🚨 CVE-2026-84896
The King Addons for Elementor WordPress plugin before 51.1.77 does not escape a widget display-style setting before outputting it in an HTML attribute, allowing users with Contributor-level access and above to store JavaScript that executes in the browser of any visitor to the affected page, including logged-in administrators.
🎖@cveNotify
The King Addons for Elementor WordPress plugin before 51.1.77 does not escape a widget display-style setting before outputting it in an HTML attribute, allowing users with Contributor-level access and above to store JavaScript that executes in the browser of any visitor to the affected page, including logged-in administrators.
🎖@cveNotify
WPScan
King Addons for Elementor < 51.1.77 - Contributor+ Stored XSS via Magazine Grid Widget
See details on King Addons for Elementor < 51.1.77 - Contributor+ Stored XSS via Magazine Grid Widget CVE 2026-84896. View the latest Plugin Vulnerabilities on WPScan.
🚨 CVE-2026-84898
The Eventin WordPress plugin before 4.1.21 does not properly validate a template path value before using it to include a local file, allowing users with contributor-level access and above to include and execute arbitrary local PHP files.
🎖@cveNotify
The Eventin WordPress plugin before 4.1.21 does not properly validate a template path value before using it to include a local file, allowing users with contributor-level access and above to include and execute arbitrary local PHP files.
🎖@cveNotify
WPScan
Eventin < 4.1.21 - Contributor+ LFI via Event Layout Meta
See details on Eventin < 4.1.21 - Contributor+ LFI via Event Layout Meta CVE 2026-84898. View the latest Plugin Vulnerabilities on WPScan.
🚨 CVE-2026-84899
The VikWidgetsLoader WordPress plugin before 1.12.0 does not sanitise or escape a block attribute before outputting it inside an inline script, allowing users with the Contributor role to store arbitrary JavaScript that executes in the browser of any user viewing the affected post, including the administrator who reviews the pending submission.
🎖@cveNotify
The VikWidgetsLoader WordPress plugin before 1.12.0 does not sanitise or escape a block attribute before outputting it inside an inline script, allowing users with the Contributor role to store arbitrary JavaScript that executes in the browser of any user viewing the affected post, including the administrator who reviews the pending submission.
🎖@cveNotify
WPScan
VikWidgetsLoader < 1.12.0 - Contributor+ Stored XSS via Gutenberg Block class_suffix
See details on VikWidgetsLoader < 1.12.0 - Contributor+ Stored XSS via Gutenberg Block class_suffix CVE 2026-84899. View the latest Plugin Vulnerabilities on WPScan.
🚨 CVE-2026-84901
The Eventin WordPress plugin before 4.1.22 does not properly check authorization on several of its event-management REST routes, allowing users with contributor-level access and above to change the site's front-page setting to an event they do not own and to create, edit and delete global event and speaker taxonomy terms they should not be able to manage.
🎖@cveNotify
The Eventin WordPress plugin before 4.1.22 does not properly check authorization on several of its event-management REST routes, allowing users with contributor-level access and above to change the site's front-page setting to an event they do not own and to create, edit and delete global event and speaker taxonomy terms they should not be able to manage.
🎖@cveNotify
WPScan
Eventin < 4.1.22 - Contributor+ Site Homepage Hijack and Event Taxonomy Manipulation via Missing Authorization
See details on Eventin < 4.1.22 - Contributor+ Site Homepage Hijack and Event Taxonomy Manipulation via Missing Authorization CVE 2026-84901. View the latest Plugin Vulnerabilities on WPScan.
🚨 CVE-2026-84926
The EmbedPress WordPress plugin before 4.6.4 does not correctly restrict access to one of its Google Reviews REST routes to administrators, allowing any authenticated user with contributor-level access or above to read the site administrator's email address, a value WordPress core withholds from that role.
🎖@cveNotify
The EmbedPress WordPress plugin before 4.6.4 does not correctly restrict access to one of its Google Reviews REST routes to administrators, allowing any authenticated user with contributor-level access or above to read the site administrator's email address, a value WordPress core withholds from that role.
