🚨 CVE-2026-78438
The W3 Total Cache plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Comment Content via LazyLoad Background Mutator in all versions up to, and including, 2.10.5 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This requires the "Lazy Load Images" feature with "Process background images" to be enabled, and the malicious comment to be approved by a moderator before execution is triggered.
🎖@cveNotify
The W3 Total Cache plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Comment Content via LazyLoad Background Mutator in all versions up to, and including, 2.10.5 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This requires the "Lazy Load Images" feature with "Process background images" to be enabled, and the malicious comment to be approved by a moderator before execution is triggered.
🎖@cveNotify
🚨 CVE-2026-81404
The IPGP Visitors Origin WordPress plugin before 1.6 does not sanitise or escape user input before reflecting it back in the HTTP response, allowing unauthenticated attackers to perform Reflected Cross-Site Scripting attacks against users who are tricked into submitting a crafted request.
🎖@cveNotify
The IPGP Visitors Origin WordPress plugin before 1.6 does not sanitise or escape user input before reflecting it back in the HTTP response, allowing unauthenticated attackers to perform Reflected Cross-Site Scripting attacks against users who are tricked into submitting a crafted request.
🎖@cveNotify
WPScan
IPGP Visitors Origin < 1.6 - Reflected XSS
See details on IPGP Visitors Origin < 1.6 - Reflected XSS CVE 2026-81404. View the latest Plugin Vulnerabilities on WPScan.
🚨 CVE-2026-81423
The Accept Stripe Payments WordPress plugin before 2.1.4 does not validate a user-supplied URL before using it in a redirect, allowing unauthenticated attackers to redirect visitors to an arbitrary external website, which can be leveraged for phishing.
🎖@cveNotify
The Accept Stripe Payments WordPress plugin before 2.1.4 does not validate a user-supplied URL before using it in a redirect, allowing unauthenticated attackers to redirect visitors to an arbitrary external website, which can be leveraged for phishing.
🎖@cveNotify
WPScan
Accept Stripe Payments < 2.1.4 - Open Redirect via IPN Handler
See details on Accept Stripe Payments < 2.1.4 - Open Redirect via IPN Handler CVE 2026-81423. View the latest Plugin Vulnerabilities on WPScan.
🚨 CVE-2026-81424
The Accept Stripe Payments WordPress plugin before 2.1.4 does not verify that the product fulfilled when a checkout is completed matches the product the authoritative payment was actually made for, checking only that the amount paid is at least the referenced product's price, allowing unauthenticated attackers who complete a genuine payment to obtain fulfilment for a different, equal- or lower-priced product than the one they paid for.
🎖@cveNotify
The Accept Stripe Payments WordPress plugin before 2.1.4 does not verify that the product fulfilled when a checkout is completed matches the product the authoritative payment was actually made for, checking only that the amount paid is at least the referenced product's price, allowing unauthenticated attackers who complete a genuine payment to obtain fulfilment for a different, equal- or lower-priced product than the one they paid for.
🎖@cveNotify
WPScan
Accept Stripe Payments < 2.1.4 - Unauthenticated Product Substitution via IDOR
See details on Accept Stripe Payments < 2.1.4 - Unauthenticated Product Substitution via IDOR CVE 2026-81424. View the latest Plugin Vulnerabilities on WPScan.
🚨 CVE-2026-82304
The Music Store WordPress plugin before 1.4.5 does not sanitise and escape user input before using it in a SQL statement, leading to a SQL injection exploitable by unauthenticated users.
🎖@cveNotify
The Music Store WordPress plugin before 1.4.5 does not sanitise and escape user input before using it in a SQL statement, leading to a SQL injection exploitable by unauthenticated users.
🎖@cveNotify
WPScan
Music Store – WordPress eCommerce < 1.4.5 - Unauthenticated SQLi via paypal-data Handler
See details on Music Store – WordPress eCommerce < 1.4.5 - Unauthenticated SQLi via paypal-data Handler CVE 2026-82304. View the latest Plugin Vulnerabilities on WPScan.
🚨 CVE-2026-82846
The Masteriyo LMS WordPress plugin before 3.4.0 does not sanitise and escape some course settings before outputting them in a page available to all visitors, allowing users with a course-author role to perform Stored Cross-Site Scripting attacks that run in the session of anyone viewing the course, including a logged-in administrator.
🎖@cveNotify
The Masteriyo LMS WordPress plugin before 3.4.0 does not sanitise and escape some course settings before outputting them in a page available to all visitors, allowing users with a course-author role to perform Stored Cross-Site Scripting attacks that run in the session of anyone viewing the course, including a logged-in administrator.
