🚨 CVE-2026-19723
The Social Media Share Buttons & Social Sharing Icons WordPress plugin before 3.0.1 does not properly escape a value taken from the incoming request before outputting it in an inline JavaScript event handler, leading to Reflected Cross-Site Scripting which is triggered when a user interacts with the affected button.
Exploitation requires the Social Media Share Buttons & Social Sharing Icons WordPress plugin before 3.0.1 to be running a non-default icon display configuration.
🎖@cveNotify
The Social Media Share Buttons & Social Sharing Icons WordPress plugin before 3.0.1 does not properly escape a value taken from the incoming request before outputting it in an inline JavaScript event handler, leading to Reflected Cross-Site Scripting which is triggered when a user interacts with the affected button.
Exploitation requires the Social Media Share Buttons & Social Sharing Icons WordPress plugin before 3.0.1 to be running a non-default icon display configuration.
🎖@cveNotify
WPScan
Social Media Share Buttons & Social Sharing Icons < 3.0.1 - Reflected XSS via Pin It Share Handler
See details on Social Media Share Buttons & Social Sharing Icons < 3.0.1 - Reflected XSS via Pin It Share Handler CVE 2026-19723. View the latest Plugin Vulnerabilities on WPScan.
🚨 CVE-2026-74927
The MultiVendorX WordPress plugin before 5.0.15 does not have proper authorisation controls on one of its REST API listing routes, allowing unauthenticated users to retrieve vendor contact and payout details, pending payout amounts, and administrative notes attached to store applications.
🎖@cveNotify
The MultiVendorX WordPress plugin before 5.0.15 does not have proper authorisation controls on one of its REST API listing routes, allowing unauthenticated users to retrieve vendor contact and payout details, pending payout amounts, and administrative notes attached to store applications.
🎖@cveNotify
WPScan
MultiVendorX 5.0.13 - 5.0.14 - Unauthenticated Vendor PII and Payout Data Disclosure via stores REST Endpoint
See details on MultiVendorX 5.0.13 - 5.0.14 - Unauthenticated Vendor PII and Payout Data Disclosure via stores REST Endpoint CVE 2026-74927. View the latest Plugin Vulnerabilities on WPScan.
🚨 CVE-2026-77764
The GamiPress WordPress plugin before 7.9.9.6 does not properly restrict its video watch-tracking functionality, allowing users with a role as low as Subscriber to award the configured gamification points, achievements and ranks to arbitrary users including administrators, and to accrue them without limit.
🎖@cveNotify
The GamiPress WordPress plugin before 7.9.9.6 does not properly restrict its video watch-tracking functionality, allowing users with a role as low as Subscriber to award the configured gamification points, achievements and ranks to arbitrary users including administrators, and to accrue them without limit.
🎖@cveNotify
WPScan
GamiPress < 7.9.9.6 - Subscriber+ Arbitrary User Points and Achievement Award via Watch-Video Listeners
See details on GamiPress < 7.9.9.6 - Subscriber+ Arbitrary User Points and Achievement Award via Watch-Video Listeners CVE 2026-77764. View the latest Plugin Vulnerabilities on WPScan.
🚨 CVE-2026-77782
The Rank Math SEO WordPress plugin before 1.0.277.1 does not check whether a post is password protected before using its content to build publicly generated SEO metadata, allowing unauthenticated users to read the content of password-protected posts.
🎖@cveNotify
The Rank Math SEO WordPress plugin before 1.0.277.1 does not check whether a post is password protected before using its content to build publicly generated SEO metadata, allowing unauthenticated users to read the content of password-protected posts.
🎖@cveNotify
WPScan
Rank Math SEO < 1.0.277.1 - Unauthenticated Password-Protected Post Content Disclosure via Post Metadata and llms.txt
See details on Rank Math SEO < 1.0.277.1 - Unauthenticated Password-Protected Post Content Disclosure via Post Metadata and llms.txt CVE 2026-77782. View the latest Plugin Vulnerabilities on WPScan.