🎖@cveNotify
WPScan
EmbedPress 4.6.0 - 4.6.3 - Contributor+ Administrator Email Disclosure via Google Reviews REST Route
See details on EmbedPress 4.6.0 - 4.6.3 - Contributor+ Administrator Email Disclosure via Google Reviews REST Route CVE 2026-84926. View the latest Plugin Vulnerabilities on WPScan.
🚨 CVE-2026-84927
The EmbedPress WordPress plugin before 4.6.4 does not perform a sufficient authorization check on one of its Google Reviews REST API routes, allowing users with the Contributor role and above to modify a site-wide store, deleting entries an administrator configured and injecting their own, which are rendered publicly across the site.
🎖@cveNotify
The EmbedPress WordPress plugin before 4.6.4 does not perform a sufficient authorization check on one of its Google Reviews REST API routes, allowing users with the Contributor role and above to modify a site-wide store, deleting entries an administrator configured and injecting their own, which are rendered publicly across the site.
🎖@cveNotify
WPScan
EmbedPress 4.6.0 - 4.6.3 - Contributor+ Google Reviews Modification
See details on EmbedPress 4.6.0 - 4.6.3 - Contributor+ Google Reviews Modification CVE 2026-84927. View the latest Plugin Vulnerabilities on WPScan.
🚨 CVE-2026-84930
The CatFolders Document Gallery & PDF Library WordPress plugin before 2.0.7 does not properly validate a block attribute before using it as an HTML tag name in its gallery output, allowing users with the Author role and above to inject arbitrary web scripts that execute in the browser of anyone who views the affected post.
🎖@cveNotify
The CatFolders Document Gallery & PDF Library WordPress plugin before 2.0.7 does not properly validate a block attribute before using it as an HTML tag name in its gallery output, allowing users with the Author role and above to inject arbitrary web scripts that execute in the browser of anyone who views the affected post.
🎖@cveNotify
WPScan
CatFolders Document Gallery < 2.0.7 - Author+ Stored XSS via titleTag Block Attribute
See details on CatFolders Document Gallery < 2.0.7 - Author+ Stored XSS via titleTag Block Attribute CVE 2026-84930. View the latest Plugin Vulnerabilities on WPScan.
🚨 CVE-2026-84931
The Joli Table Of Contents WordPress plugin before 3.0.3 does not sanitise or escape a shortcode attribute value before outputting it inside an HTML element's attribute, allowing users with the Author role and above to inject arbitrary HTML attributes and JavaScript that execute in the browser of any user who views the post, including higher-privileged users such as administrators. This crosses a privilege boundary even on multisite, where such users are not permitted to post unfiltered HTML.
🎖@cveNotify
The Joli Table Of Contents WordPress plugin before 3.0.3 does not sanitise or escape a shortcode attribute value before outputting it inside an HTML element's attribute, allowing users with the Author role and above to inject arbitrary HTML attributes and JavaScript that execute in the browser of any user who views the post, including higher-privileged users such as administrators. This crosses a privilege boundary even on multisite, where such users are not permitted to post unfiltered HTML.
🎖@cveNotify
WPScan
Joli Table Of Contents < 3.0.3 - Author+ Stored XSS via joli-toc Shortcode Theme Attribute
See details on Joli Table Of Contents < 3.0.3 - Author+ Stored XSS via joli-toc Shortcode Theme Attribute CVE 2026-84931. View the latest Plugin Vulnerabilities on WPScan.
🚨 CVE-2026-84934
The JCH Optimize WordPress plugin before 6.0.1 does not perform a capability check on one of its authenticated AJAX actions and lets the request choose which internal action runs, allowing any authenticated users such as Subscribers to import arbitrary JCH Optimize WordPress plugin before 6.0.1 settings and store a script that executes in the browser of any visitor or administrator viewing the site.
🎖@cveNotify
The JCH Optimize WordPress plugin before 6.0.1 does not perform a capability check on one of its authenticated AJAX actions and lets the request choose which internal action runs, allowing any authenticated users such as Subscribers to import arbitrary JCH Optimize WordPress plugin before 6.0.1 settings and store a script that executes in the browser of any visitor or administrator viewing the site.
