π¨ CVE-2026-77005
The CODE MONKEYS PROPOSALS WordPress plugin through 1.0.1 does not validate a user-supplied file path before deleting a file, and does not check the capability of the user making the request, allowing any authenticated user, such as a subscriber, to delete arbitrary files on the server, which can lead to a site takeover.
π@cveNotify
The CODE MONKEYS PROPOSALS WordPress plugin through 1.0.1 does not validate a user-supplied file path before deleting a file, and does not check the capability of the user making the request, allowing any authenticated user, such as a subscriber, to delete arbitrary files on the server, which can lead to a site takeover.
π@cveNotify
WPScan
Code Monkeys Proposals <= 1.0.1 - Subscriber+ Arbitrary File Deletion via Path Traversal
See details on Code Monkeys Proposals <= 1.0.1 - Subscriber+ Arbitrary File Deletion via Path Traversal CVE 2026-77005. View the latest Plugin Vulnerabilities on WPScan.
π¨ CVE-2026-77006
The WebTotem Backups WordPress plugin through 1.0.1 does not validate a user-supplied file path, does not check the capability of the user making the request, and discards the result of its own CSRF check, allowing any authenticated user, such as a subscriber, to delete arbitrary files on the server, which can lead to a site takeover.
π@cveNotify
The WebTotem Backups WordPress plugin through 1.0.1 does not validate a user-supplied file path, does not check the capability of the user making the request, and discards the result of its own CSRF check, allowing any authenticated user, such as a subscriber, to delete arbitrary files on the server, which can lead to a site takeover.
π@cveNotify
WPScan
WebTotem Backups <= 1.0.1 - Subscriber+ Arbitrary File Deletion via Path Traversal
See details on WebTotem Backups <= 1.0.1 - Subscriber+ Arbitrary File Deletion via Path Traversal CVE 2026-77006. View the latest Plugin Vulnerabilities on WPScan.
π¨ CVE-2026-77689
The Booking for Appointments and Events Calendar WordPress plugin before 9.8.1 does not verify that a payment was actually taken before recording a booking as paid, trusting the payment gateway named in a public, unauthenticated booking request even when the site has never configured that gateway. This lets an unauthenticated attacker obtain confirmed, fully paid appointments and events without any payment being collected.
π@cveNotify
The Booking for Appointments and Events Calendar WordPress plugin before 9.8.1 does not verify that a payment was actually taken before recording a booking as paid, trusting the payment gateway named in a public, unauthenticated booking request even when the site has never configured that gateway. This lets an unauthenticated attacker obtain confirmed, fully paid appointments and events without any payment being collected.
π@cveNotify
WPScan
Amelia Pro 9.0 - 9.8 - Unauthenticated Payment Bypass
See details on Amelia Pro 9.0 - 9.8 - Unauthenticated Payment Bypass CVE 2026-77689. View the latest Plugin Vulnerabilities on WPScan.
π¨ CVE-2026-77705
The Booking for Appointments and Events Calendar WordPress plugin before 2.4.10 does not verify that the user editing a customer or employee record is entitled to modify the WordPress account linked to it, allowing users holding Amelia's customer or employee management permissions to set the password and email address of other users' WordPress accounts and take them over.
π@cveNotify
The Booking for Appointments and Events Calendar WordPress plugin before 2.4.10 does not verify that the user editing a customer or employee record is entitled to modify the WordPress account linked to it, allowing users holding Amelia's customer or employee management permissions to set the password and email address of other users' WordPress accounts and take them over.
π@cveNotify
WPScan
Amelia < 2.4.10 - Amelia Manager+ WordPress Account Takeover
See details on Amelia < 2.4.10 - Amelia Manager+ WordPress Account Takeover CVE 2026-77705. View the latest Plugin Vulnerabilities on WPScan.