🚨 CVE-2026-77783
The Rank Math SEO WordPress plugin before 1.0.277 does not verify that the post whose schema it renders on the front end is publicly viewable, allowing unauthenticated visitors to disclose the schema and associated content of draft, pending, private, scheduled and password-protected posts.
🎖@cveNotify
The Rank Math SEO WordPress plugin before 1.0.277 does not verify that the post whose schema it renders on the front end is publicly viewable, allowing unauthenticated visitors to disclose the schema and associated content of draft, pending, private, scheduled and password-protected posts.
🎖@cveNotify
WPScan
Rank Math SEO < 1.0.277 - Unauthenticated Non-Public Post Schema and Content Disclosure
See details on Rank Math SEO < 1.0.277 - Unauthenticated Non-Public Post Schema and Content Disclosure CVE 2026-77783. View the latest Plugin Vulnerabilities on WPScan.
🚨 CVE-2026-77784
The Rank Math SEO WordPress plugin before 1.0.277 does not verify that a user is allowed to edit the object being modified before updating its SEO indexing metadata, allowing users with the Author role and above to alter that metadata on content, taxonomy terms and user profiles they do not own, and to remove other users' content from the site's sitemap and search engine index.
🎖@cveNotify
The Rank Math SEO WordPress plugin before 1.0.277 does not verify that a user is allowed to edit the object being modified before updating its SEO indexing metadata, allowing users with the Author role and above to alter that metadata on content, taxonomy terms and user profiles they do not own, and to remove other users' content from the site's sitemap and search engine index.
🎖@cveNotify
WPScan
Rank Math SEO < 1.0.277 - Author+ Robots and Pillar Content Meta Update on Non-Owned Objects via mark_page_as
See details on Rank Math SEO < 1.0.277 - Author+ Robots and Pillar Content Meta Update on Non-Owned Objects via mark_page_as CVE 2026-77784. View the latest Plugin Vulnerabilities on WPScan.
🚨 CVE-2026-77787
The Rank Math SEO WordPress plugin before 1.0.277 does not perform a capability check when bulk metadata updates target taxonomy terms, and reuses the supplied object identifier across object types, allowing users with the Author role and above to modify the SEO metadata of terms they cannot edit and to overwrite the titles of posts belonging to other users.
🎖@cveNotify
The Rank Math SEO WordPress plugin before 1.0.277 does not perform a capability check when bulk metadata updates target taxonomy terms, and reuses the supplied object identifier across object types, allowing users with the Author role and above to modify the SEO metadata of terms they cannot edit and to overwrite the titles of posts belonging to other users.
🎖@cveNotify
WPScan
Rank Math SEO < 1.0.277 - Author+ Term Metadata Update and Cross-Object Post Title Overwrite via updateMetaBulk
See details on Rank Math SEO < 1.0.277 - Author+ Term Metadata Update and Cross-Object Post Title Overwrite via updateMetaBulk CVE 2026-77787. View the latest Plugin Vulnerabilities on WPScan.
🚨 CVE-2026-77788
The Rank Math SEO WordPress plugin before 1.0.277 does not verify that the metadata row being updated belongs to the object the user was authorised against, allowing users with the Author role and above to overwrite arbitrary post and user metadata, including that belonging to higher-privileged users.
🎖@cveNotify
The Rank Math SEO WordPress plugin before 1.0.277 does not verify that the metadata row being updated belongs to the object the user was authorised against, allowing users with the Author role and above to overwrite arbitrary post and user metadata, including that belonging to higher-privileged users.
🎖@cveNotify
WPScan
Rank Math SEO < 1.0.277 - Author+ Arbitrary Post and User Metadata Overwrite via updateSchemas
See details on Rank Math SEO < 1.0.277 - Author+ Arbitrary Post and User Metadata Overwrite via updateSchemas CVE 2026-77788. View the latest Plugin Vulnerabilities on WPScan.
