🚨 CVE-2026-16058
The YayCurrency WordPress plugin before 3.3.5 does not perform any capability or ownership check on several of its multi-vendor integration handlers that are reachable by unauthenticated users, allowing anyone to read the store's order totals and its vendors' earnings, balance ledgers, and withdrawal histories by iterating identifiers.
🎖@cveNotify
The YayCurrency WordPress plugin before 3.3.5 does not perform any capability or ownership check on several of its multi-vendor integration handlers that are reachable by unauthenticated users, allowing anyone to read the store's order totals and its vendors' earnings, balance ledgers, and withdrawal histories by iterating identifiers.
🎖@cveNotify
WPScan
YayCurrency < 3.3.5 - Unauthenticated Order and Vendor Financial Data Disclosure via Dokan Integration
See details on YayCurrency < 3.3.5 - Unauthenticated Order and Vendor Financial Data Disclosure via Dokan Integration CVE 2026-16058. View the latest Plugin Vulnerabilities on WPScan.
🚨 CVE-2026-16570
The NextScripts: Social Networks Auto-Poster WordPress plugin before 4.4.8 does not escape some of the query-string parameters it reflects back on one of its admin pages, allowing attackers to perform Reflected Cross-Site Scripting attacks against logged-in users such as administrators who are tricked into opening a crafted link.
🎖@cveNotify
The NextScripts: Social Networks Auto-Poster WordPress plugin before 4.4.8 does not escape some of the query-string parameters it reflects back on one of its admin pages, allowing attackers to perform Reflected Cross-Site Scripting attacks against logged-in users such as administrators who are tricked into opening a crafted link.
🎖@cveNotify
WPScan
NextScripts: Social Networks Auto-Poster < 4.4.8 - Reflected XSS via Facebook OAuth Callback
See details on NextScripts: Social Networks Auto-Poster < 4.4.8 - Reflected XSS via Facebook OAuth Callback CVE 2026-16570. View the latest Plugin Vulnerabilities on WPScan.
🚨 CVE-2026-16616
The Simple File List WordPress plugin through 6.3.11 does not validate the source path of a file-move operation reachable by unauthenticated users, allowing them to read arbitrary files on the server and to relocate critical files out of the web root, leading to sensitive information disclosure and potential site takeover.
🎖@cveNotify
The Simple File List WordPress plugin through 6.3.11 does not validate the source path of a file-move operation reachable by unauthenticated users, allowing them to read arbitrary files on the server and to relocate critical files out of the web root, leading to sensitive information disclosure and potential site takeover.
🎖@cveNotify
WPScan
Simple File List <= 6.3.11 - Unauthenticated Arbitrary File Read and Move via Path Traversal
See details on Simple File List <= 6.3.11 - Unauthenticated Arbitrary File Read and Move via Path Traversal CVE 2026-16616. View the latest Plugin Vulnerabilities on WPScan.
🚨 CVE-2026-16617
The Simple File List WordPress plugin through 6.3.11 does not properly sanitise and escape a file's description before outputting it on the public file list, allowing unauthenticated users (when front-end file management is enabled) to perform Stored Cross-Site Scripting attacks that execute in the browser of any visitor viewing the list.
🎖@cveNotify
The Simple File List WordPress plugin through 6.3.11 does not properly sanitise and escape a file's description before outputting it on the public file list, allowing unauthenticated users (when front-end file management is enabled) to perform Stored Cross-Site Scripting attacks that execute in the browser of any visitor viewing the list.
🎖@cveNotify
WPScan
Simple File List <= 6.3.11 - Unauthenticated Stored XSS via File Description
See details on Simple File List <= 6.3.11 - Unauthenticated Stored XSS via File Description CVE 2026-16617. View the latest Plugin Vulnerabilities on WPScan.
🚨 CVE-2026-16950
The Product Shortlist WordPress plugin through 1.0.4 does not properly sanitise and escape a parameter before using it in a SQL statement, allowing unauthenticated attackers to perform SQL injection attacks.
🎖@cveNotify
The Product Shortlist WordPress plugin through 1.0.4 does not properly sanitise and escape a parameter before using it in a SQL statement, allowing unauthenticated attackers to perform SQL injection attacks.
🎖@cveNotify
WPScan
Product Shortlist <= 1.0.4 - Unauthenticated SQL Injection via get_shortlisted_products
See details on Product Shortlist <= 1.0.4 - Unauthenticated SQL Injection via get_shortlisted_products CVE 2026-16950. View the latest Plugin Vulnerabilities on WPScan.
🚨 CVE-2026-16979
The SmartCrawl SEO checker, analyzer & optimizer WordPress plugin before 3.16.3 does not perform capability checks on two of its AJAX actions, allowing users with at least the Subscriber role to read the titles of private and draft posts by ID and to enumerate stored post-meta key names.