π¨ CVE-2026-77752
The Temporary Login Without Password WordPress plugin before 1.9.9 does not verify that the user requesting a temporary login holds network super admin rights before granting the new account those rights, allowing an administrator of a single site on a multisite network to take over the whole network. The same missing check also allows an existing account, including the attacker's own, to be promoted.
π@cveNotify
The Temporary Login Without Password WordPress plugin before 1.9.9 does not verify that the user requesting a temporary login holds network super admin rights before granting the new account those rights, allowing an administrator of a single site on a multisite network to take over the whole network. The same missing check also allows an existing account, including the attacker's own, to be promoted.
π@cveNotify
WPScan
Temporary Login Without Password 1.5 - 1.9.8 - Multisite Subsite Admin+ Network Super Admin Privilege Escalation
See details on Temporary Login Without Password 1.5 - 1.9.8 - Multisite Subsite Admin+ Network Super Admin Privilege Escalation CVE 2026-77752. View the latest Plugin Vulnerabilities on WPScan.
π¨ CVE-2026-77753
The Temporary Login Without Password WordPress plugin before 1.9.9 does not prevent a temporary user from creating an Application Password, and does not revoke one when the temporary access expires or is disabled, allowing the recipient of a temporary login to retain working access to the site over REST and XML-RPC after the administrator believes it has been withdrawn. The retained access carries whatever role was granted, which for the Temporary Login Without Password WordPress plugin before 1.9.9's main use case is Administrator.
π@cveNotify
The Temporary Login Without Password WordPress plugin before 1.9.9 does not prevent a temporary user from creating an Application Password, and does not revoke one when the temporary access expires or is disabled, allowing the recipient of a temporary login to retain working access to the site over REST and XML-RPC after the administrator believes it has been withdrawn. The retained access carries whatever role was granted, which for the Temporary Login Without Password WordPress plugin before 1.9.9's main use case is Administrator.
π@cveNotify
WPScan
Temporary Login Without Password < 1.9.9 - Authenticated Temporary Access Revocation Bypass via Application Passwords
See details on Temporary Login Without Password < 1.9.9 - Authenticated Temporary Access Revocation Bypass via Application Passwords CVE 2026-77753. View the latest Plugin Vulnerabilities on WPScan.
π¨ CVE-2026-78152
The SureRank SEO WordPress plugin before 1.10.1 does not exclude users' registered account email addresses from the structured data it outputs on public pages by default, allowing unauthenticated visitors to obtain the email address of any user who has published content.
π@cveNotify
The SureRank SEO WordPress plugin before 1.10.1 does not exclude users' registered account email addresses from the structured data it outputs on public pages by default, allowing unauthenticated visitors to obtain the email address of any user who has published content.
π@cveNotify
WPScan
SureRank 1.6.2 - 1.10.0 - Unauthenticated Author Email Disclosure via Person Schema
See details on SureRank 1.6.2 - 1.10.0 - Unauthenticated Author Email Disclosure via Person Schema CVE 2026-78152. View the latest Plugin Vulnerabilities on WPScan.
π¨ CVE-2026-80491
The SAMO Forms WordPress plugin through 1.0.0 does not properly sanitise and escape user input before using it in SQL queries in several unauthenticated actions, allowing unauthenticated attackers to perform SQL injection attacks.
π@cveNotify
The SAMO Forms WordPress plugin through 1.0.0 does not properly sanitise and escape user input before using it in SQL queries in several unauthenticated actions, allowing unauthenticated attackers to perform SQL injection attacks.
π@cveNotify
WPScan
SAMO Forms <= 1.0.0 - Unauthenticated SQLi
See details on SAMO Forms <= 1.0.0 - Unauthenticated SQLi CVE 2026-80491. View the latest Plugin Vulnerabilities on WPScan.
π¨ CVE-2026-80494
The Yogeta WP Cloud WordPress plugin through 1.0 does not validate a user-supplied file path before passing it to a file-read function on a public endpoint that lacks any authorization check, allowing unauthenticated attackers to download arbitrary files from the server, including files containing sensitive credentials.
