo Feed – Easy Social Feeds Plugin

medium
Vulnerability
Smash Balloon Social Photo Feed – Easy Social Feeds Plugin — Reflected Cross-Site Scripting
Severity
medium Medium risk
Affected Versions
<=6.11.3
CVE Reference
Patch Status
No patch
Source
NVD
Plugin Page

Udimi Tools

medium
Vulnerability
Udimi Tools — Unauthorized modification of data
Severity
medium Medium risk
Affected Versions
<=3.2
CVE Reference
Patch Status
No patch
Source
NVD
Plugin Page

Nexter Blocks

medium
Vulnerability
Nexter Blocks — Sanitize uploaded SVG files and allows SVG uploads for any user able to upload files (Author by defa
Severity
medium Medium risk
Affected Versions
<=5.0.2
CVE Reference
Patch Status
No patch
Source
NVD

EONSR AEO Agent

medium
Vulnerability
EONSR AEO Agent — Perform any authorisation check on one of its REST API routes and disables HTML sanitisation before
Severity
medium Medium risk
Affected Versions
<=3.7.9
CVE Reference
Patch Status
No patch
Source
NVD

WPCargo Track & Trace

medium
Vulnerability
WPCargo Track & Trace — Properly sanitise and escape a parameter before using it in a SQL statement
Severity
medium Medium risk
Affected Versions
<=8.0.4
CVE Reference
Patch Status
No patch
Source
NVD

Gutenberg Essential Blocks

medium
Vulnerability
Gutenberg Essential Blocks — Restrict access to one of its public REST routes and over-fetches a non-public WooCommerce per-produ
Severity
medium Medium risk
Affected Versions
<=6.4.0
CVE Reference
Patch Status
No patch
Source
NVD

Gutenberg Essential Blocks

medium
Vulnerability
Gutenberg Essential Blocks — Verify that an attacker-supplied post type is publicly viewable before querying it in one of its pub
Severity
medium Medium risk
Affected Versions
<=6.4.0
CVE Reference
Patch Status
No patch
Source
NVD

SEO Redirection Plugin

medium
Vulnerability
SEO Redirection Plugin — Perform a capability check in one of its authenticated AJAX actions
Severity
medium Medium risk
Affected Versions
<=9.19
CVE Reference
Patch Status
No patch
Source
NVD

Google Authenticator

medium
Vulnerability
Google Authenticator — Verify a CSRF nonce when saving its two-factor setup
Severity
medium Medium risk
Affected Versions
<=0.56
CVE Reference
Patch Status
No patch
Source
NVD

tourmaster

medium
Vulnerability
tourmaster — CVE-2026-14240
Severity
medium Medium risk
Affected Versions
<=5.4.9
CVE Reference
Patch Status
No patch
Source
NVD

PeproDev WooCommerce Receipt Uploader (PeproDev WooCommerce Receipt Uploader

medium
Vulnerability
PeproDev WooCommerce Receipt Uploader (PeproDev WooCommerce Receipt Uploader — CVE-2026-14313
Severity
medium Medium risk
Affected Versions
<=2.8.0
CVE Reference
Patch Status
No patch
Source
NVD

PeproDev WooCommerce Receipt Uploader

medium
Vulnerability
PeproDev WooCommerce Receipt Uploader — Verify that a requested attachment belongs to the order referenced by its access token
Severity
medium Medium risk
Affected Versions
<=2.8.0
CVE Reference
Patch Status
No patch
Source
NVD

Estatik Real Estate Plugin

medium
Vulnerability
Estatik Real Estate Plugin — Properly enforce its anti-spam check or restrict the recipient routing of its property request form
Severity
medium Medium risk
Affected Versions
<=4.3.3
CVE Reference
Patch Status
No patch
Source
NVD

Checkimate — WooCommerce Checkout, Abandoned Cart Recovery & Order Bumps

medium
Vulnerability
Checkimate — WooCommerce Checkout, Abandoned Cart Recovery & Order Bumps — Properly restrict access to its license-management functionality
Severity
medium Medium risk
Affected Versions
<=1.0.13
CVE Reference
Patch Status
No patch
Source
NVD

Drag and Drop Multiple File Upload for WooCommerce

medium
Vulnerability
Drag and Drop Multiple File Upload for WooCommerce — Prevent unauthenticated users from obtaining a valid nonce that is the only control gating its file-
Severity
medium Medium risk
Affected Versions
<=1.1.8
CVE Reference
Patch Status
No patch
Source
NVD