🎖@cveNotify
WPScan
Masteriyo LMS 1.18.0 - 2.3.3 - Instructor+ Stored XSS via Course Custom Fields
See details on Masteriyo LMS 1.18.0 - 2.3.3 - Instructor+ Stored XSS via Course Custom Fields CVE 2026-82846. View the latest Plugin Vulnerabilities on WPScan.
🚨 CVE-2026-83543
The Greenshift WordPress plugin before 13.2.0 does not validate a user-supplied URL before fetching it server-side, allowing users with contributor-level access and above to make the server issue requests to arbitrary hosts and read the response.
🎖@cveNotify
The Greenshift WordPress plugin before 13.2.0 does not validate a user-supplied URL before fetching it server-side, allowing users with contributor-level access and above to make the server issue requests to arbitrary hosts and read the response.
🎖@cveNotify
WPScan
Greenshift < 13.2.0 - Contributor+ SSRF via get-csv-to-json REST Endpoint
See details on Greenshift < 13.2.0 - Contributor+ SSRF via get-csv-to-json REST Endpoint CVE 2026-83543. View the latest Plugin Vulnerabilities on WPScan.
🚨 CVE-2026-83544
The Greenshift WordPress plugin before 13.2.0 does not properly escape a block animation attribute before outputting it within an HTML attribute, allowing users with contributor-level access and above to inject arbitrary web scripts that execute when the content is viewed.
🎖@cveNotify
The Greenshift WordPress plugin before 13.2.0 does not properly escape a block animation attribute before outputting it within an HTML attribute, allowing users with contributor-level access and above to inject arbitrary web scripts that execute when the content is viewed.
🎖@cveNotify
WPScan
Greenshift < 13.2.0 - Contributor+ Stored XSS via Block Animation customProps Attribute
See details on Greenshift < 13.2.0 - Contributor+ Stored XSS via Block Animation customProps Attribute CVE 2026-83544. View the latest Plugin Vulnerabilities on WPScan.
🚨 CVE-2026-84021
The Bold Page Builder WordPress plugin before 5.9.8 does not properly validate a link URL before outputting it in an HTML attribute, relying on a filter that can be evaded, allowing users with the Contributor role and above to inject arbitrary web scripts that execute when a user clicks the affected link.
🎖@cveNotify
The Bold Page Builder WordPress plugin before 5.9.8 does not properly validate a link URL before outputting it in an HTML attribute, relying on a filter that can be evaded, allowing users with the Contributor role and above to inject arbitrary web scripts that execute when a user clicks the affected link.
🎖@cveNotify
WPScan
Bold Page Builder < 5.9.8 - Contributor+ Stored XSS via bt_bb_button/bt_bb_headline/bt_bb_icon URL
See details on Bold Page Builder < 5.9.8 - Contributor+ Stored XSS via bt_bb_button/bt_bb_headline/bt_bb_icon URL CVE 2026-84021. View the latest Plugin Vulnerabilities on WPScan.
🚨 CVE-2026-84022
The Bold Page Builder WordPress plugin before 5.9.8 does not sanitise and escape several shortcode attributes before outputting them in HTML attributes, allowing users with the Contributor role and above to inject arbitrary web scripts that execute when a user views the affected page.
🎖@cveNotify
The Bold Page Builder WordPress plugin before 5.9.8 does not sanitise and escape several shortcode attributes before outputting them in HTML attributes, allowing users with the Contributor role and above to inject arbitrary web scripts that execute when a user views the affected page.
🎖@cveNotify
WPScan
Bold Page Builder < 5.9.8 - Contributor+ Stored XSS via Multiple Shortcode Element Attributes
See details on Bold Page Builder < 5.9.8 - Contributor+ Stored XSS via Multiple Shortcode Element Attributes CVE 2026-84022. View the latest Plugin Vulnerabilities on WPScan.
🚨 CVE-2026-84221
The Kirki WordPress plugin before 6.3.0 does not escape a user-supplied identifier before using it in a SQL query, allowing users with editor-level access and above to append arbitrary SQL and read the contents of the database, including user credentials.
🎖@cveNotify
The Kirki WordPress plugin before 6.3.0 does not escape a user-supplied identifier before using it in a SQL query, allowing users with editor-level access and above to append arbitrary SQL and read the contents of the database, including user credentials.
🎖@cveNotify
WPScan
Kirki 6.0.0 - 6.2.5 - Editor+ SQLi via Content Manager Field ID
See details on Kirki 6.0.0 - 6.2.5 - Editor+ SQLi via Content Manager Field ID CVE 2026-84221. View the latest Plugin Vulnerabilities on WPScan.