π@cveNotify
The Yogeta WP Cloud WordPress plugin through 1.0 does not validate a user-supplied file path before passing it to a file-read function on a public endpoint that lacks any authorization check, allowing unauthenticated attackers to download arbitrary files from the server, including files containing sensitive credentials.
π@cveNotify
WPScan
Yogeta WP Cloud <= 1.0 - Unauthenticated Arbitrary File Download
See details on Yogeta WP Cloud <= 1.0 - Unauthenticated Arbitrary File Download CVE 2026-80494. View the latest Plugin Vulnerabilities on WPScan.
π¨ CVE-2026-81090
The Gpx2Graphics WordPress plugin through 0.3 does not perform a CSRF check when handling file uploads, nor validate the type of the uploaded file, allowing attackers to make a logged-in administrator upload arbitrary files such as PHP via a CSRF attack, leading to Remote Code Execution.
π@cveNotify
The Gpx2Graphics WordPress plugin through 0.3 does not perform a CSRF check when handling file uploads, nor validate the type of the uploaded file, allowing attackers to make a logged-in administrator upload arbitrary files such as PHP via a CSRF attack, leading to Remote Code Execution.
π@cveNotify
WPScan
Gpx2Graphics <= 0.3 - Arbitrary File Upload via CSRF
See details on Gpx2Graphics <= 0.3 - Arbitrary File Upload via CSRF CVE 2026-81090. View the latest Plugin Vulnerabilities on WPScan.
π¨ CVE-2026-81402
The DS Ad Rotator WordPress plugin through 0.8 does not perform any capability check, nonce verification, or file-type validation on its image upload handler, allowing unauthenticated attackers to upload arbitrary files, including PHP, to a web-accessible directory, which can lead to remote code execution.
π@cveNotify
The DS Ad Rotator WordPress plugin through 0.8 does not perform any capability check, nonce verification, or file-type validation on its image upload handler, allowing unauthenticated attackers to upload arbitrary files, including PHP, to a web-accessible directory, which can lead to remote code execution.
π@cveNotify
WPScan
DS Ad Rotator <= 0.8 - Unauthenticated Arbitrary File Upload
See details on DS Ad Rotator <= 0.8 - Unauthenticated Arbitrary File Upload CVE 2026-81402. View the latest Plugin Vulnerabilities on WPScan.
π¨ CVE-2026-81429
The Export & Import WPBakery Page Builder WordPress plugin through 1.0.2 does not perform any CSRF check on its template-import feature and does not sanitise the imported data before storing it and echoing it back, allowing attackers to make a logged-in administrator import a crafted template via a forged request that results in Stored Cross-Site Scripting executed in the administrator's session.
π@cveNotify
The Export & Import WPBakery Page Builder WordPress plugin through 1.0.2 does not perform any CSRF check on its template-import feature and does not sanitise the imported data before storing it and echoing it back, allowing attackers to make a logged-in administrator import a crafted template via a forged request that results in Stored Cross-Site Scripting executed in the administrator's session.
π@cveNotify
WPScan
Export & Import WPBakery Page Builder <= 1.0.2 - Stored XSS via CSRF
See details on Export & Import WPBakery Page Builder <= 1.0.2 - Stored XSS via CSRF CVE 2026-81429. View the latest Plugin Vulnerabilities on WPScan.
π¨ CVE-2026-81742
The BE REST Endpoints WordPress plugin through 1.0.0 does not perform any authorization check before allowing widgets to be read, created, updated and deleted, and does not sanitize the values it stores in them, allowing unauthenticated users to inject arbitrary web scripts which will execute in the browser of any user visiting the site.
π@cveNotify
The BE REST Endpoints WordPress plugin through 1.0.0 does not perform any authorization check before allowing widgets to be read, created, updated and deleted, and does not sanitize the values it stores in them, allowing unauthenticated users to inject arbitrary web scripts which will execute in the browser of any user visiting the site.
