🚨 CVE-2026-9273
The Membership Plugin – Kadence Memberships plugin for WordPress (formerly Restrict Content) is vulnerable to password reset link poisoning leading to account takeover in all versions up to, and including, 4.0.0. This is due to the legacy lost-password handler rc_process_lost_password_form() consuming the attacker-controlled rc_redirect POST parameter into two unvalidated sinks in legacy/includes/forms.php: wp_redirect( esc_url( $_POST['rc_redirect'] ) . ... ) at line 243, and add_query_arg( array( 'key' => $key, 'login' => ... ), $_POST['rc_redirect'] ) inside rc_send_password_reset_email() at line 306. The nonce required to reach the handler is broadcast by the public [login_form] shortcode at line 207 to any anonymous visitor. This makes it possible for unauthenticated attackers to issue a password-reset request for any account (including administrators) whose reset email body points the victim at an attacker-controlled host carrying a valid reset key/login. When the victim clicks the link, the reset key leaks to the attacker, who can replay it against the legitimate site to complete account takeover.
🎖@cveNotify
The Membership Plugin – Kadence Memberships plugin for WordPress (formerly Restrict Content) is vulnerable to password reset link poisoning leading to account takeover in all versions up to, and including, 4.0.0. This is due to the legacy lost-password handler rc_process_lost_password_form() consuming the attacker-controlled rc_redirect POST parameter into two unvalidated sinks in legacy/includes/forms.php: wp_redirect( esc_url( $_POST['rc_redirect'] ) . ... ) at line 243, and add_query_arg( array( 'key' => $key, 'login' => ... ), $_POST['rc_redirect'] ) inside rc_send_password_reset_email() at line 306. The nonce required to reach the handler is broadcast by the public [login_form] shortcode at line 207 to any anonymous visitor. This makes it possible for unauthenticated attackers to issue a password-reset request for any account (including administrators) whose reset email body points the victim at an attacker-controlled host carrying a valid reset key/login. When the victim clicks the link, the reset key leaks to the attacker, who can replay it against the legitimate site to complete account takeover.
🎖@cveNotify
🚨 CVE-2025-15677
The GeoDirectory WordPress plugin before 2.8.110 does not sanitise and escape a place-category setting before outputting it back in an admin page, allowing high-privilege users such as editors and above to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in a multisite setup).
🎖@cveNotify
The GeoDirectory WordPress plugin before 2.8.110 does not sanitise and escape a place-category setting before outputting it back in an admin page, allowing high-privilege users such as editors and above to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in a multisite setup).
🎖@cveNotify
WPScan
GeoDirectory < 2.8.110 - Editor+ Stored XSS via Place Categories
See details on GeoDirectory < 2.8.110 - Editor+ Stored XSS via Place Categories CVE 2025-15677. View the latest Plugin Vulnerabilities on WPScan.
🚨 CVE-2026-14553
The zportals WordPress plugin before 6.3.4 does not properly validate uploaded files, trusting the client-supplied content type and preserving the original file extension, allowing any authenticated user (Subscriber or higher) to upload arbitrary PHP files and achieve remote code execution.
🎖@cveNotify
The zportals WordPress plugin before 6.3.4 does not properly validate uploaded files, trusting the client-supplied content type and preserving the original file extension, allowing any authenticated user (Subscriber or higher) to upload arbitrary PHP files and achieve remote code execution.
🎖@cveNotify
WPScan
Zportals < 6.3.4 - Subscriber+ Arbitrary File Upload
See details on Zportals < 6.3.4 - Subscriber+ Arbitrary File Upload CVE 2026-14553. View the latest Plugin Vulnerabilities on WPScan.
🚨 CVE-2026-15210
The OTP Login With Phone Number, OTP Verification WordPress plugin before 1.8.71 does not limit the number of OTP verification attempts or invalidate a one-time login code after a wrong guess, and an unauthenticated user can request a login code for any account. Because the code is a short numeric OTP, an attacker can brute-force it and take over any account, including an administrator's.
