🚨 CVE-2026-14293
The Autopay WordPress plugin before 5.0.1 does not perform any capability or nonce check before saving a styling option from a public request, and does not escape that value when it is later output on the checkout page, allowing unauthenticated attackers to store JavaScript that executes in the browser of any user, including administrators, who loads the checkout page.
🎖@cveNotify
The Autopay WordPress plugin before 5.0.1 does not perform any capability or nonce check before saving a styling option from a public request, and does not escape that value when it is later output on the checkout page, allowing unauthenticated attackers to store JavaScript that executes in the browser of any user, including administrators, who loads the checkout page.
🎖@cveNotify
WPScan
Autopay / Blue Media for WooCommerce < 5.0.1 - Unauthenticated Stored XSS via CSS Editor
See details on Autopay / Blue Media for WooCommerce < 5.0.1 - Unauthenticated Stored XSS via CSS Editor CVE 2026-14293. View the latest Plugin Vulnerabilities on WPScan.
🚨 CVE-2026-14860
The Podcast Player WordPress plugin before 8.3.1 does not validate the destination of a server-side request built from user-supplied input, allowing unauthenticated attackers to make the server issue requests to arbitrary hosts and read back responses that parse as RSS/XML.
🎖@cveNotify
The Podcast Player WordPress plugin before 8.3.1 does not validate the destination of a server-side request built from user-supplied input, allowing unauthenticated attackers to make the server issue requests to arbitrary hosts and read back responses that parse as RSS/XML.
🎖@cveNotify
WPScan
Podcast Player < 8.3.1 - Unauthenticated Server-Side Request Forgery
See details on Podcast Player < 8.3.1 - Unauthenticated Server-Side Request Forgery CVE 2026-14860. View the latest Plugin Vulnerabilities on WPScan.
🚨 CVE-2026-14941
The Customer Reviews for WooCommerce WordPress plugin before 5.116.0 does not perform nonce or capability checks on several settings-related AJAX actions, allowing users with minimal permissions such as Subscribers to invoke administrative settings handlers, update Customer Reviews for WooCommerce WordPress plugin before 5.116.0 options, and disclose store configuration.
🎖@cveNotify
The Customer Reviews for WooCommerce WordPress plugin before 5.116.0 does not perform nonce or capability checks on several settings-related AJAX actions, allowing users with minimal permissions such as Subscribers to invoke administrative settings handlers, update Customer Reviews for WooCommerce WordPress plugin before 5.116.0 options, and disclose store configuration.
🎖@cveNotify
WPScan
Customer Reviews for WooCommerce < 5.116.0 - Subscriber+ Missing Authorization via Multiple Settings AJAX Actions
See details on Customer Reviews for WooCommerce < 5.116.0 - Subscriber+ Missing Authorization via Multiple Settings AJAX Actions CVE 2026-14941. View the latest Plugin Vulnerabilities on WPScan.
🚨 CVE-2026-15047
The s2Member WordPress plugin before 260805 does not escape several shortcode attributes before outputting them inside an inline script context, allowing users with contributor-level access to inject arbitrary JavaScript that executes when a viewer opens the post (stored XSS).
🎖@cveNotify
The s2Member WordPress plugin before 260805 does not escape several shortcode attributes before outputting them inside an inline script context, allowing users with contributor-level access to inject arbitrary JavaScript that executes when a viewer opens the post (stored XSS).
🎖@cveNotify
WPScan
s2Member < 260805 - Contributor+ Stored XSS via Shortcode
See details on s2Member < 260805 - Contributor+ Stored XSS via Shortcode CVE 2026-15047. View the latest Plugin Vulnerabilities on WPScan.
🚨 CVE-2026-15229
The Pinpoint Booking System WordPress plugin through 2.9.9.6.9 does not validate the booking price on the server side, allowing unauthenticated users to create bookings at an arbitrary price (including zero) and, by selecting a specific payment method, obtain an instantly-approved reservation.
