🚨 CVE-2026-12983
The Dinatur WordPress plugin through 1.18 does not sanitize and escape user input before using it in a SQL query, allowing unauthenticated users to perform SQL injection attacks. The same handler also performs a database table truncation without any authorization check, allowing any unauthenticated visitor to wipe the Dinatur WordPress plugin through 1.18's data.
🎖@cveNotify
The Dinatur WordPress plugin through 1.18 does not sanitize and escape user input before using it in a SQL query, allowing unauthenticated users to perform SQL injection attacks. The same handler also performs a database table truncation without any authorization check, allowing any unauthenticated visitor to wipe the Dinatur WordPress plugin through 1.18's data.
🎖@cveNotify
WPScan
Dinatur <= 1.18 - Unauthenticated SQL Injection via Column Name Injection
See details on Dinatur <= 1.18 - Unauthenticated SQL Injection via Column Name Injection CVE 2026-12983. View the latest Plugin Vulnerabilities on WPScan.
🚨 CVE-2026-13169
The Eventin WordPress plugin before 4.1.21 does not properly verify ownership of events before allowing them to be modified, deleted, or reassigned to a different author, allowing users with contributor-level access and above to alter, delete, or take over events created by other users including administrators.
🎖@cveNotify
The Eventin WordPress plugin before 4.1.21 does not properly verify ownership of events before allowing them to be modified, deleted, or reassigned to a different author, allowing users with contributor-level access and above to alter, delete, or take over events created by other users including administrators.
🎖@cveNotify
WPScan
Eventin < 4.1.21 - Contributor+ Arbitrary Event Modification, Deletion and Ownership Takeover via IDOR
See details on Eventin < 4.1.21 - Contributor+ Arbitrary Event Modification, Deletion and Ownership Takeover via IDOR CVE 2026-13169. View the latest Plugin Vulnerabilities on WPScan.
🚨 CVE-2026-13173
The Eventin WordPress plugin before 4.1.21 does not verify the current user's permission to edit other users before assigning roles and updating user metadata during speaker creation, allowing users with contributor-level access and above to modify other users' roles and metadata.
🎖@cveNotify
The Eventin WordPress plugin before 4.1.21 does not verify the current user's permission to edit other users before assigning roles and updating user metadata during speaker creation, allowing users with contributor-level access and above to modify other users' roles and metadata.
🎖@cveNotify
WPScan
Eventin < 4.1.21 - Contributor+ User Role and Meta Modification via Speaker Creation
See details on Eventin < 4.1.21 - Contributor+ User Role and Meta Modification via Speaker Creation CVE 2026-13173. View the latest Plugin Vulnerabilities on WPScan.
🚨 CVE-2026-13174
The Eventin WordPress plugin before 4.1.21 does not verify ownership or capability before deleting user accounts, allowing users with contributor-level access and above to permanently delete other users' accounts.
🎖@cveNotify
The Eventin WordPress plugin before 4.1.21 does not verify ownership or capability before deleting user accounts, allowing users with contributor-level access and above to permanently delete other users' accounts.
🎖@cveNotify
WPScan
Eventin < 4.1.21 - Contributor+ Speaker Account Deletion via IDOR
See details on Eventin < 4.1.21 - Contributor+ Speaker Account Deletion via IDOR CVE 2026-13174. View the latest Plugin Vulnerabilities on WPScan.
🚨 CVE-2026-13175
The Eventin WordPress plugin before 4.1.21 does not verify ownership before allowing schedule records to be modified or deleted, allowing users with contributor-level access and above to alter or delete schedule entries created by other users.
🎖@cveNotify
The Eventin WordPress plugin before 4.1.21 does not verify ownership before allowing schedule records to be modified or deleted, allowing users with contributor-level access and above to alter or delete schedule entries created by other users.
