🚨 CVE-2025-15669
The Bit Form WordPress plugin before 3.1.4 does not sanitise one of its conversational-form display settings before rendering it on the public-facing form, allowing high-privilege users (such as administrators, who do not hold the unfiltered_html capability on multisite) to store JavaScript that executes in the browser of any visitor who views the form.
🎖@cveNotify
The Bit Form WordPress plugin before 3.1.4 does not sanitise one of its conversational-form display settings before rendering it on the public-facing form, allowing high-privilege users (such as administrators, who do not hold the unfiltered_html capability on multisite) to store JavaScript that executes in the browser of any visitor who views the form.
🎖@cveNotify
WPScan
Bit Form < 3.1.4 - Admin+ Stored XSS via Conversational Form Progress Label
See details on Bit Form < 3.1.4 - Admin+ Stored XSS via Conversational Form Progress Label CVE 2025-15669. View the latest Plugin Vulnerabilities on WPScan.
🚨 CVE-2026-10827
The Spectra Legacy WordPress plugin before 2.20.0 does not validate or escape several block style attributes before using them to build the CSS it outputs on the front end, allowing users with the Contributor role and above to inject arbitrary CSS into the pages that render the affected block. The injected styles are served to anonymous visitors of those pages and can force external resource loads, deface/redress the page, or exfiltrate data via CSS attribute selectors. JavaScript execution is not possible at this role (the script-tag breakout is removed by KSES), so the impact is limited to CSS injection.
🎖@cveNotify
The Spectra Legacy WordPress plugin before 2.20.0 does not validate or escape several block style attributes before using them to build the CSS it outputs on the front end, allowing users with the Contributor role and above to inject arbitrary CSS into the pages that render the affected block. The injected styles are served to anonymous visitors of those pages and can force external resource loads, deface/redress the page, or exfiltrate data via CSS attribute selectors. JavaScript execution is not possible at this role (the script-tag breakout is removed by KSES), so the impact is limited to CSS injection.
🎖@cveNotify
WPScan
Spectra (Ultimate Addons for Gutenberg) < 2.20.0 - Contributor+ Stored CSS Injection via Block Attributes
See details on Spectra (Ultimate Addons for Gutenberg) < 2.20.0 - Contributor+ Stored CSS Injection via Block Attributes CVE 2026-10827. View the latest Plugin Vulnerabilities on WPScan.
🚨 CVE-2026-11882
The Builderall for WordPress plugin before 3.0.2 does not bind the state value of its public OAuth authentication routes to the initiating user session, allowing unauthenticated attackers to complete the connection flow and overwrite the stored third-party integration access token. A durable overwrite requires the site to already be connected to a paid account.
🎖@cveNotify
The Builderall for WordPress plugin before 3.0.2 does not bind the state value of its public OAuth authentication routes to the initiating user session, allowing unauthenticated attackers to complete the connection flow and overwrite the stored third-party integration access token. A durable overwrite requires the site to already be connected to a paid account.
🎖@cveNotify
WPScan
Builderall for WordPress < 3.0.2 - Unauthenticated OAuth Access Token Poisoning via Public REST Routes
See details on Builderall for WordPress < 3.0.2 - Unauthenticated OAuth Access Token Poisoning via Public REST Routes CVE 2026-11882. View the latest Plugin Vulnerabilities on WPScan.
🚨 CVE-2026-12696
The wpForo Forum WordPress plugin before 3.1.2 does not sanitize and escape a user profile field before outputting it inside an HTML attribute on the public participant profile page, allowing users with a subscriber-level account to inject JavaScript that executes in the browser of any visitor who views the profile, including a logged-in administrator.
🎖@cveNotify
The wpForo Forum WordPress plugin before 3.1.2 does not sanitize and escape a user profile field before outputting it inside an HTML attribute on the public participant profile page, allowing users with a subscriber-level account to inject JavaScript that executes in the browser of any visitor who views the profile, including a logged-in administrator.
