๐จ CVE-2026-12255
The MainWP Child WordPress plugin before 6.1.2 does not verify the requester's identity in its site-registration request handler when password authentication has been disabled for the targeted account, allowing an unauthenticated attacker to obtain a valid authentication session as that account, including an administrator, by naming its login in a single registration request.
๐@cveNotify
The MainWP Child WordPress plugin before 6.1.2 does not verify the requester's identity in its site-registration request handler when password authentication has been disabled for the targeted account, allowing an unauthenticated attacker to obtain a valid authentication session as that account, including an administrator, by naming its login in a single registration request.
๐@cveNotify
WPScan
MainWP Child < 6.1.2 - Unauthenticated Administrator Authentication Bypass via Passwordless Site Registration
See details on MainWP Child < 6.1.2 - Unauthenticated Administrator Authentication Bypass via Passwordless Site Registration CVE 2026-12255. View the latest Plugin Vulnerabilities on WPScan.
๐จ CVE-2026-12394
The MemberGlut WordPress plugin before 1.1.5 does not validate the role chosen during front-end registration, allowing unauthenticated users to register an account with an arbitrary role, including administrator, leading to full site compromise.
๐@cveNotify
The MemberGlut WordPress plugin before 1.1.5 does not validate the role chosen during front-end registration, allowing unauthenticated users to register an account with an arbitrary role, including administrator, leading to full site compromise.
๐@cveNotify
WPScan
MemberGlut < 1.1.5 - Unauthenticated Privilege Escalation to Administrator
See details on MemberGlut < 1.1.5 - Unauthenticated Privilege Escalation to Administrator CVE 2026-12394. View the latest Plugin Vulnerabilities on WPScan.
๐จ CVE-2026-12493
The Clover Payment Gateway by Zaytech for WooCommerce WordPress plugin before 1.3.6 does not verify that an approved external payment record actually belongs to the WooCommerce order being completed, nor that the paid amount matches the order total, allowing unauthenticated users to mark arbitrary orders as paid by replaying a single genuinely-approved payment reference (for example one obtained from their own minimal purchase).
๐@cveNotify
The Clover Payment Gateway by Zaytech for WooCommerce WordPress plugin before 1.3.6 does not verify that an approved external payment record actually belongs to the WooCommerce order being completed, nor that the paid amount matches the order total, allowing unauthenticated users to mark arbitrary orders as paid by replaying a single genuinely-approved payment reference (for example one obtained from their own minimal purchase).
๐@cveNotify
WPScan
Clover Payment Gateway by Zaytech for WooCommerce < 1.3.6 - Unauthenticated Payment Bypass via check_order
See details on Clover Payment Gateway by Zaytech for WooCommerce < 1.3.6 - Unauthenticated Payment Bypass via check_order CVE 2026-12493. View the latest Plugin Vulnerabilities on WPScan.
๐จ CVE-2026-12982
The Document Gallery WordPress plugin before 5.1.1 does not properly sanitise and escape user input before reflecting it back in the response of an unauthenticated AJAX action, leading to a Reflected Cross-Site Scripting vulnerability which can be exploited against unauthenticated users.
๐@cveNotify
The Document Gallery WordPress plugin before 5.1.1 does not properly sanitise and escape user input before reflecting it back in the response of an unauthenticated AJAX action, leading to a Reflected Cross-Site Scripting vulnerability which can be exploited against unauthenticated users.
๐@cveNotify
WPScan
Document Gallery < 5.1.1 - Reflected XSS via dg_generate_gallery
See details on Document Gallery < 5.1.1 - Reflected XSS via dg_generate_gallery CVE 2026-12982. View the latest Plugin Vulnerabilities on WPScan.
๐จ CVE-2026-13152
The Custom Fields Account Registration For Woocommerce WordPress plugin before 1.4 does not prevent its custom registration fields from writing to the user capabilities meta key on sites that use a non-default database table prefix, so an unauthenticated user who registers an account can be granted the administrator role when a correspondingly named field has been configured.