🚨 CVE-2026-84225
The Kirki WordPress plugin before 6.3.0 does not check that a user is allowed to act on a collaboration comment before changing its state, allowing users whom an administrator has granted content-level access to the page builder to modify comments left by other users, including on pages they cannot themselves open.
🎖@cveNotify
The Kirki WordPress plugin before 6.3.0 does not check that a user is allowed to act on a collaboration comment before changing its state, allowing users whom an administrator has granted content-level access to the page builder to modify comments left by other users, including on pages they cannot themselves open.
🎖@cveNotify
WPScan
Kirki 6.0.0 - 6.2.5 - Authenticated Collaboration Comment Status Modification via IDOR
See details on Kirki 6.0.0 - 6.2.5 - Authenticated Collaboration Comment Status Modification via IDOR CVE 2026-84225. View the latest Plugin Vulnerabilities on WPScan.
🚨 CVE-2026-84745
The Events Calendar WordPress plugin before 6.17.3.1 does not restrict non-public content to the users entitled to read it on its public REST archives, allowing users with a low-privilege role such as contributor to read the full contents of every unpublished record on the site, including other users'.
🎖@cveNotify
The Events Calendar WordPress plugin before 6.17.3.1 does not restrict non-public content to the users entitled to read it on its public REST archives, allowing users with a low-privilege role such as contributor to read the full contents of every unpublished record on the site, including other users'.
🎖@cveNotify
WPScan
The Events Calendar < 6.17.3.1 - Contributor+ Non-Public Event, Venue and Organizer Content Disclosure via REST API
See details on The Events Calendar < 6.17.3.1 - Contributor+ Non-Public Event, Venue and Organizer Content Disclosure via REST API CVE 2026-84745. View the latest Plugin Vulnerabilities on WPScan.
🚨 CVE-2026-84896
The King Addons for Elementor WordPress plugin before 51.1.77 does not escape a widget display-style setting before outputting it in an HTML attribute, allowing users with Contributor-level access and above to store JavaScript that executes in the browser of any visitor to the affected page, including logged-in administrators.
🎖@cveNotify
The King Addons for Elementor WordPress plugin before 51.1.77 does not escape a widget display-style setting before outputting it in an HTML attribute, allowing users with Contributor-level access and above to store JavaScript that executes in the browser of any visitor to the affected page, including logged-in administrators.
🎖@cveNotify
WPScan
King Addons for Elementor < 51.1.77 - Contributor+ Stored XSS via Magazine Grid Widget
See details on King Addons for Elementor < 51.1.77 - Contributor+ Stored XSS via Magazine Grid Widget CVE 2026-84896. View the latest Plugin Vulnerabilities on WPScan.
🚨 CVE-2026-84898
The Eventin WordPress plugin before 4.1.21 does not properly validate a template path value before using it to include a local file, allowing users with contributor-level access and above to include and execute arbitrary local PHP files.
🎖@cveNotify
The Eventin WordPress plugin before 4.1.21 does not properly validate a template path value before using it to include a local file, allowing users with contributor-level access and above to include and execute arbitrary local PHP files.
🎖@cveNotify
WPScan
Eventin < 4.1.21 - Contributor+ LFI via Event Layout Meta
See details on Eventin < 4.1.21 - Contributor+ LFI via Event Layout Meta CVE 2026-84898. View the latest Plugin Vulnerabilities on WPScan.
🚨 CVE-2026-84899
The VikWidgetsLoader WordPress plugin before 1.12.0 does not sanitise or escape a block attribute before outputting it inside an inline script, allowing users with the Contributor role to store arbitrary JavaScript that executes in the browser of any user viewing the affected post, including the administrator who reviews the pending submission.
🎖@cveNotify
The VikWidgetsLoader WordPress plugin before 1.12.0 does not sanitise or escape a block attribute before outputting it inside an inline script, allowing users with the Contributor role to store arbitrary JavaScript that executes in the browser of any user viewing the affected post, including the administrator who reviews the pending submission.
🎖@cveNotify
WPScan
VikWidgetsLoader < 1.12.0 - Contributor+ Stored XSS via Gutenberg Block class_suffix
See details on VikWidgetsLoader < 1.12.0 - Contributor+ Stored XSS via Gutenberg Block class_suffix CVE 2026-84899. View the latest Plugin Vulnerabilities on WPScan.
🚨 CVE-2026-84901
The Eventin WordPress plugin before 4.1.22 does not properly check authorization on several of its event-management REST routes, allowing users with contributor-level access and above to change the site's front-page setting to an event they do not own and to create, edit and delete global event and speaker taxonomy terms they should not be able to manage.