π@cveNotify
WPScan
BE REST Endpoints <= 1.0.0 - Unauthenticated Stored XSS and Widget Manipulation
See details on BE REST Endpoints <= 1.0.0 - Unauthenticated Stored XSS and Widget Manipulation CVE 2026-81742. View the latest Plugin Vulnerabilities on WPScan.
π¨ CVE-2026-82845
The Masteriyo LMS WordPress plugin before 3.4.1 does not prevent user-supplied values held as metadata from being deserialized when they are read back, allowing users with a minimal account to inject arbitrary PHP objects and, by way of a class shipped in a library bundled with the Masteriyo LMS WordPress plugin before 3.4.1, write and execute arbitrary code on the server. A weaker form of the same issue is reachable without an account and yields an arbitrary file write rather than code execution.
π@cveNotify
The Masteriyo LMS WordPress plugin before 3.4.1 does not prevent user-supplied values held as metadata from being deserialized when they are read back, allowing users with a minimal account to inject arbitrary PHP objects and, by way of a class shipped in a library bundled with the Masteriyo LMS WordPress plugin before 3.4.1, write and execute arbitrary code on the server. A weaker form of the same issue is reachable without an account and yields an arbitrary file write rather than code execution.
π@cveNotify
WPScan
Masteriyo LMS < 3.4.1 - Subscriber+ PHP Object Injection
See details on Masteriyo LMS < 3.4.1 - Subscriber+ PHP Object Injection CVE 2026-82845. View the latest Plugin Vulnerabilities on WPScan.
π¨ CVE-2026-82847
The Masteriyo LMS WordPress plugin before 3.4.1 does not sanitise and escape one of its course fields before outputting it back in the course editor, allowing users with the instructor role to perform Stored Cross-Site Scripting attacks against higher privileged users such as administrators.
π@cveNotify
The Masteriyo LMS WordPress plugin before 3.4.1 does not sanitise and escape one of its course fields before outputting it back in the course editor, allowing users with the instructor role to perform Stored Cross-Site Scripting attacks against higher privileged users such as administrators.
π@cveNotify
WPScan
Masteriyo LMS < 3.4.1 - Instructor+ Stored XSS via Course Highlights
See details on Masteriyo LMS < 3.4.1 - Instructor+ Stored XSS via Course Highlights CVE 2026-82847. View the latest Plugin Vulnerabilities on WPScan.
π¨ CVE-2026-83532
The Custom Menu Wizard Widget WordPress plugin through 3.3.1 does not sanitize and escape several shortcode attributes before rendering them into HTML, allowing users with contributor-level access and above to inject arbitrary web scripts that execute when the affected content is viewed.
π@cveNotify
The Custom Menu Wizard Widget WordPress plugin through 3.3.1 does not sanitize and escape several shortcode attributes before rendering them into HTML, allowing users with contributor-level access and above to inject arbitrary web scripts that execute when the affected content is viewed.
π@cveNotify
WPScan
Custom Menu Wizard <= 3.3.1 - Contributor+ Stored XSS via Shortcode Attributes
See details on Custom Menu Wizard <= 3.3.1 - Contributor+ Stored XSS via Shortcode Attributes CVE 2026-83532. View the latest Plugin Vulnerabilities on WPScan.
π¨ CVE-2026-84023
The BEAR WordPress plugin before 1.2.2 does not verify a CSRF nonce or check user capabilities before updating taxonomy terms, allowing an attacker to modify arbitrary terms by tricking a logged-in privileged user into visiting a crafted page.
π@cveNotify
The BEAR WordPress plugin before 1.2.2 does not verify a CSRF nonce or check user capabilities before updating taxonomy terms, allowing an attacker to modify arbitrary terms by tricking a logged-in privileged user into visiting a crafted page.