🎖@cveNotify
The OTP Login With Phone Number, OTP Verification WordPress plugin before 1.8.71 does not limit the number of OTP verification attempts or invalidate a one-time login code after a wrong guess, and an unauthenticated user can request a login code for any account. Because the code is a short numeric OTP, an attacker can brute-force it and take over any account, including an administrator's.
🎖@cveNotify
WPScan
Login/Signup with Phone Number, OTP Verification < 1.8.71 - Unauthenticated Account Takeover via OTP Brute Force
See details on Login/Signup with Phone Number, OTP Verification < 1.8.71 - Unauthenticated Account Takeover via OTP Brute Force CVE 2026-15210. View the latest Plugin Vulnerabilities on WPScan.
🚨 CVE-2026-15230
The YayPricing WordPress plugin before 3.5.7 does not perform capability checks on several of its REST API routes, relying only on a shared nonce, allowing any authenticated user such as a subscriber to overwrite the store's pricing configuration and to disclose private coupon codes.
🎖@cveNotify
The YayPricing WordPress plugin before 3.5.7 does not perform capability checks on several of its REST API routes, relying only on a shared nonce, allowing any authenticated user such as a subscriber to overwrite the store's pricing configuration and to disclose private coupon codes.
🎖@cveNotify
WPScan
YayPricing < 3.5.7 - Subscriber+ Pricing Configuration Modification and Coupon Code Disclosure
See details on YayPricing < 3.5.7 - Subscriber+ Pricing Configuration Modification and Coupon Code Disclosure CVE 2026-15230. View the latest Plugin Vulnerabilities on WPScan.
🚨 CVE-2026-15360
The Ajax Load More WordPress plugin before 8.0.1 does not properly sanitise and escape a parameter before using it in a SQL query, allowing unauthenticated attackers to perform time-based blind SQL injection and extract sensitive data from the database.
🎖@cveNotify
The Ajax Load More WordPress plugin before 8.0.1 does not properly sanitise and escape a parameter before using it in a SQL query, allowing unauthenticated attackers to perform time-based blind SQL injection and extract sensitive data from the database.
🎖@cveNotify
WPScan
Ajax Load More < 8.0.1 - Unauthenticated SQL Injection via custom_args
See details on Ajax Load More < 8.0.1 - Unauthenticated SQL Injection via custom_args CVE 2026-15360. View the latest Plugin Vulnerabilities on WPScan.
🚨 CVE-2026-15372
The WP 2FA WordPress plugin before 4.1.0 does not validate the second authentication factor when one of its supported methods is selected at login, allowing an attacker who already knows a user's password to bypass two-factor authentication and fully access the account, including administrator accounts.
🎖@cveNotify
The WP 2FA WordPress plugin before 4.1.0 does not validate the second authentication factor when one of its supported methods is selected at login, allowing an attacker who already knows a user's password to bypass two-factor authentication and fully access the account, including administrator accounts.
🎖@cveNotify
WPScan
WP 2FA < 4.1.0 - Two-Factor Authentication Bypass via Passkeys Provider
See details on WP 2FA < 4.1.0 - Two-Factor Authentication Bypass via Passkeys Provider CVE 2026-15372. View the latest Plugin Vulnerabilities on WPScan.
🚨 CVE-2026-16036
The miniOrange 2FA WordPress plugin before 6.2.7 does not bind the second factor being configured during the pre-login two-factor challenge to the target account's existing factor, allowing an attacker who knows a user's password to rebind that user's second factor to an attacker-controlled destination, complete the challenge, and take over the account, including administrator accounts.
🎖@cveNotify
The miniOrange 2FA WordPress plugin before 6.2.7 does not bind the second factor being configured during the pre-login two-factor challenge to the target account's existing factor, allowing an attacker who knows a user's password to rebind that user's second factor to an attacker-controlled destination, complete the challenge, and take over the account, including administrator accounts.