🎖@cveNotify
WPScan
JCH Optimize < 6.0.1 - Subscriber+ Stored XSS via getcacheinfo Task Override
See details on JCH Optimize < 6.0.1 - Subscriber+ Stored XSS via getcacheinfo Task Override CVE 2026-84934. View the latest Plugin Vulnerabilities on WPScan.
🚨 CVE-2026-84935
The HT Menu WordPress plugin before 1.2.7 does not perform any capability or object-ownership check when saving navigation menu-item settings, and does not escape those stored settings when the menu is rendered, allowing users with minimal permissions such as Subscribers to store JavaScript that executes in the browser of any visitor, administrators included, who views the affected menu.
🎖@cveNotify
The HT Menu WordPress plugin before 1.2.7 does not perform any capability or object-ownership check when saving navigation menu-item settings, and does not escape those stored settings when the menu is rendered, allowing users with minimal permissions such as Subscribers to store JavaScript that executes in the browser of any visitor, administrators included, who views the affected menu.
🎖@cveNotify
WPScan
HT Menu < 1.2.7 - Subscriber+ Stored XSS via Menu Settings
See details on HT Menu < 1.2.7 - Subscriber+ Stored XSS via Menu Settings CVE 2026-84935. View the latest Plugin Vulnerabilities on WPScan.
🚨 CVE-2026-84936
The EmbedPress WordPress plugin before 4.6.4 does not have proper authorization on a public review-loading action, allowing unauthenticated users to force the site to make repeated billable third-party API requests using the site's own configured API key, and to create an unbounded number of attacker-controlled rows in the database.
🎖@cveNotify
The EmbedPress WordPress plugin before 4.6.4 does not have proper authorization on a public review-loading action, allowing unauthenticated users to force the site to make repeated billable third-party API requests using the site's own configured API key, and to create an unbounded number of attacker-controlled rows in the database.
🎖@cveNotify
WPScan
EmbedPress 4.6.0 - 4.6.3 - Unauthenticated Google Reviews API Quota Consumption and Database Bloat
See details on EmbedPress 4.6.0 - 4.6.3 - Unauthenticated Google Reviews API Quota Consumption and Database Bloat CVE 2026-84936. View the latest Plugin Vulnerabilities on WPScan.
🚨 CVE-2026-84937
The Video Player for YouTube WordPress plugin before 2.1.0 does not properly sanitise and escape user-supplied input before using it in a SQL statement, allowing users with the Contributor role and above to perform SQL injection attacks and read arbitrary data from the database.
🎖@cveNotify
The Video Player for YouTube WordPress plugin before 2.1.0 does not properly sanitise and escape user-supplied input before using it in a SQL statement, allowing users with the Contributor role and above to perform SQL injection attacks and read arbitrary data from the database.
🎖@cveNotify
WPScan
YT Player < 2.1.0 - Contributor+ SQLi via ytp_ajax
See details on YT Player < 2.1.0 - Contributor+ SQLi via ytp_ajax CVE 2026-84937. View the latest Plugin Vulnerabilities on WPScan.
🚨 CVE-2026-13159
The Real Estate Papi WordPress theme through 1.0.5 does not perform capability or CSRF checks on one of its AJAX actions, allowing any authenticated user, such as a subscriber, to install a fixed set of companion from the WordPress.org repository. Where the request runs in the session of a user who can activate , those are activated as well.
🎖@cveNotify
The Real Estate Papi WordPress theme through 1.0.5 does not perform capability or CSRF checks on one of its AJAX actions, allowing any authenticated user, such as a subscriber, to install a fixed set of companion from the WordPress.org repository. Where the request runs in the session of a user who can activate , those are activated as well.
🎖@cveNotify
WPScan
Real Estate Papi <= 1.0.5 - Subscriber+ Plugin Installation
See details on Real Estate Papi <= 1.0.5 - Subscriber+ Plugin Installation CVE 2026-13159. View the latest Theme Vulnerabilities on WPScan.