🎖@cveNotify
WPScan
Eventin < 4.1.21 - Contributor+ Schedule Deletion and Modification via IDOR
See details on Eventin < 4.1.21 - Contributor+ Schedule Deletion and Modification via IDOR CVE 2026-13175. View the latest Plugin Vulnerabilities on WPScan.
🚨 CVE-2026-14196
The WCFM Marketplace WordPress plugin before 3.8.1 does not verify that a marketplace vendor owns a review before allowing it to be unapproved or deleted, allowing any vendor to modify or permanently delete reviews belonging to other vendors' stores.
🎖@cveNotify
The WCFM Marketplace WordPress plugin before 3.8.1 does not verify that a marketplace vendor owns a review before allowing it to be unapproved or deleted, allowing any vendor to modify or permanently delete reviews belonging to other vendors' stores.
🎖@cveNotify
WPScan
WCFM Marketplace < 3.8.1 - Store Vendor+ Cross-Vendor Review Deletion and Status Update via IDOR
See details on WCFM Marketplace < 3.8.1 - Store Vendor+ Cross-Vendor Review Deletion and Status Update via IDOR CVE 2026-14196. View the latest Plugin Vulnerabilities on WPScan.
🚨 CVE-2026-14287
The 10Web Booster WordPress plugin before 2.33.5 does not correctly validate an access token on an unauthenticated request handler and does not escape attacker-supplied stylesheet content before rendering it into the page head, allowing an unauthenticated attacker to store markup that executes as JavaScript in the browser of anonymous visitors to an affected page.
🎖@cveNotify
The 10Web Booster WordPress plugin before 2.33.5 does not correctly validate an access token on an unauthenticated request handler and does not escape attacker-supplied stylesheet content before rendering it into the page head, allowing an unauthenticated attacker to store markup that executes as JavaScript in the browser of anonymous visitors to an affected page.
🎖@cveNotify
WPScan
TenWeb Speed Optimizer < 2.33.5 - Unauthenticated Stored XSS via Critical CSS Token Bypass
See details on TenWeb Speed Optimizer < 2.33.5 - Unauthenticated Stored XSS via Critical CSS Token Bypass CVE 2026-14287. View the latest Plugin Vulnerabilities on WPScan.
🚨 CVE-2026-14334
The Booking calendar, Appointment Booking System WordPress plugin through 3.2.36 does not properly sanitize uploaded SVG files, allowing unauthenticated attackers to upload a file that bypasses the Booking calendar, Appointment Booking System WordPress plugin through 3.2.36's script-stripping and executes arbitrary JavaScript when the SVG is opened, including in the session of an administrator who reviews the submitted booking.
🎖@cveNotify
The Booking calendar, Appointment Booking System WordPress plugin through 3.2.36 does not properly sanitize uploaded SVG files, allowing unauthenticated attackers to upload a file that bypasses the Booking calendar, Appointment Booking System WordPress plugin through 3.2.36's script-stripping and executes arbitrary JavaScript when the SVG is opened, including in the session of an administrator who reviews the submitted booking.
🎖@cveNotify
WPScan
Booking calendar, Appointment Booking System <= 3.2.36 - Unauthenticated Stored XSS via SVG File Upload
See details on Booking calendar, Appointment Booking System <= 3.2.36 - Unauthenticated Stored XSS via SVG File Upload CVE 2026-14334. View the latest Plugin Vulnerabilities on WPScan.
🚨 CVE-2026-14825
The Quiz and Survey Master (QSM) WordPress plugin before 11.2.4 does not perform a per-object ownership check before saving a quiz's front-end text settings, allowing users with contributor-level access and above to modify the text settings of quizzes created by other users.
🎖@cveNotify
The Quiz and Survey Master (QSM) WordPress plugin before 11.2.4 does not perform a per-object ownership check before saving a quiz's front-end text settings, allowing users with contributor-level access and above to modify the text settings of quizzes created by other users.