🎖@cveNotify
WPScan
miniOrange 2FA < 6.2.7 - 2FA Bypass via Password-Only Second-Factor Rebinding
See details on miniOrange 2FA < 6.2.7 - 2FA Bypass via Password-Only Second-Factor Rebinding CVE 2026-16036. View the latest Plugin Vulnerabilities on WPScan.
🚨 CVE-2026-16055
The Contest Gallery WordPress plugin before 30.0.7 does not route its front-end login through the standard WordPress authentication flow, issuing an authentication cookie directly after the password check, which bypasses installed brute-force-protection and two-factor-authentication Contest Gallery WordPress plugin before 30.0.7 and enables unlimited, unthrottled password guessing against any account (including administrators) up to full account takeover.
🎖@cveNotify
The Contest Gallery WordPress plugin before 30.0.7 does not route its front-end login through the standard WordPress authentication flow, issuing an authentication cookie directly after the password check, which bypasses installed brute-force-protection and two-factor-authentication Contest Gallery WordPress plugin before 30.0.7 and enables unlimited, unthrottled password guessing against any account (including administrators) up to full account takeover.
🎖@cveNotify
WPScan
Contest Gallery < 30.0.7 - Unauthenticated Login-Protection and 2FA Bypass via post_cg_login
See details on Contest Gallery < 30.0.7 - Unauthenticated Login-Protection and 2FA Bypass via post_cg_login CVE 2026-16055. View the latest Plugin Vulnerabilities on WPScan.
🚨 CVE-2026-16561
The Sunshine Photo Cart WordPress plugin before 3.6.12 does not perform access control checks in one of its AJAX actions, allowing unauthenticated users to retrieve the comments of images belonging to private, password-protected or otherwise access-restricted galleries.
🎖@cveNotify
The Sunshine Photo Cart WordPress plugin before 3.6.12 does not perform access control checks in one of its AJAX actions, allowing unauthenticated users to retrieve the comments of images belonging to private, password-protected or otherwise access-restricted galleries.
🎖@cveNotify
WPScan
Sunshine Photo Cart < 3.6.12 - Unauthenticated Private Gallery Comment Disclosure
See details on Sunshine Photo Cart < 3.6.12 - Unauthenticated Private Gallery Comment Disclosure CVE 2026-16561. View the latest Plugin Vulnerabilities on WPScan.
🚨 CVE-2026-16573
The Bit Form WordPress plugin before 3.2.0 does not sanitize an uploaded signature image before storing it, allowing unauthenticated attackers to upload a crafted SVG file containing JavaScript that executes when the file is viewed, leading to Stored Cross-Site Scripting.
🎖@cveNotify
The Bit Form WordPress plugin before 3.2.0 does not sanitize an uploaded signature image before storing it, allowing unauthenticated attackers to upload a crafted SVG file containing JavaScript that executes when the file is viewed, leading to Stored Cross-Site Scripting.
🎖@cveNotify
WPScan
Bit Form < 3.2.0 - Unauthenticated Stored XSS via SVG Signature Upload
See details on Bit Form < 3.2.0 - Unauthenticated Stored XSS via SVG Signature Upload CVE 2026-16573. View the latest Plugin Vulnerabilities on WPScan.
🚨 CVE-2026-16583
The Orbit Fox: Duplicate Page, Menu Icons, SVG Support, Cookie Notice, Custom Fonts & More WordPress plugin before 3.0.8 does not sanitize uploaded SVG files when its SVG upload feature is enabled, allowing authenticated users with the upload capability (Author and above by default, without the unfiltered_html capability) to upload SVG files containing JavaScript that executes in the site context when the file is viewed, leading to Stored Cross-Site Scripting.
🎖@cveNotify
The Orbit Fox: Duplicate Page, Menu Icons, SVG Support, Cookie Notice, Custom Fonts & More WordPress plugin before 3.0.8 does not sanitize uploaded SVG files when its SVG upload feature is enabled, allowing authenticated users with the upload capability (Author and above by default, without the unfiltered_html capability) to upload SVG files containing JavaScript that executes in the site context when the file is viewed, leading to Stored Cross-Site Scripting.