🚨 CVE-2026-18480
The SureCart WordPress plugin before 4.6.3 does not ensure that the account affected by a customer update is the same account its permission check authorised, allowing users with a subscriber-level account to change another user's email address, including an administrator's, and take over that account via a password reset. It further allows an attacker-controlled customer record to be associated with an arbitrary user, and discloses customer identifiers and email addresses to any authenticated user, which together make the takeover reachable from a subscriber-level account alone.
🎖@cveNotify
The SureCart WordPress plugin before 4.6.3 does not ensure that the account affected by a customer update is the same account its permission check authorised, allowing users with a subscriber-level account to change another user's email address, including an administrator's, and take over that account via a password reset. It further allows an attacker-controlled customer record to be associated with an arbitrary user, and discloses customer identifiers and email addresses to any authenticated user, which together make the takeover reachable from a subscriber-level account alone.
🎖@cveNotify
WPScan
SureCart < 4.6.3 - Subscriber+ Administrator Account Takeover
See details on SureCart < 4.6.3 - Subscriber+ Administrator Account Takeover CVE 2026-18480. View the latest Plugin Vulnerabilities on WPScan.
🚨 CVE-2026-75793
The SureCart WordPress plugin before 4.7.0 does not consult the site's user registration setting before creating WordPress accounts, allowing unauthenticated users to create an account and receive a logged-in session even when registration is disabled.
🎖@cveNotify
The SureCart WordPress plugin before 4.7.0 does not consult the site's user registration setting before creating WordPress accounts, allowing unauthenticated users to create an account and receive a logged-in session even when registration is disabled.
🎖@cveNotify
WPScan
SureCart < 4.7.0 - Unauthenticated Account Creation with Automatic Login
See details on SureCart < 4.7.0 - Unauthenticated Account Creation with Automatic Login CVE 2026-75793. View the latest Plugin Vulnerabilities on WPScan.
🚨 CVE-2026-84028
The Bold Page Builder WordPress plugin before 5.9.9 does not sanitise and escape a shortcode attribute before outputting it in an HTML attribute, allowing users with the Contributor role and above to inject arbitrary web scripts that execute when a user views the affected page.
🎖@cveNotify
The Bold Page Builder WordPress plugin before 5.9.9 does not sanitise and escape a shortcode attribute before outputting it in an HTML attribute, allowing users with the Contributor role and above to inject arbitrary web scripts that execute when a user views the affected page.
🎖@cveNotify
WPScan
Bold Page Builder < 5.9.9 - Contributor+ Stored XSS via Slider Elements' additional_settings
See details on Bold Page Builder < 5.9.9 - Contributor+ Stored XSS via Slider Elements' additional_settings CVE 2026-84028. View the latest Plugin Vulnerabilities on WPScan.
🚨 CVE-2026-84219
The Kirki WordPress plugin before 6.3.0 does not hold back every spelling of the HTML entities it decodes when rendering, allowing unauthenticated users to store JavaScript in a comment which then runs in the session of anyone viewing a page that displays it, including an administrator, and on every page of the site when its header or footer is built to show comments.
🎖@cveNotify
The Kirki WordPress plugin before 6.3.0 does not hold back every spelling of the HTML entities it decodes when rendering, allowing unauthenticated users to store JavaScript in a comment which then runs in the session of anyone viewing a page that displays it, including an administrator, and on every page of the site when its header or footer is built to show comments.
🎖@cveNotify
WPScan
Kirki 6.2.1 - 6.2.5 - Unauthenticated Stored XSS via HTML Entity Decoding
See details on Kirki 6.2.1 - 6.2.5 - Unauthenticated Stored XSS via HTML Entity Decoding CVE 2026-84219. View the latest Plugin Vulnerabilities on WPScan.