🎖@cveNotify
WPScan
wpForo Forum < 3.1.2 - Subscriber+ Stored XSS via Profile Location Field
See details on wpForo Forum < 3.1.2 - Subscriber+ Stored XSS via Profile Location Field CVE 2026-12696. View the latest Plugin Vulnerabilities on WPScan.
🚨 CVE-2026-12966
The Direct Payments for WooCommerce WordPress plugin before 2.5.3 does not verify that the requester owns the targeted WooCommerce order in several unauthenticated AJAX handlers before changing its status and overwriting its payment metadata, allowing unauthenticated attackers to tamper with other customers' orders, including forging a "payment sent" state, overwriting the payment-method label, and attaching forged payment-proof files.
🎖@cveNotify
The Direct Payments for WooCommerce WordPress plugin before 2.5.3 does not verify that the requester owns the targeted WooCommerce order in several unauthenticated AJAX handlers before changing its status and overwriting its payment metadata, allowing unauthenticated attackers to tamper with other customers' orders, including forging a "payment sent" state, overwriting the payment-method label, and attaching forged payment-proof files.
🎖@cveNotify
WPScan
Direct Payments for WooCommerce < 2.5.3 - Unauthenticated Cross-Customer Order Tampering via digages AJAX Actions
See details on Direct Payments for WooCommerce < 2.5.3 - Unauthenticated Cross-Customer Order Tampering via digages AJAX Actions CVE 2026-12966. View the latest Plugin Vulnerabilities on WPScan.
🚨 CVE-2026-13157
The Demo Import WordPress plugin through 1.1.3 does not validate the type of files uploaded during demo-content import (the WordPress file-type test is disabled), allowing high-privilege users (Administrator by default, including non-super-admin site administrators on multisite) to upload executable PHP files to the uploads directory.
🎖@cveNotify
The Demo Import WordPress plugin through 1.1.3 does not validate the type of files uploaded during demo-content import (the WordPress file-type test is disabled), allowing high-privilege users (Administrator by default, including non-super-admin site administrators on multisite) to upload executable PHP files to the uploads directory.
🎖@cveNotify
WPScan
Theme Demo Import <= 1.1.3 - Admin+ Arbitrary File Upload
See details on Theme Demo Import <= 1.1.3 - Admin+ Arbitrary File Upload CVE 2026-13157. View the latest Plugin Vulnerabilities on WPScan.
🚨 CVE-2026-13158
The Everest Toolkit WordPress plugin through 1.2.3 does not validate the type of files uploaded during demo-content import (the WordPress file-type test is disabled), allowing high-privilege users (Administrator by default, including non-super-admin site administrators on multisite) to upload executable PHP files to the uploads directory.
🎖@cveNotify
The Everest Toolkit WordPress plugin through 1.2.3 does not validate the type of files uploaded during demo-content import (the WordPress file-type test is disabled), allowing high-privilege users (Administrator by default, including non-super-admin site administrators on multisite) to upload executable PHP files to the uploads directory.
🎖@cveNotify
WPScan
Everest Toolkit <= 1.2.3 - Admin+ Arbitrary File Upload
See details on Everest Toolkit <= 1.2.3 - Admin+ Arbitrary File Upload CVE 2026-13158. View the latest Plugin Vulnerabilities on WPScan.
🚨 CVE-2026-13329
The Buckaroo Woocommerce Payments Plugin WordPress plugin before 4.9.0 does not perform any capability check or nonce validation on an AJAX action that processes payment capture refunds, allowing any authenticated user, including Subscribers, to trigger refunds against captured orders.
🎖@cveNotify
The Buckaroo Woocommerce Payments Plugin WordPress plugin before 4.9.0 does not perform any capability check or nonce validation on an AJAX action that processes payment capture refunds, allowing any authenticated user, including Subscribers, to trigger refunds against captured orders.
🎖@cveNotify
WPScan
WC Buckaroo BPE Gateway < 4.9.0 - Subscriber+ Unauthorized Order Refund
See details on WC Buckaroo BPE Gateway < 4.9.0 - Subscriber+ Unauthorized Order Refund CVE 2026-13329. View the latest Plugin Vulnerabilities on WPScan.
