CVE-2026-97643 - GiveWP <= 4.17.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via givewp_campaign_grid Shortcode Attributes
CVE ID :CVE-2026-97643
Published : Oct. 10, 2026, 5:31 a.m. | 58 minutes ago
Description :The GiveWP – Donation Plugin and Fundraising Platform plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's `givewp_campaign_grid` shortcode in versions up to, and including, 4.17.0 This is due to insufficient input sanitization and output escaping on user supplied shortcode attributes (`filter_by`, `layout`, `sort_by`, `order_by`) in the CampaignGridShortcode::parseAttributes() function combined with the render template emitting `json_encode($attributes)` inside a single-quoted HTML attribute without esc_attr() — json_encode() does not escape single quotes by default, so a `'` in an attribute value breaks out of the enclosing attribute. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Severity: 6.4 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-97643
Published : Oct. 10, 2026, 5:31 a.m. | 58 minutes ago
Description :The GiveWP – Donation Plugin and Fundraising Platform plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's `givewp_campaign_grid` shortcode in versions up to, and including, 4.17.0 This is due to insufficient input sanitization and output escaping on user supplied shortcode attributes (`filter_by`, `layout`, `sort_by`, `order_by`) in the CampaignGridShortcode::parseAttributes() function combined with the render template emitting `json_encode($attributes)` inside a single-quoted HTML attribute without esc_attr() — json_encode() does not escape single quotes by default, so a `'` in an attribute value breaks out of the enclosing attribute. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Severity: 6.4 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-93775 - Podlove Podcast Publisher <= 4.5.6 - Unauthenticated Stored Cross-Site Scripting via Auphonic Webhook
CVE ID :CVE-2026-93775
Published : Oct. 10, 2026, 5:31 a.m. | 58 minutes ago
Description :The Podlove Podcast Publisher plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Auphonic Webhook in all versions up to, and including, 4.5.6 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. The injection is triggered by submitting a request to the Auphonic webhook endpoint with any POST body where the status_string field is not the literal string 'Done', causing the full raw POST superglobal to be stored in the plugin log before any authentication key validation is performed.
Severity: 7.2 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-93775
Published : Oct. 10, 2026, 5:31 a.m. | 58 minutes ago
Description :The Podlove Podcast Publisher plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Auphonic Webhook in all versions up to, and including, 4.5.6 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. The injection is triggered by submitting a request to the Auphonic webhook endpoint with any POST body where the status_string field is not the literal string 'Done', causing the full raw POST superglobal to be stored in the plugin log before any authentication key validation is performed.
Severity: 7.2 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-14877 - Data Tables Generator by Supsystic <= 1.12.03 - Authenticated (Contributor+) Stored Cross-Site Scripting via Table 'id' HTML Attribute
CVE ID :CVE-2026-14877
Published : Oct. 10, 2026, 5:31 a.m. | 58 minutes ago
Description :The Data Tables Generator by Supsystic plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the id attribute in all versions up to, and including, 1.12.03 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Severity: 6.4 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-14877
Published : Oct. 10, 2026, 5:31 a.m. | 58 minutes ago
Description :The Data Tables Generator by Supsystic plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the id attribute in all versions up to, and including, 1.12.03 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Severity: 6.4 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-103482 - Simple Newsletter Plugin <= 4.3.10 - Unauthenticated Stored Cross-Site Scripting via Subscriber Custom Field via Manage Preferences Form + Campaign Preview noptin_key Pivot
CVE ID :CVE-2026-103482
Published : Oct. 10, 2026, 5:31 a.m. | 58 minutes ago
Description :The Simple Newsletter Plugin – Noptin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'noptin_fields[] (e.g. first_name)' parameter in all versions up to, and including, 4.3.10 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. The attack chain requires a published campaign post whose body contains a [[subscriber.*]] merge tag; the unauthenticated attacker first POSTs the entity-encoded payload to the public manage_preferences form (which issues its own nonce on the same page), then pivots execution by embedding their confirm_key in a campaign preview URL sent to a privileged user via social engineering.
Severity: 5.4 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-103482
Published : Oct. 10, 2026, 5:31 a.m. | 58 minutes ago
Description :The Simple Newsletter Plugin – Noptin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'noptin_fields[] (e.g. first_name)' parameter in all versions up to, and including, 4.3.10 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. The attack chain requires a published campaign post whose body contains a [[subscriber.*]] merge tag; the unauthenticated attacker first POSTs the entity-encoded payload to the public manage_preferences form (which issues its own nonce on the same page), then pivots execution by embedding their confirm_key in a campaign preview URL sent to a privileged user via social engineering.