Welcart e-Commerce

medium
Vulnerability
Welcart e-Commerce — Properly sanitise a value taken from an imported CSV file before using it in a SQL statement
Severity
medium Medium risk
Affected Versions
<=2.11.32
CVE Reference
Patch Status
No patch
Source
NVD

Newsletters

medium
Vulnerability
Newsletters — Authenticate or validate a bounce-processing request before fetching a user-supplied URL on the serv
Severity
medium Medium risk
Affected Versions
<=4.16
CVE Reference
Patch Status
No patch
Source
NVD

ProfileGrid

medium
Vulnerability
ProfileGrid — Perform authorization checks before returning a group's member list
Severity
medium Medium risk
Affected Versions
<=6.0.0.0
CVE Reference
Patch Status
No patch
Source
NVD

Slick Slider

medium
Vulnerability
Slick Slider — Sanitize and escape a shortcode attribute value before outputting it in an HTML attribute
Severity
medium Medium risk
Affected Versions
<=0.5.3
CVE Reference
Patch Status
No patch
Source
NVD

Stripe Payment Forms by WP Full Pay

medium
Vulnerability
Stripe Payment Forms by WP Full Pay — Verify that the caller owns the Stripe payment intent referenced by two unauthenticated payment-form
Severity
medium Medium risk
Affected Versions
<=8.5.2
CVE Reference
Patch Status
No patch
Source
NVD

AI Engine

medium
Vulnerability
AI Engine — Redact secret configuration values before exposing them in an admin page's inline script data
Severity
medium Medium risk
Affected Versions
<=3.6.4
CVE Reference
Patch Status
No patch
Source
NVD

Events Manager

medium
Vulnerability
Events Manager — Perform any authorization check on a REST route that serves temporarily stored file uploads
Severity
medium Medium risk
Affected Versions
<=7.4
CVE Reference
Patch Status
No patch
Source
NVD

Child Pages Card

medium
Vulnerability
Child Pages Card — Sanitise and escape some of its shortcode attributes before outputting them back in a page
Severity
medium Medium risk
Affected Versions
<=1.09
CVE Reference
Patch Status
No patch
Source
NVD

Slider, Gallery, and Carousel by MetaSlider – Image Slider, Video Slider

medium
Vulnerability
Slider, Gallery, and Carousel by MetaSlider – Image Slider, Video Slider — Stored Cross-Site Scripting
Severity
medium Medium risk
Affected Versions
<=3.111.0
CVE Reference
Patch Status
No patch
Source
NVD
Plugin Page

ElementsKit Elementor Addons

low
Vulnerability
ElementsKit Elementor Addons — Sanitize or escape certain megamenu menu-item settings before storing them and outputting them on th
Severity
low Low risk
Affected Versions
<=3.10.01
CVE Reference
Patch Status
No patch
Source
NVD
low
Vulnerability
Paid Membership Subscriptions — Protect the member and payment export files it writes to a predictable location in the uploads direc
Severity
low Low risk
Affected Versions
<=3.0.7
CVE Reference
Patch Status
No patch
Source
NVD

Support Genix

low
Vulnerability
Support Genix — Properly authorize access to support-ticket attachment downloads
Severity
low Low risk
Affected Versions
<=1.4.48
CVE Reference
Patch Status
No patch
Source
NVD

FluentCart A New Era of eCommerce

low
Vulnerability
FluentCart A New Era of eCommerce — Perform any authorization or ownership check before rendering customer order documents keyed on a se
Severity
low Low risk
Affected Versions
<=1.5.3
CVE Reference
Patch Status
No patch
Source
NVD

WP Go Maps

low
Vulnerability
WP Go Maps — Properly sanitise and escape a parameter before using it in a SQL query
Severity
low Low risk
Affected Versions
<=10.1.04
CVE Reference
Patch Status
No patch
Source
NVD

Spectra Legacy

low
Vulnerability
Spectra Legacy — Validate or escape several block style attributes before using them to build the CSS it outputs on t
Severity
low Low risk
Affected Versions
<=2.20.0
CVE Reference
Patch Status
No patch
Source
NVD

Builderall for

low
Vulnerability
Builderall for — Bind the state value of its public OAuth authentication routes to the initiating user session
Severity
low Low risk
Affected Versions
<=3.0.2
CVE Reference
Patch Status
No patch
Source
NVD