🎖@cveNotify
WPScan
Quiz And Survey Master < 11.2.4 - Contributor+ Arbitrary Quiz Text Settings Update via IDOR
See details on Quiz And Survey Master < 11.2.4 - Contributor+ Arbitrary Quiz Text Settings Update via IDOR CVE 2026-14825. View the latest Plugin Vulnerabilities on WPScan.
🚨 CVE-2026-14826
The Quiz and Survey Master (QSM) WordPress plugin before 11.2.4 does not perform a per-object ownership check on the REST routes that return a quiz's email-notification and results-page configuration, allowing users with contributor-level access and above to read the configuration, including notification recipient addresses, of quizzes created by other users.
🎖@cveNotify
The Quiz and Survey Master (QSM) WordPress plugin before 11.2.4 does not perform a per-object ownership check on the REST routes that return a quiz's email-notification and results-page configuration, allowing users with contributor-level access and above to read the configuration, including notification recipient addresses, of quizzes created by other users.
🎖@cveNotify
WPScan
Quiz And Survey Master < 11.2.4 - Contributor+ Cross-Quiz Email and Results Configuration Disclosure via IDOR
See details on Quiz And Survey Master < 11.2.4 - Contributor+ Cross-Quiz Email and Results Configuration Disclosure via IDOR CVE 2026-14826. View the latest Plugin Vulnerabilities on WPScan.
🚨 CVE-2026-14861
The User Verification by PickPlugins WordPress plugin through 2.0.47 does not verify that a request to resend a verification email is authorized to act on the supplied user, nor bind the protecting token to that user, allowing unauthenticated attackers to reset arbitrary users' email-verification status and lock them, including administrators, out of their accounts.
🎖@cveNotify
The User Verification by PickPlugins WordPress plugin through 2.0.47 does not verify that a request to resend a verification email is authorized to act on the supplied user, nor bind the protecting token to that user, allowing unauthenticated attackers to reset arbitrary users' email-verification status and lock them, including administrators, out of their accounts.
🎖@cveNotify
WPScan
User Verification <= 2.0.47 - Unauthenticated Arbitrary Account Lockout via IDOR
See details on User Verification <= 2.0.47 - Unauthenticated Arbitrary Account Lockout via IDOR CVE 2026-14861. View the latest Plugin Vulnerabilities on WPScan.
🚨 CVE-2026-15253
The Easy Media Replace WordPress plugin through 0.2.0 does not sanitise and escape an attachment title before outputting it in an HTML attribute in the media library list view, allowing users with the Author role and above to inject arbitrary web scripts that are executed in the browser of a higher privileged user who views the media library.
🎖@cveNotify
The Easy Media Replace WordPress plugin through 0.2.0 does not sanitise and escape an attachment title before outputting it in an HTML attribute in the media library list view, allowing users with the Author role and above to inject arbitrary web scripts that are executed in the browser of a higher privileged user who views the media library.
🎖@cveNotify
WPScan
Easy Media Replace <= 0.2.0 - Author+ Stored XSS via Attachment Title
See details on Easy Media Replace <= 0.2.0 - Author+ Stored XSS via Attachment Title CVE 2026-15253. View the latest Plugin Vulnerabilities on WPScan.
🚨 CVE-2026-16058
The YayCurrency WordPress plugin before 3.3.5 does not perform any capability or ownership check on several of its multi-vendor integration handlers that are reachable by unauthenticated users, allowing anyone to read the store's order totals and its vendors' earnings, balance ledgers, and withdrawal histories by iterating identifiers.
🎖@cveNotify
The YayCurrency WordPress plugin before 3.3.5 does not perform any capability or ownership check on several of its multi-vendor integration handlers that are reachable by unauthenticated users, allowing anyone to read the store's order totals and its vendors' earnings, balance ledgers, and withdrawal histories by iterating identifiers.