๐@cveNotify
The Custom Fields Account Registration For Woocommerce WordPress plugin before 1.4 does not prevent its custom registration fields from writing to the user capabilities meta key on sites that use a non-default database table prefix, so an unauthenticated user who registers an account can be granted the administrator role when a correspondingly named field has been configured.
๐@cveNotify
WPScan
Custom Fields Account Registration For WooCommerce < 1.4 - Unauthenticated Privilege Escalation
See details on Custom Fields Account Registration For WooCommerce < 1.4 - Unauthenticated Privilege Escalation CVE 2026-13152. View the latest Plugin Vulnerabilities on WPScan.
๐จ CVE-2026-13390
The Events Calendar WordPress plugin before 6.16.5.1 does not perform an authorization check on one of its Event Aggregator import REST API routes and skips an integrity check for a particular status value, allowing unauthenticated attackers to mark existing import records as failed and to store arbitrary content in a hidden comment record.
๐@cveNotify
The Events Calendar WordPress plugin before 6.16.5.1 does not perform an authorization check on one of its Event Aggregator import REST API routes and skips an integrity check for a particular status value, allowing unauthenticated attackers to mark existing import records as failed and to store arbitrary content in a hidden comment record.
๐@cveNotify
WPScan
The Events Calendar < 6.16.5.1 - Unauthenticated Event Aggregator Import Status Manipulation
See details on The Events Calendar < 6.16.5.1 - Unauthenticated Event Aggregator Import Status Manipulation CVE 2026-13390. View the latest Plugin Vulnerabilities on WPScan.
๐จ CVE-2026-13400
Simply Schedule Appointments is vulnerable to unauthenticated Stored Cross-Site Scripting in all versions up to and including 1.6.12.2. The root cause is a sanitization-ordering defect: the rendered notification content is decoded back into live HTML after it has already passed through the Simply Schedule Appointments WordPress plugin before 1.6.12.4's wp_kses_post() filter, so a double-encoded payload survives intake and is reintroduced as an executable element at render time.
๐@cveNotify
Simply Schedule Appointments is vulnerable to unauthenticated Stored Cross-Site Scripting in all versions up to and including 1.6.12.2. The root cause is a sanitization-ordering defect: the rendered notification content is decoded back into live HTML after it has already passed through the Simply Schedule Appointments WordPress plugin before 1.6.12.4's wp_kses_post() filter, so a double-encoded payload survives intake and is reintroduced as an executable element at render time.
๐@cveNotify
WPScan
Simply Schedule Appointments < 1.6.12.4 - Unauthenticated Stored XSS via Booking Customer Information
See details on Simply Schedule Appointments < 1.6.12.4 - Unauthenticated Stored XSS via Booking Customer Information CVE 2026-13400. View the latest Plugin Vulnerabilities on WPScan.
๐จ CVE-2026-13597
The ๅพฎไฟกไบ็ปด็ ็ป้ WordPress plugin through 1.3 does not properly validate WeChat webhook requests, as its signature check always passes, and it discloses the generated login code in the webhook response. This allows an unauthenticated attacker to forge a login event for any existing username, read the login code, and redeem it through an unauthenticated AJAX action to log in as that user, including an administrator, without a password.
๐@cveNotify
The ๅพฎไฟกไบ็ปด็ ็ป้ WordPress plugin through 1.3 does not properly validate WeChat webhook requests, as its signature check always passes, and it discloses the generated login code in the webhook response. This allows an unauthenticated attacker to forge a login event for any existing username, read the login code, and redeem it through an unauthenticated AJAX action to log in as that user, including an administrator, without a password.
๐@cveNotify
WPScan
QRcode Login for WeChat <= 1.3 - Unauthenticated Account Takeover
See details on QRcode Login for WeChat <= 1.3 - Unauthenticated Account Takeover CVE 2026-13597. View the latest Plugin Vulnerabilities on WPScan.
๐จ CVE-2026-13714
The Realtyna Organic IDX plugin + WPL Real Estate WordPress plugin before 5.3.0 does not validate the type of uploaded files, and its file upload functionality is gated only by an API that is enabled by default and authenticated with hardcoded credentials shipped identically across all installations. This makes it possible for unauthenticated attackers to upload arbitrary PHP files and achieve remote code execution.