🚨 CVE-2026-77792
The RegistrationMagic WordPress plugin before 6.0.9.9 does not escape a registration form field value before outputting it in an HTML attribute on an administrative page, allowing unauthenticated users to perform Stored Cross-Site Scripting attacks against high privilege users such as admin.
🎖@cveNotify
The RegistrationMagic WordPress plugin before 6.0.9.9 does not escape a registration form field value before outputting it in an HTML attribute on an administrative page, allowing unauthenticated users to perform Stored Cross-Site Scripting attacks against high privilege users such as admin.
🎖@cveNotify
WPScan
RegistrationMagic < 6.0.9.9 - Unauthenticated Stored XSS via Rating Field
See details on RegistrationMagic < 6.0.9.9 - Unauthenticated Stored XSS via Rating Field CVE 2026-77792. View the latest Plugin Vulnerabilities on WPScan.
🚨 CVE-2026-78151
The FormLayer WordPress plugin before 1.0.9 does not perform any authorization check before returning a form's full stored configuration in the response to its public submission handler, allowing unauthenticated users to disclose notification recipient addresses, confirmation redirect targets and integration settings, including those of unpublished forms.
🎖@cveNotify
The FormLayer WordPress plugin before 1.0.9 does not perform any authorization check before returning a form's full stored configuration in the response to its public submission handler, allowing unauthenticated users to disclose notification recipient addresses, confirmation redirect targets and integration settings, including those of unpublished forms.
🎖@cveNotify
WPScan
FormLayer < 1.0.9 - Unauthenticated Form Configuration Disclosure via Form Submission Response
See details on FormLayer < 1.0.9 - Unauthenticated Form Configuration Disclosure via Form Submission Response CVE 2026-78151. View the latest Plugin Vulnerabilities on WPScan.
🚨 CVE-2026-78657
The SigmaForms Pro – AI Generated Forms plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the delete_submission_files function in all versions up to, and including, 1.4.11. This makes it possible for unauthenticated attackers to delete arbitrary files on the server, which can easily lead to remote code execution when the right file is deleted (such as wp-config.php). The malicious path traversal URL is submitted via form upload field and stored in the database, with deletion triggered when an administrator deletes the submission record from the admin panel.
🎖@cveNotify
The SigmaForms Pro – AI Generated Forms plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the delete_submission_files function in all versions up to, and including, 1.4.11. This makes it possible for unauthenticated attackers to delete arbitrary files on the server, which can easily lead to remote code execution when the right file is deleted (such as wp-config.php). The malicious path traversal URL is submitted via form upload field and stored in the database, with deletion triggered when an administrator deletes the submission record from the admin panel.
🎖@cveNotify
Bdthemes
Recent Announcements from BdThemes
New updates and improvements to BdThemes
🚨 CVE-2026-79621
The CatalogX WordPress plugin before 6.1.3 does not sanitise or escape content that an unauthenticated user can store before including it in the product enquiry notification email sent to the site administrator, allowing unauthenticated attackers to inject arbitrary content into that email, which is delivered when an unrelated visitor later submits a product enquiry.
🎖@cveNotify
The CatalogX WordPress plugin before 6.1.3 does not sanitise or escape content that an unauthenticated user can store before including it in the product enquiry notification email sent to the site administrator, allowing unauthenticated attackers to inject arbitrary content into that email, which is delivered when an unrelated visitor later submits a product enquiry.
🎖@cveNotify
WPScan
CatalogX < 6.1.3 - Unauthenticated Email Content Injection via Shared Transient
See details on CatalogX < 6.1.3 - Unauthenticated Email Content Injection via Shared Transient CVE 2026-79621. View the latest Plugin Vulnerabilities on WPScan.
🚨 CVE-2026-80467
The Advanced Custom Fields: Extended WordPress plugin before 0.9.2.7 does not restrict the role submitted through its front-end user forms to the roles the form actually offers, and its safeguard against privileged roles is incomplete, allowing unauthenticated visitors to register an account with elevated capabilities and then escalate it to administrator.