🎖@cveNotify
WPScan
Orbit Fox by ThemeIsle < 3.0.8 - Author+ Stored XSS via SVG Upload
See details on Orbit Fox by ThemeIsle < 3.0.8 - Author+ Stored XSS via SVG Upload CVE 2026-16583. View the latest Plugin Vulnerabilities on WPScan.
🚨 CVE-2026-16602
The Passster WordPress plugin before 4.3.6 does not perform a post-status check before returning post content from an unauthenticated REST endpoint, allowing unauthenticated users to disclose the content of non-public (draft, private, and pending) posts on sites that have a captcha provider configured.
🎖@cveNotify
The Passster WordPress plugin before 4.3.6 does not perform a post-status check before returning post content from an unauthenticated REST endpoint, allowing unauthenticated users to disclose the content of non-public (draft, private, and pending) posts on sites that have a captcha provider configured.
🎖@cveNotify
WPScan
Content Protector (Passster) < 4.3.6 - Unauthenticated Non-Public Post Content Disclosure via Captcha REST Endpoint
See details on Content Protector (Passster) < 4.3.6 - Unauthenticated Non-Public Post Content Disclosure via Captcha REST Endpoint CVE 2026-16602. View the latest Plugin Vulnerabilities on WPScan.
🚨 CVE-2026-16603
The Passster WordPress plugin before 4.3.6 does not enforce its category-based content protection on the WordPress REST API, allowing unauthenticated users to read the full content, title, and excerpt of category-locked posts through the core REST API.
🎖@cveNotify
The Passster WordPress plugin before 4.3.6 does not enforce its category-based content protection on the WordPress REST API, allowing unauthenticated users to read the full content, title, and excerpt of category-locked posts through the core REST API.
🎖@cveNotify
WPScan
Content Protector (Passster) < 4.3.6 - Unauthenticated Category-Locked Content Disclosure via Core REST API
See details on Content Protector (Passster) < 4.3.6 - Unauthenticated Category-Locked Content Disclosure via Core REST API CVE 2026-16603. View the latest Plugin Vulnerabilities on WPScan.
🚨 CVE-2026-16604
The Passster WordPress plugin before 4.3.6 outputs password-protected block content in the public page response before verifying the password, allowing unauthenticated users to recover the protected content without knowing the password.
🎖@cveNotify
The Passster WordPress plugin before 4.3.6 outputs password-protected block content in the public page response before verifying the password, allowing unauthenticated users to recover the protected content without knowing the password.
🎖@cveNotify
WPScan
Content Protector (Passster) < 4.3.6 - Unauthenticated Protected Content Disclosure via Content-Lock Block data-content Attribute
See details on Content Protector (Passster) < 4.3.6 - Unauthenticated Protected Content Disclosure via Content-Lock Block data-content Attribute CVE 2026-16604. View the latest Plugin Vulnerabilities on WPScan.
🚨 CVE-2026-16605
The MultiVendorX WordPress plugin before 5.0.11 does not verify that the store targeted through its REST API belongs to the requesting vendor, allowing an authenticated vendor (Store Owner and above) to view, take over, permanently delete, or modify any other vendor's store on the marketplace.
🎖@cveNotify
The MultiVendorX WordPress plugin before 5.0.11 does not verify that the store targeted through its REST API belongs to the requesting vendor, allowing an authenticated vendor (Store Owner and above) to view, take over, permanently delete, or modify any other vendor's store on the marketplace.
🎖@cveNotify
WPScan
MultiVendorX < 5.0.11 - Store Owner+ Cross-Vendor Store Takeover and Deletion via Missing Authorization
See details on MultiVendorX < 5.0.11 - Store Owner+ Cross-Vendor Store Takeover and Deletion via Missing Authorization CVE 2026-16605. View the latest Plugin Vulnerabilities on WPScan.
🚨 CVE-2026-16613
The GDPR Cookie Compliance WordPress plugin before 5.1.0 expires the visitor's cookies from an action that is reachable without authentication and performs no request-origin check, allowing an attacker to log any user out and delete the site's cookies by luring them to a crafted link.