🎖@cveNotify
The Pinpoint Booking System WordPress plugin through 2.9.9.6.9 does not validate the booking price on the server side, allowing unauthenticated users to create bookings at an arbitrary price (including zero) and, by selecting a specific payment method, obtain an instantly-approved reservation.
🎖@cveNotify
WPScan
Pinpoint Booking System <= 2.9.9.7.1 - Unauthenticated Arbitrary Booking Price Manipulation
See details on Pinpoint Booking System <= 2.9.9.7.1 - Unauthenticated Arbitrary Booking Price Manipulation CVE 2026-15229. View the latest Plugin Vulnerabilities on WPScan.
🚨 CVE-2026-15237
The MotoPress Hotel Booking WordPress plugin before 6.2.3 does not perform any authorization or ownership check on a REST endpoint that creates payment records, allowing unauthenticated users to create completed payment records against arbitrary bookings and falsely mark them as paid.
🎖@cveNotify
The MotoPress Hotel Booking WordPress plugin before 6.2.3 does not perform any authorization or ownership check on a REST endpoint that creates payment records, allowing unauthenticated users to create completed payment records against arbitrary bookings and falsely mark them as paid.
🎖@cveNotify
WPScan
Hotel Booking Lite < 6.2.3 - Unauthenticated Payment Record Creation via Checkout Payments REST Endpoint
See details on Hotel Booking Lite < 6.2.3 - Unauthenticated Payment Record Creation via Checkout Payments REST Endpoint CVE 2026-15237. View the latest Plugin Vulnerabilities on WPScan.
🚨 CVE-2026-15238
The MotoPress Hotel Booking WordPress plugin before 6.2.3 does not verify record ownership before updating customer records, allowing any authenticated user with a low-privileged account (Subscriber and above) to modify or overwrite the personal data of any customer by supplying an arbitrary identifier.
🎖@cveNotify
The MotoPress Hotel Booking WordPress plugin before 6.2.3 does not verify record ownership before updating customer records, allowing any authenticated user with a low-privileged account (Subscriber and above) to modify or overwrite the personal data of any customer by supplying an arbitrary identifier.
🎖@cveNotify
WPScan
Hotel Booking Lite < 6.2.3 - Subscriber+ Customer Data Modification via IDOR
See details on Hotel Booking Lite < 6.2.3 - Subscriber+ Customer Data Modification via IDOR CVE 2026-15238. View the latest Plugin Vulnerabilities on WPScan.
🚨 CVE-2026-16257
The Arvow AI SEO Writer WordPress plugin before 1.5.4 does not properly restrict access to one of its REST endpoints, whose only access control can be bypassed by unauthenticated users through type juggling when the Arvow AI SEO Writer WordPress plugin before 1.5.4 has not been configured, allowing them to create arbitrary posts and pages and to disclose author account and taxonomy information.
🎖@cveNotify
The Arvow AI SEO Writer WordPress plugin before 1.5.4 does not properly restrict access to one of its REST endpoints, whose only access control can be bypassed by unauthenticated users through type juggling when the Arvow AI SEO Writer WordPress plugin before 1.5.4 has not been configured, allowing them to create arbitrary posts and pages and to disclose author account and taxonomy information.
🎖@cveNotify
WPScan
Arvow AI SEO Writer < 1.5.4 - Unauthenticated Arbitrary Post Creation via Webhook Secret Type-Juggling
See details on Arvow AI SEO Writer < 1.5.4 - Unauthenticated Arbitrary Post Creation via Webhook Secret Type-Juggling CVE 2026-16257. View the latest Plugin Vulnerabilities on WPScan.
🚨 CVE-2026-16298
The FoodBoxBooker WordPress plugin before 1.0.7 does not properly validate the password reset request, allowing unauthenticated attackers to reset the password of arbitrary users, including administrators, which could lead to a full site takeover.
🎖@cveNotify
The FoodBoxBooker WordPress plugin before 1.0.7 does not properly validate the password reset request, allowing unauthenticated attackers to reset the password of arbitrary users, including administrators, which could lead to a full site takeover.