🎖@cveNotify
The Eventin WordPress plugin before 4.1.22 does not properly check authorization on several of its event-management REST routes, allowing users with contributor-level access and above to change the site's front-page setting to an event they do not own and to create, edit and delete global event and speaker taxonomy terms they should not be able to manage.
🎖@cveNotify
WPScan
Eventin < 4.1.22 - Contributor+ Site Homepage Hijack and Event Taxonomy Manipulation via Missing Authorization
See details on Eventin < 4.1.22 - Contributor+ Site Homepage Hijack and Event Taxonomy Manipulation via Missing Authorization CVE 2026-84901. View the latest Plugin Vulnerabilities on WPScan.
🚨 CVE-2026-84926
The EmbedPress WordPress plugin before 4.6.4 does not correctly restrict access to one of its Google Reviews REST routes to administrators, allowing any authenticated user with contributor-level access or above to read the site administrator's email address, a value WordPress core withholds from that role.
🎖@cveNotify
The EmbedPress WordPress plugin before 4.6.4 does not correctly restrict access to one of its Google Reviews REST routes to administrators, allowing any authenticated user with contributor-level access or above to read the site administrator's email address, a value WordPress core withholds from that role.
🎖@cveNotify
WPScan
EmbedPress 4.6.0 - 4.6.3 - Contributor+ Administrator Email Disclosure via Google Reviews REST Route
See details on EmbedPress 4.6.0 - 4.6.3 - Contributor+ Administrator Email Disclosure via Google Reviews REST Route CVE 2026-84926. View the latest Plugin Vulnerabilities on WPScan.
🚨 CVE-2026-84927
The EmbedPress WordPress plugin before 4.6.4 does not perform a sufficient authorization check on one of its Google Reviews REST API routes, allowing users with the Contributor role and above to modify a site-wide store, deleting entries an administrator configured and injecting their own, which are rendered publicly across the site.
🎖@cveNotify
The EmbedPress WordPress plugin before 4.6.4 does not perform a sufficient authorization check on one of its Google Reviews REST API routes, allowing users with the Contributor role and above to modify a site-wide store, deleting entries an administrator configured and injecting their own, which are rendered publicly across the site.
🎖@cveNotify
WPScan
EmbedPress 4.6.0 - 4.6.3 - Contributor+ Google Reviews Modification
See details on EmbedPress 4.6.0 - 4.6.3 - Contributor+ Google Reviews Modification CVE 2026-84927. View the latest Plugin Vulnerabilities on WPScan.
🚨 CVE-2026-84930
The CatFolders Document Gallery & PDF Library WordPress plugin before 2.0.7 does not properly validate a block attribute before using it as an HTML tag name in its gallery output, allowing users with the Author role and above to inject arbitrary web scripts that execute in the browser of anyone who views the affected post.
🎖@cveNotify
The CatFolders Document Gallery & PDF Library WordPress plugin before 2.0.7 does not properly validate a block attribute before using it as an HTML tag name in its gallery output, allowing users with the Author role and above to inject arbitrary web scripts that execute in the browser of anyone who views the affected post.
🎖@cveNotify
WPScan
CatFolders Document Gallery < 2.0.7 - Author+ Stored XSS via titleTag Block Attribute
See details on CatFolders Document Gallery < 2.0.7 - Author+ Stored XSS via titleTag Block Attribute CVE 2026-84930. View the latest Plugin Vulnerabilities on WPScan.
🚨 CVE-2026-84931
The Joli Table Of Contents WordPress plugin before 3.0.3 does not sanitise or escape a shortcode attribute value before outputting it inside an HTML element's attribute, allowing users with the Author role and above to inject arbitrary HTML attributes and JavaScript that execute in the browser of any user who views the post, including higher-privileged users such as administrators. This crosses a privilege boundary even on multisite, where such users are not permitted to post unfiltered HTML.
🎖@cveNotify
The Joli Table Of Contents WordPress plugin before 3.0.3 does not sanitise or escape a shortcode attribute value before outputting it inside an HTML element's attribute, allowing users with the Author role and above to inject arbitrary HTML attributes and JavaScript that execute in the browser of any user who views the post, including higher-privileged users such as administrators. This crosses a privilege boundary even on multisite, where such users are not permitted to post unfiltered HTML.
🎖@cveNotify
WPScan
Joli Table Of Contents < 3.0.3 - Author+ Stored XSS via joli-toc Shortcode Theme Attribute
See details on Joli Table Of Contents < 3.0.3 - Author+ Stored XSS via joli-toc Shortcode Theme Attribute CVE 2026-84931. View the latest Plugin Vulnerabilities on WPScan.