🎖@cveNotify
The GDPR Cookie Compliance WordPress plugin before 5.1.0 expires the visitor's cookies from an action that is reachable without authentication and performs no request-origin check, allowing an attacker to log any user out and delete the site's cookies by luring them to a crafted link.
🎖@cveNotify
WPScan
GDPR Cookie Compliance < 5.1.0 - Cookie Deletion and Forced Logout via CSRF
See details on GDPR Cookie Compliance < 5.1.0 - Cookie Deletion and Forced Logout via CSRF CVE 2026-16613. View the latest Plugin Vulnerabilities on WPScan.
🚨 CVE-2026-16736
The User Registration & Membership WordPress plugin before 5.2.6 does not enforce the site's registration-disabled setting when processing registration-form submissions, allowing unauthenticated users to create new accounts even when the administrator has turned off open registration.
🎖@cveNotify
The User Registration & Membership WordPress plugin before 5.2.6 does not enforce the site's registration-disabled setting when processing registration-form submissions, allowing unauthenticated users to create new accounts even when the administrator has turned off open registration.
🎖@cveNotify
WPScan
User Registration & Membership < 5.2.6 - Unauthenticated Account Creation While Registration Disabled
See details on User Registration & Membership < 5.2.6 - Unauthenticated Account Creation While Registration Disabled CVE 2026-16736. View the latest Plugin Vulnerabilities on WPScan.
🚨 CVE-2026-16746
The MultiVendorX WordPress plugin before 5.0.11 does not verify that the requested store belongs to the current user in one of its REST API endpoints, allowing any vendor-level user to read other vendors' commission and financial data.
🎖@cveNotify
The MultiVendorX WordPress plugin before 5.0.11 does not verify that the requested store belongs to the current user in one of its REST API endpoints, allowing any vendor-level user to read other vendors' commission and financial data.
🎖@cveNotify
WPScan
MultiVendorX < 5.0.11 - Store Owner+ Cross-Store Commission Data Disclosure via commissions REST Endpoint
See details on MultiVendorX < 5.0.11 - Store Owner+ Cross-Store Commission Data Disclosure via commissions REST Endpoint CVE 2026-16746. View the latest Plugin Vulnerabilities on WPScan.
🚨 CVE-2026-16940
The Custom Fields WordPress plugin before 1.5.1 does not validate a user-supplied file path before deletion, allowing unauthenticated users to delete arbitrary files on the server (such as wp-config.php), which can lead to a full site takeover.
🎖@cveNotify
The Custom Fields WordPress plugin before 1.5.1 does not validate a user-supplied file path before deletion, allowing unauthenticated users to delete arbitrary files on the server (such as wp-config.php), which can lead to a full site takeover.
🎖@cveNotify
WPScan
Custom Fields for WooCommerce < 1.5.1 - Unauthenticated Arbitrary File Deletion via Path Traversal
See details on Custom Fields for WooCommerce < 1.5.1 - Unauthenticated Arbitrary File Deletion via Path Traversal CVE 2026-16940. View the latest Plugin Vulnerabilities on WPScan.
🚨 CVE-2026-16942
The WP Custom HTML Page WordPress plugin through 0.6.2 does not sanitise HTML stored through one of its custom page handlers, nor restrict it to users allowed to post unfiltered HTML, allowing users with the Author role to store JavaScript that is served unescaped at a public URL and executes for any visitor, including administrators.
🎖@cveNotify
The WP Custom HTML Page WordPress plugin through 0.6.2 does not sanitise HTML stored through one of its custom page handlers, nor restrict it to users allowed to post unfiltered HTML, allowing users with the Author role to store JavaScript that is served unescaped at a public URL and executes for any visitor, including administrators.
🎖@cveNotify
WPScan
WP Custom HTML Pages <= 0.6.2 - Author+ Stored XSS
See details on WP Custom HTML Pages <= 0.6.2 - Author+ Stored XSS CVE 2026-16942. View the latest Plugin Vulnerabilities on WPScan.