🚨 CVE-2026-85038
The B2BKing — Ultimate WooCommerce B2B and Wholesale Plugin — Wholesale Prices, Bulk Order Form & More WordPress plugin before 5.2.40 does not verify that a role selected during registration is one actually offered on the registration form, allowing unauthenticated users to assign themselves to restricted B2B customer groups and to skip the manual account-approval workflow during self-registration.
🎖@cveNotify
The B2BKing — Ultimate WooCommerce B2B and Wholesale Plugin — Wholesale Prices, Bulk Order Form & More WordPress plugin before 5.2.40 does not verify that a role selected during registration is one actually offered on the registration form, allowing unauthenticated users to assign themselves to restricted B2B customer groups and to skip the manual account-approval workflow during self-registration.
🎖@cveNotify
WPScan
B2BKing < 5.2.40 - Unauthenticated B2B Group Assignment and Approval Bypass via Registration Role Selection
See details on B2BKing < 5.2.40 - Unauthenticated B2B Group Assignment and Approval Bypass via Registration Role Selection CVE 2026-85038. View the latest Plugin Vulnerabilities on WPScan.
🚨 CVE-2026-19859
The JetFormBuilder WordPress plugin before 3.6.5.2 does not sanitize a request parameter before rendering it as message content, allowing unauthenticated users to execute arbitrary shortcodes registered on the site on any page displaying a form. Escaping is applied to that content before a later shortcode-expansion pass rather than after it, so the escaping can be bypassed.
🎖@cveNotify
The JetFormBuilder WordPress plugin before 3.6.5.2 does not sanitize a request parameter before rendering it as message content, allowing unauthenticated users to execute arbitrary shortcodes registered on the site on any page displaying a form. Escaping is applied to that content before a later shortcode-expansion pass rather than after it, so the escaping can be bypassed.
🎖@cveNotify
WPScan
JetFormBuilder < 3.6.5.2 - Unauthenticated Arbitrary Shortcode Execution via 'status' Parameter
See details on JetFormBuilder < 3.6.5.2 - Unauthenticated Arbitrary Shortcode Execution via 'status' Parameter CVE 2026-19859. View the latest Plugin Vulnerabilities on WPScan.
🚨 CVE-2026-80437
The Ninja Forms WordPress plugin from 3.14.10 before 3.15.2 does not prevent shortcodes in request-derived values from being executed when it substitutes them into content it later processes for shortcodes, allowing unauthenticated users to run any shortcode registered on the site.
🎖@cveNotify
The Ninja Forms WordPress plugin from 3.14.10 before 3.15.2 does not prevent shortcodes in request-derived values from being executed when it substitutes them into content it later processes for shortcodes, allowing unauthenticated users to run any shortcode registered on the site.
🎖@cveNotify
WPScan
Ninja Forms 3.14.10 - 3.15.1 - Unauthenticated Arbitrary Shortcode Execution via IP and Referer Merge Tags
See details on Ninja Forms 3.14.10 - 3.15.1 - Unauthenticated Arbitrary Shortcode Execution via IP and Referer Merge Tags CVE 2026-80437. View the latest Plugin Vulnerabilities on WPScan.
🚨 CVE-2026-80439
The Redirection for Contact Form 7 WordPress plugin from 2.2.7 before 3.2.11 does not prevent shortcodes in submitted form values from being executed when it substitutes those values into an action's settings and then processes those settings for shortcodes, allowing unauthenticated users to run any shortcode registered on the site and read its output.
🎖@cveNotify
The Redirection for Contact Form 7 WordPress plugin from 2.2.7 before 3.2.11 does not prevent shortcodes in submitted form values from being executed when it substitutes those values into an action's settings and then processes those settings for shortcodes, allowing unauthenticated users to run any shortcode registered on the site and read its output.
🎖@cveNotify
WPScan
Redirection for Contact Form 7 2.2.7 - 3.2.10 - Unauthenticated Arbitrary Shortcode Execution via Action Setting Mail-Tags
See details on Redirection for Contact Form 7 2.2.7 - 3.2.10 - Unauthenticated Arbitrary Shortcode Execution via Action Setting Mail-Tags CVE 2026-80439. View the latest Plugin Vulnerabilities on WPScan.