Brizy

low
Vulnerability
Brizy — Properly verify authorization on a request handler before returning post content
Severity
low Low risk
Affected Versions
<=2.8.18
CVE Reference
Patch Status
No patch
Source
NVD

Fluent Support

low
Vulnerability
Fluent Support — Perform a per-ticket access check before reassigning a ticket's customer
Severity
low Low risk
Affected Versions
<=2.3.1
CVE Reference
Patch Status
No patch
Source
NVD

Booking for Appointments and Events Calendar

low
Vulnerability
Booking for Appointments and Events Calendar — Restrict which fields can be written through its customer import
Severity
low Low risk
Affected Versions
<=2.4.4
CVE Reference
Patch Status
No patch
Source
NVD

Event Tickets and Registration

low
Vulnerability
Event Tickets and Registration — Properly verify authorization on some of its seating actions
Severity
low Low risk
Affected Versions
<=5.29.0.1
CVE Reference
Patch Status
No patch
Source
NVD

Simple Restrict

low
Vulnerability
Simple Restrict — Enforce its content-restriction permission check on the REST API the way it does on the front end
Severity
low Low risk
Affected Versions
<=1.2.9
CVE Reference
Patch Status
No patch
Source
NVD

Tag, Category, and Taxonomy Manager

low
Vulnerability
Tag, Category, and Taxonomy Manager — Verify that a user is authorized to access a referenced post before processing it and returning deri
Severity
low Low risk
Affected Versions
<=3.51.0
CVE Reference
Patch Status
No patch
Source
NVD

Classified Listing

low
Vulnerability
Classified Listing — Perform a capability or ownership check on an AJAX action that returns a post's content
Severity
low Low risk
Affected Versions
<=5.4.4
CVE Reference
Patch Status
No patch
Source
NVD

Classified Listing

low
Vulnerability
Classified Listing — Perform a capability check on an AJAX action that returns aggregated store revenue totals
Severity
low Low risk
Affected Versions
<=5.4.4
CVE Reference
Patch Status
No patch
Source
NVD

MonsterInsights

low
Vulnerability
MonsterInsights — Correctly validate the signature on one of its unauthenticated AJAX actions: when the MonsterInsight
Severity
low Low risk
Affected Versions
<=11.1.0
CVE Reference
Patch Status
No patch
Source
NVD

Brizy

low
Vulnerability
Brizy — Properly restrict who can modify its site-global design data and does not sanitise part of that data
Severity
low Low risk
Affected Versions
<=2.8.19
CVE Reference
Patch Status
No patch
Source
NVD

Brizy

low
Vulnerability
Brizy — Properly verify authorization on the object being modified before updating a template's type meta
Severity
low Low risk
Affected Versions
<=2.8.19
CVE Reference
Patch Status
No patch
Source
NVD

GeoDirectory

low
Vulnerability
GeoDirectory — Sanitise and escape a place-category setting before outputting it back in an admin page
Severity
low Low risk
Affected Versions
<=2.8.110
CVE Reference
Patch Status
No patch
Source
NVD

DHL Shipping Germany for WooCommerce

low
Vulnerability
DHL Shipping Germany for WooCommerce — Protect its shipping-label storage directory with server-independent access control
Severity
low Low risk
Affected Versions
<=4.0.1
CVE Reference
Patch Status
No patch
Source
NVD

WordPress Theme Vulnerabilities (1)

Lenxel WP

high
Vulnerability
Lenxel WP — Perform any authorization or ownership check on its password-reset action
Severity
high High risk
Affected Versions
<=1.0.31
CVE Reference
Patch Status
No patch
Source
NVD

WordPress Core Vulnerabilities (0)

No vulnerabilities reported in this category this week.

Recommendations

1
Update immediately
Install the latest versions of all plugins, themes, and WordPress core.
2
Enable auto-updates
Turn on automatic updates for minor WordPress releases and plugins where possible.
3
Remove unused plugins
Deactivate and delete any plugins or themes you no longer use.
4
Run a security scan
Use our free WordPress security scanner to check your site for known vulnerabilities.
5
Monitor regularly
Set up uptime monitoring and periodic security scans to catch issues early.

Methodology

This report is compiled automatically from multiple trusted sources:

NIST National Vulnerability Database (NVD)
CVE records with CVSS severity scores
Wordfence Intelligence
WordPress-specific vulnerability data with patch information
Our Scanning Database
Vulnerabilities detected through active WordPress security scans

Tags

Related Posts