Severity: 5.4 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-103912 - JetFormBuilder <= 3.6.6 - Reflected DOM-Based Cross-Site Scripting via 'query_var' Dynamic Preset via data-jfb-macro / JFB_FIELD:: Macro Renderer
CVE ID :CVE-2026-103912
Published : Oct. 10, 2026, 5:31 a.m. | 58 minutes ago
Description :The JetFormBuilder — Dynamic Blocks Form Builder plugin for WordPress is vulnerable to Reflected DOM-Based Cross-Site Scripting via the '' parameter in all versions up to, and including, 3.6.6 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link. This is only exploitable on pages embedding a form that has a text field configured with a query_var Dynamic Preset and a data-jfb-macro or JFB_FIELD:: macro reference targeting that field, both of which are standard, documented plugin features.
Severity: 4.7 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-103912
Published : Oct. 10, 2026, 5:31 a.m. | 58 minutes ago
Description :The JetFormBuilder — Dynamic Blocks Form Builder plugin for WordPress is vulnerable to Reflected DOM-Based Cross-Site Scripting via the '' parameter in all versions up to, and including, 3.6.6 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link. This is only exploitable on pages embedding a form that has a text field configured with a query_var Dynamic Preset and a data-jfb-macro or JFB_FIELD:: macro reference targeting that field, both of which are standard, documented plugin features.
Severity: 4.7 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-14882 - Brizy <= 2.8.18 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'brizy-compiled-sections' Post Meta
CVE ID :CVE-2026-14882
Published : Oct. 10, 2026, 5:31 a.m. | 58 minutes ago
Description :The Brizy – Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'brizy-compiled-sections' parameter in all versions up to, and including, 2.8.18 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Severity: 6.4 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-14882
Published : Oct. 10, 2026, 5:31 a.m. | 58 minutes ago
Description :The Brizy – Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'brizy-compiled-sections' parameter in all versions up to, and including, 2.8.18 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Severity: 6.4 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-17025 - Graphene <= 2.9.4 - Authenticated (Subscriber+) Stored Cross-Site Scripting via Profile Fields
CVE ID :CVE-2026-17025
Published : Oct. 10, 2026, 5:31 a.m. | 58 minutes ago
Description :The Graphene theme for WordPress is vulnerable to Stored Cross-Site Scripting via 'Current location' and 'Author profile image URL' Profile Fields in all versions up to, and including, 2.9.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Subscriber-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Severity: 6.4 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-17025
Published : Oct. 10, 2026, 5:31 a.m. | 58 minutes ago
Description :The Graphene theme for WordPress is vulnerable to Stored Cross-Site Scripting via 'Current location' and 'Author profile image URL' Profile Fields in all versions up to, and including, 2.9.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Subscriber-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Severity: 6.4 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-14335 - Easy Digital Downloads <= 3.6.9 - Unauthenticated Stored Cross-Site Scripting via PayPal IPN Parameters
CVE ID :CVE-2026-14335
Published : Oct. 10, 2026, 5:31 a.m. | 58 minutes ago
Description :The Easy Digital Downloads – eCommerce Payments and Subscriptions made easy plugin for WordPress is vulnerable to Stored Cross-Site Scripting via PayPal IPN Parameters in all versions up to, and including, 3.6.9 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Severity: 7.2 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-14335
Published : Oct. 10, 2026, 5:31 a.m. | 58 minutes ago
Description :The Easy Digital Downloads – eCommerce Payments and Subscriptions made easy plugin for WordPress is vulnerable to Stored Cross-Site Scripting via PayPal IPN Parameters in all versions up to, and including, 3.6.9 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Severity: 7.2 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-12054 - Download Manager <= 3.3.57 - Unauthenticated DOM-Based Reflected Cross-Site Scripting via 'REFERRER' Parameter
CVE ID :CVE-2026-12054
Published : Oct. 10, 2026, 5:31 a.m. | 58 minutes ago
Description :The Download Manager plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via 'REFERRER' parameter in all versions up to, and including, 3.3.57 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts that execute in a victim's browser.
Severity: 6.1 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-12054
Published : Oct. 10, 2026, 5:31 a.m. | 58 minutes ago
Description :The Download Manager plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via 'REFERRER' parameter in all versions up to, and including, 3.3.57 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts that execute in a victim's browser.