๐@cveNotify
The Realtyna Organic IDX plugin + WPL Real Estate WordPress plugin before 5.3.0 does not validate the type of uploaded files, and its file upload functionality is gated only by an API that is enabled by default and authenticated with hardcoded credentials shipped identically across all installations. This makes it possible for unauthenticated attackers to upload arbitrary PHP files and achieve remote code execution.
๐@cveNotify
WPScan
Realtyna Organic IDX plugin + WPL Real Estate < 5.3.0 - Unauthenticated Arbitrary File Upload to Remote Code Execution
See details on Realtyna Organic IDX plugin + WPL Real Estate < 5.3.0 - Unauthenticated Arbitrary File Upload to Remote Code Execution CVE 2026-13714. View the latest Plugin Vulnerabilities on WPScan.
๐จ CVE-2026-13726
The MPG WordPress plugin before 4.1.8 does not sanitise and escape a parameter before reflecting it back in the response, allowing unauthenticated attackers to perform Reflected Cross-Site Scripting against a victim who is induced to send a crafted request.
๐@cveNotify
The MPG WordPress plugin before 4.1.8 does not sanitise and escape a parameter before reflecting it back in the response, allowing unauthenticated attackers to perform Reflected Cross-Site Scripting against a victim who is induced to send a crafted request.
๐@cveNotify
WPScan
Multiple Page Generator Plugin โ MPG < 4.1.8 - Reflected XSS via mpg_shortcode
See details on Multiple Page Generator Plugin โ MPG < 4.1.8 - Reflected XSS via mpg_shortcode CVE 2026-13726. View the latest Plugin Vulnerabilities on WPScan.
๐จ CVE-2026-14189
The WPBot WordPress plugin before 8.5.2 does not validate administrator-configured field identifiers before using them in a SQL query, allowing users with administrator access to perform SQL injection that executes when a visitor triggers a search.
๐@cveNotify
The WPBot WordPress plugin before 8.5.2 does not validate administrator-configured field identifiers before using them in a SQL query, allowing users with administrator access to perform SQL injection that executes when a visitor triggers a search.
๐@cveNotify
WPScan
WPBot AI ChatBot < 8.5.2 - Admin+ Second-Order SQL Injection via qc_bot_str_fields
See details on WPBot AI ChatBot < 8.5.2 - Admin+ Second-Order SQL Injection via qc_bot_str_fields CVE 2026-14189. View the latest Plugin Vulnerabilities on WPScan.
๐จ CVE-2026-14190
The Sina Extension for Elementor WordPress plugin before 3.10.2 does not escape a value reconstructed from request input in one of its unauthenticated AJAX handlers before reflecting it into the HTML response, allowing unauthenticated attackers to execute arbitrary JavaScript in the browser of anyone who triggers a crafted request.
๐@cveNotify
The Sina Extension for Elementor WordPress plugin before 3.10.2 does not escape a value reconstructed from request input in one of its unauthenticated AJAX handlers before reflecting it into the HTML response, allowing unauthenticated attackers to execute arbitrary JavaScript in the browser of anyone who triggers a crafted request.
๐@cveNotify
WPScan
Sina Extension for Elementor < 3.10.2 - Reflected XSS
See details on Sina Extension for Elementor < 3.10.2 - Reflected XSS CVE 2026-14190. View the latest Plugin Vulnerabilities on WPScan.
๐จ CVE-2026-14203
The Smart Manager WordPress plugin before 8.92.0 does not properly encode a post field before rendering it into an HTML attribute in its management grid, allowing users with the Contributor role or above to inject JavaScript that executes in the browser session of an administrator who views the grid.
๐@cveNotify
The Smart Manager WordPress plugin before 8.92.0 does not properly encode a post field before rendering it into an HTML attribute in its management grid, allowing users with the Contributor role or above to inject JavaScript that executes in the browser session of an administrator who views the grid.