🚨 CVE-2026-13596
The Participants Database WordPress plugin before 2.7.8.4 does not properly sanitize and escape a user-supplied parameter before using it in a SQL query, allowing unauthenticated attackers to perform SQL injection attacks.
🎖@cveNotify
The Participants Database WordPress plugin before 2.7.8.4 does not properly sanitize and escape a user-supplied parameter before using it in a SQL query, allowing unauthenticated attackers to perform SQL injection attacks.
🎖@cveNotify
WPScan
Participants Database < 2.7.8.4 - Unauthenticated SQL Injection via List Search
See details on Participants Database < 2.7.8.4 - Unauthenticated SQL Injection via List Search CVE 2026-13596. View the latest Plugin Vulnerabilities on WPScan.
🚨 CVE-2026-13604
The Pixelavo WordPress plugin before 1.5.4 registers an unauthenticated AJAX action, gated only by a nonce that it emits publicly on every front-end page, that forwards client-supplied event data to the configured Facebook Conversions API using the administrator's stored access token. This allows an unauthenticated visitor to inject arbitrary conversion events into the administrator's Facebook ads account and exhaust the configured API quota.
🎖@cveNotify
The Pixelavo WordPress plugin before 1.5.4 registers an unauthenticated AJAX action, gated only by a nonce that it emits publicly on every front-end page, that forwards client-supplied event data to the configured Facebook Conversions API using the administrator's stored access token. This allows an unauthenticated visitor to inject arbitrary conversion events into the administrator's Facebook ads account and exhaust the configured API quota.
🎖@cveNotify
WPScan
Pixelavo < 1.5.4 - Unauthenticated Facebook CAPI Event Injection via pixelavo_event AJAX
See details on Pixelavo < 1.5.4 - Unauthenticated Facebook CAPI Event Injection via pixelavo_event AJAX CVE 2026-13604. View the latest Plugin Vulnerabilities on WPScan.
🚨 CVE-2026-13725
The Dynamic Pricing With Discount Rules for WooCommerce WordPress plugin before 5.0.0 does not validate a nonce or user capabilities on one of its AJAX actions and reflects unsanitised user input in the response, allowing unauthenticated attackers to perform Reflected Cross-Site Scripting against a victim who is induced to send a crafted request.
🎖@cveNotify
The Dynamic Pricing With Discount Rules for WooCommerce WordPress plugin before 5.0.0 does not validate a nonce or user capabilities on one of its AJAX actions and reflects unsanitised user input in the response, allowing unauthenticated attackers to perform Reflected Cross-Site Scripting against a victim who is induced to send a crafted request.
🎖@cveNotify
WPScan
Dynamic Pricing With Discount Rules for WooCommerce < 5.0.0 - Reflected XSS via wdpAjax
See details on Dynamic Pricing With Discount Rules for WooCommerce < 5.0.0 - Reflected XSS via wdpAjax CVE 2026-13725. View the latest Plugin Vulnerabilities on WPScan.
🚨 CVE-2026-13729
The Podlove Podcast Publisher WordPress plugin before 4.5.3 does not perform nonce validation on some of its administrative create and delete actions, allowing attackers to create rogue records or delete legitimate ones via a forged request (CSRF) when a logged-in administrator is tricked into visiting a crafted page.
🎖@cveNotify
The Podlove Podcast Publisher WordPress plugin before 4.5.3 does not perform nonce validation on some of its administrative create and delete actions, allowing attackers to create rogue records or delete legitimate ones via a forged request (CSRF) when a logged-in administrator is tricked into visiting a crafted page.
🎖@cveNotify
WPScan
Podlove Podcast Publisher < 4.5.3 - Podcast Contributor/Group/Role Creation and Deletion via CSRF
See details on Podlove Podcast Publisher < 4.5.3 - Podcast Contributor/Group/Role Creation and Deletion via CSRF CVE 2026-13729. View the latest Plugin Vulnerabilities on WPScan.
🚨 CVE-2026-14195
The Brizy WordPress plugin before 2.8.18 does not properly verify authorization on a request handler before returning post content, allowing users with the Contributor role or higher to read the content of arbitrary posts, including other users' private, pending, and draft posts.