🎖@cveNotify
The Advanced Custom Fields: Extended WordPress plugin before 0.9.2.7 does not restrict the role submitted through its front-end user forms to the roles the form actually offers, and its safeguard against privileged roles is incomplete, allowing unauthenticated visitors to register an account with elevated capabilities and then escalate it to administrator.
🎖@cveNotify
WPScan
Advanced Custom Fields: Extended 0.9.2.2 - 0.9.2.6 - Unauthenticated Privilege Escalation via Front-End User Insert Action
See details on Advanced Custom Fields: Extended 0.9.2.2 - 0.9.2.6 - Unauthenticated Privilege Escalation via Front-End User Insert Action CVE 2026-80467. View the latest Plugin Vulnerabilities on WPScan.
🚨 CVE-2026-81194
The MasterStudy LMS WordPress Plugin WordPress plugin before 3.7.46 does not properly verify authorization when retrieving order line-item data, allowing any authenticated user including Subscribers to read other instructors' course sales records by supplying another user's identifier.
🎖@cveNotify
The MasterStudy LMS WordPress Plugin WordPress plugin before 3.7.46 does not properly verify authorization when retrieving order line-item data, allowing any authenticated user including Subscribers to read other instructors' course sales records by supplying another user's identifier.
🎖@cveNotify
WPScan
MasterStudy LMS < 3.7.46 - Subscriber+ Cross-Instructor Order Data Disclosure via author_id Parameter
See details on MasterStudy LMS < 3.7.46 - Subscriber+ Cross-Instructor Order Data Disclosure via author_id Parameter CVE 2026-81194. View the latest Plugin Vulnerabilities on WPScan.
🚨 CVE-2026-81195
The MasterStudy LMS WordPress Plugin WordPress plugin before 3.7.46 does not perform an authorization check before returning per-student course enrollment and progress data, allowing unauthenticated attackers to disclose the enrolled courses and learning progress of any registered user.
🎖@cveNotify
The MasterStudy LMS WordPress Plugin WordPress plugin before 3.7.46 does not perform an authorization check before returning per-student course enrollment and progress data, allowing unauthenticated attackers to disclose the enrolled courses and learning progress of any registered user.
🎖@cveNotify
WPScan
MasterStudy LMS < 3.7.46 - Unauthenticated Student Enrollment Disclosure via student-courses REST Route
See details on MasterStudy LMS < 3.7.46 - Unauthenticated Student Enrollment Disclosure via student-courses REST Route CVE 2026-81195. View the latest Plugin Vulnerabilities on WPScan.
🚨 CVE-2026-81196
The MasterStudy LMS WordPress Plugin WordPress plugin before 3.7.46 does not properly verify ownership of quiz question identifiers, allowing users with instructor access to read other instructors' quiz questions, including the correct answers and explanations.
🎖@cveNotify
The MasterStudy LMS WordPress Plugin WordPress plugin before 3.7.46 does not properly verify ownership of quiz question identifiers, allowing users with instructor access to read other instructors' quiz questions, including the correct answers and explanations.
🎖@cveNotify
WPScan
MasterStudy LMS < 3.7.46 - Instructor+ Quiz Answer Disclosure via IDOR
See details on MasterStudy LMS < 3.7.46 - Instructor+ Quiz Answer Disclosure via IDOR CVE 2026-81196. View the latest Plugin Vulnerabilities on WPScan.
🚨 CVE-2026-81197
The MasterStudy LMS WordPress Plugin WordPress plugin before 3.7.46 does not restrict access to a REST route that lists an author's courses, nor does it filter that listing by publication status, allowing unauthenticated users to read the titles and IDs of unpublished (draft, pending and private) courses.
🎖@cveNotify
The MasterStudy LMS WordPress Plugin WordPress plugin before 3.7.46 does not restrict access to a REST route that lists an author's courses, nor does it filter that listing by publication status, allowing unauthenticated users to read the titles and IDs of unpublished (draft, pending and private) courses.