🎖@cveNotify
WPScan
FoodBoxBooker < 1.0.7 - Unauthenticated Arbitrary Password Reset
See details on FoodBoxBooker < 1.0.7 - Unauthenticated Arbitrary Password Reset CVE 2026-16298. View the latest Plugin Vulnerabilities on WPScan.
🚨 CVE-2026-16299
The Single Sign On For TNG WordPress plugin before 2.2.0 does not properly validate a password reset request, allowing unauthenticated attackers to reset the password of arbitrary users, including administrators, which could lead to a full site takeover.
🎖@cveNotify
The Single Sign On For TNG WordPress plugin before 2.2.0 does not properly validate a password reset request, allowing unauthenticated attackers to reset the password of arbitrary users, including administrators, which could lead to a full site takeover.
🎖@cveNotify
WPScan
Single Sign On For TNG < 2.2.0 - Unauthenticated Arbitrary Password Reset
See details on Single Sign On For TNG < 2.2.0 - Unauthenticated Arbitrary Password Reset CVE 2026-16299. View the latest Plugin Vulnerabilities on WPScan.
🚨 CVE-2026-16985
The Squeeze WordPress plugin before 1.7.12 does not validate the file type or extension of the per-size image data written by one of its attachment-update actions, allowing users with the upload_files capability (Author and above) to write an executable PHP file into the uploads directory and achieve remote code execution.
🎖@cveNotify
The Squeeze WordPress plugin before 1.7.12 does not validate the file type or extension of the per-size image data written by one of its attachment-update actions, allowing users with the upload_files capability (Author and above) to write an executable PHP file into the uploads directory and achieve remote code execution.
🎖@cveNotify
WPScan
Squeeze < 1.7.12 - Author+ Arbitrary File Upload
See details on Squeeze < 1.7.12 - Author+ Arbitrary File Upload CVE 2026-16985. View the latest Plugin Vulnerabilities on WPScan.
🚨 CVE-2026-17010
The Saitama Addon Pack WordPress plugin through 1.0.8 does not sanitise and escape certain post metadata values before outputting them, allowing users with contributor-level access and above to inject stored Cross-Site Scripting payloads that execute in the browser of a higher-privileged user who reviews the content.
🎖@cveNotify
The Saitama Addon Pack WordPress plugin through 1.0.8 does not sanitise and escape certain post metadata values before outputting them, allowing users with contributor-level access and above to inject stored Cross-Site Scripting payloads that execute in the browser of a higher-privileged user who reviews the content.
🎖@cveNotify
WPScan
Saitama Addon Pack <= 1.0.8 - Contributor+ Stored XSS via Post Meta
See details on Saitama Addon Pack <= 1.0.8 - Contributor+ Stored XSS via Post Meta CVE 2026-17010. View the latest Plugin Vulnerabilities on WPScan.
🚨 CVE-2026-17012
The Accept PayPal & Stripe with Subscriptions for WooCommerce WordPress plugin through 3.1.0 does not verify that the PayPal account which received a payment matches the merchant's configured account before marking the order as paid, allowing unauthenticated buyers to complete a WooCommerce order by paying the full amount to their own PayPal account instead of the merchant's.
🎖@cveNotify
The Accept PayPal & Stripe with Subscriptions for WooCommerce WordPress plugin through 3.1.0 does not verify that the PayPal account which received a payment matches the merchant's configured account before marking the order as paid, allowing unauthenticated buyers to complete a WooCommerce order by paying the full amount to their own PayPal account instead of the merchant's.
🎖@cveNotify
WPScan
Restore PayPal Standard for WooCommerce <= 3.1.0 - Payment Bypass via Unvalidated receiver_email
See details on Restore PayPal Standard for WooCommerce <= 3.1.0 - Payment Bypass via Unvalidated receiver_email CVE 2026-17012. View the latest Plugin Vulnerabilities on WPScan.