🎖@cveNotify
The Brizy WordPress plugin before 2.8.18 does not properly verify authorization on a request handler before returning post content, allowing users with the Contributor role or higher to read the content of arbitrary posts, including other users' private, pending, and draft posts.
🎖@cveNotify
WPScan
Brizy – Page Builder < 2.8.18 - Contributor+ Sensitive Information Disclosure via get_post_info
See details on Brizy – Page Builder < 2.8.18 - Contributor+ Sensitive Information Disclosure via get_post_info CVE 2026-14195. View the latest Plugin Vulnerabilities on WPScan.
🚨 CVE-2026-14197
The Fluent Support WordPress plugin before 2.3.1 does not perform a per-ticket access check before reassigning a ticket's customer, allowing a restricted support agent to change the assigned customer of any ticket in the system, including tickets outside their granted scope.
🎖@cveNotify
The Fluent Support WordPress plugin before 2.3.1 does not perform a per-ticket access check before reassigning a ticket's customer, allowing a restricted support agent to change the assigned customer of any ticket in the system, including tickets outside their granted scope.
🎖@cveNotify
WPScan
Fluent Support < 2.3.1 - Agent+ Arbitrary Ticket Customer Reassignment via IDOR
See details on Fluent Support < 2.3.1 - Agent+ Arbitrary Ticket Customer Reassignment via IDOR CVE 2026-14197. View the latest Plugin Vulnerabilities on WPScan.
🚨 CVE-2026-14214
The Booking for Appointments and Events Calendar WordPress plugin before 2.4.4 does not restrict which fields can be written through its customer import, allowing a user with the Amelia Manager role to modify arbitrary columns of any stored user record by supplying them in the import request.
🎖@cveNotify
The Booking for Appointments and Events Calendar WordPress plugin before 2.4.4 does not restrict which fields can be written through its customer import, allowing a user with the Amelia Manager role to modify arbitrary columns of any stored user record by supplying them in the import request.
🎖@cveNotify
WPScan
Amelia < 2.4.4 - Amelia Manager+ Arbitrary User-Field Modification via Mass Assignment
See details on Amelia < 2.4.4 - Amelia Manager+ Arbitrary User-Field Modification via Mass Assignment CVE 2026-14214. View the latest Plugin Vulnerabilities on WPScan.
🚨 CVE-2026-14292
The Download Manager WordPress plugin before 3.3.66 does not properly escape a package's title before outputting it in the front-end package templates, allowing users with the Author role or above to store a title that results in arbitrary JavaScript execution in the browser of any user, including unauthenticated visitors, who views a page displaying the package.
🎖@cveNotify
The Download Manager WordPress plugin before 3.3.66 does not properly escape a package's title before outputting it in the front-end package templates, allowing users with the Author role or above to store a title that results in arbitrary JavaScript execution in the browser of any user, including unauthenticated visitors, who views a page displaying the package.
🎖@cveNotify
WPScan
WordPress Download Manager < 3.3.66 - Author+ Stored XSS via Package Title
See details on WordPress Download Manager < 3.3.66 - Author+ Stored XSS via Package Title CVE 2026-14292. View the latest Plugin Vulnerabilities on WPScan.
🚨 CVE-2026-14309
The Chat On Desk Order Notifications WordPress plugin before 1.0.9 does not verify that the one-time password has been validated before processing a password-reset request, allowing unauthenticated attackers to reset the password of arbitrary users, including administrators, and take over their accounts when SMS one-time-password password reset is enabled.
🎖@cveNotify
The Chat On Desk Order Notifications WordPress plugin before 1.0.9 does not verify that the one-time password has been validated before processing a password-reset request, allowing unauthenticated attackers to reset the password of arbitrary users, including administrators, and take over their accounts when SMS one-time-password password reset is enabled.
🎖@cveNotify
WPScan
Chat On Desk < 1.0.9 - Unauthenticated Account Takeover via Password Reset OTP Bypass
See details on Chat On Desk < 1.0.9 - Unauthenticated Account Takeover via Password Reset OTP Bypass CVE 2026-14309. View the latest Plugin Vulnerabilities on WPScan.