🎖@cveNotify
WPScan
YayCurrency < 3.3.5 - Unauthenticated Order and Vendor Financial Data Disclosure via Dokan Integration
See details on YayCurrency < 3.3.5 - Unauthenticated Order and Vendor Financial Data Disclosure via Dokan Integration CVE 2026-16058. View the latest Plugin Vulnerabilities on WPScan.
🚨 CVE-2026-16570
The NextScripts: Social Networks Auto-Poster WordPress plugin before 4.4.8 does not escape some of the query-string parameters it reflects back on one of its admin pages, allowing attackers to perform Reflected Cross-Site Scripting attacks against logged-in users such as administrators who are tricked into opening a crafted link.
🎖@cveNotify
The NextScripts: Social Networks Auto-Poster WordPress plugin before 4.4.8 does not escape some of the query-string parameters it reflects back on one of its admin pages, allowing attackers to perform Reflected Cross-Site Scripting attacks against logged-in users such as administrators who are tricked into opening a crafted link.
🎖@cveNotify
WPScan
NextScripts: Social Networks Auto-Poster < 4.4.8 - Reflected XSS via Facebook OAuth Callback
See details on NextScripts: Social Networks Auto-Poster < 4.4.8 - Reflected XSS via Facebook OAuth Callback CVE 2026-16570. View the latest Plugin Vulnerabilities on WPScan.
🚨 CVE-2026-16616
The Simple File List WordPress plugin through 6.3.11 does not validate the source path of a file-move operation reachable by unauthenticated users, allowing them to read arbitrary files on the server and to relocate critical files out of the web root, leading to sensitive information disclosure and potential site takeover.
🎖@cveNotify
The Simple File List WordPress plugin through 6.3.11 does not validate the source path of a file-move operation reachable by unauthenticated users, allowing them to read arbitrary files on the server and to relocate critical files out of the web root, leading to sensitive information disclosure and potential site takeover.
🎖@cveNotify
WPScan
Simple File List <= 6.3.11 - Unauthenticated Arbitrary File Read and Move via Path Traversal
See details on Simple File List <= 6.3.11 - Unauthenticated Arbitrary File Read and Move via Path Traversal CVE 2026-16616. View the latest Plugin Vulnerabilities on WPScan.
🚨 CVE-2026-16617
The Simple File List WordPress plugin through 6.3.11 does not properly sanitise and escape a file's description before outputting it on the public file list, allowing unauthenticated users (when front-end file management is enabled) to perform Stored Cross-Site Scripting attacks that execute in the browser of any visitor viewing the list.
🎖@cveNotify
The Simple File List WordPress plugin through 6.3.11 does not properly sanitise and escape a file's description before outputting it on the public file list, allowing unauthenticated users (when front-end file management is enabled) to perform Stored Cross-Site Scripting attacks that execute in the browser of any visitor viewing the list.
🎖@cveNotify
WPScan
Simple File List <= 6.3.11 - Unauthenticated Stored XSS via File Description
See details on Simple File List <= 6.3.11 - Unauthenticated Stored XSS via File Description CVE 2026-16617. View the latest Plugin Vulnerabilities on WPScan.
🚨 CVE-2026-16950
The Product Shortlist WordPress plugin through 1.0.4 does not properly sanitise and escape a parameter before using it in a SQL statement, allowing unauthenticated attackers to perform SQL injection attacks.
🎖@cveNotify
The Product Shortlist WordPress plugin through 1.0.4 does not properly sanitise and escape a parameter before using it in a SQL statement, allowing unauthenticated attackers to perform SQL injection attacks.
🎖@cveNotify
WPScan
Product Shortlist <= 1.0.4 - Unauthenticated SQL Injection via get_shortlisted_products
See details on Product Shortlist <= 1.0.4 - Unauthenticated SQL Injection via get_shortlisted_products CVE 2026-16950. View the latest Plugin Vulnerabilities on WPScan.
🚨 CVE-2026-16979
The SmartCrawl SEO checker, analyzer & optimizer WordPress plugin before 3.16.3 does not perform capability checks on two of its AJAX actions, allowing users with at least the Subscriber role to read the titles of private and draft posts by ID and to enumerate stored post-meta key names.