๐@cveNotify
WPScan
Smart Manager < 8.92.0 - Contributor+ Stored XSS via Post Title
See details on Smart Manager < 8.92.0 - Contributor+ Stored XSS via Post Title CVE 2026-14203. View the latest Plugin Vulnerabilities on WPScan.
๐จ CVE-2026-14235
The Download Manager WordPress plugin before 3.3.62 does not bind its temporary download token to the requesting session nor expire it promptly, making the token a long-lived, multi-use, portable bearer token, so that an attacker who obtains one leaked download key can repeatedly download a role- or password-protected package file without authorization.
๐@cveNotify
The Download Manager WordPress plugin before 3.3.62 does not bind its temporary download token to the requesting session nor expire it promptly, making the token a long-lived, multi-use, portable bearer token, so that an attacker who obtains one leaked download key can repeatedly download a role- or password-protected package file without authorization.
๐@cveNotify
WPScan
WordPress Download Manager < 3.3.62 - Unauthorized Protected File Download via Reusable Download Key
See details on WordPress Download Manager < 3.3.62 - Unauthorized Protected File Download via Reusable Download Key CVE 2026-14235. View the latest Plugin Vulnerabilities on WPScan.
๐จ CVE-2026-14236
The Contact Form 7 WordPress plugin before 2.5 does not validate the host of a user-supplied return URL before using it as the success and cancel redirect targets of a Stripe checkout, allowing an unauthenticated attacker to redirect a victim, via a crafted link, to an arbitrary external site after the checkout flow.
๐@cveNotify
The Contact Form 7 WordPress plugin before 2.5 does not validate the host of a user-supplied return URL before using it as the success and cancel redirect targets of a Stripe checkout, allowing an unauthenticated attacker to redirect a victim, via a crafted link, to an arbitrary external site after the checkout flow.
๐@cveNotify
WPScan
Contact Form 7 โ PayPal & Stripe Add-on < 2.5 - Open Redirect
See details on Contact Form 7 โ PayPal & Stripe Add-on < 2.5 - Open Redirect CVE 2026-14236. View the latest Plugin Vulnerabilities on WPScan.
๐จ CVE-2026-14289
The FacturaONE para WooCommerce con VeriFactu WordPress plugin before 5.37 does not authenticate one of its request handlers, whose only protection is derived from a cryptographic key that is empty in the default, unconfigured state, allowing unauthenticated attackers to write an arbitrary file into a web-accessible directory and achieve remote code execution.
๐@cveNotify
The FacturaONE para WooCommerce con VeriFactu WordPress plugin before 5.37 does not authenticate one of its request handlers, whose only protection is derived from a cryptographic key that is empty in the default, unconfigured state, allowing unauthenticated attackers to write an arbitrary file into a web-accessible directory and achieve remote code execution.
๐@cveNotify
WPScan
WP FacturaONE < 5.37 - Unauthenticated Remote Code Execution
See details on WP FacturaONE < 5.37 - Unauthenticated Remote Code Execution CVE 2026-14289. View the latest Plugin Vulnerabilities on WPScan.
๐จ CVE-2026-14568
The User Frontend: AI Powered Frontend Post Submission, User Directory, User Profile, Membership & User Registration WordPress plugin before 4.3.8 does not correctly verify ownership before deleting an attachment, allowing unauthenticated attackers to permanently delete author-less attachments such as guest uploads and User Frontend: AI Powered Frontend Post Submission, User Directory, User Profile, Membership & User Registration WordPress plugin before 4.3.8-installed placeholder media.
๐@cveNotify
The User Frontend: AI Powered Frontend Post Submission, User Directory, User Profile, Membership & User Registration WordPress plugin before 4.3.8 does not correctly verify ownership before deleting an attachment, allowing unauthenticated attackers to permanently delete author-less attachments such as guest uploads and User Frontend: AI Powered Frontend Post Submission, User Directory, User Profile, Membership & User Registration WordPress plugin before 4.3.8-installed placeholder media.