🎖@cveNotify
The SmartCrawl SEO checker, analyzer & optimizer WordPress plugin before 3.16.3 does not perform capability checks on two of its AJAX actions, allowing users with at least the Subscriber role to read the titles of private and draft posts by ID and to enumerate stored post-meta key names.
🎖@cveNotify
WPScan
SmartCrawl < 3.16.3 - Subscriber+ Private/Draft Post Title Disclosure and Post Meta Key Enumeration
See details on SmartCrawl < 3.16.3 - Subscriber+ Private/Draft Post Title Disclosure and Post Meta Key Enumeration CVE 2026-16979. View the latest Plugin Vulnerabilities on WPScan.
🚨 CVE-2026-17565
The Animation Addons for Elementor WordPress plugin before 2.7.2 does not validate a user-supplied value before using it to build the host of a server-side HTTP request, allowing unauthenticated users to make the site issue requests to internal hosts and read the responses back.
🎖@cveNotify
The Animation Addons for Elementor WordPress plugin before 2.7.2 does not validate a user-supplied value before using it to build the host of a server-side HTTP request, allowing unauthenticated users to make the site issue requests to internal hosts and read the responses back.
🎖@cveNotify
WPScan
Animation Addons for Elementor < 2.7.2 - Unauthenticated Server-Side Request Forgery
See details on Animation Addons for Elementor < 2.7.2 - Unauthenticated Server-Side Request Forgery CVE 2026-17565. View the latest Plugin Vulnerabilities on WPScan.
🚨 CVE-2026-18051
The W3 Total Cache WordPress plugin before 2.10.5 does not properly validate the request path it uses to build cache file names, allowing unauthenticated attackers to write a file into any existing directory on the server, inside or outside the web root, overwriting whatever occupies the target name.
On Apache, the same flaw overwrites the site's .htaccess files, which breaks the site and can strip hardening rules that other security measures rely on.
🎖@cveNotify
The W3 Total Cache WordPress plugin before 2.10.5 does not properly validate the request path it uses to build cache file names, allowing unauthenticated attackers to write a file into any existing directory on the server, inside or outside the web root, overwriting whatever occupies the target name.
On Apache, the same flaw overwrites the site's .htaccess files, which breaks the site and can strip hardening rules that other security measures rely on.
🎖@cveNotify
WPScan
W3 Total Cache < 2.10.5 - Unauthenticated Arbitrary Directory File Write and .htaccess Overwrite via Path Traversal in the Page…
See details on W3 Total Cache < 2.10.5 - Unauthenticated Arbitrary Directory File Write and .htaccess Overwrite via Path Traversal in the Page Cache Key CVE 2026-18051. View the latest Plugin Vulnerabilities on WPScan.
🚨 CVE-2026-18202
The JetEngine WordPress plugin before 3.8.14 adds SVG to the site-wide list of allowed upload types without sanitising the file contents, allowing users with the upload files capability, such as Authors, to upload a file containing malicious JavaScript that executes in the browser of any user who opens it (Stored Cross-Site Scripting). On multisite, this also overrides an upload-type restriction set by the network administrator.
🎖@cveNotify
The JetEngine WordPress plugin before 3.8.14 adds SVG to the site-wide list of allowed upload types without sanitising the file contents, allowing users with the upload files capability, such as Authors, to upload a file containing malicious JavaScript that executes in the browser of any user who opens it (Stored Cross-Site Scripting). On multisite, this also overrides an upload-type restriction set by the network administrator.
🎖@cveNotify
WPScan
JetEngine < 3.8.14 - Author+ Stored XSS via SVG Upload
See details on JetEngine < 3.8.14 - Author+ Stored XSS via SVG Upload CVE 2026-18202. View the latest Plugin Vulnerabilities on WPScan.
🚨 CVE-2026-18231
The WP Directory Kit WordPress plugin before 1.5.7 does not perform any authorization check on one of its public AJAX actions and returns unfiltered database rows, allowing unauthenticated attackers to retrieve the usernames and email addresses of users holding the WP Directory Kit WordPress plugin before 1.5.7's own roles.
🎖@cveNotify
The WP Directory Kit WordPress plugin before 1.5.7 does not perform any authorization check on one of its public AJAX actions and returns unfiltered database rows, allowing unauthenticated attackers to retrieve the usernames and email addresses of users holding the WP Directory Kit WordPress plugin before 1.5.7's own roles.
🎖@cveNotify
WPScan
WP Directory Kit < 1.5.7 - Unauthenticated User Email Disclosure via select_2_ajax_user
See details on WP Directory Kit < 1.5.7 - Unauthenticated User Email Disclosure via select_2_ajax_user CVE 2026-18231. View the latest Plugin Vulnerabilities on WPScan.