🚨 CVE-2026-14315
The Pixel Tag Manager for WooCommerce WordPress plugin before 2.2.1 does not perform an authorization check on one of its AJAX actions, allowing unauthenticated users to submit forged e-commerce conversion events to the site's configured server-side advertising conversion APIs using the site's stored credentials.
🎖@cveNotify
The Pixel Tag Manager for WooCommerce WordPress plugin before 2.2.1 does not perform an authorization check on one of its AJAX actions, allowing unauthenticated users to submit forged e-commerce conversion events to the site's configured server-side advertising conversion APIs using the site's stored credentials.
🎖@cveNotify
WPScan
Pixel Manager for WooCommerce < 2.2.1 - Unauthenticated Forged Conversion Event Submission
See details on Pixel Manager for WooCommerce < 2.2.1 - Unauthenticated Forged Conversion Event Submission CVE 2026-14315. View the latest Plugin Vulnerabilities on WPScan.
🚨 CVE-2026-14561
The Authora : Easy login with mobile number WordPress plugin before 1.7.7 does not keep its one-time login code confidential, returning the code and a valid verification token in the response of an unauthenticated action, allowing unauthenticated attackers to log in as any user whose registered mobile number they know (including administrators) or to create arbitrary accounts.
🎖@cveNotify
The Authora : Easy login with mobile number WordPress plugin before 1.7.7 does not keep its one-time login code confidential, returning the code and a valid verification token in the response of an unauthenticated action, allowing unauthenticated attackers to log in as any user whose registered mobile number they know (including administrators) or to create arbitrary accounts.
🎖@cveNotify
WPScan
Authora - Easy Login with Mobile Number < 1.7.7 - Unauthenticated Account Takeover via OTP Disclosure
See details on Authora - Easy Login with Mobile Number < 1.7.7 - Unauthenticated Account Takeover via OTP Disclosure CVE 2026-14561. View the latest Plugin Vulnerabilities on WPScan.
🚨 CVE-2026-14596
The DynamicKit for Elementor WordPress plugin before 1.0.3 does not validate the host of a user-supplied URL used as the base of the password-reset link it emails, allowing unauthenticated attackers to send a target user a legitimately-formatted reset email whose link points to an attacker-controlled host and carries a valid reset key, leading to account takeover when the victim clicks it.
🎖@cveNotify
The DynamicKit for Elementor WordPress plugin before 1.0.3 does not validate the host of a user-supplied URL used as the base of the password-reset link it emails, allowing unauthenticated attackers to send a target user a legitimately-formatted reset email whose link points to an attacker-controlled host and carries a valid reset key, leading to account takeover when the victim clicks it.
🎖@cveNotify
WPScan
DynamicKit for Elementor < 1.0.3 - Unauthenticated Account Takeover via Password Reset Link Host Injection
See details on DynamicKit for Elementor < 1.0.3 - Unauthenticated Account Takeover via Password Reset Link Host Injection CVE 2026-14596. View the latest Plugin Vulnerabilities on WPScan.
🚨 CVE-2026-14823
The Event Tickets and Registration WordPress plugin before 5.29.0.1 does not properly verify authorization on some of its seating actions, allowing users with contributor-level access and above to overwrite the seating layout, ticket inventory, and attendee seat assignments of events they do not own.
🎖@cveNotify
The Event Tickets and Registration WordPress plugin before 5.29.0.1 does not properly verify authorization on some of its seating actions, allowing users with contributor-level access and above to overwrite the seating layout, ticket inventory, and attendee seat assignments of events they do not own.
🎖@cveNotify
WPScan
Event Tickets < 5.29.0.1 - Contributor+ Seating Layout and Ticket Inventory Modification via IDOR
See details on Event Tickets < 5.29.0.1 - Contributor+ Seating Layout and Ticket Inventory Modification via IDOR CVE 2026-14823. View the latest Plugin Vulnerabilities on WPScan.