๐@cveNotify
WPScan
WP User Frontend < 4.3.8 - Unauthenticated Author-less Attachment Deletion
See details on WP User Frontend < 4.3.8 - Unauthenticated Author-less Attachment Deletion CVE 2026-14568. View the latest Plugin Vulnerabilities on WPScan.
๐จ CVE-2026-14820
The Quiz and Survey Master (QSM) WordPress plugin before 11.1.3 does not implement rate limiting or standard failed-login auditing on its front-end credential-check functionality and returns distinct responses for valid and invalid accounts, allowing unauthenticated attackers to enumerate valid usernames and to brute-force passwords while bypassing brute-force protection Quiz and Survey Master (QSM) WordPress plugin before 11.1.3.
๐@cveNotify
The Quiz and Survey Master (QSM) WordPress plugin before 11.1.3 does not implement rate limiting or standard failed-login auditing on its front-end credential-check functionality and returns distinct responses for valid and invalid accounts, allowing unauthenticated attackers to enumerate valid usernames and to brute-force passwords while bypassing brute-force protection Quiz and Survey Master (QSM) WordPress plugin before 11.1.3.
๐@cveNotify
WPScan
Quiz And Survey Master < 11.1.3 - Unauthenticated User Enumeration and Password Oracle via Quiz Login
See details on Quiz And Survey Master < 11.1.3 - Unauthenticated User Enumeration and Password Oracle via Quiz Login CVE 2026-14820. View the latest Plugin Vulnerabilities on WPScan.
๐จ CVE-2026-14827
The Calendar WordPress plugin before 1.3.18 does not properly escape a user-supplied event field before outputting it inside an HTML attribute on a public-facing page, allowing users with the Contributor role to inject arbitrary JavaScript that executes in the browser of anyone viewing the calendar.
๐@cveNotify
The Calendar WordPress plugin before 1.3.18 does not properly escape a user-supplied event field before outputting it inside an HTML attribute on a public-facing page, allowing users with the Contributor role to inject arbitrary JavaScript that executes in the browser of anyone viewing the calendar.
๐@cveNotify
WPScan
Calendar < 1.3.18 - Contributor+ Stored XSS via event_link Parameter
See details on Calendar < 1.3.18 - Contributor+ Stored XSS via event_link Parameter CVE 2026-14827. View the latest Plugin Vulnerabilities on WPScan.
๐จ CVE-2026-9830
The bookingpress-appointment-booking-pro WordPress plugin before 5.7.3 does not correctly invoke its REST permission callback, leaving every route in one of its API namespaces reachable without authentication and allowing unauthenticated attackers to read customer booking data and modify other users' bookings.
๐@cveNotify
The bookingpress-appointment-booking-pro WordPress plugin before 5.7.3 does not correctly invoke its REST permission callback, leaving every route in one of its API namespaces reachable without authentication and allowing unauthenticated attackers to read customer booking data and modify other users' bookings.
๐@cveNotify
WPScan
BookingPress Pro < 5.7.3 - Unauthenticated Customer PII Disclosure and Booking Tampering via Permission Callback Bug
See details on BookingPress Pro < 5.7.3 - Unauthenticated Customer PII Disclosure and Booking Tampering via Permission Callback Bug CVE 2026-9830. View the latest Plugin Vulnerabilities on WPScan.
๐จ CVE-2026-65893
This vulnerability exists in CP PLUS EZ-P21 IP Camera due to an insecure debug feature enabled in the firmware.
An attacker with physical access could exploit this vulnerability by placing arbitrary code on removable media and triggering their execution through the debug mechanism.
Successful exploitation of this vulnerability could allow an attacker to execute arbitrary code with elevated privileges on the targeted device.
๐@cveNotify
This vulnerability exists in CP PLUS EZ-P21 IP Camera due to an insecure debug feature enabled in the firmware.
An attacker with physical access could exploit this vulnerability by placing arbitrary code on removable media and triggering their execution through the debug mechanism.
Successful exploitation of this vulnerability could allow an attacker to execute arbitrary code with elevated privileges on the targeted device.
๐@cveNotify