🚨 CVE-2026-17016
The Accept PayPal & Stripe with Subscriptions for WooCommerce WordPress plugin through 3.1.0 does not validate the amount actually paid against the order total in its PayPal Data Transfer return handler, allowing a customer to pay less than the order total and still have the order marked as fully paid when the PayPal Data Transfer feature is enabled.
🎖@cveNotify
The Accept PayPal & Stripe with Subscriptions for WooCommerce WordPress plugin through 3.1.0 does not validate the amount actually paid against the order total in its PayPal Data Transfer return handler, allowing a customer to pay less than the order total and still have the order marked as fully paid when the PayPal Data Transfer feature is enabled.
🎖@cveNotify
WPScan
Restore PayPal Standard for WooCommerce <= 3.1.0 - Payment Bypass via PDT Underpayment
See details on Restore PayPal Standard for WooCommerce <= 3.1.0 - Payment Bypass via PDT Underpayment CVE 2026-17016. View the latest Plugin Vulnerabilities on WPScan.
🚨 CVE-2026-17018
The CubeWP Framework WordPress plugin through 1.1.30 does not perform a per-object read authorization check, nor restrict which metadata keys may be requested, on one of its REST API endpoints, allowing users with the Contributor role and above to read arbitrary post metadata (including that of other users' draft, pending, private, and password-protected posts) and arbitrary user metadata of any user, including administrators.
🎖@cveNotify
The CubeWP Framework WordPress plugin through 1.1.30 does not perform a per-object read authorization check, nor restrict which metadata keys may be requested, on one of its REST API endpoints, allowing users with the Contributor role and above to read arbitrary post metadata (including that of other users' draft, pending, private, and password-protected posts) and arbitrary user metadata of any user, including administrators.
🎖@cveNotify
WPScan
CubeWP Framework <= 1.1.30 - Contributor+ Arbitrary Post and User Meta Disclosure via IDOR
See details on CubeWP Framework <= 1.1.30 - Contributor+ Arbitrary Post and User Meta Disclosure via IDOR CVE 2026-17018. View the latest Plugin Vulnerabilities on WPScan.
🚨 CVE-2026-17019
The JetEngine WordPress plugin before 3.8.13.1 does not sanitise uploaded SVG files before storing and serving them, and does not adequately restrict who can upload them, allowing unauthenticated attackers to upload a file containing malicious JavaScript that executes in the browser of any user who opens it (Stored Cross-Site Scripting).
🎖@cveNotify
The JetEngine WordPress plugin before 3.8.13.1 does not sanitise uploaded SVG files before storing and serving them, and does not adequately restrict who can upload them, allowing unauthenticated attackers to upload a file containing malicious JavaScript that executes in the browser of any user who opens it (Stored Cross-Site Scripting).
🎖@cveNotify
WPScan
JetEngine < 3.8.13.1 - Unauthenticated Stored XSS via Form File Upload (SVG)
See details on JetEngine < 3.8.13.1 - Unauthenticated Stored XSS via Form File Upload (SVG) CVE 2026-17019. View the latest Plugin Vulnerabilities on WPScan.
🚨 CVE-2026-17020
The Salon Booking System WordPress plugin through 10.30.33 does not verify that a requested booking belongs to the caller on one of its REST API endpoints, requiring only a basic read capability, allowing any authenticated user (including a Subscriber or self-registered customer account) to disclose any customer's booking personal data such as name, email, phone number, address and private notes by enumerating booking identifiers.
🎖@cveNotify
The Salon Booking System WordPress plugin through 10.30.33 does not verify that a requested booking belongs to the caller on one of its REST API endpoints, requiring only a basic read capability, allowing any authenticated user (including a Subscriber or self-registered customer account) to disclose any customer's booking personal data such as name, email, phone number, address and private notes by enumerating booking identifiers.
🎖@cveNotify
WPScan
Salon Booking System – Free Version <= 10.31.3 - Subscriber+ Arbitrary Booking PII Disclosure
See details on Salon Booking System – Free Version <= 10.31.3 - Subscriber+ Arbitrary Booking PII Disclosure CVE 2026-17020. View the latest Plugin Vulnerabilities on WPScan.