🎖@cveNotify
WPScan
MasterStudy LMS < 3.7.46 - Unauthenticated Unpublished Course Title Disclosure via course-list REST Route
See details on MasterStudy LMS < 3.7.46 - Unauthenticated Unpublished Course Title Disclosure via course-list REST Route CVE 2026-81197. View the latest Plugin Vulnerabilities on WPScan.
🚨 CVE-2026-81198
The MasterStudy LMS WordPress Plugin WordPress plugin before 3.7.46 does not properly verify ownership of a curriculum object before acting on it, allowing authenticated users with the instructor role to delete or modify curriculum sections and materials belonging to courses owned by other instructors.
🎖@cveNotify
The MasterStudy LMS WordPress Plugin WordPress plugin before 3.7.46 does not properly verify ownership of a curriculum object before acting on it, allowing authenticated users with the instructor role to delete or modify curriculum sections and materials belonging to courses owned by other instructors.
🎖@cveNotify
WPScan
MasterStudy LMS < 3.7.46 - Instructor+ Cross-Course Curriculum Deletion and Tampering via IDOR
See details on MasterStudy LMS < 3.7.46 - Instructor+ Cross-Course Curriculum Deletion and Tampering via IDOR CVE 2026-81198. View the latest Plugin Vulnerabilities on WPScan.
🚨 CVE-2026-81199
The MasterStudy LMS WordPress Plugin WordPress plugin before 3.7.46 does not perform an authorization check before returning a student's learning statistics, allowing unauthenticated attackers to disclose the course counts, points, certificates, quiz and assignment totals of any registered user.
🎖@cveNotify
The MasterStudy LMS WordPress Plugin WordPress plugin before 3.7.46 does not perform an authorization check before returning a student's learning statistics, allowing unauthenticated attackers to disclose the course counts, points, certificates, quiz and assignment totals of any registered user.
🎖@cveNotify
WPScan
MasterStudy LMS < 3.7.46 - Unauthenticated Student Statistics Disclosure via student/stats REST Route
See details on MasterStudy LMS < 3.7.46 - Unauthenticated Student Statistics Disclosure via student/stats REST Route CVE 2026-81199. View the latest Plugin Vulnerabilities on WPScan.
🚨 CVE-2026-81426
The WC Vendors WordPress plugin before 2.7.2.1 does not have CSRF protection on some of its front-end order shipment status actions, which could allow attackers to make a logged-in vendor change the shipment status of their own orders via a crafted request.
🎖@cveNotify
The WC Vendors WordPress plugin before 2.7.2.1 does not have CSRF protection on some of its front-end order shipment status actions, which could allow attackers to make a logged-in vendor change the shipment status of their own orders via a crafted request.
🎖@cveNotify
WPScan
WC Vendors < 2.7.2.1 - Order Shipment Status Change via CSRF
See details on WC Vendors < 2.7.2.1 - Order Shipment Status Change via CSRF CVE 2026-81426. View the latest Plugin Vulnerabilities on WPScan.
🚨 CVE-2026-81427
The WC Vendors WordPress plugin before 2.7.2.1 does not verify that the vendor submitting a front-end order shipment status change owns the referenced order, allowing any authenticated vendor to mark another vendor's order as shipped, add an order note falsely attributed to the victim vendor, and trigger the customer shipment notification email.
🎖@cveNotify
The WC Vendors WordPress plugin before 2.7.2.1 does not verify that the vendor submitting a front-end order shipment status change owns the referenced order, allowing any authenticated vendor to mark another vendor's order as shipped, add an order note falsely attributed to the victim vendor, and trigger the customer shipment notification email.
🎖@cveNotify
WPScan
WC Vendors < 2.7.2.1 - Vendor+ Cross-Vendor Order Shipment Status Change
See details on WC Vendors < 2.7.2.1 - Vendor+ Cross-Vendor Order Shipment Status Change CVE 2026-81427. View the latest Plugin Vulnerabilities on WPScan.