🚨 CVE-2026-18466
The WP Maps WordPress plugin before 4.9.8 does not perform a capability check, nor validate a nonce, in one of its AJAX actions, allowing users with a Subscriber account to create an unlimited number of options in the database, each of which is loaded on every page request.
🎖@cveNotify
The WP Maps WordPress plugin before 4.9.8 does not perform a capability check, nor validate a nonce, in one of its AJAX actions, allowing users with a Subscriber account to create an unlimited number of options in the database, each of which is loaded on every page request.
🎖@cveNotify
WPScan
WP Maps < 4.9.8 - Subscriber+ Unlimited Autoloaded Option Creation
See details on WP Maps < 4.9.8 - Subscriber+ Unlimited Autoloaded Option Creation CVE 2026-18466. View the latest Plugin Vulnerabilities on WPScan.
🚨 CVE-2026-18776
The TrueBooker WordPress plugin before 1.2.7 does not have proper authorisation checks in some of its AJAX actions, allowing unauthenticated users to change the email address of arbitrary users, including administrators, and subsequently take over their account via the password reset flow.
🎖@cveNotify
The TrueBooker WordPress plugin before 1.2.7 does not have proper authorisation checks in some of its AJAX actions, allowing unauthenticated users to change the email address of arbitrary users, including administrators, and subsequently take over their account via the password reset flow.
🎖@cveNotify
WPScan
TrueBooker Appointment Booking < 1.2.7 - Unauthenticated Account Takeover via Multiple AJAX Actions
See details on TrueBooker Appointment Booking < 1.2.7 - Unauthenticated Account Takeover via Multiple AJAX Actions CVE 2026-18776. View the latest Plugin Vulnerabilities on WPScan.
🚨 CVE-2026-18777
The TrueBooker WordPress plugin before 1.2.7 does not have proper authorisation checks in one of its AJAX actions, allowing unauthenticated users to change the status of arbitrary appointments, as well as to trigger notification emails to the affected customers.
🎖@cveNotify
The TrueBooker WordPress plugin before 1.2.7 does not have proper authorisation checks in one of its AJAX actions, allowing unauthenticated users to change the status of arbitrary appointments, as well as to trigger notification emails to the affected customers.
🎖@cveNotify
WPScan
TrueBooker Appointment Booking < 1.2.7 - Unauthenticated Arbitrary Appointment Status Change via update_appointment_status
See details on TrueBooker Appointment Booking < 1.2.7 - Unauthenticated Arbitrary Appointment Status Change via update_appointment_status CVE 2026-18777. View the latest Plugin Vulnerabilities on WPScan.
🚨 CVE-2026-18778
The TrueBooker WordPress plugin before 1.2.7 does not have proper authorisation checks in some of its AJAX actions, allowing unauthenticated users to retrieve the personal information of customers who booked an appointment, including their name, email address, phone number and postal address.
🎖@cveNotify
The TrueBooker WordPress plugin before 1.2.7 does not have proper authorisation checks in some of its AJAX actions, allowing unauthenticated users to retrieve the personal information of customers who booked an appointment, including their name, email address, phone number and postal address.
🎖@cveNotify
WPScan
TrueBooker Appointment Booking < 1.2.7 - Unauthenticated Customer PII Disclosure via Multiple AJAX Actions
See details on TrueBooker Appointment Booking < 1.2.7 - Unauthenticated Customer PII Disclosure via Multiple AJAX Actions CVE 2026-18778. View the latest Plugin Vulnerabilities on WPScan.
🚨 CVE-2026-18779
The TrueBooker WordPress plugin before 1.2.7 does not have proper authorisation checks in one of its AJAX actions, allowing unauthenticated users to delete arbitrary appointment records along with their associated booking items and payment records.
🎖@cveNotify
The TrueBooker WordPress plugin before 1.2.7 does not have proper authorisation checks in one of its AJAX actions, allowing unauthenticated users to delete arbitrary appointment records along with their associated booking items and payment records.
🎖@cveNotify
WPScan
TrueBooker Appointment Booking < 1.2.7 - Unauthenticated Appointment and Payment Record Deletion via update_appointment_booked
See details on TrueBooker Appointment Booking < 1.2.7 - Unauthenticated Appointment and Payment Record Deletion via update_appointment_booked CVE 2026-18779. View the latest Plugin Vulnerabilities on WPScan.
🚨 CVE-2026-18937
The Broken Link Checker WordPress plugin before 2.4.12 does not limit which query variables it accepts from user input on sites using plain permalinks, allowing unauthenticated users to overwrite arbitrary PHP global variables, and to execute arbitrary code on the server when a classic (non-block) is active.