🎖@cveNotify
The SmartCrawl SEO checker, analyzer & optimizer WordPress plugin before 3.16.3 does not perform capability checks on two of its AJAX actions, allowing users with at least the Subscriber role to read the titles of private and draft posts by ID and to enumerate stored post-meta key names.
🎖@cveNotify
WPScan
SmartCrawl < 3.16.3 - Subscriber+ Private/Draft Post Title Disclosure and Post Meta Key Enumeration
See details on SmartCrawl < 3.16.3 - Subscriber+ Private/Draft Post Title Disclosure and Post Meta Key Enumeration CVE 2026-16979. View the latest Plugin Vulnerabilities on WPScan.
🚨 CVE-2026-17565
The Animation Addons for Elementor WordPress plugin before 2.7.2 does not validate a user-supplied value before using it to build the host of a server-side HTTP request, allowing unauthenticated users to make the site issue requests to internal hosts and read the responses back.
🎖@cveNotify
The Animation Addons for Elementor WordPress plugin before 2.7.2 does not validate a user-supplied value before using it to build the host of a server-side HTTP request, allowing unauthenticated users to make the site issue requests to internal hosts and read the responses back.
🎖@cveNotify
WPScan
Animation Addons for Elementor < 2.7.2 - Unauthenticated Server-Side Request Forgery
See details on Animation Addons for Elementor < 2.7.2 - Unauthenticated Server-Side Request Forgery CVE 2026-17565. View the latest Plugin Vulnerabilities on WPScan.
🚨 CVE-2026-18051
The W3 Total Cache WordPress plugin before 2.10.5 does not properly validate the request path it uses to build cache file names, allowing unauthenticated attackers to write a file into any existing directory on the server, inside or outside the web root, overwriting whatever occupies the target name.
On Apache, the same flaw overwrites the site's .htaccess files, which breaks the site and can strip hardening rules that other security measures rely on.
🎖@cveNotify
The W3 Total Cache WordPress plugin before 2.10.5 does not properly validate the request path it uses to build cache file names, allowing unauthenticated attackers to write a file into any existing directory on the server, inside or outside the web root, overwriting whatever occupies the target name.
On Apache, the same flaw overwrites the site's .htaccess files, which breaks the site and can strip hardening rules that other security measures rely on.
🎖@cveNotify
WPScan
W3 Total Cache < 2.10.5 - Unauthenticated Arbitrary Directory File Write and .htaccess Overwrite via Path Traversal in the Page…
See details on W3 Total Cache < 2.10.5 - Unauthenticated Arbitrary Directory File Write and .htaccess Overwrite via Path Traversal in the Page Cache Key CVE 2026-18051. View the latest Plugin Vulnerabilities on WPScan.
🚨 CVE-2026-18202
The JetEngine WordPress plugin before 3.8.14 adds SVG to the site-wide list of allowed upload types without sanitising the file contents, allowing users with the upload files capability, such as Authors, to upload a file containing malicious JavaScript that executes in the browser of any user who opens it (Stored Cross-Site Scripting). On multisite, this also overrides an upload-type restriction set by the network administrator.
🎖@cveNotify
The JetEngine WordPress plugin before 3.8.14 adds SVG to the site-wide list of allowed upload types without sanitising the file contents, allowing users with the upload files capability, such as Authors, to upload a file containing malicious JavaScript that executes in the browser of any user who opens it (Stored Cross-Site Scripting). On multisite, this also overrides an upload-type restriction set by the network administrator.
🎖@cveNotify
WPScan
JetEngine < 3.8.14 - Author+ Stored XSS via SVG Upload
See details on JetEngine < 3.8.14 - Author+ Stored XSS via SVG Upload CVE 2026-18202. View the latest Plugin Vulnerabilities on WPScan.