Severity: 6.1 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-104752 - Rank Math SEO < 1.0.280 - Admin+ Arbitrary File Upload to RCE via Settings Import
CVE ID :CVE-2026-104752
Published : Oct. 10, 2026, 6 a.m. | 29 minutes ago
Description :The Rank Math SEO WordPress plugin before 1.0.280 does not correctly validate the type of a file uploaded through its settings import feature, allowing users with administrator-level access to upload a PHP file and achieve remote code execution.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-104752
Published : Oct. 10, 2026, 6 a.m. | 29 minutes ago
Description :The Rank Math SEO WordPress plugin before 1.0.280 does not correctly validate the type of a file uploaded through its settings import feature, allowing users with administrator-level access to upload a PHP file and achieve remote code execution.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-104753 - Rank Math SEO < 1.0.280 - Admin+ SQLi via 'per_page' Parameter
CVE ID :CVE-2026-104753
Published : Oct. 10, 2026, 6 a.m. | 29 minutes ago
Description :The Rank Math SEO WordPress plugin before 1.0.280 does not properly sanitise and escape a parameter before using it in a SQL query, allowing high-privilege users such as administrators to perform SQL injection attacks.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-104753
Published : Oct. 10, 2026, 6 a.m. | 29 minutes ago
Description :The Rank Math SEO WordPress plugin before 1.0.280 does not properly sanitise and escape a parameter before using it in a SQL query, allowing high-privilege users such as administrators to perform SQL injection attacks.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-104754 - Rank Math SEO < 1.0.280 - Admin+ Stored XSS via Redirection Source URL
CVE ID :CVE-2026-104754
Published : Oct. 10, 2026, 6 a.m. | 29 minutes ago
Description :The Rank Math SEO WordPress plugin before 1.0.280 does not escape a stored redirection source value before outputting it in an administrative list view, allowing users who can manage redirections (Administrators by default) to store JavaScript that executes in the session of any user who later opens that view, including a Super Administrator on multisite.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-104754
Published : Oct. 10, 2026, 6 a.m. | 29 minutes ago
Description :The Rank Math SEO WordPress plugin before 1.0.280 does not escape a stored redirection source value before outputting it in an administrative list view, allowing users who can manage redirections (Administrators by default) to store JavaScript that executes in the session of any user who later opens that view, including a Super Administrator on multisite.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-105976 - Portfolio Filter Gallery < 2.2.1 - Contributor+ Missing Authorization via Multiple AJAX Actions
CVE ID :CVE-2026-105976
Published : Oct. 10, 2026, 6 a.m. | 29 minutes ago
Description :The Portfolio Filter Gallery WordPress plugin before 2.2.1 does not perform proper authorization checks in a set of AJAX actions, allowing users with at least the Contributor role to read, modify and delete other users' galleries as well as site-wide gallery filters.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-105976
Published : Oct. 10, 2026, 6 a.m. | 29 minutes ago
Description :The Portfolio Filter Gallery WordPress plugin before 2.2.1 does not perform proper authorization checks in a set of AJAX actions, allowing users with at least the Contributor role to read, modify and delete other users' galleries as well as site-wide gallery filters.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-105977 - Portfolio Filter Gallery 2.0.2 - 2.2.0 - Contributor+ Cross-User Video Thumbnail Deletion via pfg_delete_video_thumbnail
CVE ID :CVE-2026-105977
Published : Oct. 10, 2026, 6 a.m. | 29 minutes ago
Description :The Portfolio Filter Gallery WordPress plugin before 2.2.1 does not perform a per-object authorization check before deleting an attachment, allowing users with the Contributor role and above to permanently delete certain media attachments belonging to other users, including administrators.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-105977
Published : Oct. 10, 2026, 6 a.m. | 29 minutes ago
Description :The Portfolio Filter Gallery WordPress plugin before 2.2.1 does not perform a per-object authorization check before deleting an attachment, allowing users with the Contributor role and above to permanently delete certain media attachments belonging to other users, including administrators.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-105989 - Accept PayPal Payments using Contact Form 7 < 4.0.7 - Unauthenticated Transaction Status Forgery
CVE ID :CVE-2026-105989
Published : Oct. 10, 2026, 6 a.m. | 29 minutes ago
Description :The Accept PayPal Payments using Contact Form 7 WordPress plugin before 4.0.7 does not perform any authorization or request-validation checks on one of its AJAX actions, allowing unauthenticated attackers to forge the stored transaction status of records and to write the Accept PayPal Payments using Contact Form 7 WordPress plugin before 4.0.7's status metadata onto arbitrary posts.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-105989
Published : Oct. 10, 2026, 6 a.m. | 29 minutes ago
Description :The Accept PayPal Payments using Contact Form 7 WordPress plugin before 4.0.7 does not perform any authorization or request-validation checks on one of its AJAX actions, allowing unauthenticated attackers to forge the stored transaction status of records and to write the Accept PayPal Payments using Contact Form 7 WordPress plugin before 4.0.7's status metadata onto arbitrary posts.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-105990 - Accept PayPal Payments Using Contact Form 7 < 4.0.7 - Unauthenticated PII Disclosure via CSV Export
CVE ID :CVE-2026-105990
Published : Oct. 10, 2026, 6 a.m. | 29 minutes ago