🎖@cveNotify
The Broken Link Checker WordPress plugin before 2.4.12 does not limit which query variables it accepts from user input on sites using plain permalinks, allowing unauthenticated users to overwrite arbitrary PHP global variables, and to execute arbitrary code on the server when a classic (non-block) is active.
🎖@cveNotify
WPScan
Broken Link Checker < 2.4.12 - Unauthenticated RCE via Query Variable Injection
See details on Broken Link Checker < 2.4.12 - Unauthenticated RCE via Query Variable Injection CVE 2026-18937. View the latest Plugin Vulnerabilities on WPScan.
🚨 CVE-2026-19055
The ProSolution WP Client WordPress plugin before 2.0.11 does not sanitise and escape several parameters before reflecting them into HTML attributes on its public pages, leading to reflected Cross-Site Scripting that can be triggered against any visitor, including a logged-in administrator.
🎖@cveNotify
The ProSolution WP Client WordPress plugin before 2.0.11 does not sanitise and escape several parameters before reflecting them into HTML attributes on its public pages, leading to reflected Cross-Site Scripting that can be triggered against any visitor, including a logged-in administrator.
🎖@cveNotify
WPScan
ProSolution WP Client < 2.0.11 - Reflected XSS via Multiple Parameters
See details on ProSolution WP Client < 2.0.11 - Reflected XSS via Multiple Parameters CVE 2026-19055. View the latest Plugin Vulnerabilities on WPScan.
🚨 CVE-2026-19056
The ProSolution WP Client WordPress plugin before 2.0.11 does not sanitise and escape a parameter before reflecting it into an HTML attribute on one of its administrative pages, leading to reflected Cross-Site Scripting that runs in the session of an administrator induced to submit a crafted request.
🎖@cveNotify
The ProSolution WP Client WordPress plugin before 2.0.11 does not sanitise and escape a parameter before reflecting it into an HTML attribute on one of its administrative pages, leading to reflected Cross-Site Scripting that runs in the session of an administrator induced to submit a crafted request.
🎖@cveNotify
WPScan
ProSolution WP Client < 2.0.11 - Reflected XSS via 'page' Parameter
See details on ProSolution WP Client < 2.0.11 - Reflected XSS via 'page' Parameter CVE 2026-19056. View the latest Plugin Vulnerabilities on WPScan.
🚨 CVE-2026-19406
The Easy Appointments WordPress plugin before 4.0.1 does not restrict one of its appointment-listing REST endpoints to the records belonging to the requesting user, allowing users with contributor-level access to read all bookings on the site, including customer names, schedules, and statuses.
🎖@cveNotify
The Easy Appointments WordPress plugin before 4.0.1 does not restrict one of its appointment-listing REST endpoints to the records belonging to the requesting user, allowing users with contributor-level access to read all bookings on the site, including customer names, schedules, and statuses.
🎖@cveNotify
WPScan
Easy Appointments < 4.0.1 - Contributor+ Sensitive Information Disclosure via REST Appointments Listing
See details on Easy Appointments < 4.0.1 - Contributor+ Sensitive Information Disclosure via REST Appointments Listing CVE 2026-19406. View the latest Plugin Vulnerabilities on WPScan.
🚨 CVE-2026-19416
The KiviCare WordPress plugin before 4.5.4 does not verify that the requesting user owns the appointment being modified, allowing authenticated patient-level users to cancel and reschedule other patients' appointments.
🎖@cveNotify
The KiviCare WordPress plugin before 4.5.4 does not verify that the requesting user owns the appointment being modified, allowing authenticated patient-level users to cancel and reschedule other patients' appointments.
🎖@cveNotify
WPScan
KiviCare < 4.5.4 - Patient+ Cross-Patient Appointment Modification via IDOR
See details on KiviCare < 4.5.4 - Patient+ Cross-Patient Appointment Modification via IDOR CVE 2026-19416. View the latest Plugin Vulnerabilities on WPScan.
🚨 CVE-2026-19417
The KiviCare WordPress plugin before 4.5.4 does not verify that the requesting user is entitled to the media file being served, allowing authenticated patient-level users to download any file in the media library, including other patients' uploaded medical reports.
🎖@cveNotify
The KiviCare WordPress plugin before 4.5.4 does not verify that the requesting user is entitled to the media file being served, allowing authenticated patient-level users to download any file in the media library, including other patients' uploaded medical reports.
🎖@cveNotify
WPScan
KiviCare < 4.5.4 - Patient+ Arbitrary Media Attachment Read via IDOR
See details on KiviCare < 4.5.4 - Patient+ Arbitrary Media Attachment Read via IDOR CVE 2026-19417. View the latest Plugin Vulnerabilities on WPScan.