π@cveNotify
WPScan
BEAR - Bulk Editor and Products Manager Professional for WooCommerce < 1.2.2 - Taxonomy Term Modification via CSRF
See details on BEAR - Bulk Editor and Products Manager Professional for WooCommerce < 1.2.2 - Taxonomy Term Modification via CSRF CVE 2026-84023. View the latest Plugin Vulnerabilities on WPScan.
π¨ CVE-2026-84024
The BEAR WordPress plugin before 1.2.2 does not verify a CSRF nonce before saving its meta field configuration, allowing an attacker to overwrite that configuration by tricking a logged-in administrator into visiting a crafted page.
π@cveNotify
The BEAR WordPress plugin before 1.2.2 does not verify a CSRF nonce before saving its meta field configuration, allowing an attacker to overwrite that configuration by tricking a logged-in administrator into visiting a crafted page.
π@cveNotify
WPScan
BEAR - Bulk Editor and Products Manager Professional for WooCommerce < 1.2.2 - Meta Field Configuration Update via CSRF
See details on BEAR - Bulk Editor and Products Manager Professional for WooCommerce < 1.2.2 - Meta Field Configuration Update via CSRF CVE 2026-84024. View the latest Plugin Vulnerabilities on WPScan.
π¨ CVE-2026-84025
The BEAR WordPress plugin before 1.2.2 does not perform ownership checks on several handlers that return product data by a user-supplied identifier, allowing users who are restricted to their own products to read other owners' product information, including protected downloadable file URLs and private product metadata.
π@cveNotify
The BEAR WordPress plugin before 1.2.2 does not perform ownership checks on several handlers that return product data by a user-supplied identifier, allowing users who are restricted to their own products to read other owners' product information, including protected downloadable file URLs and private product metadata.
π@cveNotify
WPScan
BEAR - Bulk Editor and Products Manager Professional for WooCommerce < 1.2.2 - Authenticated Product Download URL and Meta Disclosureβ¦
See details on BEAR - Bulk Editor and Products Manager Professional for WooCommerce < 1.2.2 - Authenticated Product Download URL and Meta Disclosure via IDOR CVE 2026-84025. View the latest Plugin Vulnerabilities on WPScan.
π¨ CVE-2026-84047
The Album Cover Finder WordPress plugin through 0.7.0 does not properly sanitize and escape a parameter before using it in a SQL query, allowing unauthenticated users to perform SQL injection attacks.
π@cveNotify
The Album Cover Finder WordPress plugin through 0.7.0 does not properly sanitize and escape a parameter before using it in a SQL query, allowing unauthenticated users to perform SQL injection attacks.
π@cveNotify
WPScan
Album Cover Finder <= 0.7.0 - Unauthenticated SQLi via and_action
See details on Album Cover Finder <= 0.7.0 - Unauthenticated SQLi via and_action CVE 2026-84047. View the latest Plugin Vulnerabilities on WPScan.
π¨ CVE-2026-84099
The wpstorecart WordPress plugin through 5.0.7 does not prevent direct, unauthenticated access to a bundled add-on that deserializes user-supplied input without restricting the permitted classes, allowing unauthenticated attackers to inject arbitrary PHP objects, which may be escalated further when a suitable gadget chain is present on the site.
π@cveNotify
The wpstorecart WordPress plugin through 5.0.7 does not prevent direct, unauthenticated access to a bundled add-on that deserializes user-supplied input without restricting the permitted classes, allowing unauthenticated attackers to inject arbitrary PHP objects, which may be escalated further when a suitable gadget chain is present on the site.
π@cveNotify
WPScan
IDB Ecommerce (wpStoreCart 5) <= 5.0.7 - Unauthenticated PHP Object Injection via bundled wpsc-membership-pro paypal.php
See details on IDB Ecommerce (wpStoreCart 5) <= 5.0.7 - Unauthenticated PHP Object Injection via bundled wpsc-membership-pro paypal.php CVE 2026-84099. View the latest Plugin Vulnerabilities on WPScan.