Description :The Accept PayPal Payments using Contact Form 7 WordPress plugin before 4.0.7 does not perform any authorization checks before exporting stored form submissions, allowing unauthenticated attackers to download the personal data (name, email, telephone, postal address, message) and payment metadata of everyone who submitted a payment form.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-105990
Published : Oct. 10, 2026, 6 a.m. | 29 minutes ago
Description :The Accept PayPal Payments using Contact Form 7 WordPress plugin before 4.0.7 does not perform any authorization checks before exporting stored form submissions, allowing unauthenticated attackers to download the personal data (name, email, telephone, postal address, message) and payment metadata of everyone who submitted a payment form.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-105995 - Booking Package < 1.7.30 - Unauthenticated Booking Customer PII Disclosure
CVE ID :CVE-2026-105995
Published : Oct. 10, 2026, 6 a.m. | 29 minutes ago
Description :The Booking Package WordPress plugin before 1.7.30 does not perform authorization checks before returning stored reservation data, allowing unauthenticated users to disclose other customers' personal information and booking cancellation tokens.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-105995
Published : Oct. 10, 2026, 6 a.m. | 29 minutes ago
Description :The Booking Package WordPress plugin before 1.7.30 does not perform authorization checks before returning stored reservation data, allowing unauthenticated users to disclose other customers' personal information and booking cancellation tokens.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-107120 - Contest Gallery < 33.0.1 - Unauthenticated Email Verification Bypass via Brute-Forceable Registration PIN
CVE ID :CVE-2026-107120
Published : Oct. 10, 2026, 6 a.m. | 29 minutes ago
Description :The Contest Gallery WordPress plugin before 33.0.1 does not limit the number of attempts against its front-end registration email-verification step, which relies on a short numeric PIN, allowing unauthenticated attackers to brute-force the PIN and create and activate a WordPress account bound to an email address they do not own, gaining an authenticated session.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-107120
Published : Oct. 10, 2026, 6 a.m. | 29 minutes ago
Description :The Contest Gallery WordPress plugin before 33.0.1 does not limit the number of attempts against its front-end registration email-verification step, which relies on a short numeric PIN, allowing unauthenticated attackers to brute-force the PIN and create and activate a WordPress account bound to an email address they do not own, gaining an authenticated session.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-107321 - W3 Total Cache < 2.10.6 - Author+ Path Traversal via CDN Media Library Import
CVE ID :CVE-2026-107321
Published : Oct. 10, 2026, 6 a.m. | 29 minutes ago
Description :The W3 Total Cache WordPress plugin before 2.10.6 does not confine a media-import file copy to the document root, nor enforce an effective file-type restriction on it, allowing users with the Author role or higher to plant content that, once an administrator runs the import, copies an arbitrary server-readable file into a publicly served directory, exposing it to unauthenticated retrieval.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-107321
Published : Oct. 10, 2026, 6 a.m. | 29 minutes ago
Description :The W3 Total Cache WordPress plugin before 2.10.6 does not confine a media-import file copy to the document root, nor enforce an effective file-type restriction on it, allowing users with the Author role or higher to plant content that, once an administrator runs the import, copies an arbitrary server-readable file into a publicly served directory, exposing it to unauthenticated retrieval.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-107323 - Gallery PhotoBlocks 1.3.5 - Contributor+ Stored XSS
CVE ID :CVE-2026-107323
Published : Oct. 10, 2026, 6 a.m. | 29 minutes ago
Description :The Gallery PhotoBlocks WordPress plugin before 1.3.6 does not sanitize and escape one of its gallery settings before outputting it into an HTML attribute, allowing users with Contributor-level access and above to store JavaScript that executes in the browser of anyone who views a page containing the gallery, including administrators.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-107323
Published : Oct. 10, 2026, 6 a.m. | 29 minutes ago
Description :The Gallery PhotoBlocks WordPress plugin before 1.3.6 does not sanitize and escape one of its gallery settings before outputting it into an HTML attribute, allowing users with Contributor-level access and above to store JavaScript that executes in the browser of anyone who views a page containing the gallery, including administrators.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-85571 - Tutor LMS 4.0.5 - 4.1.0 - Instructor+ Arbitrary Post Reparenting via IDOR
CVE ID :CVE-2026-85571
Published : Oct. 10, 2026, 6 a.m. | 29 minutes ago
Description :The Tutor LMS WordPress plugin before 4.1.1 does not verify that the posts named in its course content ordering requests belong to a course the requester manages, allowing users with instructor level access to reassign the parent of any post on the site, taking other instructors' course content into their own courses and making arbitrary published content unreachable.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-85571
Published : Oct. 10, 2026, 6 a.m. | 29 minutes ago
Description :The Tutor LMS WordPress plugin before 4.1.1 does not verify that the posts named in its course content ordering requests belong to a course the requester manages, allowing users with instructor level access to reassign the parent of any post on the site, taking other instructors' course content into their own courses and making arbitrary published content unreachable.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...