🚨 CVE-2026-17021
The Salon Booking System WordPress plugin through 10.30.33 does not properly restrict access to some of its booking-modification AJAX actions and does not verify ownership of the targeted booking, allowing unauthenticated users to tamper with the stored total of arbitrary bookings.
🎖@cveNotify
The Salon Booking System WordPress plugin through 10.30.33 does not properly restrict access to some of its booking-modification AJAX actions and does not verify ownership of the targeted booking, allowing unauthenticated users to tamper with the stored total of arbitrary bookings.
🎖@cveNotify
WPScan
Salon Booking System – Free Version < 10.30.34 - Unauthenticated Arbitrary Booking Total Tampering
See details on Salon Booking System – Free Version < 10.30.34 - Unauthenticated Arbitrary Booking Total Tampering CVE 2026-17021. View the latest Plugin Vulnerabilities on WPScan.
🚨 CVE-2026-17022
The Salon Booking System WordPress plugin through 10.30.33 does not properly validate a booking's ownership token before loading it in its booking-wizard confirmation steps, allowing unauthenticated attackers to disclose other customers' booking records, including personal information, by supplying a sequential booking identifier.
🎖@cveNotify
The Salon Booking System WordPress plugin through 10.30.33 does not properly validate a booking's ownership token before loading it in its booking-wizard confirmation steps, allowing unauthenticated attackers to disclose other customers' booking records, including personal information, by supplying a sequential booking identifier.
🎖@cveNotify
WPScan
Salon Booking System – Free Version < 10.30.34 - Unauthenticated Booking Information Disclosure via Booking Wizard
See details on Salon Booking System – Free Version < 10.30.34 - Unauthenticated Booking Information Disclosure via Booking Wizard CVE 2026-17022. View the latest Plugin Vulnerabilities on WPScan.
🚨 CVE-2026-17023
The Salon Booking System WordPress plugin through 10.30.33 does not perform any capability check or validate an OAuth state value on its Google Calendar authorization callback, which is also hooked for unauthenticated users, allowing an unauthenticated attacker to overwrite the site's stored Google Calendar connection tokens with attacker-controlled ones and hijack the integration. Exploitation requires the site to have configured its own Google OAuth client for the calendar feature.
🎖@cveNotify
The Salon Booking System WordPress plugin through 10.30.33 does not perform any capability check or validate an OAuth state value on its Google Calendar authorization callback, which is also hooked for unauthenticated users, allowing an unauthenticated attacker to overwrite the site's stored Google Calendar connection tokens with attacker-controlled ones and hijack the integration. Exploitation requires the site to have configured its own Google OAuth client for the calendar feature.
🎖@cveNotify
WPScan
Salon Booking System – Free Version <= 10.31.3 - Unauthenticated Google Calendar Connection Hijack via OAuth Callback
See details on Salon Booking System – Free Version <= 10.31.3 - Unauthenticated Google Calendar Connection Hijack via OAuth Callback CVE 2026-17023. View the latest Plugin Vulnerabilities on WPScan.
🚨 CVE-2026-17540
The File Manager WordPress plugin before 6.9.1 does not properly authorise its file management commands, allowing any authenticated user, such as a subscriber, to read and delete arbitrary files under the WordPress installation directory, which could lead to the disclosure of the site's configuration secrets and to denial of service.
🎖@cveNotify
The File Manager WordPress plugin before 6.9.1 does not properly authorise its file management commands, allowing any authenticated user, such as a subscriber, to read and delete arbitrary files under the WordPress installation directory, which could lead to the disclosure of the site's configuration secrets and to denial of service.
🎖@cveNotify
WPScan
Bit File Manager < 6.9.1 - Subscriber+ Arbitrary File Read and Deletion via Connector Command Request-Source Mismatch
See details on Bit File Manager < 6.9.1 - Subscriber+ Arbitrary File Read and Deletion via Connector Command Request-Source Mismatch CVE 2026-17540. View the latest Plugin Vulnerabilities on WPScan.